Resources

Curated links for red team, blue team, recon, malware analysis, forums, and ham radio frequency/repeater tools. Use responsibly and only on systems you own or have explicit authorization to test.

Shodan

Internet-wide device & service search engine. Essential for external attack-surface discovery.

RED · RECON

Censys

Internet scan data with strong certificate and structured host intelligence.

RED · RECON

Nmap

Industry-standard network discovery and security auditing tool.

RED · SCANNING

Metasploit

Penetration testing framework for exploitation and post-exploitation workflows.

RED · EXPLOIT

Burp Suite

Web application security testing platform (proxy, scanner, intruder).

RED · WEB

BloodHound

Active Directory attack-path mapping using graph theory.

RED · AD

Atomic Red Team

Small, portable tests mapped to MITRE ATT&CK for validating detections.

RED · EMULATION

MITRE Caldera

Automated adversary emulation platform built on ATT&CK.

RED · EMULATION

Hack The Box

Hands-on penetration testing labs and challenges.

RED · TRAINING

TryHackMe

Guided rooms for offensive and defensive skill development.

RED · TRAINING

MITRE ATT&CK

Knowledge base of adversary tactics and techniques. Core reference for detection engineering.

BLUE · FRAMEWORK

Sigma

Generic signature format for SIEM detections. Convert to Splunk, Elastic, etc.

BLUE · DETECTION

Elastic Security

Open-source SIEM + detection engineering platform (ELK stack roots).

BLUE · SIEM

Splunk

Enterprise log aggregation, search, and security analytics.

BLUE · SIEM

Awesome Blue Team

Curated collection of blue-team tools, resources, and playbooks.

BLUE · LIST

BlueTeam-Tools

Tools and techniques focused on incident response and defensive operations.

BLUE · IR

SANS White Papers

Authoritative research and practical guidance on defensive security.

BLUE · RESEARCH

OSINT Framework

Tree of free OSINT tools organized by data type.

OSINT

Exploit-DB

Archive of public exploits and proof-of-concept code.

OSINT · EXPLOIT

urlscan.io

Scan and analyze websites and URLs for malicious indicators.

OSINT · URL

AbuseIPDB

Community-driven IP reputation and abuse reporting.

OSINT · REPUTATION

WHOIS / Domain Tools

Domain registration and ownership lookup.

OSINT · DOMAIN

VirusTotal

Multi-engine file, URL, domain, and IP scanning with rich threat intelligence.

MALWARE · TRIAGE

Hybrid Analysis

Free community malware sandbox with behavioral reports (Falcon Sandbox).

MALWARE · SANDBOX

ANY.RUN

Interactive malware analysis sandbox with real-time visibility.

MALWARE · SANDBOX

MalwareBazaar

Sample sharing platform for malware researchers (abuse.ch).

MALWARE · SAMPLES

Joe Sandbox

Deep automated malware analysis across multiple platforms.

MALWARE · SANDBOX

r/netsec

Technical network security discussion and paper sharing.

FORUM

r/blueteamsec

Blue-team focused community and tool discussion.

FORUM

r/AskNetsec

Career and practical questions from the infosec community.

FORUM

DEF CON

Premier hacking conference — villages, talks, and CTFs.

EVENT

Black Hat

Technical security conference with deep briefings and trainings.

EVENT

IppSec

Excellent Hack The Box walkthroughs and search interface.

LEARNING

RepeaterBook

World’s free amateur radio repeater directory. GPS search, filters, Chirp export. Apps available.

HAM · REPEATERS

IZ8WNH Interactive Map

Real-time worldwide map of amateur radio repeaters and beacons with filters and CSV export.

HAM · MAP

Dxtra Repeater Directory

US-focused repeater search with Longley-Rice coverage maps (HT / mobile / base scenarios).

HAM · COVERAGE

Routers & Repeaters

Highway-oriented repeater finder — select road + city, get nearby repeaters for travel.

HAM · TRAVEL

FreqBuddy

Searchable database of radio frequencies (amateur, shortwave, utility, numbers stations).

HAM · FREQ

CQ Toolworks

Browser tools for hams: net control, coax loss, grid squares, propagation, satellites, repeater cards.

HAM · TOOLS

ARRL

American Radio Relay League — licensing, band plans, training, and the official Repeater Directory.

HAM · ORG

QRZ

Callsign lookup, forums, and ham radio community hub.

HAM · CALLSIGN

OWASP Top 10 for LLM Applications

Canonical risks for LLM apps: prompt injection, data leakage, supply chain, over-reliance, and more.

AI · FRAMEWORK

MITRE ATLAS

Adversarial Threat Landscape for AI Systems — tactics and techniques against ML/AI.

AI · ATT&CK-STYLE

garak

LLM vulnerability scanner from NVIDIA — probe models for jailbreaks, leakage, and failures.

AI · SCANNER

promptfoo

Open-source eval and red-teaming toolkit for prompts, RAG, and agents.

AI · RED TEAM

Prompt Injection guide

Educational deep-dive into prompt injection and related LLM attack patterns.

AI · LEARNING

NIST AI RMF

NIST Artificial Intelligence Risk Management Framework for trustworthy AI systems.

AI · GOVERNANCE

LLM Guard

Security toolkit for sanitizing and detecting threats in LLM inputs and outputs.

AI · DEFENSE

Adversarial Robustness Toolbox

IBM ART library for ML evasion, poisoning, extraction, and inference attacks/defenses.

AI · ML SEC