Remember: "Things can be different..."
• "However the future unfolds, it's not something to be predicted, like the passage of a comet. It's something we build." by Robert Kunzig - behind a National Geographic paywall
• "What matters most, is what people, human people, we, do. Not what other people do…" Timothy Holborn
• "The fact that there are pressures and costs does not absolve people of their moral responsibility. The primary custodian of one's actions is oneself." Noam Chomsky Tue, 3 Apr 2018 - quoted by Timothy Holborn
• "Reality exists, regardless of your emotional support of it." Kenneth Reitz. 'A Concise List of Personal Values'
• "A lie is a fiction made up to take away someone else's power." Elizabeth Mitchell, Guernica Magazine. Essay/Lit World/Politics, January 15, 2021
• "Without facts, you can’t have truth. Without truth, you can’t have trust. Without all three, we have no shared reality, and democracy as we know it -- and all meaningful human endeavors -- are dead." Maria A Ressa in "How to Stand Up to a Dictator: A Nobel Laureate's Fight Against Authoritarianism
• "Chance favors only the prepared mind." quote from Louis Pasteur
• Core Values Matter: Guiding principles shape our lives -- don't drift, identify your priorities
• To write is to act. (Scribere est agere.)
• Withholding the truth suggests falsehood. (Suppressio veri suggestio est falsi.)
• "Draw close what you want more of, push away what you want less." by Angela Duckworth - in the NYT and in Latin: Accede quod vis plus, repelle quod vis minus.
• and If you're not paying for it, you're the product. (Si non solvente pro eo, productum es.)🫲🏼
This is a collection of reusable references. Hosted at: mccright.github.io/references/
- Don't ignore it. See: Wikipedia: Russo-Ukrainian War. And resist/confront Trump 47’s shameful early efforts to strengthen ties with Putin by making material concessions before any negotiations about ending Putin's war with Ukraine.
See '''Trumps_Indictments''' here
See '''Agnotology''' here
- U.S. Energy flow 2025: eia.gov/totalenergy/data/flow-graphs/total-energy.php
- Flex your perceptions and imagination with the Astronomy Photo of the Day apod.nasa.gov/apod/astropix.html (if you have just a minute right now, I recommend this Euclid photo of the Perseus Galaxy Cluster having a 1000+ galaxies in the foreground about 250 million light years away plus more than 100,000 galaxies in the background, and review an explanation of what you are looking at) or see what is new from the James Webb Space Telescope webbtelescope.org/news/news-releases [or their Flicker collection] or read at length from NASA's ebook collection www.nasa.gov/connect/ebooks/index.html or explore the Apollo Lunar Surface Journal [high-tech from a different age] www.hq.nasa.gov/alsj/main.html
- Flex your perceptions and imagination with a real-time visualization of global marine shipping www.marinetraffic.com/en/ais/home/centerx:80.5/centery:8.7/zoom:3
- Here is the "NASA JPL Asteroid Watch --> The Next Five Asteroid Approaches" www.jpl.nasa.gov/asteroid-watch/next-five-approaches to help fuel your "it's always something..." catastrophe habit
- Begin [or continue] to work individually and collectively to slow climate change. Little of what we do is relevant in a world destablized by climate change.
- We need to act on many, many fronts, but there are some offenders that deserve special attention. For example, please Treat Big Oil and Big Ag Like Big Tobacco
- I have begun to accumulate links to some of my climate reading (and planned reading) in another repository github.com/mccright/rand-notes/blob/master/Climate-Resources.md
- As an easy-to-understand illustration of climate change see the USDA Plant Hardiness Zone Map. Look at these maps from previous decades to see warmer winters creep north.
- Find something new/different to read with Libby, the library reading app, you can use to borrow ebooks, audiobooks, magazines, and more from your local library for free. Libby is the newer library reading app by OverDrive. See: https://www.overdrive.com/apps/libby or take a more commercial route through books.google.com/
- Explore these falsehoods (too many) programmers believe in (which too often produce errors at runtime) -- Awesome Falsehood github.com/kdeldycke/awesome-falsehood
- Or, if you are needing a break from your normal grind, join others doing people-powered research www.zooniverse.org/projects?page=1&status=live
- Writing well is difficult. The Strunkifier may help [think 'Strunk and White' from school written in PHP with a web front end]vinoisnotouzo.com/strunkifier/ and the source at github.com/BSVino/Strunkifier/blob/master/strunkify.php
- Remember the Ten simple rules for making research software more robust journals.plos.org/ploscompbiol/article?id=10.1371/journal.pcbi.1005412
- If you work in a corporate environment, ensure it is supporting open source:
- "Why have an open source program office?." RedHat Brief, Last Updated: 4 February 2021 www.redhat.com/en/resources/open-source-program-office-brief
- "What does an open source program office do?" By Brian Proffitt, 19 December 2019 www.redhat.com/en/blog/what-does-open-source-program-office-do
- "Creating an Open Source Program." By Chris Aniszczyk, COO, Cloud Native Computing Foundation; Jeff McAffer, Director, Open Source Programs Office, Microsoft; Will Norris, Open Source Office Manager, Google; and Andrew Spyker, Container Cloud Manager, Netflix. www.linuxfoundation.org/tools/creating-an-open-source-program/
- "Open source best practices for the enterprise." (A collection of 12 best practices guides for running an open source program office or starting an open source project in your organization. Developed by The Linux Foundation in partnership with the TODO Group, these resources represent the experience of our [Linux Foundation] staff, projects, and members.) www.linuxfoundation.org/resources/open-source-guides/
- "A guide to setting up your Open Source Program Office (OSPO) for success -- Learn how to best grow and maintain your open source communities and allies." By J. Manrique Lopez de la Fuente, 08 May 2020 opensource.com/article/20/5/open-source-program-office
- "Software Licenses in Plain English -- Lookup popular software licenses summarized at-a-glance." tldrlegal.com/
- Finally, pay attention to where you invest your attention. A recent essay by Ezra Klein exploring how technology choices influence how/what we learn and behave is worth a careful read: www.nytimes.com/2022/08/07/opinion/media-message-twitter-instagram.html.
A recent study linked higher levels of phubbing to [partner] dissatisfaction, and a 2022 study found it can lead to feelings of distrust and ostracism. One study found that those who phub a lot are more likely to be phubbed themselves, creating a kind of ripple effect. www.nytimes.com/2023/07/27/well/family/phubbing-phone-snubbing-relationship.html
- The time changed again... See how NIST explains daylight saving time
First and foremost: a couple git cheat sheets
- training.github.com/downloads/github-git-cheat-sheet.pdf
- and TimGreen's list of git & github features -- with a table of resources and books at the bottom: github.com/tiimgreen/github-cheat-sheet maybe also
- Michael Gieson's git cheat cheet www.gieson.com/Library/cheatsheets/md.html?git
- "The simple guide" rogerdudler.github.io/git-guide/ and
- github.com/vineetpandey/github-cheat-sheet and page 2 of
- www.git-tower.com/blog/git-cheat-sheet/ and documenation at git-scm.com/docs
- Git Pocket Guide. By Richard E. Silverman www.oreilly.com/library/view/git-pocket-guide/9781449327507/
- Monorepos can hide a lot of different problems. git-sizer can help. git-sizer computes various size metrics for a local Git repository, flagging those that might cause you problems or inconvenience.
- Finally, git repos may contain sensitive files and the scale of their history can slow pipeline activities. In some use cases git-filter-repo can help.
Just get started...
git remote -v (view the full addresses of your configured remotes)
cd into your new project directory
git init (builds a .git directory that contains all the metadata and repository history)
git add . (instructs Git to begin tracking all files within and beneath the current directory)
git commit –m'This is the first commit' (creates the permanent history of all files, with the -m option supplying a message alongside the history marker)
- or install Joel Parker Henderson's GitAlias and do the same more efficiently.
Rename your old github repo 'master' branch to 'main'...
git branch -m master main
git fetch origin
git branch -u origin/main main
git remote set-head origin -a- A github profile summary: profile-summary-for-github.com/user/githubUserName/ Thank you tipsy
- A curated list of awesome lists: github.com/sindresorhus/awesome
- A collection of awesome lists for hackers, pentesters & security researchers github.com/Hack-with-Github/Awesome-Hacking
- A curated list of Terminal frameworks, plugins & resources for CLI lovers github.com/k4m4/terminals-are-sexy
- Awesome TUIs -- List of projects that provide terminal user interfaces github.com/rothgar/awesome-tuis
- Awesome Finder -- TUI based finder for searching the awesome resources on awesome series such as awesome-python, awesome-go and so on github.com/mingrammer/awesome-finder
- Several Awesome resource navigation projects at github.com/skyllwt?tab=repositories
- Awesome Claude Code github.com/jqueryscript/awesome-claude-code
Sears catalog of Linux software -- Awesome Linux Software github.com/luongvo209/Awesome-Linux-Software
- and if you need a little Linux help using it gto76.github.io/linux-cheatsheet/ and github.com/gto76/linux-cheatsheet
- Daniel Roesler's excellent Privacy Checklist: github.com/diafygi/privacy-checklist
- W3C Data Privacy Vocabularies and Controls CG (DPVCG) www.w3.org/community/dpvcg/
- 11 tips for protecting your privacy... by Olivia Martin freedom.press/training/blog/11-tips-protecting-your-privacy-and-digital-security-age-trump/
- Your IP address is sometimes your identity myexternalip.com/
- Is the target already beyond its end of life / End-of-life (EOL/EoL)? endoflife.date/ or github.com/endoflife-date/endoflife.date or for infrastructure software versionlog.com/
- DevSecOps tool lists github.com/hahwul/DevSecOps
- U.S. National Checklist Program checklists.nist.gov and web.nvd.nist.gov/view/ncp/repository
- Security Content Automation Protocol (SCAP)
- Nist Overview: csrc.nist.gov/groups/SMA/forum/documents/august2015/forum-august2015-booth.pdf
- SCAP Home: scap.nist.gov/
- State-of-the-Art Resources (SOAR) for Software Vulnerability Detection, Test, and Evaluation apps.dtic.mil/sti/pdfs/AD1106086.pdf
- State-of-the-Art Resources (SOAR) for Software Assurance people.cs.ksu.edu/~hatcliff/890-High-Assurance/Reading/IATAC-SOAR-Software-Security-Assurance.pdf
- Common Vulnerability Scoring System (CVSS) cve.mitre.org/ and nvd.nist.gov/cvss.cfm?calculator&adv&version=2
- Vulnerability and exploit lists:
o www.cisa.gov/known-exploited-vulnerabilities-catalog
o cve.mitre.org/
o www.cvedetails.com/
o w.0day.today/
o www.securityfocus.com/bid/
o www.exploit-db.com/
o nvd.nist.gov/
o github.com/vulsio (json files) - Library for interacting with Synack API github.com/abdilahrf/synackAPI
- CyberSecurityMalaysia, 3rd Party Information Security Assessment Guideline www.cybersecurity.my/data/content_files/11/650.pdf
- Fortify Taxonomy of Secure Software Errors. vulncat.fortify.com/en
- Or host your own list to keep your research more private:
o A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. github.com/nexB/vulnerablecode
o Vulnerabilities and Attacks github.com/hannob/vulns
o The CVE-Search Project www.cve-search.org/software/, and cve-search - a tool to perform local searches for known vulnerabilities github.com/cve-search/cve-search - Scripts to help run Fortify -- and other code assessment tools -- in your Amazon cloud github.com/awslabs/one-line-scan/
- There are situations where you may be given a repository without any accompanying information... What is in the repo?? crazymax assembled a Docker image -- crazymax/docker-linguist -- that runs GitHub Linguist, a library used on GitHub.com to detect blob languages. You can use is to easily, quickly and reasonable accurately identify what languages are used in a given local repository. Here are some examples of it in use: github.com/mccright/FortifyStuff/blob/master/Developer-Access-to-Static-Analysis-Data.md#what-languages-are-in-a-given-target-repository
- Vulns: Vulnerability scanner for Linux/FreeBSD, agent-less, written in Go. github.com/future-architect/vuls
- This is tool to build a local copy of the CPE (Common Platform Enumeration) github.com/vulsio/go-cpe-dictionary
- boofuzz: Network Protocol Fuzzing for Humans (Boofuzz is a fork of and the successor to the venerable Sulley fuzzing framework.) github.com/jtpereyda/boofuzz
- mdinfo: Meta Data Info (mdinfo) is a command line tool for printing metadata information about files. github.com/RhetTbull/mdinfo
- BSIMM Definitions of Architecture Risk Analysis - Builds an ARA definition by describing a set of increasingly mature risk analysis practices: www.bsimm.com/framework/software-security-development-lifecycle/architecture-analysis/
- U.S. CERT Definition & Best Practices Document on Architecture Risk Analysis: www.us-cert.gov/bsi/articles/best-practices/architectural-risk-analysis/architectural-risk-analysis
- Lecture 28: Threat Modeling, or Architectural Risk Analysis - Coursera-hosted lecture on this topic by Michael Hicks, University of Maryland, College Park: www.coursera.org/learn/software-security/lecture/bQAoU/threat-modeling-or-architectural-risk-analysis
- "A Non-Trivial Task of Introducing Architecture Risk Analysis into Software Development Process." OWASP EU presentation by Denis Pilipchuk, Global Product Security, Oracle: 2014.appsec.eu/wp-content/uploads/2014/07/Denis.Pilipchuk-A-non-trivial-task-of-Introducing-Architecture-Risk-Analysis-into-the-Software-Development-Process.pdf
- Mitre Att&ck Enterprise threat list mitre.github.io/attack-navigator/enterprise/
"ATT&CK® is a catalog of techniques and tactics that describe post-compromise adversary behavior on typical enterprise IT environments. The core use cases involve using the catalog to analyze, triage, compare, describe, relate, and share post-compromise adversary behavior." - Mitre D3FEND™ technical knowledge base of defensive countermeasures for common offensive techniques that is complementary to MITRE's ATT&CK, a knowledge base of cyber adversary behavior. D3FEND complements Mitre Att&ck by establishing a terminology of computer network defensive techniques and illuminating previously-unspecified relationships between defensive and offensive methods. d3fend.mitre.org/
- Related works:
- MITRE ATT&CK® Matrix for Enterprise -- with specialized versions for the following platforms: Windows, macOS, Linux, PRE, Azure AD, Office 365, Google Workspace, SaaS, IaaS, Network, Containers attack.mitre.org/matrices/enterprise/
- MITRE ATT&CK® Matrix for Mobile -- with specialized versions for the following platforms: Android and iOS attack.mitre.org/matrices/mobile/
- NIST 800-53 Controls to ATT&CK Mappings ctid.mitre-engenuity.org/our-work/nist-800-53-control-mappings/
- Mitre ATT&CK® for Industrial Control Systems threat list collaborate.mitre.org/attackics/index.php/Main_Page "ATT&CK for ICS is a knowledge base useful for describing the actions an adversary may take while operating within an ICS network. The knowledge base can be used to better characterize and describe post-compromise adversary behavior."
