Skip to main content

Offensive Resources

Offensive Platforms
#

Top
#

Altered Security Online Labs

  • Have CRTP, CRTE, CRTM, CARTP, etc.
  • Hands-on Active Directory labs

Vulnlab

  • Created by xct
  • Realistic hacking challenges (now integrating into HTB)

Vulnmachines

Pentester Academy

  • Owned by INE
  • Extensive pentesting courses

Cyberwarfare Labs

  • Have multiple certification paths, including offensive cloud certifications

Proving Grounds Play and Practice

Other
#

CyberSecLabs

  • Dead link, similar to HTB

Virtual Hacking Labs

  • Pentesting labs, certificates, has IoT course

Root Me

Web Application Resources
#

Top
#

Web Security Academy - PortSwigger

  • Free web security lessons / training

PentesterLab

  • Web app security exercises

APIsec University

  • API security learning platform

HackerOne

  • Bug bounty platform and training

OWASP Foundation

Create Your Own
#

Juice Shop

  • Intentionally vulnerable app

DVWA - Damn Vulnerable Web Application

  • Test web exploit skills

Other
#

Hack This Site!

  • Web challenges

XSS game

  • XSS challenges

Rana Khalil’s Academy

  • Web hacking courses

CTF Challenge - Web App Security Challenges

  • CTF-style web puzzles

alert(1) to win

  • Tiny XSS challenges

Gin & Juice Shop

  • Publicly hosted Juice Shop variant

Online tools
#

Exploit Database

  • Public exploit search

Shodan

  • Find vulnerable devices

DeHashed

  • Search leaked accounts

Public Buckets by GrayhatWarfare

  • Open storage bucket finder

BreachDirectory

  • Check leaked credentials

breachbase

  • Breached database search

Cloud
#

cloudbreach.io

  • Cloud pentesting courses and certs (Azure and AWS)

HackTricks Cloud

  • Cloud hacking cheatsheet
  • Home of ARTE, GRTE, and AzRTE training and certifications

flAWS

  • AWS flaws walkthrough

flAWS2.cloud

  • More AWS flaw challenges

Hacking The Cloud

  • Another Hacktricks for cloud

PWNED LABS

  • Cloud security training

Mobile
#

Mobile Hacking Lab

  • Moblie courses and certifications

Resource Pages
#

The C2 Matrix

  • Compare C2 frameworks

IppSec - Search

  • HTB video walkthroughs

Payloads All The Things

  • Attack payload collection

Red Team Notes

  • Red team tactics guide

The Hacker Recipes

  • HackTricks clone

Dark Wolf Drone Playbook

  • Drone hacking guide

HideAndSec

  • Good AD cheatsheets

offsec.tools

  • List of offensive security tools and scripts

Dark Wolf Android Security Research Playbook

  • Android hacking playbook

Training
#

Zero-Point Security

  • Red team training (CRTO and CRTL)

Red Team Alliance

  • Physical pentesting training and certifications

DroneSec Training

  • Drone hacking courses

Black Hat Ethical Hacking

  • Pentesting courses

RedTeam Security Training

K > FiveFour

  • Trainings for RTAC and RTAJ

TheSecOps Group

  • Multiple pentesting courses and training

Red Team Sorcery

  • Red team online courses (Maldev and red teaming focused)

MalDev Academy

  • Malware development training (and phishing)

BREAKDEV Academy

  • Evilginx training course

Advanced Security Training

  • Mobile, Hardware, IoT (and many more) pentesting courses

Red Teamers Academy

  • Physical pentesting training in the EU

RET2 WarGames

  • Binary exploitation course

Rickcen

SEKTOR7 Institute

  • Malware development training

Red Team Field Manual (RTFM) Video Library

  • Video library for the RTFMv2 book. Has challenge coin

Corelan Consulting - Exploit Development Training for Windows

  • Windows MalDev courses

HackingHub - Ethical Hacking Training

ControlThings.io

  • ICS training

binary-offensive

Extreme Red Team Laboratories

  • Red team labs

Other
#

Hack.me

  • Dead link, hosted vulnerable web apps for download

Exploit Education :: Andrew Griffiths’ Exploit Education

  • VMs for exploit development and buffer overflow attacks

NetSecFocus Trophy Room - Google Sheets

  • HTB box prep list for OSCP (TJNull)

Dark Vortex

The Penetration Testing Execution Standard

  • Standardized pentesting guide (PTES)

SEED Project

  • Security lab exercises

Penetration Test reports

  • Public pentest reports

Dreadnode

Expliot: IoT Security Testing

  • IoT security tool

REDTEAM.GUIDE

  • Book

Lists
#

GTFOBins

  • Unix binary exploits

LOLBAS

  • Living Off The Land Binaries, Scripts and Libraries

LOOBINS

  • Living Off the Orchard

LOLAPPS

  • Living Off the Land apps

WADComs

  • List of offensive tools for Windows/AD

LOTP - Living Off the Pipeline

  • CI/CD RCE methods

HijackLibs

  • DLL Hijacking list

LOLDrivers

  • Living Off The Land Drivers

Living Off the Living Off the Land | LOLOL

  • List of lists (GTFOBins, LOLBAS, etc.)

Online Resources
#

Online - Reverse Shell Generator

  • Command-line shell generator

Cradle Wizard

  • Download cradle stuff