Skip to content

Resources

The kit on screen, and where to practise.

Standards, legal practice labs, tools and wordlists, each with its licence. The short list: the one actually used in the videos.

Standards and cheat sheets

The frameworks the videos follow, and the pages we keep open while testing.

OWASP MASVS & MASTG

The mobile security standard and its testing guide, with test apps and techniques for Android and iOS.

Licence: CC BY-SA 4.0

OWASP MASVS & MASTG

The mobile security standard and its testing guide, with test apps and techniques for Android and iOS.

Licence: CC BY-SA 4.0

OWASP MASVS & MASTG

The mobile security standard and its testing guide, with test apps and techniques for Android and iOS.

Licence: CC BY-SA 4.0

OWASP API Security Top 10

BOLA, broken authentication, unrestricted resource consumption: the 2023 list the API videos follow.

Licence: CC BY-SA 4.0

Practice labs

Targets built to be broken. The only place to practise an attack you have not been authorised to run elsewhere.

OWASP Juice Shop

A deliberately insecure web shop that runs locally in one Docker command. Ideal for filming.

Licence: MIT

OWASP Juice Shop

A deliberately insecure web shop that runs locally in one Docker command. Ideal for filming.

Licence: MIT

OWASP crAPI

A vulnerable API platform covering the OWASP API Top 10, with microservices and a mobile-style client.

Licence: Apache-2.0

Damn Vulnerable DeFi

DeFi challenges on flash loans, oracles, governance and more. Solved on a local fork, never on mainnet.

Licence: MIT

Damn Vulnerable DeFi

DeFi challenges on flash loans, oracles, governance and more. Solved on a local fork, never on mainnet.

Licence: MIT

Ethernaut

OpenZeppelin's Solidity wargame. Each level is a vulnerable contract to take over on a testnet.

Licence: MIT

flAWS.cloud

A series of AWS mistakes to exploit, level by level, on infrastructure built for it.

Licence: Free, no licence stated

CloudGoat

Vulnerable-by-design AWS scenarios deployed in your own account with Terraform. Tear them down after use.

Licence: BSD-3-Clause

OWASP IoTGoat

A deliberately insecure firmware based on OpenWrt, to practise on the IoT Top 10 without buying hardware.

Licence: MIT

Tools

The software on screen in the videos. Check the licence on the source page before commercial use: it can change.

ZAP

The open-source alternative to Burp, scriptable and easy to run in CI.

Licence: Apache-2.0

Frida

Dynamic instrumentation for Android and iOS: hook a function, bypass pinning, read what the app hides.

Licence: wxWindows Library Licence 3.1

Frida

Dynamic instrumentation for Android and iOS: hook a function, bypass pinning, read what the app hides.

Licence: wxWindows Library Licence 3.1

Nuclei

A template-based scanner. Useful for recon on authorised scopes, dangerous anywhere else.

Licence: MIT

Foundry

The Solidity toolkit used to fork a chain locally and write the exploit as a test.

Licence: MIT or Apache-2.0

Foundry

The Solidity toolkit used to fork a chain locally and write the exploit as a test.

Licence: MIT or Apache-2.0

binwalk

Finds and extracts what is packed inside a firmware image.

Licence: MIT

garak

An LLM vulnerability scanner: probes for prompt injection, jailbreaks and data leakage.

Licence: Apache-2.0

Wordlists and payloads

Collections to fuzz and test with, on targets you are allowed to touch.

SecLists

Wordlists for discovery, fuzzing, usernames and payloads. The first thing installed on a new machine.

Licence: MIT

SecLists

Wordlists for discovery, fuzzing, usernames and payloads. The first thing installed on a new machine.

Licence: MIT

PayloadsAllTheThings

Payloads and bypasses sorted by vulnerability class, with the context to understand them.

Licence: MIT

PayloadsAllTheThings

Payloads and bypasses sorted by vulnerability class, with the context to understand them.

Licence: MIT

PayloadsAllTheThings

Payloads and bypasses sorted by vulnerability class, with the context to understand them.

Licence: MIT

Newsletter

Get the fix before the exploit goes viral.

One email when there is something to show: a new video, a write-up cleared for disclosure, or an advisory that hits a stack we cover. No weekly recap, no fear-selling.

An address is enough. One-click unsubscribe.