- Stripe's FT3: Fraud Tools, Tactics, and Techniques Framework is Stripe's adaptation of ATT&CK-style security frameworks, specifically designed to enhance their understanding of the tactics, techniques, and procedures (TTPs) used by actors in fraudulent activities. Developed as a resource for combating financial crime and improving organizational fraud prevention, FT3 is targeted at serving a variety of stakeholders across the anti-fraud/fraud-detection ecosystem. github.com/stripe/ft3/blob/master/
- MITRE ATT&CK® and CAPEC™ datasets expressed in STIX 2.0 github.com/mitre/cti
- Github organization for MITRE ATT&CK github.com/mitre-attack
- Atomic Red Team™ is a library of tests mapped to the MITRE ATT&CK® framework. Its mission is to help security teams quickly, portably, and reproducibly test their environments github.com/redcanaryco/atomic-red-team
- infosecn1nja's Awesome Mitre ATT&CK™ Framework github.com/infosecn1nja/awesome-mitre-attack
- The Common Attack Pattern Enumeration and Classification dictionary and classification taxonomy (CAPEC):
Understanding how the adversary operates is essential to effective cyber security. CAPEC™ helps by providing a comprehensive dictionary of known patterns of attacks employed by adversaries to exploit known weaknesses in cyber-enabled capabilities. It can be used by analysts, developers, testers, and educators to advance community understanding and enhance defenses.- Focuses on application security
- Enumerates exploits against vulnerable systems
- Includes social engineering / supply chain
- Associated with Common Weakness Enumeration (CWE)
capec.mitre.org/data/
- Example Attack Taxonomy from CAPEC capec.mitre.org/data/definitions/2000.html
- "The Universal Cloud Threat Model" securosis.com/research/papers/the-universal-cloud-threat-model-for-cloud-native-security/
- "The STRIDE Threat Model." msdn.microsoft.com/en-US/library/ee823878(v=cs.20).aspx
- "Improving Web Application Security: Chapter 3, Threat Modeling -- Threats and Countermeasures." msdn.microsoft.com/en-us/library/ff648644.aspx (In depth review of STRIDE and DREAD.)
- NIST's SP 800-160 Vol. 1 Rev. 1 (2022) "Engineering Trustworthy Secure Systems." With special attention to the 30 security principles in "Appendix E. Principles for Trustworthy Secure Design." csrc.nist.gov/publications/detail/sp/800-160/vol-1-rev-1/final
- "How To: Create a Threat Model for a Web Application at Design Time." msdn.microsoft.com/en-us/library/ms978527.aspx
- "Walkthrough: Creating a Threat Model for a Web Application." msdn.microsoft.com/en-us/library/ms978538.aspx
- "Application Threat Modeling (OWASP)" owasp.org/index.php/Application_Threat_Modeling
- "Threat Modeling Cheat Sheet (OWASP)" github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Threat_Modeling_Cheat_Sheet.md
- "OWASP Risk Rating Methodology" owasp.org/index.php/OWASP_Risk_Rating_Methodology
- "A Complete Guide to the Common Vulnerability Scoring System Version 3.1" www.first.org/cvss/v3-1/cvss-v31-specification_r1.pdf
- The System Design Primer github.com/donnemartin/system-design-primer
- Use Cases and Requirements on HTTPS-enabled Local Network Servers httpslocal.github.io/usecases/, www.w3.org/community/httpslocal/ and github.com/httpslocal/proposals/tree/master
- How Complex Systems Fail (Being a Short Treatise on the Nature of Failure; How Failure is Evaluated; How Failure is Attributed to Proximate Cause; and the Resulting New Understanding of Patient Safety) how.complexsystems.fail/
- I have no direct association with Tesla or Tesla engineering efforts, but based on my reading of general news and narrow analysis of descriptions of Tesla's auto-driving and its AI it seems like a material failure of their Architecture Risk Analysis practices. See: "Tesla Self-Driving Deaths." The linked map indicates registered deaths associated with Tesla’s self-driving software since 2016 in the United States. The information contains fatalities recorded by NHTSA’s Standing General Order on Crash Reporting for Level 2 ADAS-equipped vehicles since its inception in June 2021, and confirmed self-driving deaths pre-dating NHTSA’s database of crash statistics: dawnproject.com/nhtsa-map-1/. If crash and death numbers are not convincing, you might look at some videos by The Dawn Project of Tesla's Full Self-Driving AI: vimeo.com/988491613/fcfcdf7190 (Blow past stopped school buses), vimeo.com/942153183/9b3848b364 (Run down children crossing the road) or vimeo.com/843429267/bc871414fd (Blow through stop signs).
- The Secure ur Ass By Learning Cybersecurity repository SUASS. It describes itself as "a comprehensive resource for cybersecurity professionals, students, beginners, and anyone interested in the field of cybersecurity. Here, you'll find a wide range of cybersecurity study materials to help you enhance your knowledge and skills." github.com/GTekSD/SUASS
- List of awesome penetration testing resources, tools and other shiny things github.com/enaqx/awesome-pentest
- Awesome collection of hacking tools github.com/jekil/awesome-hacking
- Tooling is great, but understanding how software systems fail is a critical capability as well. See "Be Suspicious of Success, Successful software is buggy software" for some input about what to think about when "testing."
Kitsec, a toolkit CLI to help simplify and centralize your risk eval. workflow github.com/kitsec-labs/kitsec-core- Osmedeus - a Workflow Engine for Offensive Security. It was designed to build a foundation with the capability and flexibility that allows you to build your own reconnaissance system and run it on a large number of targets. github.com/j3ssie/osmedeus
- Mantis - command-line framework designed to automate the workflow of asset discovery, reconnaissance, and scanning github.com/PhonePe/mantis
- "All in One Hacking tool For Hackers" github.com/Z4nzu/hackingtool
- Arsenal - an inventory, reminder and launcher to simplify the use of all the hard-to-remember pentest commands github.com/Orange-Cyberdefense/arsenal
- Red Teaming Toolkit github.com/infosecn1nja/Red-Teaming-Toolkit
- Red Team Scripts github.com/infosecn1nja/red-team-scripts
- bugcrowd / methodology-taxonomy github.com/bugcrowd/methodology-taxonomy
- Bugcrowd Vulnerability Rating Taxonomy (VRT) bugcrowd.com/vulnerability-rating-taxonomy and github.com/bugcrowd/vulnerability-rating-taxonomy
- "A collection of tools used by Web hackers" github.com/hahwul/WebHackersWeapons
- six2dez pentest-book pentestbook.six2dez.com/ and the source at github.com/six2dez/pentest-book
- If you are creative and persistent, you will accumulate valuable passwords and tokens. Keep them safe from abuse. Assuming that need support for Linux, Windows, or Mac, you might consider using KeePassXC on an encrypted+password protected USB drive. See the recent code review report by Zaur Molotnikov to help evaluate the risks.
- Sometimes you will need to share secrets. scrt.link/ with a link that only works one time and then self-destructs. It is imperfect, but likely good-enough for many use cases.
- Penetration Testing Checklist github.com/infinite-omicron/pentesting-checklist and its companion Pentesting Guide github.com/infinite-omicron/pentesting-guide/
- Automated NoSQL database enumeration and web application exploitation tool github.com/codingo/NoSQLMap
- An eccentric collection of links to pen testing resources github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE
- The Open Penetration Testing Bookmarks Collection github.com/Oweoqi/pentest-bookmarks/blob/master/BookmarksList.md
- Collection of pentest resources github.com/1N3/
- Active Directory Attack Cheat Sheet medium.com/@dw3113r/active-directory-attack-cheat-sheet-ea9e9744028d or formatted better at dw3113r.com/2022/07/20/active-directory-attack-cheat-sheet/
- Active Directory Cheatsheet: github.com/OriolOriolOriol/Active-Directory-Cheat-Sheet
- Active Directory Kill Chain Attack & Defense github.com/infosecn1nja/AD-Attack-Defense
- OWASP Web Application Security Testing Cheatsheet owasp.org/index.php/Web_Application_Security_Testing_Cheat_Sheet
- ngrok: ngrok is a globally distributed reverse proxy fronting your web services running on a given endpoint, or in any cloud or private network. Paid ngrok has additional features that support its promotion as "the programmable network edge that adds connectivity, security, and observability to your apps with no code changes." Pay attention to the details of every request. The free version may not be suitable for your business, your local environment, or your regulators/investors/customers. ngrok.com
- Weird Proxies: a cheat sheet about behaviour of various reverse proxies, cache proxies, load balancers, etc. github.com/GrrrDog/weird_proxies
- Fetch a list of currently-working proxies github.com/stamparm/fetch-some-proxies
- Collection of security tool cheat sheets github.com/gnebbia/cheatsheets/tree/master/sectool
- OWASP based Web Application Security Testing Checklist as an Excel Workbook github.com/tanprathan/OWASP-Testing-Checklist
- Web Application Security Guide/Checklist. en.wikibooks.org/wiki/Web_Application_Security_Guide/Checklist
- Awesome WAF github.com/0xInfection/Awesome-WAF
- identYwaf is a WAF protection type identification tool using loud techniques github.com/stamparm/identYwaf
- Open Source Security Testing Methodology Manual (OSSTMM) www.isecom.org/research/osstmm.html
- Session Hijacking Cheat Sheet resources.infosecinstitute.com/session-hijacking-cheat-sheet/
- Payloads All The Things -- A list of useful payloads and bypasses for Web Application Security. by Swissky github.com/swisskyrepo/PayloadsAllTheThings
- SecLists is the security tester's companion. It is a collection of multiple types of lists used during security assessments. List types include usernames, passwords, URLs, sensitive data grep strings, fuzzing payloads, and many more. github.com/danielmiessler/SecLists
- Pen testing payloads with supporting resources (this could/should be named 'awsome-payloads'!) github.com/swisskyrepo/PayloadsAllTheThings and, easier to navigate swisskyrepo.github.io/PayloadsAllTheThings/
- Penetration Testers Framework (PTF) github.com/trustedsec/ptf
- Social-Engineer Toolkit (SET) github.com/trustedsec/social-engineer-toolkit
- A Python based web application scanner - BlackWidow - with Docker help github.com/1N3/BlackWidow
- Sn1per - Automated pentest framework for offensive security experts github.com/1N3/Sn1per
- Arachni Web Application Security Scanner Framework {Ruby centric} www.arachni-scanner.com/
- Sn1per is an automated scanner {php} to enumerate and scan for vulnerabilities github.com/1N3/Sn1per
- WhatWeb - Next generation web scanner github.com/urbanadventurer/WhatWeb
- Cloudflare's in-house lightweight network vulnerability scanner blog.cloudflare.com/introducing-flan-scan/ and github.com/cloudflare/flan
- OWASP-Nettacker - Automated Penetration Testing Framework github.com/zdresearch/OWASP-Nettacker
- Jaeles - An extensible framework written in Go for building your own Web Application Scanner. github.com/jaeles-project/jaeles
- Some starter scripts to (help) set up a clean Windows 10 endpoint: github.com/Hecsall/clean-windows
- windows-privesc-check - Security Auditing Tool For Windows code.google.com/archive/p/windows-privesc-check/source/default/source and github.com/1N3/PrivEsc/blob/master/windows/windows-privesc-check/windows-privesc-check.py
- securitywing.com/63-web-application-security-checklist-auditors-developers/ (very high level)
- Website fingerprint script github.com/bgiarrizzo/website-fingerprint
- Awesome Mainframe Hacking/Pentesting Resources.github.com/samanL33T/Awesome-Mainframe-Hacking/
- Excellent list of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc. github.com/toniblyx/my-arsenal-of-aws-security-tools
- Audit and secure your AWS environment(s): YATAS "is a simple and easy to use tool to audit your infrastructure for misconfiguration or potential security issues." ..."The goal of YATAS is to help you create a secure AWS environment without too much hassle." github.com/padok-team/yatas and www.primates.dev/aws-security-misconfiguration-audit-in-30-seconds/
- AWS is a gigantic ecosystem. There may be opportunities that you are not yet aware of: github.com/donnemartin/awesome-aws
- CloudGoat, Rhino Security Labs' "Vulnerable by Design" AWS deployment tool. github.com/RhinoSecurityLabs/cloudgoat
- Offensive security testing of your AWS environment github.com/RhinoSecurityLabs/pacu
- Offensive security testing of your CMS - CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 170 other CMSs github.com/Tuhinshubhra/CMSeeK
- Tool-X - a kali linux tool installer for Android Termux github.com/rajkumardusad/Tool-X
- An interesting study script intended to automate your reconnaissance work github.com/0blio/lazyrecon
- Abbreviated vulnerability assessment/recon github.com/jivoi/pentest
- 'domain-scan' A lightweight scan pipeline for orchestrating third party tools, at scale and (optionally) using serverless infrastructure github.com/18F/domain-scan
- Offensive Web Testing Framework (OWTF), is a framework github.com/owtf/owtf
- Offensive Web Application Penetration Testing Framework github.com/0xInfection/TIDoS-Framework
- Metabigor - An Intelligence tool to do OSINT tasks and more but without any API keys. github.com/j3ssie/metabigor
- ReconFTW automates some reconnaisance activities. github.com/six2dez/reconftw
- Reconnoitre: A reconnaissance tool made for the OSCP labs to automate information gathering and service enumeration whilst creating a directory structure to store results, findings and exploits used for each host, recommended commands to execute and directory structures for storing loot and flags. github.com/codingo/Reconnoitre
- Jenkins Pentesting github.com/gquere/pwn_jenkins
- Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit github.com/0xInfection/XSRFProbe
- Cross Site Scripting detection suite github.com/s0md3v/XSStrike
- Web Application Firewall Fingerprinting Tool github.com/EnableSecurity/wafw00f
- Know your network -- The Ultimate PCAP weberblog.net/the-ultimate-pcap/
- BurpSuite
- OWASP Zap
- HUNT Suite is a collection of Burp Suite Pro/Free and OWASP ZAP extensions github.com/bugcrowd/HUNT
- Deploy a private Burp Collaborator Server in Azure. By Javier Olmedo, Jun 17, 2019 medium.com/bugbountywriteup/deploy-a-private-burp-collaborator-server-in-azure-f0d932ae1d70
- and Chrome's internal URLs for problem solving chrome://chrome-urls/
- DNS research github.com/ogham/dog
- Some domains might be outside your intended target list? See the official, full list of registered domains in the .gov zone. The US Government's executive, legislative, and judicial branches are represented, as are US-based state, territory, tribal, city, and county governments: github.com/cisagov/dotgov-data
- There may be some additional useful information you might extract from the target's DNS records -- see "You’re Closer Than You Think: The Only 6 DNS Concepts You Really Need." that includes a "complete list of DNS Functionality and Descriptions" that might help you think it through.
- HTTPie, a user-friendly command-line HTTP client for the API era httpie.io/
- nmap tutorial github.com/gnebbia/nmap_tutorial
- Using custom nmap port sets bsago.me/tech-notes/custom-nmap-port-sets
- Scanners Box [also known as scanbox] is a sizable, categorized collection of scanners from across GitHub.com github.com/We5ter/Scanners-Box
- Very simple Python-based recon github.com/naltun/eyes.py
- Damn Small JS Scanner (DSJS) is a JavaScript library vulnerability scanner github.com/stamparm/DSJS
- What might those PDF files be hiding? Here are some tools that can help you automate the answer(s):
- Awk/gawk manual www.gnu.org/software/gawk/manual/gawk.pdf
- Airbus security lab publications airbus-seclab.github.io/ and their tools at github.com/airbus-seclab/
- Run your own VPN(s) github.com/trailofbits/algo
- "8 Best VPNs in 2021: Tested All Apps, Speed, Security & More." by Chase Williams September 01, 2021 www.wizcase.com/vpn-reviews/
- Email address parser from website list github.com/skeitel/Python-Programs-and-Exercises-by-Javier-Marti/blob/master/email_parser_from_website_list.py
- Detect secrets within a code base github.com/Yelp/detect-secrets
- git-secrets -- Prevents you from committing passwords and other sensitive information to a git repository github.com/awslabs/git-secrets
- Python script to check HTTP security headers github.com/juerkkil/securityheaders
- sslyze github.com/iSECPartners/sslyze
- Sometimes it is important to carefully explore the content of given resources. Here is an excellent, comprehensive Unicode reference jrgraphix.net/research/unicode_blocks.php
- OK. You found your way to a remote shell or access to arbitrary remote code execution -- what next?
- In order to better understand your options, consider what kernel vulnerabilities are present on that target. An option for that is the shell script
LES(Linux privilege escalation auditing tool), it is "designed to assist in detecting security deficiencies for a given Linux kernel/Linux-based machine." github.com/The-Z-Labs/linux-exploit-suggester ... Before you get too busy with that, you might use it on your own Linux platforms to see if you are vulnerable. - If you land on a Windows platform: "WES-NG is a tool based on the output of Windows' systeminfo utility which provides the list of vulnerabilities the OS is vulnerable to, including any exploits for these vulnerabilities. Every Windows OS between Windows XP and Windows 11, including their Windows Server counterparts, is supported." github.com/bitsadmin/wesng
- In order to better understand your options, consider what kernel vulnerabilities are present on that target. An option for that is the shell script
- Velociraptor - Endpoint visibility and collection tool github.com/Velocidex/velociraptor. This is a feature rich toolset that contains tooling that may have value in your vulnerability assessments. Caution: Like any endpoint monitoring tool, there is a risk that it can be used in unintended ways. In Sept. 2025 threat actors are using Velociraptor endpoint monitoring feature set to deploy Visual Studio Code for command and control tunneling, likely to establish persistent backdoor access.
- You will regularly need to know if something you started is finished, or get notified of an event you are waiting for. ntfy is a fantastic service that lets you send push notifications to your phone or desktop via scripts from any computer, using simple HTTP PUT or POST requests. I use it to notify myself when scripts fail, or long-running commands complete. ntfy.sh/
- OWASP BLT 🐜🪳 bug 🦗🪰 logging tool github.com/OWASP-BLT/BLT
- ArchStrike (idle since 2021) archstrike.org
- BackBox backbox.org/
- Blackarch blackarch.org/ and github.com/BlackArch/blackarch
- Caine Security www.caine-live.net
- DemonLinux demonlinux.com/about.php
- Fedora Security Lab labs.fedoraproject.org/en/security/
- Kali www.kali.org/
- Network Security Toolkit, NST www.networksecuritytoolkit.org/nst/index.html
- Parrot Security OS www.parrotsec.org/
- Shell Script to Convert Your Debian Into Parrot OS Pentesting Mach1ne github.com/blackhatethicalhacking/parrotfromdebian
- Pentoo www.pentoo.ch/
- mx-live-usb-maker github.com/MX-Linux/mx-live-usb-maker and github.com/MX-Linux/lum-qt-appimage/releases
