• Stars
    star
    524
  • Rank 84,541 (Top 2 %)
  • Language
  • Created about 5 years ago
  • Updated almost 2 years ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

A shorter, less intimidating list of infosec resources helpful for anyone trying to learn.

Getting into Cybersecurity

A concentrated list of Cybersecurity resources to help anyone interested in learning more about cybersecurity. Link to GoVanguard’s full list of tools and resources is located at the bottom of the page.

Cybersecurity: What It Is and Why It Matters

Free Online Courses to Get Started

Informative Cybersecurity YouTube Channels

Help With Coding

Help With Linux

Web Application Hacking Guides

Hacking References and Cheatsheets

Hacking Books


Hands-on Training and Practice Exercises

  • OWASP security knowledge framework - OWASP security knowledge framework labs exercises complete with write-ups.
  • Hacker101 CTF - Webapp CTF style exercises.
  • XSS Exercises - Webapp Cross-site scripting (XSS) bug hunting exercises.
  • Rapid7 Metsploitable - Metasploitable is essentially a penetration testing lab in a box, available as a VMware virtual machine (VMX).
  • OWASP WebGoat - WebGoat is an insecure application that allows the testing of vulnerabilities commonly found in Java-based applications that use common and popular open source components.
  • Gruyere - Gruyere is a web application that has multiple security bugs ranging from cross-site scripting and cross-site request forgery, to information disclosure, denial of service, and remote code execution.
  • OWASP Damn Vulnerable Web Sockets (DVWS) - Vulnerable web application which works on web sockets for client-server communication.
  • OWASP NodeGoat - Includes Node.js web applications for learning the OWASP top 10.
  • OWASP SecurityShepard - Web and mobile application security training platform.
  • OWASP Juice Shop - JavaScript based intentionally insecure web application.
  • CPTE Courseware Kit - Paid Official training kit for CPTE exam.
  • OSCP-like Vulnhub VMs - Intentionally vulnerable VMs resembling OSCP.
  • Over the Wire: Natas - Web application challenges.
  • Hack the Box - Online pentesting labs with Windows VMs.
  • Hack This Site - Web application security exercises.
  • RopeyTasks - Simple deliberately vulnerable web application.
  • Railsgoat - A vulnerable version of Rails that follows the OWASP Top 10.
  • TryHackMe - Hands on cybersecurity training platform with free and paid tiers.
  • CyberStart - Hands on cybersecurity training platform with free and paid tiers. Like TryHackMe but a bit more engaging and interactive.

TryHackMe Beginner Paths (Online platform for learning cyber security, using hands-on exercises and labs)

Fun Web-Based Tools to Tinker With

Cybersecurity News Websites

Darknet Diaries Hacking Episodes to Pique Your Interest

Cybersecurity Podcasts

Detailed GoVanguard Cybersecurity Resources

More Repositories

1

legion

Legion is an open source, easy-to-use, super-extensible and semi-automated network penetration testing tool that aids in discovery, reconnaissance and exploitation of information systems.
Python
1,013
star
2

list-infosec-encyclopedia

A list of information security related awesome lists and other resources.
562
star
3

main-security-testing-tools

A curated list of network penetration testing tools.
53
star
4

pyExploitDb

An optimized Python3 library to fetch the most recent exploit-database, create searchable indexes for CVE->EDBID and EDBID -> CVE, and provide methods to perform searches.
Python
26
star
5

karmbian

GoVanguard fork of Armbian with complete Kali 2020 support
Shell
23
star
6

pyShodan

Python 3 script for interacting with Shodan API
Python
19
star
7

Log4jShell_Scanner

Python script to tamper with pages to test for Log4J Shell vulnerability.
Python
13
star
8

pentest-scripts

List of pentest related scripts edited or created by GoVanguard
Python
10
star
9

compliance-hipaa-softwaredev

A modern and easy to use guide about software development and HIPAA compliance.
8
star
10

pyHaveIBeenPwned

Python library to query HaveIBeenPwned.com with handling for CloudFlare anti-bot.
Python
8
star
11

IP-Blacklist-CSV-Generator

Short multiprocessed Python 3 script that generates CSV files containing blacklisted IP addresses, pulling from firehol/blocklist-ipsets repo
Python
6
star
12

script-win-privescalate-headstart

The lazy mans local Windows privilege escalation script.
PowerShell
6
star
13

owasp-top10-memecards

Just a fun way to help promote basic security awareness among developers.
5
star
14

SecretScanner

Shell script for performing secret scanning on a directory of files
Shell
5
star
15

AzureSnake

A suite of PowerShell scripts to automate portions of Azure Risk Assessments and Penetration Tests
PowerShell
4
star
16

SecretSearcher

Python re-implementation of the classic SecretScanner shell script
Python
3
star
17

state-breach-notifications

Full markdown table with details of each states' breach notification information
3
star
18

doc-infosec-report-samples

GoVanguard's Sample Information Security Assessment Reports
2
star
19

script-mac-lynis-headstart

Automated Lynis install and local report generation for Macs.
Shell
1
star
20

script-win-rubberducky-headstart

Empty, unused repo
1
star
21

wazuh-helm

Wazuh-helm is a helm template for deploying Wazuh
1
star
22

veracodeIntegration

Veracode integrations
Python
1
star
23

GothamSuperTemplate

A Microsoft Threat modeling template containing stencils, threat types and assessment rules for AWS and Azure
1
star
24

Log4jShell_Vulnerable_Site

Test site that is intentionally vulnerable to log4jshell
Java
1
star