{"id":21347477,"url":"https://github.com/zishanadthandar/pentest","last_synced_at":"2025-05-16T15:09:04.055Z","repository":{"id":59847205,"uuid":"254319914","full_name":"ZishanAdThandar/pentest","owner":"ZishanAdThandar","description":"Pentesting and Bug Bounty Notes, Cheetsheets and Guide for Ethical Hacker, Whitehat Pentesters and CTF Players.","archived":false,"fork":false,"pushed_at":"2025-04-30T14:33:39.000Z","size":5809,"stargazers_count":296,"open_issues_count":0,"forks_count":49,"subscribers_count":9,"default_branch":"main","last_synced_at":"2025-04-30T15:52:03.728Z","etag":null,"topics":["activedirectory","cheetsheet","cyber-security","cybersecurity","cybersecurity-tool","ethical-hacking","hacking","hacking-tool","infosec","penetration-testing","penetration-testing-tools","pentest","pentesting","powershell","redteam","redteaming","security","web-application-penetration-testing","web-application-security","whitehat-hacker"],"latest_commit_sha":null,"homepage":"https://zishanadthandar.github.io/pentest/","language":"PHP","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ZishanAdThandar.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null},"funding":{"github":"ZishanAdThandar","patreon":null,"open_collective":null,"ko_fi":null,"tidelift":null,"community_bridge":null,"liberapay":"ZishanAdThandar","issuehunt":null,"otechie":null,"custom":["https://paypal.me/ZishanAdThandar"]}},"created_at":"2020-04-09T08:53:51.000Z","updated_at":"2025-04-30T14:33:43.000Z","dependencies_parsed_at":"2024-01-21T06:31:01.461Z","dependency_job_id":"19198aea-aed6-4d21-9a89-2a8e764f0cd4","html_url":"https://github.com/ZishanAdThandar/pentest","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ZishanAdThandar%2Fpentest","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ZishanAdThandar%2Fpentest/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ZishanAdThandar%2Fpentest/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ZishanAdThandar%2Fpentest/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ZishanAdThandar","download_url":"https://codeload.github.com/ZishanAdThandar/pentest/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":254553958,"owners_count":22090417,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["activedirectory","cheetsheet","cyber-security","cybersecurity","cybersecurity-tool","ethical-hacking","hacking","hacking-tool","infosec","penetration-testing","penetration-testing-tools","pentest","pentesting","powershell","redteam","redteaming","security","web-application-penetration-testing","web-application-security","whitehat-hacker"],"created_at":"2024-11-22T02:14:19.520Z","updated_at":"2025-05-16T15:08:59.029Z","avatar_url":"https://github.com/ZishanAdThandar.png","language":"PHP","funding_links":["https://github.com/sponsors/ZishanAdThandar","https://liberapay.com/ZishanAdThandar","https://paypal.me/ZishanAdThandar"],"categories":[],"sub_categories":[],"readme":"# Pentester Guide\nA Comprehensive Resource for Pentesters: Tools, Methodologies, Scripts, Certifications, Learning Resources, Labs, Career Opportunities, Entertainment, and Freelancing Tips.