- and some Security-oriented Docker containers github.com/khast3x/Offensive-Dockerfiles
- and a cloud-enabled approach to the same idea, RedCloud github.com/khast3x/Redcloud
- and if you need a little Linux help gto76.github.io/linux-cheatsheet/ and github.com/gto76/linux-cheatsheet
Explore your Live Linux Kernel Image - Berkeley Packet Filters & eBPF
- BPF Compiler Collection (BCC) - Tools for BPF-based Linux IO analysis, networking, monitoring, and more github.com/iovisor/bcc
- yougetsignal www.yougetsignal.com/tools/open-ports/
- Reverse IP Domain Check www.yougetsignal.com/tools/web-sites-on-web-server/
- Network Location Check www.yougetsignal.com/tools/network-location/
- viewdns [a range of dns tools] viewdns.info/
- hackertarget hackertarget.com/nmap-online-port-scanner/
- Dump links from a page hackertarget.com/extract-links/
- And a range of related tools hackertarget.com/ip-tools/
- ipfingerprints www.ipfingerprints.com/portscan.php
- pingeu ping.eu/port-chk/
- spiderip spiderip.com/online-port-scan.php
- t1shopper www.t1shopper.com/tools/port-scan/
- Whois Ping Port Scanner NSlookup & Traceroute @ t1shopper www.t1shopper.com/tools/
- standingtech portscanner.standingtech.com/
- Convert IP Address to Binary, Hexadecimal, Octal, and Long Integer ipaddress.standingtech.com/online-ip-address-converter
- Or use a Python-based command-line utility for using websites that can perform port scans on your behalf github.com/vesche/scanless
- Fortify Taxonomy of Secure Software Errors. vulncat.fortify.com/en
- Awesome App-Sec. A curated list of resources for learning about application security. github.com/paragonie/awesome-appsec
- Static analysis tools for all programming languages github.com/analysis-tools-dev/static-analysis
- Awesome Static Analysis - a collection of static analysis tools and code quality checkers. github.com/mre/awesome-static-analysis
- Python Taint -- pyt -- A Static Analysis Tool for Detecting common Security Vulnerabilities in Python Web Applications github.com/python-security/pyt
- Bandit -- A security linter for detecting common security vulnerabilities in Python applications github.com/PyCQA/bandit
- Clair is an open source project for the static analysis of vulnerabilities in application containers (currently including OCI and docker) github.com/quay/clair
- Awesome CI {Continuation Integration}, Incl. tools for git, file and static source code security analysis - github.com/cytopia/awesome-ci
- "Avoiding the Top 10 Security Flaws." Design guidance by the IEEE Center for Secure Design (CSD), cybersecurity.ieee.org/center-for-secure-design/avoiding-the-top-10-security-flaws.html
- The IEEE Computer Society Center for Secure Design. cybersecurity.ieee.org/center-for-secure-design.html
- The OWASP Application Security Verification Standard (ASVS) Project attempts to provide a basis for testing web application technical security controls. owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project
- OWASP Cheat Sheet Series -- a collection of high value information on specific web application security topics owasp.org/index.php/Cheat_Sheets and cheatsheetseries.owasp.org/
- Or if just getting the code to work first is your issue: github.com/Neklaustares-tPtwP/Resources/tree/main/Cheat%20Sheets
- Collection of OWASP Web Application Security Testing Cheat Sheets owasp.org/index.php/Web_Application_Security_Testing_Cheat_Sheet
- Web Application Security Guide/Checklist en.wikibooks.org/wiki/Web_Application_Security_Guide/Checklist
- CSRN Security Checklist for Software Developers security.web.cern.ch/security/recommendations/en/checklist_for_coders.shtml
- Web Application Security Guide en.wikibooks.org/wiki/Web_Application_Security_Guide
- DISA Information Assurance Support Environment public.cyber.mil/
- Security Technical Implementation Guides (STIGs) public.cyber.mil/stigs/
- Application Security STIGs hhttps://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security
- Application Security and Development Security Technical Implementation Guide, Version 5, Release 1 - 26 October 2020 dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_ASD_V5R1_STIG.zip
- DoD Cloud Computing Security public.cyber.mil/stigs/downloads/?_dl_facet_stigs=cloud-security-stigs
- IASE Application Security dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_ASD_V5R1_STIG.zip
- Excellent STIG viewer www.stigviewer.com/stigs
- Equally excellent Common Controls viewer www.unifiedcompliance.com/products/search-controls/
- DOD Instruction 8500.2 Full Control List www.stigviewer.com/controls/8500
- NIST 800-53 Controls Veiwer www.stigviewer.com/controls/800-53
- Unified Compliance Hub for navigating the ever-evolving rats nest of public and private mandates www.unifiedcompliance.com/products/
- www.cheatography.com/tag/programming/
- PortSwigger's Cross-site scripting (XSS) cheat sheet portswigger.net/web-security/cross-site-scripting/cheat-sheet
- A small collection of XSS-Payloads github.com/terjanq/Tiny-XSS-Payloads
- XSS-Payloads github.com/RenwaX23/XSS-Payloads
- Awesome XSS github.com/s0md3v/AwesomeXSS
- XSS Prevention Cheat Sheet from OWASP: owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet
- Fortify Taxonomy of Secure Software Errors. vulncat.fortify.com/en
- Java Deserialization Cheat Sheet github.com/GrrrDog/Java-Deserialization-Cheat-Sheet
- The Offensive 360 Knowledge base knowledge-base.offensive360.com/
- HTTP Status Codes on-line httpstatuses.com/
- HTTP Status Codes local github.com/mychris/scripts/blob/master/httpstatus
- IANA Hypertext Transfer Protocol (HTTP) Status Code Registry www.iana.org/assignments/http-status-codes/http-status-codes.xhtml
- Sometimes it is just important to get started: "Hello world in every computer language." github.com/leachim6/hello-world
- And a 'free' temporary platform may also be important: "A list of SaaS, PaaS and IaaS offerings that have free tiers of interest to devops and infradev." github.com/haneefmubarak/free-for-dev
- Collection of the most common vulnerabilities found in iOS applications github.com/felixgr/secure-ios-app-dev
- Application logging guidance github.com/mccright/references/blob/master/AppSec-Logging.md
- AWS logging guidance betterdev.blog/aws-lambda-logging-best-practices/
- One approach to logging in your shell scripts www.cubicrace.com/2016/03/efficient-logging-mechnism-in-shell.html
- The TIOBE Index of programming language popularity www.tiobe.com/tiobe-index/
- A collection of ready-to-deploy-in-AWS Serverless Framework services github.com/serverless/examples
- An evolving "command-line tool allowing developers to find security vulnerabilities within a Java project." It incorporates some static analysis (SAST) and some software composition analysis (SCA). github.com/xJonah/REPELSEC
- A useful script to help manage Java installation and removal on your Linux host github.com/chrishantha/install-java
- An edge case: Protecting your scripts - PowerShell, Visual Basic (VB), and C# code obfuscation -- "A Beginner's Guide to Obfuscation" github.com/BC-SECURITY/Beginners-Guide-to-Obfuscation
- Attack-resistant programming requires a threshold understanding of your current language.
esolang-boxis an "easy and standardized docker images for 200+ esoteric (and non-esoteric) languages." github.com/hakatashi/esolang-box - A Python implementation of RFC 7519. github.com/jpadilla/pyjwt
- Awesome PHP. A curated list of PHP libraries, resources and shiny things. github.com/ziadoz/awesome-php
- www.cheatography.com/tag/php/
- PHP Security Guide, 2005. phpsec.org/projects/guide/
- Survive The Deep End: PHP Security, 2015. phpsecurity.readthedocs.org/en/latest/
- Hacking with PHP -> Securty Concerns. www.hackingwithphp.com/17/0/0/security-concerns
- PHP The Right Way -> Security. www.phptherightway.com/#security
- PHP Best Practices -- A short, practical guide for common and confusing PHP tasks: phpbestpractices.org/
- Describe the environment (sometimes for Python troubleshooting): github.com/rapidsai/cudf/blob/branch-25.10/print_env.sh
- Fun. Image2Text utilities: github.com/vietnh1009/ASCII-generator
- "The Complete Python Development Guide." testdriven.io/guides/complete-python/
- Hitchhiker's Guide to Python github.com/realpython/python-guide
- and its 'Web Applications & Frameworks' section github.com/realpython/python-guide/blob/master/docs/scenarios/web.rst
- Python Cheatsheet, comprehensive gto76.github.io/python-cheatsheet/ and github.com/gto76/python-cheatsheet
- Python Cheatsheet cheatsheets.quantecon.org/python-cheatsheet.html
- another Python CheatSheet - my current favorite perso.limsi.fr/pointal/_media/python:cours:mementopython3-english.pdf
- A small collection of Python cheatsheets github.com/Neklaustares-tPtwP/Resources/tree/main/Cheat%20Sheets/Python%20%26%20All%20Libraries%20Cheat%20Sheets
- Python Cheatsheet from kickstartcoding github.com/kickstartcoding/cheatsheets/blob/master/build/topical/python.pdf
- A neat set of PDF topical Python cheatsheets by the author of "Python Crash Course" by Eric Matthes ehmatthes.github.io/pcc/cheatsheets/README.html and another version for the 2nd edition of PCC at ehmatthes.github.io/pcc_2e/cheat_sheets/cheat_sheets/
- The standard Python resources:
- Main website: python.org/
- Documentation: docs.python.org/
- Developer resources: devguide.python.org/
- Downloads: www.python.org/downloads/
- Module repository: pypi.org/
- 73 Examples to Help You Master Python's f-strings miguendes.me/73-examples-to-help-you-master-pythons-f-strings
- Docker Official Python Images hub.docker.com/_/python
- A deep dive into the official Docker image for Python pythonspeed.com/articles/official-python-docker-image/
- The best Docker base image for your Python application (April 2020) tl;dr; Ubuntu LTS or Docker Official Python Debian pythonspeed.com/articles/base-image-python-docker-images/
- "Docker Best Practices for Python Developers" By Amal Shaji 2021-10-05 testdriven.io/blog/docker-best-practices/
- "Don't leak your Docker image's build secrets." By Itamar Turner-Trauring, 2021-10-01 pythonspeed.com/articles/docker-build-secrets/
- unblob parses unknown binary blobs for more than 30 different archive, compression, and file-system formats, extracts their content recursively, and carves out unknown chunks that have not been accounted for -- just what is needed to explore docker images: github.com/onekey-sec/unblob
- PyFormat Using % and .format() pyformat.info/
- Python's strftime directives strftime.org/
- Python's Pathlib explained rednafi.github.io/digressions/python/2020/04/13/python-pathlib.html
- Type hints cheat sheet (Python 3) mypy.readthedocs.io/en/stable/cheat_sheet_py3.html
- Write Pythonic Code Like a Seasoned Developer Course training.talkpython.fm/courses/explore_pythonic_code/write-pythonic-code-like-a-seasoned-developer and github.com/mikeckennedy/write-pythonic-code-demos
- 71 Python Code Snippets for Everyday Problems therenegadecoder.com/code/python-code-snippets-for-everyday-problems/#checking-if-a-file-exists
- 30-seconds-of-python - Curated collection of useful Python snippets that you can understand in 30 seconds or less github.com/30-seconds/30-seconds-of-python
- Packaging Projects with Python github.com/russomi/packaging_tutorial and packaging.python.org/tutorials/packaging-projects/
- MATLAB–Python–Julia cheatsheet cheatsheets.quantecon.org/
- Awesome Python -- A curated list of awesome Python frameworks, libraries and software. Inspired by awesome-php. github.com/vinta/awesome-python
- Best-of Web Development with Python, curated & ranked list github.com/ml-tooling/best-of-web-python
- Awesome Python Security github.com/guardrailsio/awesome-python-security
- Awesome Flask github.com/mjhea0/awesome-flask
- Python Docker image with poetry as dependency manager. github.com/etienne-napoleone/docker-python-poetry
- Pythonic Data Structures and Algorithms github.com/keon/algorithms
- 'All' Algorithms implemented in Python ("may be less efficient than the implementations in the Python standard library. Use them at your discretion.") github.com/TheAlgorithms/Python
- Like the safety of with statements, just not in your code? Let 'just' take care of it github.com/kootenpv/just
