dhotrey/awesome-cybersec
GitHub: dhotrey/awesome-cybersec
一个分类清晰的社区驱动型网络安全资源合集,整合了培训平台、工具、CTF和Bug Bounty等多方向的学习资料。
Stars: 195 | Forks: 32
# awesome-cybersec
[](https://github.com/sindresorhus/awesome)

关于安全的优秀平台、博客、文档、书籍、资源和酷炫内容的合集。
虽然这个仓库仍在构建中,但其目标是建立一个分类清晰、由社区驱动的知名资源合集。
# 所有好东西都在这里
## 培训
* [Defbox](https://defbox.io)
* [Range force](https://portal.rangeforce.com/courses)
* [HTB](https://www.hackthebox.eu/)
* [Tryhackme](https://tryhackme.com/)
* [Blue team academy](https://app.letsdefend.io/academy/)
* [Blue team labs](https://blueteamlabs.online/)
* [Kali revealed](https://kali.training/)
* [Darkmoon](https://github.com/ASCIT31/Dark-Moon) - 开源 (GPL-3.0) 自主 AI 渗透测试平台,涵盖 Web、API、Active Directory 和 Kubernetes,作为 MCP 主机编排 80 多种攻击性工具,提供漏洞利用证明和本地隐私网关(LLM 永远看不到真实的 IP 或凭证)。
* [Metasploit Unleashed](https://www.offensive-security.com/metasploit-unleashed/)
* [platform.mosse-institute.com](https://platform.mosse-institute.com/#/dashboard)
* [riptutorial.com/bash](https://riptutorial.com/bash)
* [hackerrank.com/domains/shell](https://www.hackerrank.com/domains/shell)
* [https://pentesterlab.com/](https://pentesterlab.com/)
* [https://www.pentesteracademy.com/](https://www.pentesteracademy.com/)
* [https://www.offensive-security.com/labs/individual/](https://www.offensive-security.com/labs/individual/)
* [https://www.vulnhub.com/](https://www.vulnhub.com/)
* [Google 文档:vulnhub 类似 oscp 的虚拟机列表](https://docs.google.com/spreadsheets/d/1dwSMIAPIam0PuRBkCiDI88pU3yzrqqHkDtBngUHNCw8/edit#gid=0)
* [Vulnhub 上的 WordPress 靶机](https://www.reddit.com/user/therealsavalon/comments/o3cn1l/wordpress_boxes_on_vulnhub/?utm_source=share&utm_medium=web2x&context=3)
* [Vulnhub CTF Writeups](https://github.com/Ignitetechnologies/Vulnhub-CTF-Writeups)
* [Linux 权限提升速查表](https://github.com/Ignitetechnologies/Linux-Privilege-Escalation)
* [权限提升](https://github.com/Ignitetechnologies/Privilege-Escalation)
* [corelan: exploit-writing-tutorial-part-1-stack-based-overflows](https://www.corelan.be/index.php/2009/07/19/exploit-writing-tutorial-part-1-stack-based-overflows/)
* [https://scs.hacking-lab.com/](https://scs.hacking-lab.com/)
* [Malware Noob2Ninja 课程](https://www.youtube.com/watch?v=GE_aSVq8ZnQ&list=PLiFO-R_BI-kAqDPqtnOq2n70mtAZ6xg5N)
* [n3t2.3c](https://nets.ec/Main_Page)
* [Hacking-cisco](https://hackingcisco.blogspot.com/)
* [Open security training](https://opensecuritytraining.info/Training.html)
* [Pentest standard](http://www.pentest-standard.org/index.php/Main_Page)
* [Security-tube](http://www.securitytube.net/)
* [二进制分析课程](https://maxkersten.nl/binary-analysis-course/)
* [https://training.zempirians.com/start/here](https://training.zempirians.com/start/here)
* [Pwncollege](https://pwn.college/) pwn.college 是一个初级教育平台,供学生(及其他感兴趣的人)以实践方式学习和掌握网络安全核心概念。它旨在帮助网络安全“白带”成长为“蓝带”,能够应对(简单的)CTF 和攻防演练。pwn.college 的理念是“熟能生巧”。
