Pentester Guide
A comprehensive, SEO-first penetration-testing knowledge base — tools, methodologies, cheatsheets, certifications, and career resources — built as a hand-rolled Jekyll static site on GitHub Pages, with no off-the-shelf theme.
Live site: guide.zishanhack.com — this repo is the source that builds it.
The project
- Stack: Jekyll + Liquid on GitHub Pages — hand-rolled theme, no CSS framework, no build-time JS.
- Scope: 7 deep-dive modules, 7 cheatsheet suites, 10+ curated resource directories, hundreds of hand-picked tools, commands, and links.
- Engineering: custom dark-indigo design system consistent with the ZishanHack brand; SEO pipeline (per-page meta + canonical + robots.txt + single-author sitemap with zero junk URLs); fully responsive; static output for fast load.
- Skills it demonstrates: static-site architecture, Liquid/Jekyll templating, HTML/CSS accessibility & responsiveness, technical writing at scale, SEO, Git/GitHub collaboration.
Guides & Notes
Active Directory · Pentesting Methodology · Bug Bounty Methodology · Bug Bounty Collections · CTF Box Manual · Security Roadmap · Tools Index
Also check the ZishanHack Blog & WriteUps.
Contents
Important Notes
- Tools
- Active Directory
- All about Pentesting
- Bug Bounty Hunting Methodology
- HackiFy Wordlist and Tool Installer Script
- Cyber Security / Bug Bounty Hunting Roadmap
Certifications
INE eJPT $249
AlteredSecurity CRTP $249
TCM Security PNPT $499
INE eCPPT $599
Offensive Security - PEN-200 (OSCP) $1749
HTB CPTS With Annual Silver Plan $490
Offensive Security - PEN-300 (OSEP) $1649
Google Cybersecurity Professional Certificate Almost Free (Less than $20 for one month)
Microsoft Certified: Azure Security Engineer Associate (Cloud) $146
CompTIA Security+ $500 Exam Voucher
CREST CRT $500
ISC2 CISSP $750
ISC2 CCSP $599
SANS SEC560: Enterprise Penetration Testing (GPEN) $2,499
SANS SEC660: GIAC Exploit Researcher and Advanced Penetration Tester $2,499
Note: Price may vary.
Pentesting Practice Platforms
- VulnHub (Offsec) – Free
- VulnMachines (BlackHat) – Free
- Web Security Academy (PortSwigger Labs) – Free
- TryHackMe – Free + Paid
- pwnable.kr – Free
- pwnable.tw – Free
- HackTheBox – Free + Paid
- root-me – Free
- PentesterAcademy (Attackdefense) – Free + Paid
- Pentester Lab – Free + Paid
- standoff365 hackbase – Free
- LabEx Cybersecurity Labs – Free + Paid
FOSS Labs
- Vulhub
- Metasploitable3 Box
- OWASP Juice (WEB)
- DVWA (WEB)
- WebGOAT (WEB)
- Kubernetes GOAT
- Wrong Secrets (WEB)
- SQLi Lab
- HackerOne CTF
- For More Check: Awesome Vulnerable App List
Bug Bounty Hunting Platforms
- Hackerone
- Bugcrowd
- Intigriti
- YesWeHack
- Standoff365
- RedStorm
- Zerocopter
- OpenBugBounty
- Immunify Web3
- HackenProof WEB3
Independent Pentesting Platforms
- Yogosha
- Synack
0Day Market
- CrowdFense
- Zerodium (0day Bounty)
- ZeroZenx
Best OS for Hacking
- Kali Linux (OFFSEC)
- ParrotSec Security Edition
- BlackArch
Awesome Links
- The Book of Secret Knowledge
- Sirensecurity.io Windows Privilege Escalation Resources
- Awesome Link List by Sindre Sorhus
- cheatography.com cheatsheets
Hackers Manuals
- HackTricks
- HackingArticles.in
- InternalAllTheThings by swisskyrepo
- eloypgz.org Active Directory
- ExplainShell (Command Manual)
- Reverse Shell making Tool
- Hashcat Example Hashes
- GTFObins Priviledge Escalation Cheetsheet
- LOLBAS Binaries, Scripts and Libraries Exploit
- loldrivers Drivers Exploits
- WADComs Windows AD Cheetsheat
- Exploit List haxx.it
Books
- Ultimate Web Security Checklist
- The Web Applicaiton Hacker's Handbook
- Web Hacking Arsenal
- Brute XSS Payload Collection By Rodolfo Assis
About Me