Cybersecurity Tools

RED‑TEAM TOOLS & Hands-On Learning Resources

ToolDescription Free Book / PDFFree CourseFree LabFree ProjectExam Prep
Cobalt Strikefree C2 labs (but not Cobalt Strike itself, because it’s paid)Red Team Operator HandbookTHM Red Team FundamentalsSliver C2 LabGithubCRTO (Certified Red Team Operator) Prep BlogsThe main use of Cobalt Strike is to assess the security of networks and systems. It is a commercial penetration testing tool that is commonly used by security professionals to test the security of networks and systems, and to identify and exploit potential vulnerabilities and weaknesses.
https://www.cobaltstrike.com/https://tryhackme.comhttps://github.com/BishopFox/sliver
https://github.com/h3ll0clar1c3/CRTOhttps://rouvin.gitbook.io/ibreakstuff/blogs/reviews/crto-review
https://github.com/dr34mhacks/CRTO-CheatSheet/blob/main/README.md
https://8bitsecurity.com/posts/threat-hunting-cobalt-strike-the-final-guide-from-the-depths-of-beaconing-to-c2-infrastructure/
https://deetee1.medium.com/crto-certified-red-team-operator-review-june-2023-806e7b6c6bc9
MetasploitMetasploit UnleashedCybrary MetasploiteMetasploitable2Custom MSF ModuleeJPT Prep
BloodHoundAD Security 101HackTricks ADBloodHound CE LabMap AD LabCRTP Prep
EmpirePowerShell for HackersTHM PowerShellEmpire LabBuild PS Reverse ShellOSEP Prep
NmapNmap Network ScanningNmap Full GuideVulnHub ScansPython Nmap ScannerSecurity+ Prep
BeEFBrowser Security HandbookWeb AcademyBeEF + DVWACustom Hook ModuleOSWE Prep
ResponderWindows Auth InternalsHackTricks WindowsResponder LabLLMNR Poison ScriptCRTP Prep
SETArt of Human HackingSE.org TrainingSET Phishing LabPhishing SimulationCEH Prep
Burp SuiteWAHH Free ChaptersWeb AcademyBurp LabsWeb Scanner ProjectOSWE Prep
FireCompassASM GuideTHM ASRAmass/SubfinderASM PipelineOSCP Prep
HavocC2 Dev HandbookHavoc BasicsHavoc LabCustom PayloadsCRTO Prep
SliverSliver DocsSliver TrainingSliver LabCustom OperatorsOSEP Prep
Deepfake ToolsDeepfake EthicsAI For EveryoneDeepfake LabVoice Clone SimulationCEH Prep
AI Recon BotsOSINT Framework GuideOSINT FundamentalsOSINT Recon LabBuild AI Recon BoteJPT Prep

