CTF resources and tools
Getting started
Resources
Practice
Web
Techniques
Cross-site scripting (XSS)
Tools
Port scanning
- nmap
- rustscan
HTTP request tools
Tokens
Fuzzing
- ffuf
- Burpsuite with Hackvertor and Turbo Intruder
Websockets
Databases
Vulnerability scanning
Deserialization
Race conditions
- Turbo intruder for Burpsuite
Resources
Practice
Cryptography
Tools
Resources
- SageMath tutorial
- SageMath documentation
- SageMath documentation - Crypto
- Mathematical symbols
- Cloudflare’s Primer to ECC
- Rolling your own crypto: AES
- Various attacks on insecure cryptography
Practice
Reverse engineering
Tools
Process and network monitoring
Linux / WSL
Windows
Debuggers
Sandboxes
Mobile
Decompilers and disassemblers
Java
.NET
Binary analysis
Emulators
Strings
Tracing
File type
Tool sets and pre-packaged systems
Resources
- x86 and amd64 assembly reference card
- arm assembly reference card
- Intro to mobile pentesting
- The faker’s guide to reading (x86) assembly language
Practice
Forensics
Open source intelligence (OSINT)
Tools
Resources
Practice
Tools
Organizing information
Office documents
Network, USB, Bluetooth and other signals
Windows registry
Memory
Volatility 2
docker run -v (pwd):/workspace -w /workspace -ti --rm --user root --entrypoint ash sk4la/volatilityFilesystems
Files
Steganography
Images
Sound files
Other
Resources
- Memory forensics with Volatility on Linux and Windows
- Understand the hacker with MITRE ATT&CK
- Everything about forensics/DFIR
Practice
Binary exploitation
Tools
Information about the binary file
- checksec
- file
- rabin2
- strings
- binsider
- ldd
Disassemblers
- objdump
- all decompilers
Debuggers
Decompilers
Tracing
Exploit development
LIBC archives
Finding ROP gadgets
Tools for automated exploitation
Other useful tools
Resources
- Putting the “You” in CPU
- Nightmare
- Pwntools Documentation
- Linux Syscall reference
- CryptoCat’s Intro to binary exploitation
- how2heap
- Understanding the Memory Layout of Linux Executables
- How the Linux kernel runs a program
- Pwntools cheatsheet
Practice
Boot to root
Tools
General
Wordlists
C2 frameworks
Reconnaissance
Port scan
Fuzzing subdomains and subdirectories
Website scanner
Initial access
- impacket
- crackmapexec
- houdini
- NetExec (maintained successor to CrackMapExec)
- evil-winrm
- Responder
Password bruting & cracking
Privilege escalation
Linux victims
Windows victims
Potatoes
Lateral movement
- Everything under Reconnaissance and Initial access
Active Directory
Network tunneling
Packet sniffing
Resources
Practice
Attack and defense
If you’ve done boot-to-root boxes (HackTheBox, TryHackMe), A/D is the same idea, but team-based and live: everyone attacks everyone else’s services while defending their own.
Expect your exploits to get stolen and reused against you. The meta game is reversing other teams’ patches, stealing their exploits, and patching your own boxes before they do the same to you.
Tools
Network traffic capture
Network traffic analysis
Exploit runner
Intrusion Prevention System
Web Application Firewall
Proxy
TCP tunnel
Notes
- Discord
- CTFNote