百科.dev
全部条目AI 编程趋势榜开源项目技术资讯提交条目
登录
< 返回工具列表
P

pentest

> 测试质量
开源

适用于道德黑客、白帽渗透测试人员和 CTF 参赛者的渗透测试和漏洞奖励注意事项、快速参考表和指南。

736 stars0 点赞0 次浏览
访问官网GitHub

工具介绍

适用于道德黑客、白帽渗透测试人员和 CTF 参赛者的渗透测试和漏洞奖励注意事项、快速参考表和指南。

Pentester Guide

A comprehensive, SEO-first penetration-testing knowledge base — tools, methodologies, cheatsheets, certifications, and career resources — built as a hand-rolled Jekyll static site on GitHub Pages, with no off-the-shelf theme.

Live site: guide.zishanhack.com — this repo is the source that builds it.

The project

  • Stack: Jekyll + Liquid on GitHub Pages — hand-rolled theme, no CSS framework, no build-time JS.
  • Scope: 7 deep-dive modules, 7 cheatsheet suites, 10+ curated resource directories, hundreds of hand-picked tools, commands, and links.
  • Engineering: custom dark-indigo design system consistent with the ZishanHack brand; SEO pipeline (per-page meta + canonical + robots.txt + single-author sitemap with zero junk URLs); fully responsive; static output for fast load.
  • Skills it demonstrates: static-site architecture, Liquid/Jekyll templating, HTML/CSS accessibility & responsiveness, technical writing at scale, SEO, Git/GitHub collaboration.

Guides & Notes

Active Directory · Pentesting Methodology · Bug Bounty Methodology · Bug Bounty Collections · CTF Box Manual · Security Roadmap · Tools Index Also check the ZishanHack Blog & WriteUps.

Contents

  • Important Notes
  • Certifications
  • Pentesting Practice Platforms
  • Foss Labs
  • Bug Bounty Hunting Platforms
  • Independent Pentesting Platforms
  • 0Day Market
  • Operating System for Hacking
  • Awesome Links
  • Hackers Manuals
  • About Me

Important Notes

  1. Tools
  2. Active Directory
  3. All about Pentesting
  4. Bug Bounty Hunting Methodology
  5. HackiFy Wordlist and Tool Installer Script
  6. Cyber Security / Bug Bounty Hunting Roadmap

Certifications

INE eJPT $249

AlteredSecurity CRTP $249

TCM Security PNPT $499

INE eCPPT $599

Offensive Security - PEN-200 (OSCP) $1749

HTB CPTS With Annual Silver Plan $490

Offensive Security - PEN-300 (OSEP) $1649

Google Cybersecurity Professional Certificate Almost Free (Less than $20 for one month)

Microsoft Certified: Azure Security Engineer Associate (Cloud) $146

CompTIA Security+ $500 Exam Voucher

CREST CRT $500

ISC2 CISSP $750

ISC2 CCSP $599

SANS SEC560: Enterprise Penetration Testing (GPEN) $2,499

SANS SEC660: GIAC Exploit Researcher and Advanced Penetration Tester $2,499

Note: Price may vary.

Pentesting Practice Platforms

  1. VulnHub (Offsec) – Free
  2. VulnMachines (BlackHat) – Free
  3. Web Security Academy (PortSwigger Labs) – Free
  4. TryHackMe – Free + Paid
  5. pwnable.kr – Free
  6. pwnable.tw – Free
  7. HackTheBox – Free + Paid
  8. root-me – Free
  9. PentesterAcademy (Attackdefense) – Free + Paid
  10. Pentester Lab – Free + Paid
  11. standoff365 hackbase – Free
  12. LabEx Cybersecurity Labs – Free + Paid

FOSS Labs

  1. Vulhub
  2. Metasploitable3 Box
  3. OWASP Juice (WEB)
  4. DVWA (WEB)
  5. WebGOAT (WEB)
  6. Kubernetes GOAT
  7. Wrong Secrets (WEB)
  8. SQLi Lab
  9. HackerOne CTF
  10. For More Check: Awesome Vulnerable App List

Bug Bounty Hunting Platforms

  1. Hackerone
  2. Bugcrowd
  3. Intigriti
  4. YesWeHack
  5. Standoff365
  6. RedStorm
  7. Zerocopter
  8. OpenBugBounty
  9. Immunify Web3
  10. HackenProof WEB3

Independent Pentesting Platforms

  1. Yogosha
  2. Synack

0Day Market

  1. CrowdFense
  2. Zerodium (0day Bounty)
  3. ZeroZenx

Best OS for Hacking

  1. Kali Linux (OFFSEC)
  2. ParrotSec Security Edition
  3. BlackArch

Awesome Links

  1. The Book of Secret Knowledge
  2. Sirensecurity.io Windows Privilege Escalation Resources
  3. Awesome Link List by Sindre Sorhus
  4. cheatography.com cheatsheets

Hackers Manuals

  1. HackTricks
  2. HackingArticles.in
  3. InternalAllTheThings by swisskyrepo
  4. eloypgz.org Active Directory
  5. ExplainShell (Command Manual)
  6. Reverse Shell making Tool
  7. Hashcat Example Hashes
  8. GTFObins Priviledge Escalation Cheetsheet
  9. LOLBAS Binaries, Scripts and Libraries Exploit
  10. loldrivers Drivers Exploits
  11. WADComs Windows AD Cheetsheat
  12. Exploit List haxx.it

Books

  1. Ultimate Web Security Checklist
  2. The Web Applicaiton Hacker's Handbook
  3. Web Hacking Arsenal
  4. Brute XSS Payload Collection By Rodolfo Assis

About Me

  • Portfolio

Issues· 0 开放

查看全部 Issues在 GitHub 打开

暂无开放 Issues,或尚未同步最近议题。

> 标签

PHPactivedirectorycheetsheetcyber-securitycybersecurity

暂无评论,来聊聊你的看法吧

> 工具信息

发布日期2026年8月1日
最后更新2026年9月17日
分类测试质量
定价开源

> 相关工具

J
Jest
JavaScript 测试框架
P
Playwright
现代端到端测试框架
E
eslint-plugin-test-selectors
Enforces that data-test-id attributes are added to interactive DOM elements (JSX) to help with UI testing. JSX only.