BLUE‑TEAM TOOLS & Hands-On Learning Resources


ToolDescription Free Book / PDFFree CourseFree LabFree ProjectRecommended Certification
Microsoft Defender XDRMicrosoft Defender XDR is a unified enterprise defense suite designed to enhance cybersecurity by coordinating detection, prevention, investigation, and response across various components such as endpoints, identities, email, and applications. It integrates information from multiple Microsoft security products, allowing security teams to detect threats more effectively and respond to them in real-time.Microsoft Security Best PracticesSC‑200 Microsoft LearnDefender XDR SandboxBuild Home SOC SC-200T00-A, AZ‑500, CISSP
https://www.hurix.com/blogs/improve-your-it-security-posture-with-microsoft-defenders-best-practices/https://www.microsoft.com/en-au/security/business/siem-and-xdr/microsoft-defender-xdrhttps://www.google.com/search?q=Build+Home+SOC&https://learn.microsoft.com/en-us/training/courses/sc-200t00
Splunk Enterprise SecuritySplunk Enterprise Security is a SIEM system that makes use of machine-generated data to get operational insights into threats, vulnerabilities, security technologies, and identity informationSplunk FundamentalsSplunk Work+ FundamentalsBoss of the SOCBuild SIEM DashboardSplunk SPLK-3001 Actual
https://www.splunk.com/en_us/training/certification-track/splunk-certified-cybersecurity-defense-analyst.htmlhttps://www.splunk.com/en_us/training/course-catalog.html?size=n_20_n&filters=filterGroup3SOCAnalyst&sort=Newesthttps://bots.splunk.com/workshops/3HVBZjMPIxzWR1UXlpHXAz/detailhttps://www.examtopics.com/exams/splunk/splk-3001/view/#
Microsoft SentinelMicrosoft Sentinel is a cloud-native, AI-powered SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution. It centralizes log data, threat detection, investigation, and response across hybrid, multi-cloud, and Microsoft 365 environments, enabling automated threat intelligence and rapid security operations. Azure Security GuideSentinel Analyst TrainingSentinel SandboxCloud SIEM PipelineSC‑200 Prep
https://learn.microsoft.com/en-us/credentials/certifications/security-operations-analyst/?practice-assessment-type=certification
ELK / Elastic SecurityElastic Security, built on the ELK Stack (Elasticsearch, Logstash, Kibana), is an open-source platform offering SIEM, XDR, and endpoint protection for threat detection, investigation, and response. It enables real-time monitoring of logs from cloud, network, and endpoint sources, utilizing behavioral analysis and machine learning to detect threats, with integration via Elastic Agent and FleetElastic Stack BookElastic Analyst TrainingElastic Cloud LabBuild ELK SIEMElastic Analyst Prep
https://www.elastic.co/guide/index.htmlhttps://www.elastic.co/traininghttps://www.elastic.co/training/certification
SuricataSuricata is a free and open source, mature, fast and robust network threat detection engine.
Suricata provides threat detection capabilities. In IDS mode, it is going to analyse the traffic and generate an alert when a signature matches. In IPS mode, it acts like a firewall. It provides traffic filtering and monitoring and allows network administrators to write and enforce detection rules.
Suricata User GuideOISF TrainingSecurity Onion Suricata LabBuild Home IDSGIAC Certifications
https://suricata.io/learn/https://suricata.io/learn/https://www.freecodecamp.org/news/build-a-real-time-intrusion-detection-system-with-python/https://www.classcentral.com/subject/suricata?lang=english
https://securityonionsolutions.com/
https://www.sans.org/blog/lessons-learned-on-the-impact-of-training-on-hiring-success-a-mastercard-use-case
Zeek Zeek is a passive, open-source network traffic analyzer tool used by many operators. It analyzes network traffic packets and creates “Zeek logs” which can be used to detect malicious activity within a network.
Suricata excels at real-time threat detection and prevention with a focus on ease of use. Zeek provides a comprehensive view of network activity through deep analysis and historical data, but requires more technical expertise to leverage its full potential.
Zeek NSM GuideZeek Training SeriesSecurity Onion Zeek LabZeek Monitoring PipelineGCIA Prep
https://docs.zeek.org/en/current/https://docs.zeek.org/en/current/https://github.com/zeek/zeek/blob/master/README.mdhttps://securityonionsolutions.com/certification
WiresharkWireshark is a free open source tool that analyzes network traffic in real-time for Windows, Mac, Unix, and Linux systems. It captures data packets passing through a network interface (such as Ethernet, LAN, or SDRs) and translates that data into valuable information for IT professionals and cybersecurity teams.Wireshark Analysis BookWireshark UniversityPacket Capture LabsHome Network AnalysisWireshark Certifications
https://www.wireshark.org/docs/https://malware-traffic-analysis.net/index.htmlhttps://www.wireshark.org/certifications/
OSQueryOsquery is an open-source instrumentation, monitoring, and analytics framework that exposes operating systems (Linux, macOS, Windows) as high-performance relational databases. It allows users to query system data—such as running processes, network connections, and file hashes—using SQL commands, simplifying security investigation, compliance monitoring, and incident responseOSQuery DocumentationTrail of Bits TrainingFleetDM LabEndpoint Monitoring DashboardBTLO Prep
https://osquery.io/docshttps://github.com/osquery/osquery/tree/masterhttps://fleetdm.com/https://blueteamlabs.online/home
VelociraptorVelociraptor DFIR HandbookVelociraptor DFIR SeriesVelociraptor LabDFIR Collection PipelineGCFA Prep
TheHiveTheHive DocumentationDFIR Science IR TrainingTheHive + Cortex LabIR Case Management SystemGCIH Prep
Cortex XSOARSOAR Playbook GuideXSOAR FundamentalsXSOAR Community LabAutomated IR PlaybooksPCNSA Prep
OpenCTIMITRE ATT&CK TI GuideMISP + OpenCTI TrainingOpenCTI + MISP LabThreat Intel PipelineCTIA Prep
CrowdStrike FalconEDR GuideCrowdStrike UniversityLimaCharlie EDR LabEDR Telemetry CollectorGCIH Prep
Sysmon + SigmaWindows Logging GuideSigma Rule WritingSysmon + ELK LabBuild Detection RulesetBTLO Prep
WazuhWazuh DocumentationWazuh UniversityWazuh + ELK LabBuild Wazuh SIEMSecurity+ Prep

🔐 MITRE Caldera

A powerful open-source adversary emulation platform used to simulate attacker behavior, automate red team operations, and test defensive detection capabilities.

Link: https://caldera.mitre.org


🛡️ Metasploit Framework

A widely used penetration testing framework that helps learners understand exploitation techniques, payloads, and vulnerability testing in controlled environments.

Link: https://www.metasploit.com


🔍 Blue Team Labs Online

A free defensive cybersecurity platform offering hands-on labs, incident response challenges, and SOC-style investigations for blue team skill development.

Link: https://blueteamlabs.online


☁️ OWASP Juice Shop

A deliberately vulnerable web application used to teach secure coding, web exploitation, and application security testing.

Link: https://owasp.org/www-project-juice-shop/


🧪 Free Cyber Ranges

A collection of free cyber ranges and virtual labs where learners can practice offensive and defensive techniques in safe, isolated environments.

Links: