Resources
Curated links for red team, blue team, recon, malware analysis, forums, and ham radio frequency/repeater tools. Use responsibly and only on systems you own or have explicit authorization to test.
Shodan
Internet-wide device & service search engine. Essential for external attack-surface discovery.
Censys
Internet scan data with strong certificate and structured host intelligence.
Nmap
Industry-standard network discovery and security auditing tool.
Metasploit
Penetration testing framework for exploitation and post-exploitation workflows.
Burp Suite
Web application security testing platform (proxy, scanner, intruder).
BloodHound
Active Directory attack-path mapping using graph theory.
Atomic Red Team
Small, portable tests mapped to MITRE ATT&CK for validating detections.
MITRE Caldera
Automated adversary emulation platform built on ATT&CK.
Hack The Box
Hands-on penetration testing labs and challenges.
TryHackMe
Guided rooms for offensive and defensive skill development.
MITRE ATT&CK
Knowledge base of adversary tactics and techniques. Core reference for detection engineering.
Sigma
Generic signature format for SIEM detections. Convert to Splunk, Elastic, etc.
Elastic Security
Open-source SIEM + detection engineering platform (ELK stack roots).
Splunk
Enterprise log aggregation, search, and security analytics.
Awesome Blue Team
Curated collection of blue-team tools, resources, and playbooks.
BlueTeam-Tools
Tools and techniques focused on incident response and defensive operations.
SANS White Papers
Authoritative research and practical guidance on defensive security.
OSINT Framework
Tree of free OSINT tools organized by data type.
Exploit-DB
Archive of public exploits and proof-of-concept code.
urlscan.io
Scan and analyze websites and URLs for malicious indicators.
AbuseIPDB
Community-driven IP reputation and abuse reporting.
WHOIS / Domain Tools
Domain registration and ownership lookup.
VirusTotal
Multi-engine file, URL, domain, and IP scanning with rich threat intelligence.
Hybrid Analysis
Free community malware sandbox with behavioral reports (Falcon Sandbox).
ANY.RUN
Interactive malware analysis sandbox with real-time visibility.
MalwareBazaar
Sample sharing platform for malware researchers (abuse.ch).
Joe Sandbox
Deep automated malware analysis across multiple platforms.
r/netsec
Technical network security discussion and paper sharing.
r/blueteamsec
Blue-team focused community and tool discussion.
r/AskNetsec
Career and practical questions from the infosec community.
DEF CON
Premier hacking conference — villages, talks, and CTFs.
Black Hat
Technical security conference with deep briefings and trainings.
IppSec
Excellent Hack The Box walkthroughs and search interface.
RepeaterBook
World’s free amateur radio repeater directory. GPS search, filters, Chirp export. Apps available.
IZ8WNH Interactive Map
Real-time worldwide map of amateur radio repeaters and beacons with filters and CSV export.
Dxtra Repeater Directory
US-focused repeater search with Longley-Rice coverage maps (HT / mobile / base scenarios).
Routers & Repeaters
Highway-oriented repeater finder — select road + city, get nearby repeaters for travel.
FreqBuddy
Searchable database of radio frequencies (amateur, shortwave, utility, numbers stations).
CQ Toolworks
Browser tools for hams: net control, coax loss, grid squares, propagation, satellites, repeater cards.
ARRL
American Radio Relay League — licensing, band plans, training, and the official Repeater Directory.
QRZ
Callsign lookup, forums, and ham radio community hub.
OWASP Top 10 for LLM Applications
Canonical risks for LLM apps: prompt injection, data leakage, supply chain, over-reliance, and more.
MITRE ATLAS
Adversarial Threat Landscape for AI Systems — tactics and techniques against ML/AI.
garak
LLM vulnerability scanner from NVIDIA — probe models for jailbreaks, leakage, and failures.
promptfoo
Open-source eval and red-teaming toolkit for prompts, RAG, and agents.
Prompt Injection guide
Educational deep-dive into prompt injection and related LLM attack patterns.
NIST AI RMF
NIST Artificial Intelligence Risk Management Framework for trustworthy AI systems.
LLM Guard
Security toolkit for sanitizing and detecting threats in LLM inputs and outputs.
Adversarial Robustness Toolbox
IBM ART library for ML evasion, poisoning, extraction, and inference attacks/defenses.