Pentester Guide
A Comprehensive Resource for Pentesters: Tools, Methodologies, Scripts, Certifications, Learning Resources, Labs, Career Opportunities, Entertainment, and Freelancing Tips.
Contents
Important Notes
- Tools
- Active Directory
- All about Pentesting
- Bug Bounty Hunting Methodology
- HackiFy Wordlist and Tool Installer Script
- Cyber Security / Bug Bounty Hunting Roadmap
Certifications
- INE eJPT $249
- AlteredSecurity CRTP $249
- HTB CPTS With Annual Silver Plan $490
- TCM Security PNPT $499
- INE eCPPT $599
- Offensive Security - PEN-200 (OSCP) $1649
- Offensive Security - PEN-300 (OSEP) $1649
- Google Cybersecurity Professional Certificate Almost Free (Less than $20 for one month)
- Microsoft Certified: Azure Security Engineer Associate (Cloud) $146
- CompTIA Security+ $500 Exam Voucher
- CREST CRT $500
- ISC2 CISSP $750
- ISC2 CCSP $599
- SANS SEC560: Enterprise Penetration Testing (GPEN) $2,499
- SANS SEC660: GIAC Exploit Researcher and Advanced Penetration Tester $2,499
Note: Price may vary.
- VulnHub (Offsec) Free
- VulnMachines (BlackHat) Free
- Web Security Academy (PortSwigger Labs) Free
- TryHackMe Free + Paid
- pwnable.kr Free
- pwnable.tw Free
- HackTheBox Free + Paid
- https://sec-dojo.com/en Paid
- root-me Free
- PentesterAcademy (Attackdefence) Free + Paid
- Pentester Lab Free + Paid
FOSS Labs
- Vulhub
- Metasploitable3 Box
- OWASP Juice (WEB)
- DVWA (WEB)
- WebGOAT (WEB)
- Kubernetes GOAT
- Wrong Secrets (WEB)
- SQLi Lab
- HackerOne CTF
- For More Check: Awesome Vulnerable App List
- Hackerone
- Bugcrowd
- Intigriti
- YesWeHack
- RedStorm
- Zerocopter
- OpenBugBounty
- Immunify Web3
- HackenProof WEB3
- Yogosha
- Synack
- Cobalt
0Day Market
- CrowdFense
- Zerodium (0day Bounty)
Best OS for Hacking
- ParrotSec Security Edition
- Kali Linux (OFFSEC)
- BlackArch
- BackBox
Awesome Links
- The Book of Secret Knowledge
- Sirensecurity.io Windows Privilege Escalation Resources
- Awesome Link List by Sindre Sorhus
- cheatography.com cheatsheets
Hackers Manuals
- HackTricks
- HackingArticles.in
- InternalAllTheThings by swisskyrepo
- eloypgz.org Active Directory
- ExplainShell (Command Manual)
- Reverse Shell making Tool
- Hashcat Example Hashes
- GTFObins Priviledge Escalation Cheetsheet
- LOLBAS Binaries, Scripts and Libraries Exploit
- loldrivers Drivers Exploits
- WADComs Windows AD Cheetsheat
- Exploit List haxx.it
Books
- The Web Applicaiton Hacker’s Handbook
- Web Hacking Arsenal
- Brute XSS Payload Collection By Rodolfo Assis
- THERCEMAN Bug Bounty CheetSheat Book
About Me
- https://github.com/sponsors/ZishanAdThandar
- https://ZishanAdThandar.github.io/sponsor/