Home




Enhance your cyber security operations with a comprehensive range of tools and resources for both offensive and defensive strategies.

If visiting us on GitHub please visit https://infosec.house for our website version of this repo. Much more search friendly!

Found a resources that should be on here? Feel free to submit a Pull Request!

Need to report a broken/incorrect link? Feel free to submit an Issue.


  • AI - Break the machines that think. Tools for attacking and defending AI systems.
  • API - Poke every endpoint. Tools for pentesting APIs.
  • Asset Management - Keep track of your inventory. You can't protect what you don't see.

  • Blogs - Read up before you break in. Blogs and zines from offensive security researchers.
  • Bug Bounty - Hack for cash. Test your skills and get paid for finding vulnerabilities.

  • C2 - Command your implants. C2 tools and frameworks.
  • Cheat Sheets - Quick-reference cheat sheets for offensive and defensive security work.
  • Cloud & Containers - Storm the cloud. Tools for hacking cloud platforms and containers.
  • Collaboration - Hack together. Tools for red team collaboration.
  • Cracking - Everything you need to crack all the hashes.
  • Cryptography - How great is your cryptography?
  • CTF Offensive - Flex your skills. Offensive security capture-the-flag events.


  • E-Mail - Phish, spoof, and pop inboxes. E-mail pentesting tools and resources.
  • Editors & Viewers - Editors and viewers for digging into files of every format.
  • Education - Level up. Training and courses to master your craft.
  • Emulation - Emulate the adversary.
  • Endpoint Protection - Lock down every endpoint before someone else does.
  • Evasion - Evade getting caught.
  • Exploits - Gather all your exploits needed to pop that box.

  • Firewalls - Attack the castle doors.
  • Forensics - Uncover the dirty little secrets of a recovered HDD, Image, malware, and more.

  • Hardware - Gear up. The hardware every pentester keeps in their bag.
  • Honeypots - Deploy honeypots to catch attackers in the act.

  • IDS/IPS - Detect and block intrusions before they do damage.
  • Incident Response - Incident response tools and resources for when alarms pop off.

  • Linux - Tools and resources for popping those Linux boxes.

  • Malware - All the malware you could wish for, ready to reverse engineer.
  • Mobile - Root it, jailbreak it, break it. Tools for attacking and defending mobile applications.
  • Music - Kick back, relax, and enjoy some entertainment.

  • Network - Sniff the network. Modify the packets.

  • Operating Systems - Operating systems for whatever task at hand.
  • Operation Security - Seek out technologies and methods of remaining anonymous in this day and age of mass surveillance.
  • OSINT - Open-Source Intel. Get all the information needed for your target.

  • Privilege Escalation - Go from limited access to full control. Escalate your privileges on Linux, macOS, and Windows.

  • Reverse Engineering - Reverse engineering tools that both offensive and defensive operations can utilize.
  • Reconnaissance - Understand your target. Perform in-depth research and discover new attack surfaces.

  • Shells - From pre-built webshells to fully custom ones.
  • Social Engineering - Manipulation techniques that exploit human error to gain private information, access, or valuables.


  • Video - Talks, livestreams, and presentations to sharpen your skills.
  • Vulnerability Scanners - Discover vulnerabilities fast, and automate the heavy lifting.

  • Web Application - Break that web application.
  • Windows - Tools and resources for popping those Windows boxes.
  • Wireless - Go wireless. Tools for exploiting Wi-Fi, Bluetooth, RFID, and more.