Skip to content

Instantly share code, notes, and snippets.

@adricnet
Last active January 22, 2018 22:12
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save adricnet/809f1ada88e731c595dd38daafc07fb8 to your computer and use it in GitHub Desktop.
Save adricnet/809f1ada88e731c595dd38daafc07fb8 to your computer and use it in GitHub Desktop.

Theme: Learn to Attack

Why?

  • Purple is a lovely colour
  • Lose less at CTFs
  • Get another security certification

Why (srsly)

  • See life/work from the other side
  • Understand attacks and attacks better
    • Be able to run attacks (in lab) to study them
    • Get better at defence and analysis
  • Make sense of pentest reports, threat intel

Resources

a bunch of VMs**, some books, and some online challenges

** and a safe place to run them, ref: 2017 lab brownbags

  • VulnHubs like Mr Robot, Sokars, BadStore
  • Books like Erikson, Weidman (sp)
  • Chall/CTFs like (use WeChall and CTFTime)
    • Bandit
  • PPTL , HTB.eu , ...

MSFU Reddits / Stack Exchanges ?

VMs

  • Kali (BlackArch, etc)
  • Samurai WTF

P W K

PenTesting with Kali

Guided Studies (PDF, Videos) Lab Exercises

  • toolset for attack and exploitation
  • process and methods for attack and reporting Targets in Lab network

OffSec

Offensive-Security

  • Backtrack, Kali, Nethunter
  • Exploit DB , ??

O S C P : certified pentester

  • live hands on test and report exam

Scripting (still, more):

  • Bash, Powershell, Python, and Excel
  • Pluralsight, DataCamp, Codecademy, local Automation Engineers
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment