Reference · pentest-knowledge-basedual-use
OSCP-Notes
A study/reference repository for OSCP exam preparation with command references organized by tool (Nmap, Hydra, Hashcat, Wfuzz, Cewl), technique notes on reverse shells, privilege escalation, Active Directory, buffer overflow, SQLi and XSS, plus write-ups from HackTheBox, VulnHub, Proving Grounds and TryHackMe.
Use responsibly
Dual-use security content. We link to the upstream project rather than re-hosting ready-to-fire files. Use only in authorized security testing.
More references
- AboutSecurity (WgpSec)pentest-knowledge-baseA structured penetration-testing knowledge base by the WgpSec team, packaged for consumption by AI agents: 200+ attack-chain methodologies (recon through post-exploitation, cloud, code audit, CTF, malware analysis, lateral movement), password/fuzzing dictionaries, exploit payloads for SQLi/XSS/SSRF, and a 600+ entry vulnerability database organized by product. It is the knowledge layer of the WgpSec agentic pentest ecosystem (MCP server + autonomous agent).
- HackTrickspentest-knowledge-baseWidely-used community knowledge base of pentesting and web-security techniques (e.g. WAF/rate-limit bypass tactics referenced in the audit).
- LLM Hacker's Handbookpentest-knowledge-baseAn empirical, practical guide to LLM hacking from security firm Forces Unseen, covering prompt injection, offensive and defensive techniques, and interactive playgrounds. Source for the handbook hosted at doublespeak.chat.
- OWASP MASTGpentest-knowledge-baseThe OWASP Mobile Application Security Testing Guide: a comprehensive manual for mobile app security testing and reverse engineering on Android and iOS. Covers static and dynamic analysis, runtime and network-traffic analysis, cryptography testing, and mobile penetration-testing methodology, mapped to the OWASP MASVS standard and MASWE weakness enumeration.
- PentestingEverythingpentest-knowledge-baseA pentesting and VAPT/AppSec knowledge base spanning 23 security domains (web, mobile, API, cloud, network, LLM, MCP security), aggregating methodologies, 100+ reference PDFs, 200+ tools organized by category, and an AI-assisted pentest agent skill.
- [un]prompted 2026 slide archiveai-security-programCommunity GitHub archive of 49 slide decks from [un]prompted 2026, the AI Security Practitioner Conference (March 3-4, San Francisco), spanning AI governance, agent security, offensive AI and agent evaluation; no licence stated.