All resources
Topic

pentest-knowledge-base

6 resources across 1 kinds

References

  1. Widely-used community knowledge base of pentesting and web-security techniques (e.g. WAF/rate-limit bypass tactics referenced in the audit).

    Open ↗
  2. The OWASP Mobile Application Security Testing Guide: a comprehensive manual for mobile app security testing and reverse engineering on Android and iOS. Covers static and dynamic analysis, runtime and network-traffic analysis, cryptography testing, and mobile penetration-testing methodology, mapped to the OWASP MASVS standard and MASWE weakness enumeration.

    Open ↗
  3. An empirical, practical guide to LLM hacking from security firm Forces Unseen, covering prompt injection, offensive and defensive techniques, and interactive playgrounds. Source for the handbook hosted at doublespeak.chat.

    Open ↗
  4. A pentesting and VAPT/AppSec knowledge base spanning 23 security domains (web, mobile, API, cloud, network, LLM, MCP security), aggregating methodologies, 100+ reference PDFs, 200+ tools organized by category, and an AI-assisted pentest agent skill.

    Open ↗
  5. OSCP-Notesdual-use

    A study/reference repository for OSCP exam preparation with command references organized by tool (Nmap, Hydra, Hashcat, Wfuzz, Cewl), technique notes on reverse shells, privilege escalation, Active Directory, buffer overflow, SQLi and XSS, plus write-ups from HackTheBox, VulnHub, Proving Grounds and TryHackMe.

    Open ↗
  6. AboutSecurity (WgpSec)dual-usehigh-risk

    A structured penetration-testing knowledge base by the WgpSec team, packaged for consumption by AI agents: 200+ attack-chain methodologies (recon through post-exploitation, cloud, code audit, CTF, malware analysis, lateral movement), password/fuzzing dictionaries, exploit payloads for SQLi/XSS/SSRF, and a 600+ entry vulnerability database organized by product. It is the knowledge layer of the WgpSec agentic pentest ecosystem (MCP server + autonomous agent).

    Open ↗