- Error-handling examples: github.com/ianozsvald/python_exception_examples/blob/master/examples.py
- pymg is a CLI tool that can interpret Python files by the Python interpreter and display the error message in a more readable way if an exception occurs github.com/mimseyedi/pymg
- Datetime examples: github.com/ianozsvald/datetime-examples/blob/master/examples.py
- Scientific Python Cheatsheet ipgp.github.io/scientific_python_cheat_sheet/
- "10 Useful Python Data Visualization Libraries for Any Discipline" by Melissa Bierly blog.modeanalytics.com/python-data-visualization-libraries/
- Counting things in Python treyhunner.com/2015/11/counting-things-in-python/
- Crypto101: an introductory course on cryptography. www.crypto101.io/
- The Data Scientist's Toolbox www.coursera.org/learn/data-scientists-tools
- Compiler-free Python crypto library github.com/wbond/oscrypto
- Python library to convert Microsoft Outlook .msg files to .eml/MIME message files github.com/JoshData/convert-outlook-msg-file
- Understanding iteration in Python github.com/wyounas/python_training_hq/tree/master/blog_iterator_code_samples
- Virtualenv virtualenv.pypa.io/en/latest/installation.html and a how-to www.youtube.com/watch?v=N5vscPTWKOk
Along with related/supporting projects:- virtualenvwrapper - a useful set of scripts for creating and deleting virtual environments pypi.org/project/virtualenvwrapper
- pew: provides a set of commands to manage multiple virtual environments pypi.org/project/pew
- tox: a generic virtualenv management and test automation command line tool, driven by a tox.ini configuration file pypi.org/project/tox
- nox: a tool that automates testing in multiple Python environments, similar to tox, driven by a noxfile.py configuration file pypi.org/project/nox
- And a how-to www.youtube.com/watch?v=N5vscPTWKOk
- How to write good quality Python code with GitHub Actions. By Wojciech Krzywiec medium.com/@wkrzywiec/how-to-write-good-quality-python-code-with-github-actions-2f635a2ab09a
- Automating Every Aspect of Your Python Project martinheinz.dev/blog/17
- An open-source chart and map framework for realtime data github.com/pubnub/eon
- Datagen - create sample delimited data using a simple schema format so you can get to work github.com/toddwilson/datagen
- An asynchronous tasks library using asyncio github.com/joegasewicz/pytask-io
- Render local readme files before sending off to GitHub github.com/joeyespo/grip and a sample Python script to generate bulk documentation gist.github.com/mrexmelle/659abc02ae1295d60647
- A general purpose Python automatization library with real-time web UI github.com/tuomas2/automate
- tmux session manager github.com/tmux-python/tmuxp
- web.py is a web framework for Python that is as simple as it is powerful. github.com/webpy/webpy
- Need to upgrade ad-hoc calls to Requests with a client-side API for your apps? github.com/prkumar/uplink
- A basic spreadsheet to api engine github.com/18F/autoapi
- Blog with git github.com/joeyespo/gitpress
- deadlinks - link checker github.com/butuzov/deadlinks
- A rough RSS/Atom feed parser github.com/dcramer/feedreader
pyautogit github.com/jwlodek/pyautogit - Library of 60+ commonly-used validator functions github.com/insightindustry/validator-collection
- A python library for parsing multiple types of config files, envvars & command line arguments github.com/naorlivne/parse_it
- Some examples of how to use the Python module ‘configparser‘ github.com/revfran/pythonConfigParsing, github.com/VakinduPhilliam/Python_Configuration_Parser
- Search for strings in source code - at scale github.com/s0md3v/hardcodes
- Present data in tables on your terminal github.com/Robpol86/terminaltables
- Another tool for presenting data in tables github.com/jazzband/prettytable
- Progress bar github.com/verigak/progress
- present: A terminal-based presentation tool with colors and effects. github.com/vinayak-mehta/present
- Color your script output with github.com/gvalkov/python-ansimarkup or on Windows with pypi.python.org/pypi/colorama
- Colorpedia - a command-line tool for looking up colors, shades and palettes github.com/joowani/colorpedia
- "Python requests is slow and takes very long to complete HTTP or HTTPS request" -- This is fantastic troubleshooting guidance and advice! stackoverflow.com/questions/62599036/python-requests-is-slow-and-takes-very-long-to-complete-http-or-https-request
- nmappy may not be the right scanner for you, but you might find its Python source code might be interesting as it attempts to solve a range of network-centric challenges: github.com/bitsadmin/nmappy/blob/master/nmappy.py
- "Building a Full Stack Application with Flask and HTMx" codecapsules.io/docs/tutorials/build-flask-htmx-app/ and github.com/codecapsules-io/demo-flask-htmx
- Generate random user agent strings
- Now that you have a pile of Python code, here is a utility to build presentations out of Python code: pysentation, a CLI for displaying Python presentations github.com/mimseyedi/pysentation
- github.com/adam-p/markdown-here/wiki/Markdown-Cheatsheet
- docs.github.com/en/get-started/writing-on-github
- bitbucket.org/tutorials/markdowndemo
- Markdown Cheatsheet commonmark.org/help/
- guides.github.com/pdfs/markdown-cheatsheet-online.pdf
- GitHub Flavored Markdown Spec github.github.com/gfm/
- Another GitHub Flavored Markdown cheatsheet github.com/tchapi/markdown-cheatsheet
- Collection of static site generators jamstack.org/generators/ and staticsitegenerators.net/
- Static site generator written in Python github.com/getpelican/pelican
- Very basic marijnhaverbeke.nl/js-cheatsheet.html
- www.cheatography.com/acwinter/cheat-sheets/javascript-basic-advanced-and-more/ and
- www.cheatography.com/tag/javascript/ and
- www.sitepoint.com/10-javascript-cheat-sheets/
- Learning JavaScript Design Patterns. Volume 1.6.2, By Addy Osmani addyosmani.com/resources/essentialjsdesignpatterns/book/
- Programming JavaScript Applications. By Eric Elliott chimera.labs.oreilly.com/books/1234000000262/index.html
- Cheatsheets for experienced React developers getting started with TypeScript github.com/typescript-cheatsheets/react-typescript-cheatsheet
- Node: Up and Running. By Tom Hughes-Croucher and Mike Wilson chimera.labs.oreilly.com/books/1234000001808/index.html
- Narrative workbook -- This is a companion workbook that will assist you in working through the codeX Narrative that is to be provided. Resources and references provided that will assist you in your journey will be published in the repository. github.com/codex-academy/codeX_ReleaseOneNarrativeWorkbook
- "Don't make fun of JavaScript" github.com/pixari/dmfojs
- Matthew Green's List of Crypto Resources: blog.cryptographyengineering.com/
- Crypto101: an introductory course on cryptography. www.crypto101.io/
- A good place to get an overview of the correct tools to use for modern cryptography is "(Updated) Cryptographic Right Answers" by Thomas Ptacek (Thank you William Bond): gist.github.com/tqbf/be58d2d39690c3b366ad
- Peter Gutmann (a researcher at the University of Auckland) assembled his "godzilla crypto tutorial," including 973 slides in 12 parts at: www.cs.auckland.ac.nz/~pgut001/tutorial/index.html Although this material is not new, it still seems like a resource that will be of value to many.
- pyca/cryptography - A package providing cryptographic recipes and primitives to Python developers, with the goal of being your "cryptographic standard library". github.com/pyca/cryptography
- A fast, pure Python library for parsing and serializing ASN.1 structures. github.com/wbond/asn1crypto
- Compiler-free Python crypto library github.com/wbond/oscrypto
- PyNaCl: Python binding to the libsodium library github.com/pyca/pynacl
- The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis gchq.github.io/CyberChef and github.com/gchq/CyberChef
- Here is an example of using CyberChef to to deobfuscate malware: "Advanced Cyberchef Techniques - Defeating Nanocore Obfuscation With Math and Flow Control"
- Or search for other projects (there are lots of them) with: github.com/search?q=cryptography&type=repositories
- Or local search with monkeSearch github.com/monkesearch/monkeSearch
- RFC 9180 Hybrid public-key encryption (HPKE) See a useful overview from CloudFlare: blog.cloudflare.com/hybrid-public-key-encryption/.
- Test your regex on line: regex101.com/ or
- test your regex with: pythex.org/
- test and visualize your regex with: extendsclass.com/regex-tester.html
- Test your JavaScript style regex: regexper.com/
- Test your Python style regex: pythonium.net/regex
- OWASP Validation Regex Repository owasp.org/index.php/OWASP_Validation_Regex_Repository
- A really big collection of regex resources regexlib.com/
- www.cheatography.com/davechild/cheat-sheets/regular-expressions/ and
- www.cheatography.com/tag/regex/
- Another collection of examples: www.regular-expressions.info/examples.html
- Includes a collection of regexes for apikeys/tokens github.com/m4ll0k/SecretFinder/blob/master/BurpSuite-SecretFinder/SecretFinder.py
- "Regular Expressions: Regexes in Python" by John Sturtz realpython.com/regex-python/ and part 2 realpython.com/regex-python-part-2/
- Related... Personally Identifiable Information (PII) Redactor shell script github.com/infinite-omicron/pii-redactor/blob/master/pii_redactor.sh
- Guide to Batch Scripting steve-jansen.github.io/guides/windows-batch-scripting/
A starter list of information sources for your security investigations & integrations:
(Thank you github.com/cloudtracer/ThreatPinchLookup for some of this list)
- What defines a “material” cybersecurity incident? Lacework released a Securities and Exchange Commission (SEC) materiality framework paper www.lacework.com/resource/sec-materiality-framework.html
- Awesome OSINT github.com/jivoi/awesome-osint
- Ammar Amer's OSINT resources github.com/blaCCkHatHacEEkr/OSINT_TIPS
- Discover Your Attack Surface github.com/intrigueio/intrigue-core
- Alienvault OTX for IPv4, CVE, MD5, SHA1 and SHA2 lookups otx.alienvault.com/
- Bitcoin Whos Who for Bitcoin lookups bitcoinwhoswho.com/
- BlockChain.info for Bitcoin lookups blockchain.info/
- BTC for Bitcoin lookups btc.com/
- Censys.io for IPv4 lookups censys.io/
- CIRCL (Computer Incident Response Center Luxembourg) for CVE lookups www.circl.lu/
- Google Safe Browsing for URL lookups safebrowsing.google.com/
- Have I Been Pwned for Email lookups haveibeenpwned.com
- IBM XForce Exchange for IPv4, EFQDN lookups exchange.xforce.ibmcloud.com
- IP Geo Tool {free} for your script integration: [tools.keycdn.com/geo.json?host={IP or hostname}](https://tools.keycdn.com/geo.json?host={IP or hostname}) Important: See tools.keycdn.com/geo for configuring your request header User-Agent string correctly.
- MISP for MD5 and SHA2 www.misp-project.org/
- Also consider MISP Taxonomies for your integration work github.com/MISP/misp-taxonomies/
- PassiveTotal for FQDN Whois lookups www.passivetotal.org/
- PulseDive for IPv4, FQDN and URL lookups pulsedive.com/
- Recorded Future for IPv4, FQDN, MD5, SHA1 and SHA2 lookups recordedfuture.com/
- For IP lookups and much more:
- Shodan www.shodan.io/
- Search Query Fundamentals: help.shodan.io/the-basics/search-query-fundamentals
- REST and Streaming API Queries: developer.shodan.io/api/banner-specification
- Docker image to run Shodan CLI: github.com/crazy-max/docker-shodan
- Greynoise viz.greynoise.io/trends
- ZoomEye for IPv4 lookups www.zoomeye.org/
- Cloud IP Ranges github.com/nccgroup/cloud_ip_ranges
- CDN IP Ranges github.com/six2dez/ipcdn
- Shodan www.shodan.io/
- ThreatCrowd for IPv4, FQDN and MD5 lookups www.threatcrowd.org/
- ThreatMiner: IPv4, Email, FQDN, MD5, SHA1 and SHA2 lookups www.threatminer.org/
- Wigle for WiFi wigle.net/
- Sourcecode Search publicwww.com/
- Utility to identify active committers participating in targeted repositories or github.com organizations. github.com/kaakaww/contributors_tool
- Find professional email addresses hunter.io/
- VirusTotal for MD5, SHA1, SHA2, URL and FQDN lookups www.virustotal.com/
- Buster, An advanced tool for email reconnaissance github.com/sham00n/buster
- WayBulk, Search a list of domains on the wayback machine github.com/sham00n/waybulk
- General outline of information about a specific host or domain webrate.org/site/website-hostname/ (replace "website-hostname" with your target.)