* [CyberPython](https://pythoncyber.go.ro) 一个实践平台,你需要通过自己的研究并利用少量的指导和提示来完成挑战。
* [Web 应用漏洞利用与防御](https://google-gruyere.appspot.com/)此 Codelab 围绕 **Gruyere** /ɡruːˈjɛər/ 构建 —— 这是一个小巧但漏洞百出的 Web 应用程序,允许其用户发布文本片段和存储各种文件。“不幸的是”,Gruyere 存在多个安全漏洞,从跨站脚本攻击和跨站请求伪造,到信息泄露、拒绝服务以及远程代码执行。此 Codelab 的目标是指导你发现其中一些漏洞,并学习在 Gruyere 及一般情况下修复它们的方法。
* [现代二进制漏洞利用课程资料](https://github.com/RPISEC/MBE)
* [professormesser.com](https://www.professormesser.com/)
* [MCSI 免费培训](https://platform.mosse-institute.com/#/dashboard)
* [insecure.org/stf/smashstack.html](https://insecure.org/stf/smashstack.html)
* [网络基础:CCNA 200-301 认证课程,学习网络基础的全面免费课程](https://youtube.com/playlist?list=PLxbwE86jKRgMpuZuLBivzlM8s2Dk5lXBQ&si=-F99io_SSPdcHjNW)
## WebApp/Bug Bounty 资源
* [Web Security Academy](https://portswigger.net/web-security)
* [https://owasp.org/www-project-juice-shop/](https://owasp.org/www-project-juice-shop/)
* [Mutillidae II](https://github.com/webpwnized/mutillidae/)
* [VulnWeb](http://www.vulnweb.com/)
* [https://www.bugbountyhunter.com/](https://www.bugbountyhunter.com/)
* [hacker101](https://www.hacker101.com/) 是一个免费的 Web 安全课程。无论你是对 Bug Bounty 感兴趣的程序员,还是经验丰富的安全专业人士,Hacker101 都能为你提供一些有价值的内容。
* [https://www.hacksplaining.com/](https://www.hacksplaining.com/)
* [awesome-web-hacking](https://github.com/infoslack/awesome-web-hacking)
- [Resources-for-Beginner-Bug-Bounty-Hunters](https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters)
- [https://thexssrat.podia.com/dashboard](https://thexssrat.podia.com/dashboard)
- [https://github.com/websploit/websploit](https://github.com/websploit/websploit)
- [https://dvwa.co.uk/](https://dvwa.co.uk/)
- [https://owasp.org/www-project-webgoat/](https://owasp.org/www-project-webgoat/)
- [资源与已披露的报告](https://github.com/HolyBugx/HolyTips/tree/main/Resources)
- [Bug Bounty 路线图](https://github.com/1ndianl33t/Bug-Bounty-Roadmaps)
- [Bug 狩猎方法论](https://github.com/IamLucif3r/Bug-Hunting)
- [开源 Bug Bounty 指南 - 方法论、工具、资源](https://www.youtube.com/watch?v=BHIGJQdId3k)
- [Thug-bounty](https://start.me/p/vjEPvb/thug-bounty)
- [Bug Bounty Writeups](https://github.com/devanshbatham/Awesome-Bugbounty-Writeups)
- [最佳 Bug Bounty 侦察方法论](https://securib.ee/beelog/the-best-bug-bounty-recon-methodology/)
- [Web 渗透测试清单](https://pentestbook.six2dez.com/others/web-checklist/)
- [Web 应用程序速查表](https://github.com/Ignitetechnologies/Web-Application-Cheatsheet)
- [Web 渗透测试清单](https://github.com/harshinsecurity/web-pentesting-checklist)
- [OWASP Web 安全测试指南](https://owasp.org/www-project-web-security-testing-guide/)
- [OWASP Top Ten](https://owasp.org/www-project-top-ten/)
- [Bugcroud university](https://www.bugcrowd.com/hackers/bugcrowd-university/)
- [OWASP Web 安全测试指南](https://github.com/OWASP/wstg/tree/master/document)
