// PES University — Electronic City Campus

Resources

Everything the club actually uses — practice ranges, tooling and reading. No paid course funnels, no listicles. Start at the top of the path if you have never opened a terminal on purpose.

layer8@pesu — ~/resources
 
start here

Four weeks from zero to your first flag

Work through these in order. Each step is a prerequisite for the next one, and each ends with something you can actually submit.

  1. 01

    Live in the shell

    OverTheWire Bandit, levels 0–20. Teaches ssh, file handling, pipes and grep by making you need them. Budget two evenings.

    overthewire.org/wargames/bandit
  2. 02

    Break a web app

    PortSwigger's Web Security Academy — the SQL injection and access control tracks. Free labs, graded, written by the people who build Burp.

    portswigger.net/web-security
  3. 03

    Play a real CTF

    picoCTF's practice gym. Beginner categories are solvable with step 01 and 02 alone — the rest is where you find out what you like.

    play.picoctf.org/practice
  4. 04

    Turn up on Friday

    Bring one unsolved challenge to the weekly session. Explaining where you got stuck is the fastest way through it, and it is how the team gets picked.

    weekly sessions & schedule
library

The rest of the shelf

Filter by category, or search by name, tool or topic. Everything listed is free unless the card says otherwise.

60 resources

practice range

picoCTF Gym

Carnegie Mellon's beginner CTF archive. Every past challenge stays playable, and the hints nudge you without handing over the answer.

beginnerfree> open

practice range

TryHackMe

Guided rooms with an attack box in the browser. Best when you want to fill a gap in one topic rather than hack around freely.

beginnerfree tier> open

practice range

Hack The Box

Full machines to root, with no hand holding. Start on retired boxes, and only read someone's writeup after you finish.

intermediatefree tier> open

course

pwn.college

ASU's binary exploitation course, lectures and graded challenges included. It is the most complete free route into memory corruption.

advancedfree> open

practice range

CryptoHack

Cryptography taught as puzzles you solve in Python. It runs from modular arithmetic up to real RSA and AES failures.

intermediatefree> open

exercises

Cryptopals

Eight sets of attacks that you implement yourself. Slow, unglamorous, and the reason people stop trusting their own crypto code.

advancedfree> open

course

Web Security Academy

Labs and theory for every major web bug class, from injection to SSRF to request smuggling. This is what we teach from.

all levelsfree> open

practice range

Root-Me

A few hundred short challenges sorted by category. Handy when you want one problem in one topic instead of a whole machine.

all levelsfree> open

practice range

OverTheWire Wargames

Bandit is only the first game. Natas covers web, Narnia and Behemoth cover exploitation, and Krypton covers ciphers, all over ssh.

beginnerfree> open

practice range

VulnHub

Vulnerable VMs you download and run in VirtualBox. No subscription and no network limits, which helps when the campus wifi is having a day.

intermediatefree> open

practice range

Hacker101 CTF

HackerOne's web challenges, built around bugs that turn up in real bounty reports. Flags here also unlock private programme invites.

beginnerfree> open

practice range

OWASP Juice Shop

A deliberately broken shop app you host yourself, with a scoreboard built in. It is our usual target for web workshops.

beginnerfree> open

practice range

ROP Emporium

Eight challenges about return oriented programming and nothing else. Do them the week after you first get past a stack canary.

intermediatefree> open

practice range

Exploit Education

Phoenix and Nebula, which took over from Protostar. Graded overflows, format strings and privilege escalation on ready made VMs.

intermediatefree> open

practice range

pwnable.kr

Small, sharp exploitation puzzles served over ssh. Each one hides a single trick, so they work well solved in pairs.

intermediatefree> open

practice range

Microcorruption

Embedded exploitation against a fictional lock, all in the browser with a debugger attached. The gentlest way into assembly.

beginnerfree> open

practice range

crackmes.one

A steady stream of reversing binaries uploaded by other people and rated by difficulty. Pick a one star, open Ghidra, find the check.

all levelsfree> open

practice range

flAWS

Cloud misconfiguration taught as a hunt through one badly built AWS account. Six levels, and you do not need an account of your own.

beginnerfree> open

calendar

CTFtime

Every live competition, how much it is worth, and the writeups afterwards. Check it on Monday and pick the weekend event we play together.

referencefree> open

reference

HackTricks

The wiki everyone has open mid challenge. Enumeration checklists and escalation tricks for each service and platform.

referencefree> open

reference

PayloadsAllTheThings

A payload and bypass collection sorted by bug class. Read the methodology notes too, not just the strings you can paste.

referencefree> open

reference

GTFOBins

Unix binaries you can abuse to escape a restricted shell or escalate privileges. Use LOLBAS for the Windows side.

referencefree> open

reference

LOLBAS

The Windows half of the same idea. Signed Microsoft binaries that download, run or bypass things, and a good reading list for detection work.

referencefree> open

book

CTF Field Guide

Trail of Bits' short guide to how competitions work and how to prepare for one. Read it before your first live event.

beginnerfree> open

book

Nightmare

Binary exploitation explained one real CTF challenge at a time, starting at simple overflows and ending in heap grooming.

intermediatefree> open

methodology

OWASP Testing Guide

How a real web assessment gets scoped and run, test by test. It turns scattered lab tricks into something you can repeat on a job.

