tools
resources
Tools, references, cheat sheets, and labs — everything you need to build real skills.
tools
curated tools
Nmap
The go-to network discovery and security auditing tool. Map hosts, open ports, and running services.
Visit Site →Wireshark
Industry-standard packet analyzer. Capture and inspect network traffic in real time.
Visit Site →Burp Suite
The leading web vulnerability scanner and proxy. Essential for web application penetration testing.
Visit Site →Metasploit
The world's most used penetration testing framework. Develop, test, and execute exploits.
Visit Site →John the Ripper
Fast and flexible password cracker. Supports hundreds of hash and cipher types.
Visit Site →Kali Linux
The penetration testing distro of choice. Hundreds of pre-installed security tools out of the box.
Visit Site →templates
Security analyst Workbook
| # | Item Description | Type | Hash (SHA256) | Size / Format | Collected By | Date/Time Collected | Location Stored |
|---|---|---|---|---|---|---|---|
| Date/Time | Evidence Item # | Released By | Received By | Purpose / Action | Returned? |
|---|---|---|---|---|---|
| Type | Indicator | Confidence | TLP | Tags | First Seen | Last Seen | Status | Source |
|---|---|---|---|---|---|---|---|---|
| Finding | Severity | Confidence | Source | Notes |
|---|---|---|---|---|
| # | Vulnerability | CVE | CVSS | Severity | Affected System | Remediation | Priority |
|---|---|---|---|---|---|---|---|
| Tactic | Technique ID | Technique Name | Sub-Technique | Evidence / Observations | Detection? |
|---|---|---|---|---|---|
| Command / Syntax | What It Does | Example Use Case | Practiced? |
|---|---|---|---|
| Certification | Vendor | Status | Exam Date | Score | Expiry | CEUs / Renewal |
|---|---|---|---|---|---|---|
| # | Risk Description | Asset / System | Threat | Likelihood (1-5) | Impact (1-5) | Risk Score | Owner | Mitigation | Status |
|---|---|---|---|---|---|---|---|---|---|
| Ticket # | Severity | Description | Status | Next Action | Owner |
|---|---|---|---|---|---|
| Time | Inject Description | Team Response | Decision Made | Gap Identified? |
|---|---|---|---|---|
learning
reference docs & learning
-
OWASP Foundation The definitive resource for web application security. Top 10 vulnerabilities, testing guides, and more.Visit →
-
NIST Cybersecurity Framework The industry-standard framework for managing and reducing cybersecurity risk.Visit →
-
CVE Database (MITRE) Search and track Common Vulnerabilities and Exposures across all major software.Visit →
-
Exploit-DB Archive of public exploits and vulnerable software maintained by Offensive Security.Visit →
-
SANS Reading Room Thousands of free research papers covering every domain of information security.Visit →
hands-on
practice labs & platforms
TryHackMe
Browser-based learning with guided rooms and structured learning paths. Great starting point for beginners.
Visit Site →Hack The Box
Realistic machines and challenges for intermediate to advanced practitioners. Highly respected in the industry.
Visit Site →Blue Team Labs Online
Defensive security challenges focused on incident response, forensics, and threat hunting.
Visit Site →CyberDefenders
Free blue team CTF challenges with real-world scenarios covering SIEM, DFIR, and network analysis.
Visit Site →