\n\n[![Sponser](https://img.shields.io/github/sponsors/ZishanAdThandar)](https://github.com/sponsors/ZishanAdThandar)\n[![ZishanAdThandar's Pentest Repo stars](https://img.shields.io/github/stars/ZishanAdThandar/Pentest)](https://github.com/ZishanAdThandar/pentest)\n[![License: GPL v3](https://img.shields.io/github/license/ZishanAdThandar/pentest)](https://www.gnu.org/licenses/gpl-3.0)\n[![YouTube](https://img.shields.io/youtube/channel/subscribers/UChgqXa2j7ZKkHX2Y76tSxoA)](https://youtube.com/@hackerstation)\n[![LinkTree](https://img.shields.io/badge/Link-Tree-bbd343)](https://zishanadthandar.github.io/linktree/)\n\n![Banner Pentester Guide](./banner.png)\n\n## Contents\n- [Important Notes](#important-notes)\n- [Certifications](#certifications)\n- [Pentesting Practice Platforms](#pentesting-practice-platforms)\n- [Foss Labs](#foss-labs)\n- [Bug Bounty Hunting Platforms](#bug-bounty-hunting-platforms)\n- [Independent Pentesting Platforms](#independent-pentesting-platforms)\n- [0Day Market](#0Day-market)\n- [Operating System for Hacking](#best-os-for-hacking)\n- [Awesome Links](#awesome-links)\n- [Hackers Manuals](#hackers-manuals)\n- [About Me](#about-me)\n- [Sponsor](#sponsor)\n\n\n## Important Notes\n1. [Tools](./notes/TOOLS.md)\n2. [Active Directory](./notes/ActiveDirectory.md)\n3. [All about Pentesting](./notes/AllAboutPentesting.md)\n4. [Bug Bounty Hunting Methodology](./notes/BugBountyHuntingMethodology.md)\n5. [HackiFy Wordlist and Tool Installer Script](https://github.com/ZishanAdThandar/hackify)\n6. [Cyber Security / Bug Bounty Hunting Roadmap](./notes/CyberSecurityRoadmap.md)\n\n## Certifications\n\u003col\u003e\n  \u003cli\u003e\u003ca href=\"https://checkout.ine.com/\"\u003eINE eJPT\u003c/a\u003e $249\u003c/li\u003e\n  \u003cli\u003e\u003ca href=\"https://www.alteredsecurity.com/post/certified-red-team-professional-crtp\"\u003eAlteredSecurity CRTP\u003c/a\u003e $249\u003c/li\u003e\n  \u003cli\u003e\u003ca href=\"https://certifications.tcm-sec.com/pnpt/\"\u003eTCM Security PNPT\u003c/a\u003e $499\u003c/li\u003e\n  \u003cli\u003e\u003ca href=\"https://checkout.ine.com/\"\u003eINE eCPPT\u003c/a\u003e $599\u003c/li\u003e\n  \u003cli\u003e\u003ca href=\"https://www.offsec.com/courses/pen-200/\"\u003eOffensive Security - PEN-200 (OSCP)\u003c/a\u003e $1649\u003c/li\u003e\n  \u003cli\u003e\u003ca href=\"https://referral.hackthebox.com/mzxCoi6\"\u003eHTB CPTS\u003c/a\u003e With Annual Silver Plan $490\u003c/li\u003e\n  \u003cli\u003e\u003ca href=\"https://www.offsec.com/courses/web-300/\"\u003eOffensive Security - PEN-300 (OSEP)\u003c/a\u003e $1649\u003c/li\u003e\n  \u003cli\u003e\u003ca href=\"https://grow.google/certificates/cybersecurity\"\u003eGoogle Cybersecurity Professional Certificate\u003c/a\u003e Almost Free (Less than $20 for one month)\u003c/li\u003e \n  \u003cli\u003e\u003ca href=\"https://learn.microsoft.com/en-us/certifications/azure-security-engineer/\"\u003eMicrosoft Certified: Azure Security Engineer Associate (Cloud)\u003c/a\u003e $146\u003c/li\u003e\n  \u003cli\u003e\u003ca href=\"https://www.comptia.org/certifications/security\"\u003eCompTIA Security+\u003c/a\u003e $500 Exam Voucher\u003c/li\u003e   \n  \u003cli\u003e\u003ca href=\"https://www.crest-approved.org/skills-certifications-careers/examinations-in-asia/\"\u003eCREST CRT\u003c/a\u003e $500\u003c/li\u003e\n  \u003cli\u003e\u003ca href=\"https://www.isc2.org/Certifications/CISSP\"\u003eISC2 CISSP\u003c/a\u003e $750\u003c/li\u003e\n  \u003cli\u003e\u003ca href=\"https://www.isc2.org/certifications/ccsp\"\u003eISC2 CCSP\u003c/a\u003e $599\u003c/li\u003e\n  \u003cli\u003e\u003ca href=\"https://www.sans.org/cyber-security-courses/enterprise-penetration-testing/\"\u003eSANS SEC560: Enterprise Penetration Testing (GPEN)\u003c/a\u003e $2,499\u003c/li\u003e\n  \u003cli\u003e\u003ca href=\"https://www.giac.org/certifications/exploit-researcher-advanced-penetration-tester-gxpn/\"\u003eSANS SEC660: GIAC Exploit Researcher and Advanced Penetration Tester\u003c/a\u003e $2,499\u003c/li\u003e\n\u003c/ol\u003e\n\nNote: Price may vary.\n\n## Pentesting Practice Platforms\n\u003col\u003e\n  \u003cli\u003e \u003ca href=\"https://vulnhub.com\"\u003eVulnHub (Offsec)\u003c/a\u003e Free\u003c/li\u003e\n  \u003cli\u003e \u003ca href=\"https://www.vulnmachines.com/\"\u003eVulnMachines (BlackHat)\u003c/a\u003e Free\u003c/li\u003e\n  \u003cli\u003e \u003ca href=\"https://portswigger.net/web-security/all-labs\"\u003eWeb Security Academy (PortSwigger Labs)\u003c/a\u003e Free\u003c/li\u003e\n  \u003cli\u003e \u003ca href=\"https://tryhackme.com\"\u003eTryHackMe\u003c/a\u003e Free + Paid\u003c/li\u003e\n  \u003cli\u003e \u003ca href=\"https://pwnable.kr\"\u003epwnable.kr\u003c/a\u003e Free\u003c/li\u003e\n  \u003cli\u003e \u003ca href=\"https://pwnable.tw\"\u003epwnable.tw\u003c/a\u003e Free\u003c/li\u003e\n  \u003cli\u003e \u003ca href=\"https://app.hackthebox.com\"\u003eHackTheBox\u003c/a\u003e Free + Paid\u003c/li\u003e\n  \u003cli\u003e \u003ca href=\"https://app.hackthebox.com\"\u003ehttps://sec-dojo.com/en\u003c/a\u003e Paid\u003c/li\u003e\n  \u003cli\u003e \u003ca href=\"https://root-me.org\"\u003eroot-me\u003c/a\u003e Free\u003c/li\u003e\n  \u003cli\u003e \u003ca href=\"https://attackdefense.pentesteracademy.com/\"\u003ePentesterAcademy (Attackdefence)\u003c/a\u003e Free + Paid\u003c/li\u003e\n  \u003cli\u003e \u003ca href=\"https://www.pentesterlab.com/exercises\"\u003ePentester Lab\u003c/a\u003e Free + Paid\u003c/li\u003e\n\u003c/ol\u003e\n\n## FOSS Labs\n1. [Vulhub](https://github.com/vulhub/vulhub)\n2. [Metasploitable3 Box](https://github.com/rapid7/metasploitable3)\n3. [OWASP Juice (WEB)](https://owasp.org/www-project-juice-shop)\n4. [DVWA (WEB)](https://github.com/digininja/DVWA)\n5. [WebGOAT (WEB)](https://owasp.org/www-project-webgoat)\n6. [Kubernetes GOAT](https://github.com/madhuakula/kubernetes-goat)\n7. [Wrong Secrets (WEB)](https://owasp.org/www-project-wrongsecrets)\n8. [SQLi Lab](https://github.com/Audi-1/sqli-labs)\n9. [HackerOne CTF](https://github.com/Hacker0x01/hacker101)\n10. [For More Check: Awesome Vulnerable App List](https://github.com/vavkamil/awesome-vulnerable-apps)\n\n## Bug Bounty Hunting Platforms\n1. [Hackerone](https://www.hackerone.com/)\n2. [Bugcrowd](https://www.bugcrowd.com/bug-bounty-list/)\n3. [Intigriti](https://www.intigriti.com/programs)\n4. [YesWeHack](https://yeswehack.com/programs)\n5. [RedStorm](https://www.redstorm.io/program)\n6. [Zerocopter](https://zerocopter.com)\n7. [OpenBugBounty](https://www.openbugbounty.org/bugbounty-list)\n8. [Immunify Web3](https://immunefi.com/bug-bounty/)\n9. [HackenProof WEB3](https://hackenproof.com/)\n\n## Independent Pentesting Platforms\n1. [Yogosha](https://app.yogosha.com)\n2. [Synack](https://www.synack.com)\n3. [Cobalt](https://cobalt.io)\n\n## 0Day Market\n1. [CrowdFense](https://www.crowdfense.com/exploit-acquisition-program/)\n2. [Zerodium (0day Bounty)](https://zerodium.com/program.html)\n\n## Best OS for Hacking\n1. [BackBox](https://linux.backbox.org/download/)\n2. [ParrotSec Security Edition](https://parrotsec.org/download/)\n3. [Kali Linux (OFFSEC)](https://www.kali.org/get-kali/#kali-platforms)\n4. [BlackArch](https://blackarch.org/downloads.html)\n  \n## Awesome Links\n1. [The Book of Secret Knowledge](https://github.com/trimstray/the-book-of-secret-knowledge) \n2. [Sirensecurity.io Windows Privilege Escalation Resources](https://sirensecurity.io/blog/windows-privilege-escalation-resources/)\n3. [Awesome Link List by Sindre Sorhus](https://github.com/sindresorhus/awesome?tab=readme-ov-file#security)\n4. [cheatography.com cheatsheets](https://cheatography.com)\n\n## Hackers Manuals\n1. [HackTricks](https://book.hacktricks.xyz)\n2. [HackingArticles.in](https://www.hackingarticles.in)\n3. [InternalAllTheThings by swisskyrepo](https://swisskyrepo.github.io/InternalAllTheThings)\n4. [eloypgz.org Active Directory](https://web.archive.org/web/20231207200447/https://zer1t0.gitlab.io/posts/attacking_ad/)\n5. [ExplainShell (Command Manual)](https://explainshell.com)\n6. [Reverse Shell making Tool](https://www.revshells.com)\n7. [Hashcat Example Hashes](https://hashcat.net/wiki/doku.php?id=example_hashes)\n8. [GTFObins Priviledge Escalation Cheetsheet](https://gtfobins.github.io)\n9. [LOLBAS Binaries, Scripts and Libraries Exploit](https://lolbas-project.github.io)\n10. [loldrivers Drivers Exploits](https://www.loldrivers.io/)\n11. [WADComs Windows AD Cheetsheat](https://wadcoms.github.io)\n12. [Exploit List haxx.it](https://sploitify.haxx.it/)\n\n\n## Books\n1. [The Web Applicaiton Hacker's Handbook](https://github.com/0x000NULL/CSSR/blob/master/DOWNLOADED/OSCPRepo-master/PDFs%26Documents/Recommended%20Books/The%20Web%20Application%20Hackers%20Handbook%202nd%20Edition.pdf)\n2. [Web Hacking Arsenal](https://www.linkedin.com/posts/rafaybaloch_web-hacking-arsenal-a-practical-guide-to-activity-7229121194522759168-QUsw/)\n3. [Brute XSS Payload Collection By Rodolfo Assis](https://leanpub.com/brutexss)\n4. [THERCEMAN Bug Bounty CheetSheat Book](https://therceman.gumroad.com/l/book)\n\n\n## About Me\n\n| Platform  | Link  |\n|-----------|-------|\n| LinkedIn  | [LinkedIn.com/in/ZishanAdThandar](https://www.linkedin.com/in/ZishanAdThandar) |\n| YouTube   | [YouTube.com/ZishanAdThandar](https://youtube.com/ZishanAdThandar) |\n| LinkTree  | [ZishanAdThandar.github.io/linktree](https://ZishanAdThandar.github.io/linktree) |\n| Twitter   | [twitter.com/ZishanAdThandar](https://x.com/ZishanAdThandar) |\n| Telegram  | [ZishanAdThandar.t.me](https://ZishanAdThandar.t.me) |\n| GitHub    | [GitHub.com/ZishanAdThandar](https://github.com/ZishanAdThandar) |\n| Portfolio | [ZishanAdThandar.github.io](https://ZishanAdThandar.github.io) |\n| Resume    | [ZishanAdThandar.github.io/CV.pdf](https://ZishanAdThandar.github.io/CV.pdf) |\n\n\n## Sponsor  \n1. [https://github.com/sponsors/ZishanAdThandar](https://github.com/sponsors/ZishanAdThandar)\n2. [https://ZishanAdThandar.github.io/sponsor/](https://ZishanAdThandar.github.io/sponsor/)\n\n\u003c!--\n1. BTC `bc1q0qhgw5pdys7qqw07rcsyudu5wmv6208nhp5xtn`\n2. ETH `0x8cdc24eeb9d1bf46929b2106e3535e0d1953fe1b`\n3. ~~USDT (TRC20) `TGW1c7hzyszQNhQHM3aGa1nEKDNuyPueNE`~~ [Invalid]\n--\u003e\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzishanadthandar%2Fpentest","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fzishanadthandar%2Fpentest","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzishanadthandar%2Fpentest/lists"}