A living collection of the blogs, writeups, tools, and platforms I keep coming back to. Bookmark it, raid it, get lost in it.
Credits
This list started from Mushroom’s brilliant resources page. Huge thanks to them for curating it, go read the original and the rest of their blog at mushroom.cat.
Web & Client-Side
Blogs & Labs
- PortSwigger Research — cutting-edge web attack research
- Watchtowr Labs — n-day & enterprise appliance exploits
- Synacktiv Publications — deep offensive research
- Checkpoint Research — threat intel & vuln research
- SonarSource Blog — source-code vulnerability deep dives
- Elttam Blog — appsec & vuln research
- Snyk Articles — dependency & code security
- Positive Security — creative appsec research
- The Hacker Blog — web & infra vuln research
- SecurityOnline.info — security news & tool releases
- Acunetix Blog — web vulnerability writeups
- Intigriti — Bug Bytes — weekly bug bounty roundup
Researchers
- Orange Tsai — legendary web & SSRF chains
- Gareth Heyes — XSS & client-side wizard
- Huli — deep client-side security writeups
- Jorian Woltjer — web hacking & CTF
- SpaceRaccoon — appsec & supply chain research
- Shubs (Assetnote) — recon & attack surface research
- GhostCCamm — web exploit research
- Diefunction — web exploitation
- Omer Gil — web cache deception research
- Ben Hayak — XSS & web attacks
- RyoTaK — supply chain & race conditions
- Adam Caudill — appsec & crypto
- Ajin Abraham — mobile & appsec, MobSF author
- Daniel Stenberg (curl) — curl author, protocol security
- Brutecat — bug bounty & web research
- Devansh Batham — bug bounty methodology
- Rafa — web hacking writeups
- Worst.fit — Unicode & encoding attacks
Techniques & Reading
- Beyond XSS — CSP Bypass
- Beyond XSS — CSS Injection
- Client-Side Bugs Resources
- Huli — iframe & window.open
- Huli — Learn Frontend from a Security POV
XSLeaks
- XS-Leaks Wiki — the canonical reference for cross-site leaks
- x6vrn — XSLeaks Part 1 — intro to the attack class
- RewriteLab — Advanced XSLeaks Research (Part 0) — deep dive on browser-based info disclosure
JavaScript Recon & Analysis
- JavaScript Enumeration for Bug Bounty
- JavaScript Analysis for Pentesters
- Monitoring JS Files
- Bug Bounty Hunter — JS Files Guide
- Easy Bounties via JS File Analysis
- JavaScript to API Bugs
- Leaks & Disclosure — PII / API Keys
- Gowtham’s Bug Hunter Handbook
- Pwnfunction — Leaked API Keys (video)
- Zseano — .js File Analysis (video)
Notable Writeups
- Elttam — Plorming your Prisma ORM
- RyoTaK — DOM-based Race Condition
- Adam Caudill — Jackson RCE (CVE-2017-7525)
- RCE.moe — CVE-2025-41243
- Jorian Woltjer — Kittychat Secure (openECSC 2025)
- Exploiting Number Parsers in JavaScript
- arkark — ASIS CTF Finals: fire-leak — XSLeak via resource timing
Active Directory & Internal
Blogs & Orgs
- SpecterOps Blog — AD & offensive tradecraft
- Semperis — Active Directory security
- Bishop Fox — offensive security research
- Black Hills InfoSec — pentest & blue team, and hilarious
- Pentester Academy Blog — pentest techniques & tutorials
Researchers
- Dirk-jan Mollema — AD & Entra ID attack research (mitm6, ROADtools)
- harmj0y — AD tradecraft, PowerView & Rubeus author
- Elad Shamir — Kerberos, RBCD & ACL abuse research
- Podalirius — AD internals & coercion tooling
- Alexander Neff — NetExec developer
Techniques & Writeups
- AD Enumeration via MSSQL Injection (keramas)
- NetSPI — Enumerating Domain Accounts via SQL Server
- SpecterOps — Stealthy AD Collection over ADWS (SoaPy)
- iPurple Team — AD Enumeration via ADWS
Tools
- SoaPy (xforcered) — stealthy ADWS collection
- SOAPHound (FalconForce) — BloodHound data over ADWS
- SoaPy — original dev repo (logangoins) — the juicier upstream
- smbclient-ng — modern interactive SMB client
- RustHound-CE — fast BloodHound CE collector in Rust
- evil-winrm-py — Python WinRM shell
- powerview.py — PowerView-style AD recon in Python
- bloodyAD — AD privilege escalation framework
Binary Exploitation & Reversing
Learn & Practice
- pwn.college — structured pwn/reversing course
- Binary Exploitation 101 (Crypto-Cat)
- ired.team — offensive techniques & internals
- Getting Started in 2024 (dayzerosec)
- 0xinfection — Reversing
- x86 Reverse Engineering
- Pwn Challenges (playlist)
- HTB pwn series (Crypto-Cat)
- Snwo (KR)
Researchers
Cryptography
- CryptoHack — hands-on crypto challenges
- dcode.fr — Cipher Identifier — identify & solve ciphers
CTF & Practice
Platforms
- HackTheBox — machines, ProLabs & CTFs
- TryHackMe — guided rooms & learning paths
- HackSmarter — practical offensive security training
- PentesterLab — web security exercises
- DreamHack — Roadmaps — guided learning paths
- AlpacaHack — CTF-style challenges
- Wizer Training CTF — secure-coding CTF
Writeups & Creators
- ippsec — HTB video writeups
- 0xdf — HTB written writeups
- 0xRick — HTB machine writeups
- LiveOverflow — pwn & CTF video breakdowns
- John G4lt — offensive security writeups
- Mushroom — Web & CTF Writeups
Methodology & Career
- HackTricks — the pentest methodology bible
- OWASP Testing Framework — canonical web pentest methodology
- PTES — Penetration Testing Execution Standard
- OSSTMM 3 — security testing methodology manual
Tools & References
- Penelope — advanced shell/reverse-shell handler
- ExplainShell — break down any shell command
- dcode.fr — encoding/decoding & cipher toolbox
- r/websecurityresearch — web security subreddit
Found something that belongs here? Ping me. And again, much of this was curated by Mushroom; go show them some love.