01foundations / structured learning10 links
Cybrary free coursessecurity basics, SOC, networking, entry-level paths↗
SANS Cyber Acesfree intro material: OS, networking, systems↗
OpenLearn computing/securityfree university-style intro courses↗
Cisco Intro to Cybersecuritybeginner-friendly fundamentals↗
edX cybersecurity coursesaudit many courses for free↗
Security Engineering — Ross Andersonfree online classic, systems thinking↗
Crypto 101free book for practical cryptography concepts↗
OpenSSL Cookbookfree practical TLS/OpenSSL reference↗
RFC Editorprotocol source material, not tutorial fog↗
arXiv Cryptography and Securitycurrent research firehose↗
02legal practice labs / ctf12 links
TryHackMemany free rooms, guided paths↗
picoCTFexcellent beginner CTF archive↗
OverTheWireclassic Linux/network/security wargames↗
UnderTheWirePowerShell and Windows wargames↗
Hack The Box free CTF/eventssome free machines/challenges↗
VulnHubdownloadable vulnerable VMs↗
247CTFalways-on challenge platform↗
CTFtimecalendar and team rankings↗
CyberDefendersDFIR/SOC challenge sets↗
LetsDefendSOC practice, free tier↗
Malware-Traffic-Analysis.netPCAP exercises and writeups↗
Blue Team Labs Onlinesome free defensive labs↗
03web security / appsec10 links
OWASP Top 10baseline web risk categories↗
OWASP WSTGweb security testing guide↗
OWASP Cheat Sheet Seriesdefensive implementation reference↗
OWASP API Security Top 10API-specific risk baseline↗
OWASP ASVSapp security requirements checklist↗
PortSwigger Web Security Academyfree, high-quality interactive web labs↗
MDN Web Securitybrowser/web platform security docs↗
web.dev privacy learningprivacy on the web, browser side↗
DVWAlocal deliberately vulnerable web app↗
OWASP Juice Shopmodern vulnerable web app for training↗
04osint / investigation / verification14 links
OSINT Frameworkdirectory of OSINT tools by category↗
Bellingcat Guidesinvestigative workflows and case studies↗
Verification Handbooksource and media verification↗
First Draft verification archiveolder but useful verification guidance↗
Google Advanced Searchoperators without memorizing syntax↗
Censys Searchinternet-exposed asset search↗
Shodaninternet-connected service search↗
SEC EDGAR searchcompany filings and public disclosures↗
OpenCorporatescompany registry aggregation↗
Google Images reverse searchbasic reverse image pivots↗
TinEyereverse image search↗
OpenStreetMapopen map data↗
GeoNamesgeographic names database↗
Esri World Imagery Waybackhistorical satellite imagery snapshots↗
05privacy / opsec / safer communications13 links
Privacy Guidespractical privacy recommendations↗
EFF Surveillance Self-Defensethreat modeling and safer comms↗
Security in a Boxdigital security for activists/journalists↗
EFF security planthreat-model-first approach↗
Tor Projectanonymous browsing/network research↗
Tailsamnesic live OS↗
Qubes OS docscompartmentalized desktop security↗
Signalend-to-end encrypted messaging↗
VeraCryptdisk/container encryption↗
ExifToolread/remove file metadata↗
MAT2metadata anonymization toolkit↗
FileFormat docsunderstand what file types can carry↗
Metadata2Goquick online metadata inspection↗
06dfir / detection / incident response12 links
MITRE ATT&CKadversary tactics and techniques↗
MITRE D3FENDdefensive countermeasure knowledge graph↗
Sigma rules repopublic detection rules and Sigma format docs↗
sigma-cliconvert and validate Sigma rules↗
CISA incident response playbookofficial IR process guidance↗
NIST SP 800-61computer security incident handling guide↗
SANS postersfree cheat sheets and posters, including IR topics↗
Mandiant blogthreat intel and incident writeups↗
Autopsyopen-source digital forensics platform↗
The Sleuth Kitfilesystem forensic tools↗
Volatility Foundationmemory forensics↗
Velociraptorendpoint visibility and DFIR collection↗
07malware analysis / reverse engineering10 links
REMnux docsLinux malware-analysis distro docs↗
FLARE VMWindows reverse engineering lab setup↗
ANY.RUNinteractive malware sandbox, limited free tier↗
MalwareBazaarmalware sample exchange for researchers↗
URLhausmalicious URL tracking↗
Ghidrafree NSA reverse engineering suite↗
radare2open-source reverse engineering framework↗
x64dbgWindows debugger↗
YARA docsmalware identification rules↗
VirusTotal YARA hubYARA ecosystem references↗
08cloud / containers / identity12 links
AWS Security Documentationofficial AWS security docs↗
Microsoft Security documentationAzure, Defender, Entra, identity↗
Google Cloud Security resourcesGCP security documentation↗
CSA Cloud Controls Matrixcloud security control framework↗
Kubernetes security conceptsofficial k8s security docs↗
OWASP Docker security cheat sheetcontainer hardening basics↗
kube-benchCIS benchmark checks↗
Trivycontainer/IaC vulnerability scanner↗
OAuth 2.0OAuth specs and learning references↗
OpenID ConnectOIDC basics and specs↗
WebAuthn Guidepasskeys/security keys explained↗
JWT introJSON Web Token basics and pitfalls↗
09hardware / radio / embedded learning12 links
RTL-SDR quick startbeginner SDR setup↗
GNU Radiosignal processing toolkit↗
PySDRfree SDR/DSP book↗
SigIDWikisignal identification guide↗
ESP-IDF docsofficial ESP32 framework docs↗
Arduino docsembedded basics and board docs↗
PlatformIO docsembedded build tooling↗
HackTricks hardware noteshardware attack surface overview↗
OWASP IoT projectIoT security guidance↗
IoT Security Foundation guidelinespractical IoT security docs↗
FCC ID searchdevice filings, manuals, internal photos↗
ETSI IoT securitystandards and guidance↗
10tool directories / cheat sheets12 links
awesome-securitylarge security resource list↗
awesome-osintOSINT resource directory↗
awesome-pentestpentest tools/resources↗
Book of Secret Knowledgesysadmin/security reference pile↗
GTFOBinsUnix binary privilege patterns, defense relevance↗
LOLBASWindows living-off-the-land binaries↗
WADComsoffensive/defensive command reference↗
explainshellbreak down shell commands↗
CISA advisoriesofficial advisories↗
CISA KEV Catalogknown exploited vulnerabilities↗
CERT-EU advisoriesEU institutional advisories↗
Shadowserver reportsnetwork exposure reports↗
11datasets / vuln databases / standards10 links
NVDUS vulnerability database↗
CVE ProgramCVE records and program info↗
OSVopen-source vulnerability database/API↗
GitHub Security Advisoriespackage ecosystem advisories↗
EPSSexploit prediction scoring system↗
CIS Benchmarkshardening benchmarks, free account often required↗
CIS Controlspractical security control baseline↗
NIST Cybersecurity Frameworkorganizational security framework↗
NIST SP 800 seriesofficial security publications↗
ISO 27001 overviewstandard overview, full text not free↗
12law / policy / ethics references8 links
OWASP Vulnerability Disclosure Cheat Sheethow to report responsibly↗
CISA CVD processofficial coordinated disclosure guidance↗
FIRST multiparty disclosure guidelinesdisclosure with multiple affected parties↗
security.txtstandard for reporting security issues↗
EFF security issueslegal/policy context around security research↗
Access Now Digital Security Helplinesupport for civil society under threat↗
Citizen Labspyware/censorship research↗
ARTICLE 19 digital rightsdigital rights and expression policy↗