- 学习各种技术栈的工作原理似乎是 Bug Bounty 狩猎的一个重要方面,因此你至少需要了解 MERN、LAMP 或其他技术栈中的一种。
你可以通过构建自己的类似 Yelp 的餐厅评论网站来学习 MERN 技术栈。MERN 代表 MongoDB + Express + React + Node.js。然后,在课程的后半部分,你将学习如何用 Serverless 架构替换你的 Node.js/Express 后端。(3 小时的 YouTube 课程):[https://www.freecodecamp.org/news/create-a-mern-stack-app-with-a-serverless-backend/](https://www.freecodecamp.org/news/create-a-mern-stack-app-with-a-serverless-backend/)
### 来自 Hacker101 Discord 服务器的资源
**如何开始 Hacker 和 Bug Bounty?**
我们收集了一些有用的资源,帮助你开启 Bug Bounty 之旅!
- [学习 Hacker 的指南](https://www.youtube.com/watch?v=2TofunAI6fU)
- [发现你的第一个漏洞](https://portswigger.net/blog/finding-your-first-bug-bounty-hunting-tips-from-the-burp-suite-community)
- [Port Swigger Web Security Academy](https://portswigger.net/web-security/learning-path)
- [Nahamsec 的 Twitch](https://www.twitch.tv/nahamsec)
- [Nahamsec 采访顶级 Bug Bounty Hunter](https://www.youtube.com/c/Nahamsec)
- [Nahamsec 的新手仓库](https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters)
- [Stök](https://www.youtube.com/c/STOKfredrik)
- [InsiderPhD](https://www.youtube.com/c/InsiderPhD)
- [给 Bug Bounty 新手的系列内容](https://www.youtube.com/playlist?list=PLbyncTkpno5FAC0DJYuJrEqHSMdudEffw)
- [Jhaddix](https://www.youtube.com/c/jhaddix)
### Hacker101 成员关于如何开始 Hacker 的帖子
- [zonduu](https://medium.com/@zonduu/bug-bounty-beginners-guide-683e9d567b9f)
- [p4nda](https://enfinlay.github.io/bugbounty/2020/08/15/so-you-wanna-hack.html)
- [一篇关于子域名接管的博客](https://enfinlay.github.io/sto/ip/domain/bugbounty/2020/09/12/ip-server-domain.html)
- [clos2100 谈如何在没有技术背景的情况下入门](https://twitter.com/pirateducky/status/1300566000665014275)
- [al-madjus:从 0 到 Bug Bounty Hunter](https://klarsen.net/uncategorized/from-0-to-bug-hunter-my-journey/)
- [dee-see 的 Android Hacker 资源](https://blog.deesee.xyz/android/security/2020/01/13/android-application-hacking-resources.html)
- [hacker101 视频](https://www.hacker101.com/videos)
## 工具
- [Pwncat](https://github.com/calebstewart/pwncat) 是一个~~针对 Linux 目标的~~后渗透平台。它最初只是基础 bind 和 reverse shell 的一个封装,并由此逐渐发展壮大。它简化了常见的红队操作,同时从你的攻击机(而非目标机)上加载代码。
- [自动绕过(暴力破解)WAF](https://github.com/3xp10it/xwaf)
- [DFIR-Tools](https://github.com/archanchoudhury/DFIR-Tools)
- [https://pentestbox.org/](https://pentestbox.org/)
- [笔记,海量的笔记](https://enotes.nickapic.com/)
- [Writehat:一个用 Python 编写的渗透测试报告工具。把你从 Microsoft Word 中解放出来。](https://github.com/blacklanternsecurity/writehat)
- [OSINT4ALL](https://start.me/p/L1rEYQ/osint4all)
- [Shadrak:Shadrak 是一个可以生成各种格式解压缩炸弹的脚本。](https://gitlab.com/brn1337/shadrak)
- [Fish:一个钓鱼工具](https://github.com/aarav2you/Fish/)
- [Owasp Zap](https://www.zaproxy.org/), 一个免费开源的 Burp Suite 替代品
- [Pimpmykai](https://github.com/Dewalt-arch/pimpmykali)
- [Name that hash](https://github.com/HashPals/Name-That-Hash)
- [Burp Automator(burpa) - 一个 Burp Suite 自动化工具。](https://github.com/tristanlatr/burpa)
- [The harvester](https://github.com/laramies/theHarvester)
- [https://technisette.com/p/tools](https://technisette.com/p/tools)
- [Hakrawler](https://github.com/hakluke/hakrawler)
- [服务枚举](https://github.com/ssstonebraker/Pentest-Service-Enumeration)
-
## CTF
* [https://ctftime.org/](https://ctftime.org/)
* [https://ctf.hackthebox.eu/ctfs](https://ctf.hackthebox.eu/ctfs)
* [https://www.hackthissite.org/](https://www.hackthissite.org/)
* [Hack.me](https://hack.me/)
* [Try2Hackme](https://try2hack.me/)
* [Hackthissite](https://www.hackthissite.org/)
* [https://overthewire.org/wargames/](https://overthewire.org/wargames/)
* [https://underthewire.tech/wargames](https://underthewire.tech/wargames)
* [Pwnable.tw](https://pwnable.tw/challenge/)
* [Pwnable.kr](http://pwnable.kr/play.php)
* [Root-me](https://www.root-me.org/?lang=en)
* [Smash the stack](http://smashthestack.org/wargames.html)
* [Cryptohack.org](https://cryptohack.org/)
* [PicoCTF](https://www.picoctf.org/)
* [CMDchallenge](https://cmdchallenge.com/)
* [Defend the web](https://defendtheweb.net/)
* [ChaosVPN](https://wiki.hamburg.ccc.de/ChaosVPN)
* [PentestIT](https://lab.pentestit.ru/)
* [Overthewire-Warzone](https://overthewire.org/warzone/)
* [CTF 难度速查表 (Vulnhub)](https://github.com/Ignitetechnologies/CTF-Difficulty)
* [hpwnadventure](https://pwnadventure.com/)
* [ctf.komodosec](http://ctf.komodosec.com/)
* [counterhack.net](http://counterhack.net/Counter_Hack/Challenges.html)
* [hellboundhackers](https://www.hellboundhackers.org/)
* [ringzer0ctf.com](https://ringzer0ctf.com/challenges)
* [io.netgarage](https://io.netgarage.org/)
* [pwn0.com](https://pwn0.com)
* [w3c.com](https://w3challs.com/)
* [hax.tor.hu](http://hax.tor.hu/welcome/)
* [reversing.kr](http://reversing.kr/)
* [ctflearn.com](https://ctflearn.com/)
* [microcorruption.com](https://microcorruption.com/login)
* [ctf365.com](https://ctf365.com/)
* [codegate.org](http://codegate.org/en/)
* [legitbs.net](https://legitbs.net/)
* [ghostintheshellcode](http://ghostintheshellcode.com/)
* [try2hack](http://www.try2hack.nl/)
* [gameofhacks](https://www.gameofhacks.com/)
* [https://hackingzone.net/](https://hackingzone.net/) 尝试结合 Google 翻译使用
* [http://suninatas.com/challenges](http://suninatas.com/challenges)
* [Dream hack](https://dreamhack.io/) 是一个韩国网络安全课程。它也提供 CTF。你可以尝试配合 Google 翻译来体验。
* [The cyber institute](https://courses.thecyberinst.org/collections) 免费的 OSINT 课程和免费的 OSINT 挑战。
* [Sans holiday hack challenge - 往届挑战](https://holidayhackchallenge.com/past-challenges/)
* [Holidayhackchallenge-2020](https://holidayhackchallenge.com/2020/)
* [Kringlecon](https://2020.kringlecon.com/invite)
* [Sans cyber-ranges]( )
* [CTF-challenge](https://ctfchallenge.com/)
* [247CTF](https://247ctf.com/)
* [Backdoor ctf](https://backdoor.sdslabs.co/)
* [Cybersecurity.wtf](https://cybersecurity.wtf/#)
## GitHub 资源
* [恶意软件分析课程](https://github.com/hasherezade/malware_training_vol1)
* [Malware-IR-TH-TI-Resources](https://github.com/ShilpeshTrivedi/Malware-IR-TH-TI-Resources/blob/main/Malware-IR-TH-TI-Resources.md#malware-ir-th-ti-resources)
* [红队战术与技术](https://github.com/mantvydasb/RedTeam-Tactics-and-Techniques)
* [红队工具包](https://github.com/infosecn1nja/Red-Teaming-Toolkit)
* [Red Team](https://github.com/BankSecurity/Red_Team)
* [awesome red teaming](https://github.com/yeyintminthuhtut/Awesome-Red-Teaming)
* [Powershell red team](https://github.com/tobor88/PowerShell-Red-Team)
* [Red Teaming](https://github.com/winterwolf32/Red-teaming)
* [Red-team](https://github.com/Sorsnce/red-team)
* [Red team diaries](https://github.com/ihebski/A-Red-Teamer-diaries)
* [awesome-web-hacking](https://github.com/infoslack/awesome-web-hacking)
* [awesome-security](https://github.com/sbilly/awesome-security)
* [infosec-resources](https://github.com/pascalschulz/Infosec-Resources)
* [关于 Web 应用防火墙 (WAF) 的一切](https://github.com/0xInfection/Awesome-WAF)
* [awesome-hacking](https://github.com/carpedm20/awesome-hacking)
* [Awesome-Hacking-2](https://github.com/Hack-with-Github/Awesome-Hacking)
* [BARF:二进制分析和逆向工程框架](https://github.com/programa-stic/barf-project)
* [通过利用低垂果实实现 Linux 自动权限提升](https://github.com/liamg/traitor)
* [CTF-KATANA](https://github.com/JohnHammond/ctf-katana)
* [Active-directory-exploitation-cheatsheet](https://github.com/fuzz-security/Active-Directory-Exploitation-Cheat-Sheet)
* [秘密知识之书:一系列鼓舞人心的列表、手册、速查表、博客、黑客技巧、单行代码、CLI/Web 工具等。](https://github.com/trimstray/the-book-of-secret-knowledge)
* [PyWhat:识别一切](https://github.com/bee-san/pyWhat)
* [OSEE 备考资源](https://github.com/dhn/OSEE)
* [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings)
* [Thefuck](https://github.com/nvbn/thefuck)
## 博客
* [https://blog.tryhackme.com/free\_path/](https://blog.tryhackme.com/free_path/)
* [在你的第一次渗透测试中从零到大神](https://corneacristian.medium.com/from-zero-to-your-first-penetration-test-7479bce3a5)
* [所以你想在 2021 年成为一名 Hacker](https://tcm-sec.com/so-you-want-to-be-a-hacker-2021-edition/)
* [netsecfocus](https://www.netsecfocus.com/)
* [https://nosecurity.blog/cptc2020](https://nosecurity.blog/cptc2020)
* [https://null-byte.wonderhowto.com/](https://null-byte.wonderhowto.com/)
* [https://portswigger.net/blog/flying-high-in-the-web-security-academy](https://portswigger.net/blog/flying-high-in-the-web-security-academy)
* [https://www.simplycyber.io/free-cyber-resources](https://www.simplycyber.io/free-cyber-resources)
* [https://blog.g0tmi1k.com/](https://blog.g0tmi1k.com/)
* [https://www.hackingarticles.in/](https://www.hackingarticles.in/)