- Bluetooth "Wall of Sheep." "A little app that discovers bluetooth devices near by and displays them on a board." github.com/skittleson/bluetooth-wos
- Statistics in Pandas Cheatsheet cheatsheets.quantecon.org/stats-cheatsheet.html
- Manish Saraswat's list of Free books on statistics mathematics data science www.analyticsvidhya.com/blog/2016/02/free-read-books-statistics-mathematics-data-science/
- Chen's Free Data Science Books www.wzchen.com/data-science-books/
- balban's Free Statistics Books github.com/balban/Books/tree/master/Statistics
- "Unsupervised Cross-lingual Representation Learning at Scale" by Alexis Conneau and Kartikay Khandelwal, et.al. arxiv.org/pdf/1911.02116.pdf
- "What Is a Time-Series Plot, and How Can You Create One?" www.timescale.com/blog/what-is-a-time-series-plot-and-how-can-you-create-one/
- "How to Work With Time Series in Python?" www.timescale.com/blog/how-to-work-with-tim/
- "Tools for Working With Time-Series Analysis in Python" www.timescale.com/blog/tools-for-working-with-time-series-analysis-in-python/
- Complete guide to create a Time Series Forecast (Python) www.analyticsvidhya.com/blog/2016/02/time-series-forecasting-codes-python/ and in R www.analyticsvidhya.com/blog/2015/12/complete-tutorial-time-series-modeling/
- functime is a Python library for production-ready global forecasting and time-series feature engineering (comes with time-series preprocessing (box-cox, differencing etc), cross-validation splitters (expanding and sliding window), and forecast metrics (MASE, SMAPE etc)) github.com/descendant-ai/functime
- Mathics is a general-purpose computer algebra system (CAS). The mathics-core repository contains just the Python modules for WL Built-in functions, variables, core primitives, e.g. Symbol, a parser to create Expressions, and an evaluator to execute them. github.com/Mathics3/mathics-core
- VibeVoice: A Frontier Long Conversational Text-to-Speech Model github.com/microsoft/VibeVoice
- eSpeak NG github.com/espeak-ng/espeak-ng
- Using eSpeak and eSpeakNG vitux.com/convert-text-to-voice-with-espeak-on-ubuntu/
- eSpeak NG TTS Bindings for Python3 github.com/sayak-brm/espeakng-python
- Larynx -- This engine provides a complete text-to-speech solution for 9 languages in as many as 50 voices and can be used without any proprietary cloud services (each voice is roughly 250MB). This project includes an easy path using a Docker image. github.com/rhasspy/larynx
- RealtimeTTS is a state-of-the-art text-to-speech (TTS) library designed for real-time applications. It stands out in its ability to convert text streams fast into high-quality auditory output with minimal latency. github.com/KoljaB/RealtimeTTS
- Also see its cousin, RealtimeSTT "Easy-to-use, low-latency speech-to-text library for realtime applications." github.com/KoljaB/RealtimeSTT
- Speech-to-text app "Linguflex" includes local TTS. github.com/KoljaB/Linguflex
- NanoTTS: Speech synthesizer commandline utility (Thank you Gregory Naughton) github.com/gmn/nanotts
- Cheat Sheets from a terminal via curl: cheat.sh/
- OWASP Cheat Sheet Series index: github.com/OWASP/CheatSheetSeries/blob/master/Index.md and cheatsheetseries.owasp.org/
- Massive list of links to lists associated with programming and languages neverendingsecurity.wordpress.com/category/documents-manuals/mind-maps/
- SQL Injection Cheat Sheet www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/
- Collection of SQL Injection Cheat Sheets pentestmonkey.net/cheat-sheet/sql-injection/mssql-sql-injection-cheat-sheet
- Random reminder of how SQL Joins work. blog.codinghorror.com/a-visual-explanation-of-sql-joins/ Browse the comments as well. And if that doesn't do it, try gplivna.blogspot.com/2008/01/sql-join-types-im-studying-bit-sql.html
- "awesome-incident-response" a curated list of tools and resources for security incident response github.com/meirwah/awesome-incident-response
- Incident "Debriefing Facilitation Guide -- Leading Groups at Etsy to Learn From Accidents." by: John Allspaw, Morgan Evans, Daniel Schauenberg; 2016 extfiles.etsy.com/DebriefingFacilitationGuide.pdf and in MarkDown format: github.com/etsy/DebriefingFacilitationGuide
- "Digital Services Playbook." playbook.cio.gov/ and the source in MarkDown at: github.com/usds/playbook
- 101 Machine Learning Algorithms for Data Science with Cheat Sheets blog.datasciencedojo.com/machine-learning-algorithms/
- An extensive list of filetypes and the application(s) associated with them github.com/vscode-icons/vscode-icons/wiki/ListOfFiles
- AppScan Standard and AppScan Enterprise Forum www.ibm.com/developerworks/forums/forum.jspa?forumID=1320&start=0
- Fortify AppSecurity Blog community.microfocus.com/cyberres/tags/Fortify
- Fortify Security Research Blog community.microfocus.com/cyberres/b/off-by-on-software-security-blog
- HP AppSecurity Feed twitter.com/HPappsecurity
- IBM Security-Intelligence Feed securityintelligence.com/
- IBM Research News ibmresearchnews.blogspot.com/
- IBM Research Home www.research.ibm.com/
- IBM Community Blogs www-304.ibm.com/connections/communities/service/html/allcommunities
- IBM DeveloperWorks Blogs -- Recent Updates www.ibm.com/developerworks/
- Microsoft Research Blogs www.microsoft.com/en-us/research/blog/
- Microsoft Cybersecurity Blog www.microsoft.com/security/blog/
- Microsoft Office365 Developer Blog developer.microsoft.com/en-us/office supported by github.com/OfficeDev
- Google Online Security Blog googleonlinesecurity.blogspot.com/
- Google AppSecurity Research www.google.com/about/appsecurity/research/ and supporting details at code.google.com/p/google-security-research/issues/list?can=1
- PortSwigger (Burp) Blog blog.portswigger.net/
- Apple Research News/Blog/Home [oops, I guess there aren't any security blogs here](oops, I guess there aren't any) But Apple hubris is in the press -- Here is a page with links to journalism on the Pegasus Project: www.msnbc.com/rachel-maddow-show/pegasus-project-media-index-n1274437
- Software licensing explained en.wikipedia.org/wiki/Software_license
- Comparison of free and open-source software licenses en.wikipedia.org/wiki/Comparison_of_free_and_open-source_software_licenses
- Open Source Initiative list of links to license information opensource.org/licenses
- "Various Licenses and Comments about Them" from GNU www.gnu.org/philosophy/license-list.html
- "Software Licenses in Plain English -- Lookup popular software licenses summarized at-a-glance." tldrlegal.com/
- APTnotes is a repository of publicly-available papers and blogs (sorted by year) related to malicious campaigns/activity/software that have been associated with vendor-defined APT (Advanced Persistent Threat) groups and/or tool-sets. github.com/aptnotes/data or go directly to the resource links at github.com/aptnotes/data/blob/master/APTnotes.csv
- tinyurl.com/preview.php
- checkshorturl.com/
- URL-Expander / URL-Unshortener urlex.org/
- In a hurry?
- Try asking
- Anthropic's Claude Code,
- Microsoft's copilot,
- OpenAI's ChatGPT,
- Google's Gemini to write what you need.
- Awesome Algorithms -- A curated list of awesome places to learn and/or practice algorithms github.com/tayllan/awesome-algorithms
- Open Source resource for learning Data Structures & Algorithms and their implementation in any Programming Language github.com/TheAlgorithms
- c2.com/cgi/wiki?FindPage
- A large collection of sorting algorithms in many languages github.com/search?q=sorting+algorithms&ref=reposearch&utf8=%E2%9C%93
- Competitive Programming, algorithms and data structures algocoding.wordpress.com/
- virtualenv is a tool to create isolated Python environments virtualenv.pypa.io/en/latest/
- A relatively quick Python Numpy Tutorial by Justin Johnson. cs231n.github.io/python-numpy-tutorial/
- Financial Services Sector "Cybersecurity Profile" - 280 'diagnostic statements' www.fsscc.org/Financial-Sector-Cybersecurity-Profile
- NIST SP-800-53 v4
(in no particular order - and thank you Joe Fleischman for the starter set)
- Krebs On Security krebsonsecurity.com/
- Schneier on Security www.schneier.com/
- IBM X-Force Home securityintelligence.com/topics/x-force/
- Security Bloggers Network securityboulevard.com/sbn/
- News from NetCraft news.netcraft.com/ and their security category at news.netcraft.com/archives/category/security/
- Help Net Security www.net-security.org/secworld_main.php
- Malwarebytes Blog blog.malwarebytes.org/
- Sophos NakedSecurity Blog nakedsecurity.sophos.com/
- FreedomHacker freedomhacker.net/
- Wired Threat Level www.wired.com/category/threatlevel
- Homeland Security News Wire www.homelandsecuritynewswire.com/topics/cybersecurity
- CNET www.cnet.com/topics/security/
- Threat Post threatpost.com/
- SC Magazine www.scmagazine.com/news/section/100/
- Reddit (cybersecurity) www.reddit.com/r/cybersecurity/
- Mashable (cybersecurity) mashable.com/category/cybersecurity/
- Fierce IT Security www.fierceitsecurity.com/
(and for more details) - 1 Raindrop 1raindrop.typepad.com/1_raindrop/
- Information Week Dark Reading www.darkreading.com/
- Dark Reading aggregation of news about attacks and breaches www.darkreading.com/attacks-breaches.asp
- White Hat Security Blog www.whitehatsec.com/blog/
- Sucuri Blog blog.sucuri.net/
- FireEye Blog www.fireeye.com/blog/threat-research.html
- SANS Security Awareness Blog www.securingthehuman.org/blog
- SANS Digital Forensics Blog digital-forensics.sans.org/blog
- SEI Blog insights.sei.cmu.edu/blog/
- System Forensics www.sysforensics.org/
- System Admin, Powershell (inactive) sysadminconcombre.blogspot.ca/
- BOT24 www.bot24.com/
- DDoS Illustrations at www.digitalattackmap.com/ Thank you Diego Navarro.
- Kite Blog: kite.com/blog
- AWS Week in Review: aws.amazon.com/blogs/aws/tag/week-in-review/
- Center for the Study of Intelligence (CSI) Books and Monographs. cia.gov/resources/csi/books-and-monographs/
- Overview: microhams.blob.core.windows.net/content/2017/03/RTL-SDR-dongle.pdf
- FISSURE -- Frequency Independent SDR-based Signal Understanding and Reverse Engineering -- an open-source RF and reverse engineering framework for signal detection and classification, protocol discovery, vulnerability analysis and more github.com/ainfosec/FISSURE
- Big List of SDR Applications: wiki.radioreference.com/index.php/SDR_Software_Applications
- PDW (Paging decoder for monitoring POCSAG, FLEX, ACARS, MOBITEX & ERMES pager traffic): www.discriminator.nl/pdw/index-en.html and github.com/Discriminator/PDW
- Unitrunker: www.unitrunker.com/ (pager RF-to-text?). Manuals at: utahradio.org/mediawiki/index.php/UniTrunker_Guide and www.unitrunker.com/windows.html and www.unitrunker.com/realtek.html
Supported protocols (definitions at: http://wiki.radioreference.com/):
o APCO P25
o EDACS 4800
o EDACS 9600
o Motorola
o MPT1327 - SDRTrunk
- DMRDecode
- ?? Digital Speech Decoder (software package)
- R820T (integrated multi‐band RF tuner IC implemented in CMOS) data sheet: www.rtl-sdr.com/wp-content/uploads/2013/04/R820T_datasheet-Non_R-20111130_unlocked1.pdf
- Rafael Micro R820T2 Data Sheet (24-1766 MHz, newer lower noise version of the R820T): Some info in www.rtl-sdr.com/wp-content/uploads/2018/02/RTL-SDR-Blog-V3-Datasheet.pdf and register descriptions here: www.rtl-sdr.com/r820t2-register-description-data-sheet-now-available/ and www.rtl-sdr.com/wp-content/uploads/2016/12/R820T2_Register_Description.pdf
- Source Code examples for interacting with the R820TU: github.com/emeb/r820t2/tree/master/f030_r820t2
- "Hello, world!" for GNSS-SDR: gnss-sdr.org/my-first-fix/
- Dump 1090 is a Mode S decoder specifically designed for RTLSDR devices github.com/antirez/dump1090
- An improved webinterface for use with ADS-B decoders readsb / dump1090-fa github.com/wiedehopf/tar1090
- U.S. and World Population Clock: census.gov/popclock/
- readNum: This python project turns a number into a readable spelled-out form github.com/theRealProHacker/readNum/
- Review this Awesome Docker list/resource from time to time: github.com/veggiemonk/awesome-docker
- Review this Awesome Remote Job list/resource to see if there is anything useful to me: github.com/lukasz-madon/awesome-remote-job
- Top-like interface for container metrics - ctop provides a concise and condensed overview of real-time metrics for multiple containers github.com/bcicen/ctop or one of the others at github.com/veggiemonk/awesome-docker/blob/master/README.md#terminal