referencefree> open

reference

Exploit-DB

Archived public exploits with the papers behind them. Read the code before you run it, since plenty of what is posted needs fixing first.

referencefree> open

tool

Burp Suite Community

An intercepting proxy for anything over HTTP. Learn Repeater and Decoder first, because Intruder is rate limited on the free build.

toolingfree> open

tool

Ghidra

The NSA's reverse engineering suite, with a decompiler that holds up. It covers nearly every reversing challenge you will see as a student.

toolingfree> open

tool

pwntools

A Python library for writing exploits. Process and socket handling, packing, ROP and shellcode helpers in a few lines.

toolingfree> open

tool

pwndbg

A gdb plugin that makes the heap, the stack and the registers readable. Install it the same evening you install pwntools.

toolingfree> open

tool

CyberChef

Encoding, decoding and analysis chained together in the browser. First thing to try on a blob of text you cannot identify.

toolingfree> open

tool

Wireshark

Packet capture and analysis. Most network forensics challenges are one display filter and a follow stream away from solved.

toolingfree> open

tool

Volatility 3

A memory forensics framework. It pulls processes, network connections and injected code out of a RAM image.

toolingfree> open

tool

Nmap

Host discovery, port scanning and service fingerprinting. Learn what the flags do before pasting a scan line from someone's writeup.

toolingfree> open

tool

ffuf

A fast fuzzer for directories, subdomains, parameters and virtual hosts. Filter by response size early or you will drown in 200s.

toolingfree> open

wordlists

SecLists

The wordlist collection every fuzzer expects to find on disk. Paths, parameters, passwords, payloads. Clone it once and keep it.

toolingfree> open

tool

sqlmap

Automated SQL injection detection and exploitation. Use it after you have found the injection by hand, not instead of looking.

toolingfree> open

tool

Hashcat

GPU password cracking with rule based mutation. Work out the hash mode first, since most failed cracks are just the wrong -m flag.

toolingfree> open

tool

RsaCtfTool

Throws the standard RSA attacks at a weak key, from small exponent to Wiener and Fermat. Then go and read why the one that worked worked.

toolingfree> open

tool

binwalk

Finds and extracts files hidden inside other files, firmware images included. The usual first move on an unexplained binary blob.

toolingfree> open

tool

Aperi'Solve

Runs a whole steganography toolchain over an uploaded image at once. Saves twenty minutes on every flag hidden in a picture.

toolingfree> open

tool

Autopsy

Disk image forensics with timelines, deleted file recovery and keyword search. A GUI over The Sleuth Kit, and enough for most DFIR rooms.

toolingfree> open

tool

revshells.com

Builds a reverse shell one liner for whatever binary the target actually has, with the matching listener command next to it.

toolingfree> open

reference

OSINT Framework

A map of open source intelligence sources arranged by what you are starting from, whether that is a username, a domain, an image or a phone number.

referencefree> open

tool

Sherlock

Checks a username across hundreds of sites. Run it on your own handles once and see how much of a trail you have left.

toolingfree> open

tool

Shodan

A search engine for exposed services and their banners. Useful for scoping recon, and sobering when you point it at your own network.

referencefree tier> open

reference

Bellingcat Toolkit

The toolkit Bellingcat's researchers actually use. Geolocation, imagery, transport and archive sources, kept up to date.

referencefree> open

practice range

Blue Team Labs Online

Investigations from the defender's chair. Log triage, phishing analysis and incident timelines. Rarer skill, and easier hiring.

intermediatefree tier> open

practice range

CyberDefenders

Blue team CTFs built on real captures and memory images. The closest free thing to sitting a shift in a SOC.

intermediatefree tier> open

practice range

LetsDefend

A simulated SOC queue with alerts to close and evidence to attach. It teaches the workflow, not only the analysis.

beginnerfree tier> open

datasets

Malware Traffic Analysis

Years of real infection pcaps with exercises and answers. Bring one to a Friday session and build the timeline as a group.

intermediatefree> open

reference

MITRE ATT&CK

The shared vocabulary for attacker behaviour. Once you can name a technique, detection engineering starts to make sense.

referencefree> open

reference

Sigma Rules

Detection rules written once and converted to whatever SIEM you are stuck with. Read a few before you write your first one.

referencefree> open

tool

Atomic Red Team

Small scripted tests mapped to ATT&CK techniques. Run one in a lab VM, then check whether your logging noticed.

intermediatefree> open

reference

OWASP Top 10 for LLM Apps

Prompt injection, insecure output handling, data leakage and the rest. The current baseline for reviewing anything with a model in it.

referencefree> open

practice range

Gandalf

Seven levels of prompt injection against system prompts that get harder each time. Twenty minutes, and the lesson sticks.

beginnerfree> open

practice range

Prompt Airlines

A chatbot CTF where the goal is a free flight. It shows how a model with tool access turns into an application vulnerability.

beginnerfree> open

tool

garak

A vulnerability scanner for LLMs. Jailbreak, leakage and toxicity probes run as one suite against a model you host yourself.

toolingfree> open

reference

MITRE ATLAS

ATT&CK's counterpart for machine learning systems. Real tactics used against models, from evasion through to model theft.

referencefree> open

Found something better?

The list is maintained by members. Send a link and one line on why it earned a slot.