* [https://www.hackingtutorials.org/](https://www.hackingtutorials.org/)
* [https://www.hacking-tutorial.com/](https://www.hacking-tutorial.com/)
* [The Journey to Try Harder- TJnull 的 PEN-200 PWK OSCP 2.0 备考指南](https://www.netsecfocus.com/oscp/2021/05/06/The_Journey_to_Try_Harder-_TJnull-s_Preparation_Guide_for_PEN-200_PWK_OSCP_2.0.html)
* [https://hacklido.com/](https://hacklido.com/)
* [什么是块加密](https://www.freecodecamp.org/news/what-is-a-block-cipher/)
* [freecodecamp 博客](https://www.freecodecamp.org/news/)
* [Redhuntlabs 博客](https://redhuntlabs.com/blog)
* [Hackthebox 博客](https://www.hackthebox.eu/blog)
* [Tryhackme 博客](https://blog.tryhackme.com/)
* [信息安全入门](https://malicious.link/start/)
* [使用 Hack The Box 进行道德黑客攻击:一本入门道德黑客的免费书籍](https://book.ethicalhackinghtb.xyz/)
* [黑客教程](https://www.hackingtutorials.org/)
* [Halls of valhalla](https://halls-of-valhalla.org/beta/) 是一个分享知识和想法的地方。用户可以提交代码,以及科学、技术和工程类的新闻和文章。他们还有各种有趣且具有教育意义的挑战,旨在帮助用户了解更多关于编程、数学、加密、黑客等知识。
* [Pentest.blog](https://pentest.blog/)
* [https://hausec.com/](https://hausec.com/)
* [https://dirkjanm.io/]( https://dirkjanm.io/)
* [https://adsecurity.org/](https://adsecurity.org/)
* [infosec 文章](https://infosecwriteups.com/)
* [Hacksplained 博客](https://hacksplained.it/blog/)
* [准备好通过 CISSP](https://www.freecodecamp.org/news/get-ready-to-pass-cissp-exam/?utm_source=pocket_mylist)
* [Blackmorerepos](https://www.blackmoreops.com/)
## 付费培训
* [cybersec labs](https://www.cyberseclabs.co.uk/)
* [Virtual Hacking Labs](https://www.virtualhackinglabs.com/)
* [https://academy.tcm-sec.com/courses]( https://academy.tcm-sec.com/courses)
* [INE](https://my.ine.com/learning-paths)
* [https://hackersacademy.com/](https://hackersacademy.com/)
* [Red team ops](https://www.zeropointsecurity.co.uk/red-team-ops)
* [Pentester academy - red team labs](https://www.pentesteracademy.com/topics)
* [Pentester labs](https://pentesterlab.com/)
* [KodeKloud](https://learn.kodekloud.com/courses)
## 资源
* [https://startupstash.com/cybersecurity-resources/](https://startupstash.com/cybersecurity-resources/)
* [https://threatexpress.com/redteaming/resources/](https://threatexpress.com/redteaming/resources/)
* [逆向工程](https://www.infosecinstitute.com/skills/learning-paths/reverse-engineering/)
* [https://ippsec.rocks/?#](https://ippsec.rocks/?#)
* [https://liveoverflow.com/](https://liveoverflow.com/)
* [学习 vim](https://www.vim.so/) 或 [Emacs](https://www.emacswiki.org/emacs/LearningEmacs) 我不在乎,我不想引发一场战争
* [Python 网络安全 - 构建你自己的工具](https://www.reddit.com/r/Python/comments/o0dzk6/python_cybersecurity_build_your_own_tools/)
* [Osint framework](https://osintframework.com/)
* [OSINT 入门](https://www.reddit.com/r/OSINT/comments/e78he1/osint_for_beginners_part_1_introduction/?utm_source=share&utm_medium=web2x&context=3)
