A curated collection of resources gathered over the years: tools, references, methodologies, and useful links spanning pentesting, privacy, hardware hacking, and more.
★
Gadget Lab — Running catalog of hacking and cybersecurity gadgets. My goal here is to compile as complete a list as possible of the hacking hardware devices.
Pentesting Tools
Cloud Pentesting
- CloudPentestCheatsheets — Beau Bullock's comprehensive cloud pentesting cheatsheet covering Azure/O365, AWS, and GCP commands. PDF download available.
- ip2provider — Identify which cloud provider is hosting a given IP address, including service and region where available.
- GraphRunner — Post-exploitation toolset for interacting with the Microsoft Graph API.
Offensive Tools
- MailSniper — Search through email in a Microsoft Exchange environment for specific terms. Useful for credential hunting and data discovery.
- BHIS Free Tool List — Black Hills Information Security's collection of free and open-source security tools. Not all are hosted in their GitHub directly.
- Trickest — Platform to visualize, operate, and scale offensive security workflows. Includes 90+ workflow templates, 300+ tools, asset discovery, vuln scanning, fuzzing, and more.
InfoSec Career Resources
- White Knight Labs — Advanced Red Team Operations Certification
- How to Hunt for Jobs like a Hacker — BHIS
GitHub — People to Follow
- dafthack — Beau Bullock, Black Hills Information Security. Cloud pentesting, offensive tooling.
Hardware Hacking
- Mobile Hacker — Blog covering mobile hacking and hardware topics including Kali NetHunter, Raspberry Pi, ESP32, smartwatches, Flipper Zero, RFID, and Bluetooth.
- HackerBoxes — Monthly subscription hardware kits focused on electronics, hacking, and DIY projects.
Android
- apkeep — Download Android APKs directly from the command line, either from the Google Play Store or a third-party mirror. Rust-based, developed by EFF. (Intro post)
Browser Extensions
- Bitwarden
- FoxyProxy
- Hoverify
- Save Page WE
- Privacy Badger — Blocks advertisers and third-party trackers from tracking your browsing. Available for Firefox, Chrome, Edge, and Opera. Developed by EFF.
Privacy & Surveillance Defense
- Surveillance Self-Defense — EFF's guide to defending yourself from surveillance through secure technology and careful practices. Covers security hygiene, best practices, and building a personal security plan.
- Cover Your Tracks — See how trackers view your browser with a quick browser fingerprint test. Developed by EFF.
- Dangerzone — Convert potentially dangerous PDFs, Office documents, or images into safe PDFs. Free, open source, uses Docker. Created by Freedom of the Press Foundation.
AI
CTF / Labs
- Prompt Airlines — A CTF where your goal is to manipulate a customer service AI chatbot into giving you a free airline ticket. A hands-on intro to prompt-injection against a realistic support bot.
- Gandalf (Lakera) — Make Gandalf reveal the secret password at each level. Gandalf upgrades its defenses after every successful guess, so each level is harder than the last. A classic prompt-injection challenge.
General LLM Hacking
- Arcanum Security — AI red-teaming and security research.
- Prompt Injection Taxonomy (v1.6.1) — An attack classification system for AI red teaming and penetration testing.
- Executive Offense — LLM Hacking Pt 1 — Jason Haddix's introduction to hacking LLMs.
- Executive Offense — LLM Hacking Pt 2 — Jason Haddix's LLM hacking series, part two.
Misc
- msportals.io — A comprehensive directory of all Microsoft portals in one place.
- Certbot — Free, open-source tool for automatically managing Let's Encrypt certificates on self-administered websites. Developed by EFF.
- OmniTools — Thousands of browser-based utilities for editing images, text, lists, and data. Self-hostable.
- Fravia's Search Lores — Classic OSINT and search methodology site, recreated after going offline. A foundational resource.

