The channels listed here will eventually be monitored by @HackerTalkyTalk, so that whenever new videos get uploaded, there's only one Twitter account you need to watch to keep track of new material as it gets released. :D
Feel free to add more to the list; this is pretty incomplete, but better than nothing for folks who are new. Pull requests or Twitter DMs are both fine :)
PLEASE NOTE: Each list is randomly ordered. @hexwaxwing will reorder them more appropriately once more fully-enumerated lists are assembled.
UPDATE (2-20-2018): Added a History & Culture section, since I'm finding a lot of younger newcomers need help understanding the historical context of the hacker subculture in infosec. Also, added a TOC with links to the different sections. And a bunch of new entries.
UPDATE (2-19-2018): Added a few other sections that aren't really relevant to @HackerTalkyTalk, but are useful for learners: Complete & Utter Newbie Starting Resources, Practice Materials && Labs, and Workstation VMs.
- Infosec/Hacker Conference Talk Recordings [127 conferences]
- Infosec&&Hacker Cons [84]
- BSides [43]
- Meetups That Record Their Talks [2]
- Other Audiovisual Multimedia
- Shows &/or Livestreams [40]
- Podcasts [86]
- Playgrounds!: Practice Materials && Labs [31]
- Workstation VMs [9]
- Introductory Resources for the Complete Newbie [7]
- Hacker History & Culture [13]
- 3C/CCC
- DEFCON
- Infocon.org
[talk+podcast aggregator; torrents available]
- Irongeek's channel
[Collection of ~2000+ con videos from smaller American cons]
- DerbyCon: [III: 2011 • IV: 2012 • V: 2013 • IV: 2014 • V: 2015 • VI: 2016 • VII: 2017]
- Converge [2016 • 2017]
- GrrCon [2015 • 2016 • 2017]
- ANYCon [2017]
- CircleCityCon [2014 • 2015 • 2016 • 2017]
- ShowMeCon [2015 • 2016 • 2017]
- NolaCon [2016 • 2017]
- AIDE [2015 • 2017]
- CypherCon [1.0: 2016 • 2.0: 2017]
- BloomCon [2017]
- PhreakNIC [XII: 2008]
- HouSecCon [#6: 2015]
- ShmooCon [Firetalks: 2015]
- DEFCON [Wireless Village: 2014]
- OISF [2015]
- SecureWV/Hack3rcon: [VI: 2015 • VII: 2016 • VIII: 2017]
- Louisville Infosec [2013 • 2015 • 2016 • 2017]
- BSides Tampa: [2015 • 2017]
- BSides NoVa (Northern Virginia) [2017]
- BSides Cleveland [2014 • 2015 • 2017]
- BSides Detroit [2015 • 2016 • 2017]
- BSides Charm (Baltimore) [2017]
- BSides Nashville [2014 • 2015 • 2017]
- BSides Indy [2017]
- BSides Philly (Philadelphia): [2016 • 2017]
- BSides Augusta [2015 • 2016]
- BSides San Francisco [2015 • 2016]
- BSidesLV (Las Vegas) [2012 • 2013 • 2015]
- BSidesCincy (Cincinnati) [2015]
- BSides Boston [2015]
- BSides Columbus [2015]
- BSidesRI (Rhode Island): [2013]
- BSides Chicago [2014]
- BSidesDE (Delaware) [2013]
- Cooper (@Ministraitor): [YouTube • archive.org]
[Kinda like a European version of Irongeek]
- hack.lu: [2016 • 2017]
- eth0: [Winter 2017]
- MISP Summit: [2016 • 2017]
- SteelCon: [2016]
- HaxoGreen: [2016]
- hardwear.io (@hardwear_io): [2016 • 2017] (FIXME: needs separate playlists for each year)
- IRISSCON (@irisscert): [2013 • 2014 • 2015 • 2016 • 2017]
- Securi-Tay (@AlbertayHackers): [IV: 2015 • V: 2016 • VI: 2017]
- OWASP Chapter Meetings: [2016 • 2017]
- BSides Ljubljana (@BSidesLjubljana): [2016 • 2017]
- BSides Hamburg (@HamburgSides): [2015 • 2016]
- BSides Hannover (@BSidesHN): [2016 • 2017]
- BSides Belfast (@bsidesbelfast): [2016]
- BSides Munich (@BSidesMunich): [2017 (YouTube | archive.org)]
- BSides Bordeaux (@BSidesBDX): [2017]
- BSides Luxembourg (@BSidesLux): [2017]
- BSides Amsterdam (@BSidesAMS): [2017]
- BSides Manchester (@BSidesMCR): [2014 inc. • 2015 • 2016 • 2017]
- BSides
EdinburghScotland (@BSidesScot): [2017]
- PhreakNIC: VII: 2003 • VIII: 2004 • IX: 2005 • X: 2006 • XI: 2007 • XVI: 2012 • XVII: 2013 • XVIII: 2014 • IXX: 2015 • XX: 2016 • XXI: 2017 (cf. Irongeek's channel for PhreakNIC XII [2008])
- Hacktivity
- S4
[ICS]
- ZeroNights
- REcon (@reconmtl @reconbrx): 2013 [YouTube|REcon (in schedule talk descriptions)] • 2014 [YouTube|REcon+slides] • 2015 [YouTube|REcon+slides] • 2016 [YouTube|REcon] • 2017 [YouTube|REcon)
[reverse engineering]
- BruCON
- Hack in the Box (HITB)
- SANS DFIR
[DFIR + threat hunting + threat intel]
- SANS Pentesting
[penetration testing]
- SANS ISC
[netsec + nsm]
- GHP1989 • HEU1993 • HIP1997 • HAL2001 • WTH2005 • HAR2009 • OHM2013: [...do recordings exist...?]
- SHA2017: [YouTube channel • media.ccc.de]
- SAINTcon [playlists & videos]
- Toorcon
- ekoparty
- Real World Crypto
[cryptography]
- CarolinaCon
[offsec]
- Wild West Hackin' Fest
- Rooted Con
- BalCCon
- SEC-T
- FSec
- LayerOne: 2015 • 2016 • 2017
- TROOPERScon:
[defense + management + SAP + IPv6 + NGI + embedded + offsec]
- BlackAlps CyberSecurityConference
- x33fcon
[purple team]
- SkyDogCon
- SecurityOnion Con
[NSM+IDS+IPS]
- Nullcon Goa: 2013 • 2014 • 2015 • 2016 • 2017 • 2018
- KansasFest
[retro gaming, some reverse engineering]
- Botconf.eu
[malware analysis]
- ShmooCon: [2017 & 2018]
- SyScan360 Singapore: [2014 • 2015 • 2016]
- BlueHat IL (Israel): [2017 • 2018] (no official playlist, but all on this YouTube acct)
- Infiltrate: [2011 inc • 2012 • 2013 inc • 2014 • 2015 • 2016 • 2017]
- Hackers On Planet Earth (HOPE): [1994 • 1997 • 2000 • 2002 • V: 2004 • IX: 2012 • X: 2013]
- Code Blue (@codeblue_jp): [2013 • 2014 • 2015 • 2016 • 2017]
- HackerHotel: [2015 • 2016 • 2018 (livestream)] (needs to be separated into playlists)
- NLUUG: [2015 • 2017] (needs to be separated into playlists)
- eth0:winter [2014 (wiki) • 2015 (wiki) • 2016 (wiki) • 2017 (wiki)]
- Electromagnetic Field (@emfcamp): [2014 • 2016]
- Black Hat (Europe): [2014 • 2015 • 2016 • 2017]
- Black Hat (USA): [2013 • 2014 • 2015 • 2016 • 2017]
- Black Hat (Asia): [2014 • 2015 • 2016 • 2017]
- r2con: [2017]
- LevelUp: [2017]
- SteelCon: [2014 • 2015 • 2016 • 2017]
- CanSecWest: [slides for 2000–2017] [...do recordings exist...?]
- PacSec: [slides for 2003–2017] [...do recordings exist...?]
- FOSDEM: [2003 • 2004 • 2005 • 2006 • 2007 • 2008 • 2009 • 2010 • 2011 • 2012 • 2013 • 2014 • 2015 • 2016 • 2017]
- AppSecEU: [2014 • 2015 • 2016 • 2017]
- AppSecUSA: [2013 • 2014 • 2015 • 2016 • 2017]
- OWASP AppSec California: [2014 • 2015 • 2016 • 2017]
- Hack in Paris: [2011 • 2012 • 2013 • 2014 • 2015 • 2016 • 2017]
- H.A.C.K Camp:::CampZer0 (@campzer0): [2013 (slides)]
- H.A.C.K Camp:::Camp++: [2014 (slides) • 2015:0x7df • 2016:0x7e0 • 2017:0x7e1]
- NorthSec: [2015 • 2016 • 2017]
- TRISS: 2017
- BSidesLV (Las Vegas): [irongeek: 2012 • 2013 • 2015]
- BSidesLisbon
- BSidesRaleigh
- BSidesCapeTown
- BSidesStJohns
- BSidesLondon
- BSidesVancouver
- BSidesIOWA
- BSidesDE (Delaware): [irongeek: 2013]
- BSidesOrlando
- BSidesWarsaw
- BSidesSLC
- BSidesSF: [irongeek: 2015 • 2016]
- BSidesPhilly (Philadelphia): [irongeek: 2016 • 2017]
- BSides Tel Aviv: BSidesTLV2017 & BSidesTLV2016
- BSidesLA/ShellCon: ShellCon 2017.
- BSidesCharm: [2016] [irongeek: 2017]
- BSides Asheville: 2014 • 2015 (Sat, Sun) • 2016 • 2017
- BSidesCalgary (@bsides_calgary): [2016 • 2017] (FIXME: years need to be separated into playlists)
- BSidesNYC: [2018]
- BSides Ljubljana (@BSidesLjubljana): [2016 • 2017]
- BSides Hamburg (@HamburgSides): [2015 • 2016]
- BSides Hannover (@BSidesHN): [2016 • 2017]
- BSides Belfast (@bsidesbelfast): [2016 • 2017]
- BSides Munich (@BSidesMunich): [2017 (YouTube | archive.org)]
- BSides Bordeaux (@BSidesBDX): [2017]
- BSides Luxembourg (@BSidesLux): [2017]
- BSides Amsterdam (@BSidesAMS): [2017]
- BSides Manchester (@BSidesMCR): [2014 inc. • 2015 • 2016 • 2017]
- BSides
EdinburghScotland (@BSidesScot): 2017 - BSides Tampa: [irongeek: 2015 • 2017]
- BSides NoVa (Northern Virginia): [irongeek: 2017]
- BSides Cleveland: [irongeek: 2014 • 2015 • 2017]
- BSides Detroit: [irongeek: 2015 • 2016 • 2017]
- BSides Nashville: [irongeek: 2014 • 2015 • 2017]
- BSides Indy (Indianapolis): [irongeek: 2017]
- BSides Augusta: [irongeek: 2015 • 2016]
- BSidesCincy (Cincinnati): [irongeek: 2015]
- BSides Boston: [irongeek: 2015]
- BSides Columbus: [irongeek: 2015]
- BSidesRI (Rhode Island): [2013]
- BSides Chicago: [irongeek: 2014]
- [BSides Leeds] (@BSidesLeeds): [2018]
- BSides Pittsburgh: [2015 • 2016 • 2017]
- SecKC
- SecDSM
- Louisville ISSA Web Pentesting workshop [2013]
[pentesting + appsec + bug bounty]
- Louisville Nmap workshop [2014]
[pentesting]
- Steel City InfoSec
- To explore infosec/hacker events near you (& see talks in person &/or meet local infosec folk [we don't bite! usually!]), check out @nyxgeek's world map of security meetups&conferences at hackermaps.org, & check out @evilsocket's ConfWatch.Ninja (@confwatchninja) for a schedule of upcoming cons. <3
- @LiveOverflow's livestream
[CTF + reverse engineering + exploit dev]
- @TheColonial's OJ Reeves/th3colon1al livestream
[Metasploit, Meterpreter dev + exploit dev]
- @gynvael Coldwind's livestream
[CTF + reverse engineering]
- @hedgeberg's livestream
[reverse engineering + hardware hacking + console hacking]
- @ktemkin's livestream
[reverse engineering + hardware hacking]
- @_r00k_'s livestreams + walkthroughs
[CTF walkthroughs]
- @MurmusCTF's walkthroughs
[CTF walkthroughs]
- @IppSec's walkthroughs
[CTF walkthroughs]
- MeshX93
[walkthroughs]
- webpwnized
[appsec, websec, netsec]
- Micah Elizabeth Scott's @scanlime show: YouTube • Patreon
[reverse engineering + sundry]
- John Hammond's YouTube channel
[CTF walkthroughs + programming tutorials]
- Cybersecurity Camp
- @Hak5's tutorials (with @Snubs, @mubix, @hak5darren)
[basic skills + pentesting]
0. Hak5: Seasons 1-5 • Seasons 6-10 • Seasons 11-15 0. Open Source Recommendations 0. Hack Across the Planet 0. 3D Printing 0. HakTip with @Snubs 0. Metasploit Minute with @mubix - SecurityTube
- @DAkacki @da_667 @oscaron @benheise @Ajediday & @mzbat's Rally Security
[weekly news breakdown]
- @HECFBlog's Forensic Lunch
[DFIR]
- Sam Bowne's livestreamed infosec classes
[Careers in Computer Networking • Ethical Hacking & Network Defense • CISSP prep • Securing Web Applications • Exploit Development]
- vTriple livestream
[DFIR & dev]
- @struppigel's Malware Analysis for Hedgehogs
[DFIR + malware analysis]
- @hasherezade's walkthroughs
[malware analysis + reverse engineering]
- Colin Hardy
[malware analysis + reverse engineering]
- @herrcore + @seanmw's Open Analysis Labs #OpenAnalysisLive
[malware analysis + reverse engineering]
- Computerphile
- SDR intro with Michael Ossmann
- @SecureTheHuman's SANS Security Awareness: SecureTheHuman webcasts
[soft skills + security awareness]
- Big Brain Security
- @duosec's DuoSec Talks
- @BHinfoSecurity's webinars
[pentesting]
- @brompwnie's livestreams
[android hacking]
- ChiefRiver videos
[pentesting + windows]
- #nullconchat
[live infosec-themed discussion on Twitter]
- @thatsjet's @DevSecOpsLIFE
[DevSecOps]
- @424f424f, @dafthack, @ustayready, + @ralphte1's @CoinSecPodcast: YouTube • Spotify
[cryptocurrency]
- @dildog's Noctem livestream
- @FuzzySec's Patreon livestream
[red team, pentesting, exploit dev, general amazingness]
- @TrustedSec TV
- @samykamkar's tutorials
- @gattaca's Liquid Matrix Security Digest TV: [full episodes • mini episodes]
- The Internet Society's various livestreamed events: [ I • II ]
- Paul Asadoorian's Security Weekly (@securityweekly @swfeeds) podcasts: [official website • YouTube • infocon.org: PaulDotCom Weekly && Security Weekly]
- Paul's Security Weekly: with @haxorthematrix @securityweekly @Carlos_Perez @jack_daniel @MrJeffMan @joff_thyer
- Hack Naked News: with @securityweekly @Jason_Wood
- Enterprise Security Weekly: with @securityweekly @strandjs
- Business|Startup Security Weekly: with @securityweekly @catalyst
- Secure Digital Life: with @dougwhitephd @rbeauchemin
[newbie friendly • security ambassadoring]
- Tradecraft Security Weekly:
- Application Security Weekly: with @securityweekly @andMYhacks
- Interviews
- @chrissanders88's Source Code
[interviews with infosec folks re: path into infosec]
- @maliciouslink & @lerg's Defensive Security (@Defensivesec) podcast:
[general]
- @bryanbrake & @InfoSystir's @BrakeSec podcast: podcast • YouTube
[general]
- Patrick Gray (@riskybusiness)'s Risky Business security podcast: [official site • infocon]
[general]
- @steved3's #SaltedHash podcast: [video • podcast] {from @csoonline}
- @DanielMiessler's Unsupervised Learning podcast
[weekly news]
- @CyberSecStu's @TheManyHatsClub's weekly interviews with infosec folk (livestream on Discord • podcast)
[general]
- The Southern Fried Security Podcast (@SFSPodcast): [official site • infocon • iTunes]
- @phillmoore's This Week in 4n6:
[roundup of interesting DFIR items + podcast]
- @humanhackers's The Social-Engineer Podcast #SEPodcast: [official site • infocon]
[social engineering]
- @wadebaker & @jayjacobs' @cyentiainst Podcast
- @gcluley & @caroletheriault's @SmashinSecurity
[weekly news breakdown]
- @XenoPhage & AgentSixty6's Iron Sysadmin Podcast (@ironsysadmin)
[adjacent: sysad]
- @kyleshevlin's @2ndCareerDevs
[adjacent: devops + lateral]
- @7MinSec's 7 Minute Security podcast
- @PurpleSquadSec's Purple Squad Security podcast
- The Cyberwire (@thecyberwire) podcasts
- Darknet Diaries
[cybercrime]
- Stewart A. Baker's Cyberlaw Podcast
[cyberlaw stuff from former NSA general counsel]
- @LawyerLiz's #BuzzOffwithLawyerLiz
[law + policy + tech]
- @Jenny_Radcliffe's #HumanFactor podcast
[social engineering]
- @embeddedfm's Embedded
[hardware hacking-ish]
- Steve Gibson (@SGgrc) & Leo Laporte's Security Now! podcast: [infocon • iTunes • RSS • twit.tv]
- @textfiles' Jason Scott Talks His Way Out of It podcast: [YouTube • Patreon]
- Michael Bazzell (@IntelTechniques)'s Complete Privacy & Security Podcast
[privacy + OSINT]
- @edgeroute & @RobertHurlbut's @AppSecPodcast
[appsec]
- @CSI_Podcast's Cyber Security Interviews podcast
- The Security Ledger (@securityledger) podcast
- The Ask Mr. DNS Podcast
[netsec]
- SANS Internet Storm Center (@sans_isc)'s daily ISC StormCast podcast:
[threat hunting • malware analysis • blue team • DFIR]
- 2600's Off The Wall Radio Show: [archives: 2003–2018 • infocon.org: 2006–2014]
- 2600's Off The Hook Radio Show (@HackerRadioShow): [iTunes • infocon.org: 2006–2016]
- Phone Losers of America's The Snow Plow Show: phone comedy podcast: [official site • infocon • Patreon]
- @securitycurrent's Security Current podcast
- @gattaca's Liquid Matrix Security Digest podcast: [iTunes • infocon • YouTube]
- @OWASP's OWASP 24/7 Podcast: [official site • infocon: I, II] (FIXME: neither infocon directory is well-organized)
- Bob Rudis & Jay Jacob's Data Driven Security podcast
[security + data analytics • data visualization]
- The SteptoeCyberLaw Podcast: [official site • infocon]
[law]
- [Down The Security Rabbithole] (@DtSR_Podcast, wh1t3rabbit) podcast: [official site • infocon]
- The Social Media Security Podcast: [official site • infocon]
- Defrag This (@defrag_this) podcast
- Bruce Shneier (@schneierblog)'s Crypto-Gram podcast: [official site • infocon.org (pre-2010) • newsletter]
- CERT's Security for Business Leaders podcast: [iTunes]
[management]
- RunAs Radio podcast: [iTunes • RSS]
- The Standard Deviant Security Podcast (@standeviant): [Stitcher]
- The In-Security Podcast: [iTunes • RSS]
- ISMG Network Podcasts:
- The Healthcare Information Security Podcast
- The Careers Information Security Podcast
- The Data Breach Today Podcast
- The Banking Information Security Podcast
- infocon.org has archives of several older podcasts:
- CERT.org podcast: 2006–2014
- CyberSpeak podcast: 2006–2013
- Eurotrash Security podcast: pre-2014
- Exotic Liability podcast: pre-2010
- Hacker Podcast Radio: pre-2014
- Security Management Podcast: pre-2014
- Network Security Podcast podcast: 2014
- Finux Tech Whatever: (FIXME: files seem to be missing; anybody have an archive?)
- hacktv.org podcast: (FIXME: files seem to be missing; anybody have an archive?)
- Hacker News Network (HNN):
- HHNCast:: 2009–2011?
- ToolTime: 2010-2011
- Stack of Shame: 2010-2011
- ConFu: 2010-2011
- Behind The Firewall: (FIXME: only one clip; anybody have a complete archive?)
- Hak5 (@Hak5):
0. NOTE: For more up-to-date links, cf. @Hak5 entries in Shows &/or Livestreams above.
- ThreatWire: 2015-2016
- HakTip + Metasploit Minute
- Hak5: (seems to be episodes from their YouTube show?)
- @TalosSecurity's Beers with Talos podcast (from @TalosSecurity)
[news, netsec]
- @Sophos's Naked Security Podcast {from @Sophos}
- @IBM's Security Intelligence Podcast {from @IBM}
- @BrianRexroad & @jclausing's #ThreatTraq {from @ATT}
- Shaun Walsh (@cingulus)'s InSecurity Podcast {from @cylance}
- @cybereason's malicious.life (@MaliciousLife) Podcast {from @cybereason}
- TrustedSec Security Podcast {from @TrustedSec}
- Gary McGraw's Silver Bullet Security podcast: [iTunes • YouTube • infocon: [I, II]] {from IEEE Security & Privacy}
- @mike_mimoso & Chris Brook's The Threatpost Podcast: [iTunes • RSS {from @ThreatPost}
- Jessica Ortega, Ram Gall, Topher Tebow's Decoding Security podcast: [official site • YouTube • iTunes] {from @SiteLock}
- @nuix's Unscripted podcast: {from @nuix}
- @tripwire's Security Slice podcast: {from @tripwire}
- @blackroomsec's List of Hacking & CTF Challenge Sites - Updated February 2, 2018
- @FSecure's Cyber Security MOOC
- @0xmchow's COMP 116: Introduction to Computer Security
- Rensselaer Polytechnic Institute's @RPISEC CSCI 4968: Modern Binary Exploitation • CSCI 4976: Malware Analysis
[exploit dev • malware analysis]
- @XenoKovah & co's introductory infosec classes
[29 classes with videos; 63 days of open source class materials—many domains]
- Get some "help desk"-esque experience online & learn beginning malware triage/analysis for free: @BleepinComputer's Malware Removal Training Program
[malware analysis]
- @chrissanders88's The Cuckoo's Egg Decompiled
[intro to SOC • NSM • DFIR]
- @bartblaze's Introduction to Malware Analysis, Threat Intelligence, & Reverse Engineering
[malware analysis!!! • threat intelligence • reverse engineering]
- JPCERT/CC's catalogue of DFIR artifacts left by common attack tools
[threat hunting • DFIR]
- HackTheBox.eu
[mostly pentesting • red team, but a few DFIR challenges too]
- @daeken's Hacker101.com
[bug bounty • websec • appsec • pentesting • netsec]
{from @Hacker0x01} - @OWASP's collection of vulnerable web apps
[bug bounty • pentesting • websec • appsec • netsec]
- Damn Vulnerable Web App (DVWA) VM
[bug bounty • appsec]
- @b1ack0wl's Damn Vulnerable Router
[embedded • exploit dev • pentesting]
- @ProjectHoneynet challenge archive
[DFIR]
- @Fox0x01's ARM reverse engineering tutorials & ARM assembly introduction
[reverse engineering (ARM)]
- @malwareunicorn's RE101 & RE102
[reverse engineering (x86) + malware analysis intro]
- @malware_traffic's malware traffic analysis exercises
[network forensics]
- @FuzzySec's exploit dev tutorials
[exploit dev • pentesting • red team]
- @abatchy17's Windows Kernel Exploitation tutorial series + Vulnhub walkthroughs
[exploit dev • red team]
- @sambowne's samsclass.info
- @bellis1000's Exploit Challenges
[exploit dev]
- ROP Emporium
[exploit dev]
- @g0tmi1k's @VulnHub, a vulnerable VM repository + walkthroughs
[pentesting • red team • exploit dev • bug bounty]
- exploit-exercises.com
[exploit dev]
- root-me.org
[exploit dev • etc]
- GNS3
[neteng + netsec — you'll need to track down firmware images, though]
- #DailyScriptlets
[practice malware analysis • DFIR]
- @CTFtime's CTFtime.org
[find currently scheduled CTFs]
- @Magoo's Incident Response tabletop scenarios (@badthingsdaily)
[DFIR • incident response • blue team]
- Hacking Printers wiki
[pentesting]
- Want to build your own virtual homelab to practice in? GOOD. Go buy @da_667's Big Black Tome, Building Virtual Machine Labs: A Hands-On Guide.
- Issues of PoC||GTFO are usually hackable. >:D
- @SANS' SIFT Workstation VM
[DFIR Linux (Ubuntu) distro]
- @SANS' Remnux Workstation VM
[malware analysis • reverse engineering Linux (Ubuntu) distro]
- @IntelTechniques' Buscador VM
[OSINT+RECON Linux (Ubuntu) distro]
- @securityonion's SecurityOnion VM
[NSM+IDS+IPS • netsec Linux (Ubuntu) distro]
- @offsectraining's Kali VM (@kalilinux)
[offensive security • pentesting Linux distro]
- @Zero_ChaosX's Pentoo VM (@pentoo_linux)
[wireless+SDR+RF Linux (Gentoo) distro]
- @ParrotSec's Parrot Security OS VM
[pentesting • DFIR Linux (Debian) distro]
- @rootkovska's @QubesOS
- @ShadowDXS's guide to installing Arch Linux
- A Non-Nerd's Guide to the Command Line
- @mpratland's Terminus
[super gentle introduction to using a CLI]
- explainshell.com
[help break down common commands you don't understand]
- OverTheWire's Wargames
[beginning exercises for bash scripting, exploit dev, bug bounty-ish stuff...go through Bandit to get used to CLIs]
- "The Art of the Command Line"
- What happens when...: uses the example of searching Google to traverse different domains; common interview question]`
- Stack Overflow: Helping One Million Developers Exit Vim
[so you will understand the Exiting Vim memes]
- @nyxgeek's reading list: read up on your #HackerHistory, fam. <3
- The Hacker's Manifesto
- @jack_daniel's Shoulders of Infosec project
- SecLists.Org Security Mailing List Archive
- 2600: The Hacker Quarterly
- Phrack Magazine
- Uninformed Magazine: Informative Information for the Uninformed
- POC||GTFO: Proof of Concept or Get The Fuck Out!: [download mirrors: alchemistowl.org • greatscottgadgets • ludost.net • github.com/filcab] {Please note this blogpost|contalk from @ESultanik that explains how you can play with several issues' polyglots. ;)}
- Jason Scott (@textfiles)'s textfiles.com
- OpenRCE.org articles
- archive.org's HyperCard Stacks archive
- Bastard Operator from Hell (BOFH)
- DEFCON's Hacker Movie List