* [Vulnhub 资源](https://www.vulnhub.com/resources/)
## 编程资源
### **学习 Git**
[Git 的飞行规则](https://github.com/k88hudson/git-flight-rules)
[https://ohmygit.org/](https://ohmygit.org/)
[https://www.freecodecamp.org/news/what-is-git-learn-git-version-control/](https://www.freecodecamp.org/news/what-is-git-learn-git-version-control/)
### **综合**
[在线学习计算机科学(CS)的综合指南](https://qvault.io/2020/11/18/comprehensive-guide-to-learn-computer-science-online/)
[什么是测试自动化?](https://www.perfecto.io/blog/what-is-test-automation)
[用简单的方式开始学习 TypeScript](https://austingil.com/typescript-the-easy-way/)
[机器学习入门](https://rubikscode.net/2021/01/04/machine-learning-with-ml-net-introduction/)
[freecodecamp](https://www.freecodecamp.org/)
[Programiz](https://www.programiz.com/)
[Codewars](https://www.codewars.com/)
[Code academy](https://www.codecademy.com/)
[Fullstackopen:深入现代 Web 开发](https://fullstackopen.com/en/)
[学习 {Python,Java,C,JavaScript,PHP,Shell,C#}](https://www.learn-c.org/)
[JavaPoint](https://www.javatpoint.com/)
通过 [LandChad.net](https://landchad.net/) 学习建站
[Scaler](https://www.scaler.com/topics/)
### **Python**
[终极 Python 学习指南](https://github.com/huangsam/ultimate-python)
[Python 数据可视化新手指南](https://old.reddit.com/r/Python/comments/kriteb/a_beginners_guide_to_data_visualization_with/)
[与 Seaborn](https://old.reddit.com/r/Python/comments/kriteb/a_beginners_guide_to_data_visualization_with/)
[关于现代 Python 包的优秀指南](https://old.reddit.com/r/Python/comments/kxev5h/nice_guide_on_modern_python_packages/)
[面向非计算机专业学生的 Python 与编程入门](https://github.com/webartifex/intro-to-python)
[https://www.gormanalysis.com/blog/python-pandas-for-your-grandpa/](https://www.gormanalysis.com/blog/python-pandas-for-your-grandpa/)
[Practicepython.org](http://www.practicepython.org/)
[Python 教程:初学者综合指南](https://wiingy.com/learn/python/python-overview/)
### **JavaScript**
[现代 JavaScript 教程](https://javascript.info/)
[JavaScript 101 - 变量与基元](https://spdevuk.com/javascript-101-variables-and-primitives/)
[JavaScript 数组函数指南:为什么你应该为工作选择威力最小的工具](https://jesseduffield.com/array-functions-and-the-rule-of-least-power/)
[学习和练习现代 JavaScript](https://learnjavascript.online/)
### **Java**
[容器化 (Spring Boot) Java 应用的搭车客指南](https://blog.frankel.ch/hitchhiker-guide-containerizing-java-apps/)
[CDC (Change Data Capture) 新手指南](https://vladmihalcea.com/a-beginners-guide-to-cdc-change-data-capture/)
[Java 15 程序员的文本块指南](https://inside.java/2020/08/05/textblocks-programmer-guide/)
[Java 现代化 Web 开发 - (永远也)不完备的指南](https://asd.learnlearn.in/java-web/)
[Java Modules 速查表](https://old.reddit.com/r/java/comments/jyddn9/java_modules_cheat_sheet/)
[Java Modules 速查表](https://nipafx.dev/build-modules/)
### **C++**
[权威的 C++ 书籍指南与列表](https://stackoverflow.com/questions/388242/the-definitive-c-book-guide-and-list)
