Here is a list of resources (Twitter, Tools, blogs, YouTube channels, etc.) for cybersecurity profesionnal. Feel free to suggest any
Twitter accounts
Top
| Account | Quick description |
|---|---|
| Black Hat | The World's Premier Technical Security Conference Series |
| Cyberwatch | French EVM |
| HackerOne | The only official HackerOne Twitter account |
| Hackread.com | Cybersecurity news platforms |
| SecurityWeek | Cybersecurity News, Threats, Insights and Expert Analysis |
| The Hacker News | Breaking news and tech coverage on cybersecurity |
Other accounts
| Account | Quick description |
|---|---|
| 44CON | UK Information Security Conference and training event |
| ANSSI | Agence nationale de la sécurité des systèmes d'information |
| Almond | Entreprise de la Cybersécurité, du Cloud et des Infrastructures |
| Bad Packets | Cyber threatintel on emerging threats, DDoS botnets, and network abuse |
| BlueHat IL | Cybersecurity conferences |
| BreizhCTF 2022 | Annual CTF |
| BugBountyHQ | Bug bounty news |
| CERT-FR | Centre gouvernemental de veille, d'alerte et de réponse aux attaques informatiques |
| CVEnew | Latests CVEs (warning, can tweet quiet a lot) |
| Chromium Disclosed Security Bugs | Automatic report of Chromium disclosed security bugs |
| ComcyberFR | Compte officiel du Commandement de la cyberdéfense française |
| DEF CON | Hacking Conference |
| DGA | Compte officiel de la Direction générale de l'armement |
| Defense Digital Service | We are tech experts tackling the DOD's toughest problems |
| FIC_eu | French "Forum International de la Cybersécurité" |
| Gareth Heyes | Security payloads and other funny code tricks |
| HITBSecConf | Conference series held annually around the world |
| Hacking is NOT a Crime | A nonprofit organization advocating global policy reform to decriminalize hacking |
| Insomni'hack | Ethical Hacking Contest |
| Le Comptoir Sécu | Le podcast traitant des enjeux de la sécurité informatique |
| NetBlocks | Tracking network disruptions and shutdowns |
| NoLimitSecu | Podcast francophone dédié à la cybersécurité |
| NotSoSecure | Company delivering high-end IT security consultancy |
| Offensive Security | Kali and OSCP makers |
| OpexNews | Veille sur les questions militaires et de défense |
| PortSwigger Research | Web security research from the PortSwigger team |
| RedTeamVillage | Group of red teamers (Red Team Village) |
| SANS Offensive Operations | Training, Certification, and Research |
| Synacktiv | Offensive security company |
| leHACK | Hacking conferences (french) |
| vx-underground | The largest collection of malware source code, samples, and papers |
Cybersecurity researchers
- Mathias
- Orange Tsai
- Benjamin Delpy
- jermainlaforce
- LiveOverflow
- Ryan Hanson
- 偉
- Caitlin Condon
- James Kettle
Websites
Tools
| Site | Usage |
|---|---|
| APNIC | IP (ranges, cidr) transfers and history |
| CenSys | Threat intel scan |
| Cipher Suite | Infos on TLS ciphersuites |
| Crack Station | Hash reverse database |
| Damn Vulnerable Web Application | Training application for finding simple web vulnerabilities |
| EPIEOS | Infos about any email address |
| FotoForensics | Image analysis and metadata searching |
| HTTP Request Inspector | Internet-exposed temporary HTTP server for C2 |
| HackTricks | Lot of resources, tips and such |
| IPInfo | Who owns and where is a specific IP |
| Kali | The OS |
| MOHMal | Anonymous disposable email |
| Metasploit Doc | Documentation for the Kali's Metaploit framework |
| NMap | Network scanner |
| NetCraft | Find what's powering a server, from its responses |
| OSINT Framework | List of OSINT tools |
| Open PGP Keys | Email public encryption keys registry |
| OpenVAS | Vulnerability scanner |
| PasteBin | Share texts (publicly) |
| RSA Calculation | For CTF |
| Security Headers scanner | Analyze web servers response headers |
| Security Trails | DNS history and infos, plus other similar stuff |
| Wayback machine | Archiveds web pages (OSINT and bug bounty proofs) |
| Zonemaster | DNS check |
CVE, POC
Github
- LinEnum
- Linuxprivchecker.py
- Red Canary (atomic red team)
- Tsunami scanner
- ICS Pentesting Tools
- LinPEAS
- Payloads All The Things
- dnSpy
- Magic hashes
- JS package names
Blogs
- Trusted Sec
- SIM (cards) hack
- Dark Readings
- Pentest Lab
- The Hitchhiker’s Guide to Online Anonymity
- Live cyber threat map
- Blue team blog
- ALPACA Attack
- Synacktiv
- OSCP Guide
- ANSSI Logo Challenge
- No More Ransom
Security conferences and groups
Labs and trainings
- Newbie Contest
- SecNum (MOOC ANSSI)
- RingZero Team online CTF
- Hack The Box
- Offensive Security (certs and trains)
- Portswigger (BURP makers)
Bug Bounty
Cheat sheets
- Subdomains enumeration
- Windows x86-64 syscalls
- Reverse Shell Generator
- Linux Syscall
- 80x86 instructions
Docs, Specs etc
CTF
YouTube accounts
- Black Hat
- CODE BLUE
- DEFCON Conference
- Hack In The Box Security Conference
- John Hammond
- LiveOverflow
- LockPickingLawyer
- Orange Tsai
- PwnFunction
- Metasploit
- HackerSploit
- HackerOne
- GynvaelEN
- DeviantOllam (lockpick)
- Cybercrime Magazine
- Cyberspatial
- GOTO Conferences
- Adrian Crenshaw
- CarolinaConVideos
- Christiaan008