- A collection of minimal Docker images: github.com/vektorcloud
- Another collection of specialized Docker images: github.com/jessfraz/dockerfiles
- A collection of Docker files from CenturyLink Labs: github.com/CenturyLinkLabs?q=&type=&language=dockerfile
- Awesome-Security: github.com/sbilly/awesome-security
- Awesome console services github.com/gnebbia/awesome-console-services
- 'The Book of Secret Knowledge' - A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more: github.com/trimstray/the-book-of-secret-knowledge
- A pair of tools for running phishing campaigns to raise security awareness: Swordphish Phishing Awareness Tool github.com/certsocietegenerale/swordphish-awareness/ and the Outlook add-in companion to report suspicious mail easily github.com/certsocietegenerale/NotifySecurity
- W3C HTML Tidy - Usage:
'curl someURL | Tidy -iq'www.html-tidy.org/ and github.com/htacg/tidy-html5 - CanaryTokens canarytokens.org/generate
- Canary (a 'honeypot' appliance) canary.tools/
- WebSphere Password Decoders: strelitzia.net/wasXORdecoder/wasXORdecoder.html
- Conference Session Search Service - Con Collector (broken) but they still list conferences www.thinkst.com/ts.html
- Some Open Source Network Monitoring Tools:
- Snort: www.snort.org/downloads
- Suricata: suricata-ids.org/
- Bro: www.bro.org/
- OSSEC - Open Source HIDS SECurity ossec.github.io/
- Lists of IP addresses by Country - use to block or to assess your log data, etc. www.ipdeny.com/ipblocks/
- Words are important, choose them well wordnik.com/
- Check a site or service www.hurl.it/
- G Suite Toolbox Browserinfo -- very handy toolbox.googleapps.com/apps/browserinfo/
- A useful set of app-friendly utilities httpbin.org/, for example, what is your current IP address httpbin.org/ip
- A fake DNS server that allows you to stealthily extract files from a victim machine through DNS requests github.com/m57/dnsteal
- A collection of default Oracle usernames and passwords github.com/Oweoqi/oracle_creds
- Sometimes you need a little local web server github.com/kzahel/web-server-chrome
- Sometimes only ASCII is needed/allowed -- Convert a HTML table into ASCII table using Python: Colspan and Rowspan allowed github.com/gustavklopp/DashTable
- Reference (probably dated, but better than nothing) List of all generic top level domains github.com/kyleconroy/gtlds
- FuzzDB Project github.com/fuzzdb-project/fuzzdb
- Free IP geolocation API: 'curl http://api.db-ip.com/v2/free/IP-Address' or curl http://api.db-ip.com/v2/free/IP-Address/countryName [up to 1000/day]
- GetGeoIPContext web service to easily look up countries by Context www.webservicex.net/geoipservice.asmx/GetGeoIPContext? (Caution: as of October 2021, they are using a self-signed certificate)
- GetGeoIP web service to easily look up countries by IP address www.webservicex.net/geoipservice.asmx/GetGeoIP?IPAddress=string
- Get domain name registration record by Host Name / Domain Name (WhoIS) www.webservicex.net/whois.asmx/GetWhoIS?HostName=string
- Get a Weather report on the command line:
- Here is my contribution: github.com/mccright/weather-in-terminal
- Get weather report for any major cities around the world www.webservicex.net/globalweather.asmx/GetWeather?CityName=string&CountryName=string
- Another way to get weather ...in your terminal github.com/chubin/wttr.in and then try some one-liners, for example:
- ~$ curl https://wttr.in/yourCity?format="%l:+%t+%w+%h+%f"
- in your .bashrc: alias weather='curl https://wttr.in/yourCity'
- A high-functioning command line tool that displays the current weather (from OpenWeather) in the terminal written in Rust github.com/gourlaysama/girouette
- Website style analyzer for designers stylifyme.com/ and source at: github.com/micmro/Stylify-Me
- A python script that generates different sizes favicons from one image github.com/Hecsall/favicon-generator
- github.com/alebcay/awesome-shell
- Bash scripting CheatSheet devhints.io/bash
- Bash for the shell novice:
- Shell script static analysis tool -- a lint for bash/sh/zsh shellcheck
- Pure Bash Bible github.com/dylanaraps/pure-bash-bible
- Bash Strict Mode by Aaron Maxwell redsymbol.net/articles/unofficial-bash-strict-mode/
- Slack CLI via pure bash github.com/rockymadden/slack-cli
- github.com/herrbischoff/awesome-osx-command-line
- A beginner's guide to setting up a development environment on macOS github.com/nicolashery/mac-dev-setup
- A collection of one-liners github.com/jlevy/the-art-of-command-line#one-liners
- Terminal Browsers: It happens that needing freeform access to explore some Internet resources while constrained to a terminal interface is not that uncommon. Here are a some options (thanks to Mats Tage Axelsson, LXF280)
- AP Fact Check: https://www.ap.org/
- Check Your Fact: https://checkyourfact.com/
- El Detector / Univision Noticias: https://www.univision.com/especiales/noticias/detector/
- FactCheck.org, Annenberg Public Policy Center: https://www.factcheck.org/
- MediaWise: https://www.poynter.org/mediawise/
- Politifact: http://www.politifact.com/
- Snopes: https://www.snopes.com/
- T Verifica (Noticias Telemundo): https://www.telemundo.com/noticias/t-verifica
- The Dispatch Fact Check: https://thedispatch.com/
This started with a subset of the longer list at: https:// ifcncodeofprinciples.poynter.org/signatories
- A beginner's guide to setting up a development environment on macOS github.com/nicolashery/mac-dev-setup
- "A shell script which turns your Mac into an awesome web development machine." github.com/18F/laptop
- Find a class at https://www.classcentral.com/search or https://www.classcentral.com/subjects
- Find out about assistance at: https://www.classcentral.com/help/moocs
- By universities (1301 on 16 Jan 2023): https://www.classcentral.com/universities
- By sub-groups of universities: https://www.classcentral.com/collection/ivy-league-moocs
- By commercial Institutions (1721 on 16 Jan 2023): https://www.classcentral.com/institutions
- Free Online Learning Due to Coronavirus - ClassCentral maintains a list of temporarily free courses at: https://www.classcentral.com/report/free-online-learning-coronavirus/
- M.I.T. offers free content on OpenCourseWare: https://ocw.mit.edu/index.htm
- Open Culture lists more than 1,500 courses: http://www.openculture.com/freeonlinecourses
- Coursera https://www.coursera.org/ and https://www.classcentral.com/report/coursera-free-certificate-covid-19/
- edX https://www.edx.org/
- FutureLearn https://www.futurelearn.com/ and https://www.classcentral.com/report/futurelearn-free-certificates/
- Udacity https://www.udacity.com/
- Udemy https://www.udemy.com/courses/free/
- Upgrad https://www.upgrad.com/free-courses/
- Full reference of LinkedIn answers 2021 for skill assessments, LinkedIn test, questions and answers github.com/Ebazhanov/linkedin-skill-assessments-quizzes
Here are some resources to learn more about this topic:
- Open-Source Quantum Development. Qiskit [quiss-kit] is an open-source SDK for working with quantum computers at the level of pulses, circuits, and application modules. (Python 3.7+ in a virtual environment with Anaconda) quiskit
- IBM Quantum Lab quantum-computing.ibm.com/lab
- I have some old, unmaintained resources at github.com/mccright/rand-notes/blob/master/quantum-computing.md
- SVAR - Simple Voice Activated Recorder. https://github.com/Arkq/svar
- Alien invasion shoot-em-up that runs in a terminal with bash (everyone needs a break once in a while): https://github.com/vaniacer/piu-piu-SH/
- Center for the Study of Intelligence (CSI) Books and Monographs. https://www.cia.gov/resources/csi/books-and-monographs/
- The Rust-lang Book github.com/rust-lang/book
- An architecture decision record (ADR) is a document that captures an important architecture decision made along with its context and consequences. Joel Parker Henderson has a lot of resources to get you started at: github.com/joelparkerhenderson/architecture-decision-record/tree/main
- How have I known about ripgrep (rg) - an excellent 'grep' for searching through files in a directory tree? github.com/BurntSushi/ripgrep
- Get Windows Token Information github.com/FuzzySecurity/PowerShell-Suite/blob/master/Get-OSTokenInformation.ps1
- flaskql-playground github.com/cmpilato/flaskql-playground
- also look into github.com/yangyuexiong/Flask_BestPractices
- and this little model Flask app: https://github.com/gmn/PythonWeb/
- fedy: Fedora post-install tool to install multimedia codecs and additional software that Fedora doesn't want to ship, like H264 support, Adobe Flash (don't do Flash unless it is absolutely necessary for some materially-important purpose), Oracle Java etc., and much more with just a few clicks github.com/rpmfusion-infra/fedy
- Sometimes you are given data with no description of its layout/nature. Here are two data exploration utilities:
- Flenser github.com/JohnMcCambridge/flenser
- Lux github.com/lux-org/lux
- Begone Ads [Python] github.com/anned20/begoneads/tree/master/begoneads
- Raspberry Pi: Tutorials, Models, How to Get Started by Avram Piltch, Tom's Hardware www.tomshardware.com/news/raspberry-pi
- READ: "A Building Code for Building Code -- Putting What We Know Works to Work." By Carl E. Landwehr. www.landwehr.org/2013-12-cl-acsac-essay-bc.pdf
- Tufin www.tufin.com/
- Viewfinity www.viewfinity.com/
- Check Various tools for testing RFC 5077 github.com/vincentbernat/rfc5077
- Check interactive SNMP tool with Python github.com/vincentbernat/snimpy
- layer 2 network discovery application github.com/vincentbernat/wiremaps
- What Port Is? github.com/ncrocfer/whatportis
- Java 8 Cheat Sheet: zeroturnaround.com/wp-content/uploads/2015/12/RebelLabs-Java-8-cheat-sheet.png
- Crypto101: an introductory course on cryptography. www.crypto101.io/
- Handy list of browser user-agent strings (long) in PHP code: github.com/smxi/php-browser-detection/blob/master/browser_detection.inc
- 7500 user-agent strings from Jerry Gamblin github.com/jgamblin/curluseragent/blob/master/ua.txt
- Another list (short) of UA strings, categorized by device types github.com/miketaylr/useragent-switcher-xml/blob/master/useragentswitcher.xml
- Google Fiber Wifi Data Presentation apenwarr.ca/diary/wifi-data-apenwarr-201602.pdf and related utilities: gfiber.googlesource.com/vendor/google/platform/+/master/spectralanalyzer/ & github.com/apenwarr/wavedroplet/ & blip github.com/apenwarr/blip/
- blip latency trending utility github.com/apenwarr/blip hosted at gfblip.appspot.com/ and the DNS-aware version [don't have this](don't have this) hosted at 6-dot-gfblip.appspot.com))
- Performance-Bookmarklet helps to analyze the current page through the Resource Timing API, Navigation Timing API and User-Timing - requests by type, domain, load times, marks and more. github.com/micmro/performance-bookmarklet
- mitmproxy is an interactive, SSL/TLS-capable intercepting proxy with a console interface for HTTP/1, HTTP/2, and WebSockets. A free and open source swiss-army knife for debugging, testing, privacy measurements, and penetration testing. github.com/mitmproxy/mitmproxy
- Transparent proxy server github.com/apenwarr/sshuttle
- Packet decoding for the Go language github.com/apenwarr/gopacket and github.com/google/gopacket
- Here is a useful starter Flask-and-SQLite tutorial flask.palletsprojects.com/en/3.0.x/patterns/sqlite3/
- Very fast C++ importer from csv files to sqlite3 databases github.com/apenwarr/csv2sqlite
- A feature-packed Python package and for utilizing SQLite in Python by Plasticity github.com/plasticityai/supersqlite
- An idea for csv-to-json {csv2json.py} github.com/apenwarr/afterquery/blob/master/csv2json.py
- "Structured text tools" -- A useful list of text-based file formats and command line tools for manipulating each github.com/dbohdan/structured-text-tools
- Text Tools github.com/fmhy/FMHY/wiki/%F0%9F%94%A7-Tools#-text-tools and more generally "[tools](https://github.com/fmhy/FMHY/wiki/%F0%9F%94%A7-Tools](https://github.com/fmhy/FMHY/wiki/%F0%9F%94%A7-Tools)
- Simple static page development grunt setup github.com/micmro/grunt-simple-boilerplate
- WiGPSFi – ESP8266 + GPS euerdesign.de/2016/04/16/wigpsfi-esp8266-gps/
- Creepy Wireless Stalking Made Easy hackaday.com/2016/12/04/creepy-wireless-stalking-made-easy/
- WarWalking With The ESP8266 hackaday.com/2016/10/23/warwalking-with-the-esp8266/
- Windows 10 Wi-Fi Analyzer www.microsoft.com/en-us/store/p/wifi-analyzer/9nblggh33n0n
- Code Review Questions:
- Eric Farkas: ericfarkas.com/posts/questions-i-ask-during-code-review
- thoughbot's Code Review guide github.com/thoughtbot/guides/blob/main/code-review/README.md
- Examples from StackExchange security.stackexchange.com/questions/tagged/code-review
- Another productcoalition.com/code-review-questions-what-should-you-be-looking-for-e3f9c147baff
- How to give a code review medium.com/better-programming/how-to-give-a-great-code-review-7e32e5ba0771
- How to do code review (.NET) sites.google.com/site/wcfpandu/how-to-review-code
- And wildly off-topic -- but important -- Patient Rights Advocate released its "Hospital Price Files Finder," which it describes as "The first-ever free and publicly available search tool that allows consumers to view the available hospital pricing files from nearly all of the 6,000 hospitals throughout the U.S." This collection of medical cost-of-service data is not easy to use. It seems like a data source for some innovative (and possible profitable) software development efforts. hospitalpricingfiles.org/
- Learn more about what your github repos can do for you: github.com/joelparkerhenderson/github-special-files-and-paths
- Where are the power outages? poweroutage.com/ and poweroutage.us/
- Fear & Greed Index money.cnn.com/data/fear-and-greed/
- The best command line stock price grabber for a quick sanity check! Thank you Patrick Stadler. github.com/pstadler/ticker.sh
- And another great-looking command line stock price grabber:
curl https://terminal-stocks.herokuapp.com/SYMBOL. Thank you Shashi Prakash Gautam for your excellent server. github.com/shweshi/terminal-stocks - If you want to just grab a long history for any given security (through 2018-03-27), try www.quandl.com/api/v3/datasets/WIKI/symbol
- Database of False or Misleading Claims By DJ Trump During his 4-Year Presidency (more than 30,000 of them) www.washingtonpost.com/graphics/politics/trump-claims-database/
- Look into this simple mass Search & Replace tool (Rust): github.com/nvie/sr
- Who pays for writing? Here is an annotated list of organizations that pay writers: github.com/malgamves/CommunityWriterPrograms
- China Brief jamestown.org/programs/cb/
- For some background on the expanding criminal industry of ransomware where criminal syndicates have evolved a "conveyor-belt-like process of hacking, encrypting and then negotiating for ransom in cryptocurrencies:" www.nytimes.com/2021/12/06/world/europe/ransomware-russia-bitcoin.html
- For a primer on the sprawling People’s Liberation Army (PLA) Strategic Support Force that "centralizes information warfare capabilities in the cyber and space domains" from the U.S. Congressional Research Service see: China Primer: The People’s Liberation Army (PLA) (Updated December 21, 2022)
- Online SVG Editor, SVGBob ivanceras.github.io/svgbob-editor/
- SVG Python module github.com/orsinium-labs/svg.py
- svgcleaner (Rust) is used to losslessly reduce the size of an SVG image -- generally created in a vector editing application -- before publishing github.com/RazrFalcon/svgcleaner. See also:
- SVGO (Python) github.com/svg/svgo
- Scour (JavaScript/TypeScript) github.com/scour-project/scour
- MuseScore github.com/musescore/MuseScore and musescore.org/en/guitar
- Chordious github.com/jonthysell/Chordious with related github.com/svg-net/SVG
- DoD Cyber Workforce Framework - interesting way to describe roles public.cyber.mil/cw/dcwf/
- Before donating to non-profits, do your research www.open990.org/org/
- Satellite view of my weather re.ssec.wisc.edu/
- High-resolution imagery via Earth Engine explorer.earthengine.google.com/#workspace
- Remittances sent from United States to other countries in USD remittancesbycountry.site/country/united_states
- Getting communications right is hard. Language is a foundational component. WordNet sometimes helps. en-word.net/ and github.com/globalwordnet/english-wordnet
- Sometimes historical context matters when choosing a given term. Merriam-Webster hosts a neat tool that identifies when given words were first used. Look up any year to find out. From Merriam-Webster, www.merriam-webster.com/dictionary/ad%20hominem. Accessed 24 Oct. 2022
- Webster's 1913 Unabridged Dictionary at Project Gutenberg www.gutenberg.org/ebooks/29765
- International Building Code, 2012, Second Printing. codes.iccsafe.org/content/IBC2012P12/chapter-1-scope-and-administration
- ISO Country List www.iso.org/obp/ui/#search
- Script that extracts character names from a text file and performs analysis of text sentences containing the names. github.com/emdaniels/character-extraction
- The definitive list of lists (of lists) curated on GitHub github.com/jnv/lists
- Mobile App Pentesting Cheetsheet github.com/tanprathan/MobileApp-Pentest-Cheatsheet/blob/master/README.md
- Free Programming Books github.com/vhf/free-programming-books/blob/master/free-programming-books.md
- More Free Programming Books github.com/EbookFoundation/free-programming-books/blob/master/free-programming-books.md
- Tool by Tool, Skill by Skill. By Simon St.Laurent chimera.labs.oreilly.com/books/1234000000882/index.html Especially Appendix B. Sharpening and Maintenance Basics. chimera.labs.oreilly.com/books/1234000000882/apb.html
- Awesome Selfhosted. This is a list of Free Software network services and web applications which can be hosted locally. github.com/awesome-selfhosted/awesome-selfhosted
- Awesome SysAdmin. A list of open source sysadmin resources. github.com/kahun/awesome-sysadmin
- Awesome Data Science. A repository of resources to learn and apply for real world problems. github.com/okulbilisim/awesome-datascience
- And data from OurWorldInData for your experiments: github.com/owid/owid-datasets/tree/master/datasets
- Registry of Open Data on AWS registry.opendata.aws/
- 487+ Free Open Datasets from AWS: aws.amazon.com/marketplace...
- Awesome R github.com/qinwf/awesome-R and awesome-r.com/
- Managing risk in the context of a long time-horizon.
- See the "Global Risks 2014 - Ninth Edition" Insight Report from the World Economic Forum. www3.weforum.org/docs/WEF_GlobalRisks_Report_2014.pdf Especially part 2, pages 38-49. It is a short read on risks associated with -- among other topics -- the way the Internet is evolving, risks associated with "trust," and "managing risk" in the context of a long time-horizon.
- Also: "Global Risks 2015 - Tenth Edition" www3.weforum.org/docs/WEF_Global_Risks_2015_Report15.pdf
- And more recently: "Global Risks 2016 - Eleventh Edition" www3.weforum.org/docs/GRR/WEF_GRR16.pdf
- And 2017: "Global Risks 2017 -- 12th Edition" www3.weforum.org/docs/GRR17_Report_web.pdf
- And 2018: "The Global Risks Report 2018 - 13th Edition" www3.weforum.org/docs/WEF_GRR18_Report.pdf
- And 2019: "The Global Risks Report 2019 - 14th Edition" www3.weforum.org/docs/WEF_Global_Risks_Report_2019.pdf
- And 2020: "The Global Risks Report 2020 - 20th Edition" www3.weforum.org/docs/WEF_Global_Risk_Report_2020.pdf or reports.weforum.org/global-risks-report-2020/
- And 2021: "The Global Risks Report 2021 - 21st Edition"www3.weforum.org/docs/WEF_The_Global_Risks_Report_2021.pdf or www.weforum.org/publications/the-global-risks-report-2021/
- And 2022: "The Global Risks Report 2022 - 22nd Edition" www3.weforum.org/docs/WEF_The_Global_Risks_Report_2022.pdf or www.weforum.org/publications/the-global-risks-report-2022/
- And 2023: "The Global Risks Report 2023 - 23rd Edition" www3.weforum.org/docs/WEF_The_Global_Risks_Report_2023.pdf or www.weforum.org/publications/the-global-risks-report-2023/
- And most recently: "The Global Risks Report 2024 - 24th Edition" www3.weforum.org/docs/WEF_The_Global_Risks_Report_2024.pdf or www.weforum.org/publications/global-risks-report-2024/
- A definitive list of tools for generating static websites github.com/pinceladasdaweb/Static-Site-Generators
- The definitive list of newsletters to keep up to date on various web development technologies github.com/pinceladasdaweb/Upgrade-your-brain
- hack-font for your development environment www.npmjs.com/package/hack-font
- Big list of HTTP media types www.iana.org/assignments/media-types/media-types.xhtml
- Open source, free textbooks: ocw.mit.edu/courses/online-textbooks/ and openstax.org/
- WhitePages: www.therealyellowpages.com/Des-Moines-Regional-IA-2021/1/
- and something completely different ir.uiowa.edu/annals-of-iowa/
- The real cost of a car www.carboncounter.com/#!/explore
- My favorite essay on bitcoin www.nytimes.com/2021/06/14/opinion/bitcoin-cryptocurrency-flaws.html
- Architecture Patterns with Python, Enabling Test-Driven Development, Domain-Driven Design, and Event-Driven Microservices. (A Book about Pythonic Application Architecture Patterns for Managing Complexity.) By Harry Percival, Bob Gregory github.com/cosmicpython/book and shop.oreilly.com/product/0636920254638.do
- An excellent first lesson on "Dockerizing FastAPI with Postgres, Uvicorn, and Traefik (and LetsEncript)" By Amal Shaji, 2021-05-04. testdriven.io/blog/fastapi-docker-traefik/
- "Binocular Tune Up With Collimation." A binocular is a pair of refractor telescopes joined together and proper focusing depends on accurate alignment between these two telescopes. In this context,
collimationmeans fusing the two images shown in a binocular's eye-pieces reaching your eyes. Yes, most reasonably good binoculars have a way to adjust the inter-pupillary distance (IPD) and that may address most people's focus issues most of the time, but manufacturing/assembly/testing sloth or misuse may also cause collimation issues. Well collimated binoculars can reduce eyestrain or headaches caused by out-of-focus/out-of-alignment images. See: "Binocular collimation instructions from Oberwerk" and "Binocular Tune Up With Collimation."
See: github.com/mccright/rand-notes/blob/master/Novel-Corona-Virus-COVID-19.md
- cowyo is a self-contained wiki server that makes jotting notes - simple, easy and fast, but crude and it feels a little unfinished github.com/schollz/cowyo
- Linx is a more full featured pastbin-like platform github.com/ZizzyDizzyMC/linx-server/
- The world is brimming with uncertainties. If you don't have a will, create one (do it now -- you can always morph it later as needed). Under many circumstances you can start here for free: www.freewill.com/ (there are also other systems that will help you prepare a basic will for free)
- "One reason people insist that you use the proper channels to change things is because they have control of the proper channels and they're confident it won't work." twitter.com/joncstone/status/1269961630940631041
- On Being Fired third-bit.com/rules/#being-fired
- Ten quick tips for delivering programming lessons journals.plos.org/ploscompbiol/article?id=10.1371/journal.pcbi.1007433
- Ten quick tips for teaching programming journals.plos.org/ploscompbiol/article?id=10.1371/journal.pcbi.1006023
- Jesse Duffield's "Stuff I would tell my younger self" github.com/jesseduffield/wisdom/wiki
- A Thesaurus of Job Titles to help "Improve the information flowing between recruiters and job seekers. Improve how recruiters and job seekers create job postings and resumes/online profiles. Improve how recruiters and job seekers search for candidates and jobs" github.com/johnpcarty/Thesaurus-of-Job-Titles
- Ten simple rules for making research software more robust journals.plos.org/ploscompbiol/article?id=10.1371/journal.pcbi.1005412
- You have the right to film police. Here's how to do it effectively — and safely www.washingtonpost.com/technology/2021/04/22/how-to-film-police-smartphone/ and why it is important to do so www.washingtonpost.com/business/technology/a-cop-fires-a-teen-dies-yet-six-police-body-cameras-somehow-miss-what-happens
- "Companies are hoarding personal data about you. Here's how to get them to delete it." www.washingtonpost.com/technology/2021/09/26/ask-company-delete-personal-data/
- "The three fundamental Rules of Robotics"
One, a robot may not injure a human being, or, through inaction, allow a human being to come to harm. Two, a robot must obey the orders given it by human beings except where such orders would conflict with the First Law. Three, a robot must protect its own existence as long as such protection does not conflict with the First or Second Laws. [Isaac Asimov introduced these in his 1942 short story "Runaround" (included in the 1950 collection I, Robot) en.wikipedia.org/wiki/Three_Laws_of_Robotics]