[Linear-cpp](https://github.com/jesyspa/linear-cpp)
[Tony Gaddis Early Objects](http://instructor.sdu.edu.kz/~bakhyt/CPP/suggested%20books/Starting%20out%20with%20C++.pdf)
### **PHP**
[PHP The right way](https://phptherightway.com/)
## 杂项链接
* [https://freetraining.dfirdiva.com]( https://freetraining.dfirdiva.com)
* [你会在这里找到你正在寻找的大多数书籍](https://b-ok.global/)
* [ssh-audit](https://github.com/jtesta/ssh-audit)
* [保护你的 Linux 安装](https://www.reddit.com/r/linux/comments/ns7r7o/a_complete_yet_beginner_friendly_guide_on_how_to/)
* [Awesome-Linux-Software](https://github.com/luong-komorebi/Awesome-Linux-Software)
* [Twitter-geolocate](https://github.com/davidkowalk/twitter_geolocate)
* [Linux training academy](https://www.linuxtrainingacademy.com/)
* [modern-unix](https://github.com/ibraheemdev/modern-unix) 常用 unix 命令的现代/更快/更实用的替代品合集。
* [Linuxzoo](https://linuxzoo.net/)
* [Snaplabs.io](https://www.snaplabs.io/)
* [shortcutfoo.com](https://www.shortcutfoo.com/)
## YouTube 频道
[Pwnfunction](https://www.youtube.com/channel/UCW6MNdOsqv2E9AjQkv9we7A)
[zSecurity](https://www.youtube.com/user/zaidsabeeh)
[HckerSploit](https://www.youtube.com/channel/UC0ZTPkdxlAKf-V33tqXwi3Q)
[Nullbyte](https://www.youtube.com/channel/UCgTNupxATBfWmfehv21ym-g)
[LiveOverflow](https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w)
[John hammond](https://www.youtube.com/user/RootOfTheNull)
[The cyber mentor](https://www.youtube.com/channel/UC0ArlFuFYMpEewyRBzdLHiw)
[Network Chuck](https://www.youtube.com/user/NetworkChuck)
[Ippsec ](https://www.youtube.com/channel/UCa6eh7gCkpPo5XXUDfygQQA)
[Insiderphd ](https://www.youtube.com/user/RapidBug)
[David bomball ](https://www.youtube.com/user/ConfigTerm)
[Alhz4r3d ](https://www.youtube.com/channel/UCz-Z-d2VPQXHGkch0-_KovA)
## Discord 服务器
[the cyber mentor](https://discord.gg/tcm)
[infosec prep ](https://discord.gg/infosecprep)
[certification station](https://discord.gg/certstation)
[network Chuck](https://discord.gg/networkchuck)
[nahmsec](https://discord.gg/xd75Stsuxk)
[bounty hunters](https://discord.gg/bugbounty)
[The Alh4z-R3d Team](https://discord.gg/thealh4zr3dteam)
[hack the box](https://discord.gg/hackthebox)
[tryhackme](https://discord.gg/tryhackme)
[hack this site](https://discord.gg/ETm3Q8SSht)
[PG (proving grounds) ](https://discord.gg/6neBxaGjHD)
[Getting started in security ](https://discord.gg/dnEcAqZn4x)
[INE 非官方服务器 ](https://discord.gg/XGVaBeapXQ)
[Offsec 官方服务器](https://discord.gg/offsec)
[ctf learn](https://discord.gg/Susw824A2T)
[Hacker101](https://discord.gg/HuwdMBJ2WS)
### ➡️ 贡献
欢迎你的贡献。你可以通过以下方式做出贡献:
- 翻译成其他语言
- 添加更多工具和其他资源。
- 只需给这个 Github 项目加个星标 :)
如果你对这个仓库有一些新想法、问题、反馈,或者发现了一些有价值的工具,请随时提交 issue,或者直接在 Discord 上私信我 @thelastmethbender#4823
## Star 历史
标签:学习资源, 安全, 网络安全, 资源大全, 超时处理, 防御加固, 隐私保护