Skip to content
86

Awesome Cyber Security University

🎓 Because Education should be free. Contributions welcome! 🕵️

3.6k stars349 forks141 entriesLast push Sep 14, 2026 (16 days ago)License CC0-1.0

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Introduction and Pre-Security >Level 1 - Intro

OpenVPN

Learn how to connect to a virtual private network using OpenVPN.

Welcome

Learn how to use a TryHackMe room to start your upskilling in cyber security.

Intro to Researching

A brief introduction to research skills for pentesting.

Linux Fundamentals 1

Embark on the journey of learning the fundamentals of Linux. Learn to run some of the first essential commands on an interactive terminal.

Linux Fundamentals 2

Embark on the journey of learning the fundamentals of Linux. Learn to run some of the first essential commands on an interactive terminal.

Linux Fundamentals 3

Embark on the journey of learning the fundamentals of Linux. Learn to run some of the first essential commands on an interactive terminal.

Pentesting fundamentals

Fundamentals of penetration testing.

Principles of security

Learn the principles of information security that secures data and protects systems from abuse.

Red Team Engagements

Intro to red team engagements.

Hip Flask

An in-depth walkthrough covering pentest methodology against a vulnerable server.

Practice Linux Commands

A free course with 41 hands-on labs to practice and master the most commonly used Linux commands.

Google Dorking

Explaining how Search Engines work and leveraging them into finding hidden content!

In 2 lists

Osint

Intro to Open Source Intelligence.

Shodan.io

Learn about Shodan.io and how to use it for device enumeration.

In 2 lists

Free Beginner Red Team Path >Level 2 - Tooling

Tmux

Learn to use tmux, one of the most powerful multi-tasking tools on linux.

Nmap,Curl and Netcat

Get experience with Nmap, Curl and Netcat for network communications.

Web Scanning

Learn the basics of automated web scanning.

Subdomain Enumeration

Learn how to find subdomains with different techniques.

Metasploit

An introduction to the main components of the Metasploit Framework.

Hydra

Learn about and use Hydra, a fast network logon cracker, to bruteforce and obtain a website's credentials.

Linux Privesc

Practice your Linux Privilege Escalation skills on an intentionally misconfigured Debian VM with multiple ways to get root! SSH is available.

Red Team Fundamentals

Learn about the basics of a red engagement, the main components and stakeholders involved, and how red teaming differs from other cyber security engagements.

Red Team Recon

Learn how to use DNS, advanced searching, Recon-ng, and Maltego to collect information about your target.

Nmap Tutorials

Learn and practice the basics of network scanning using Nmap.

Vulnversity

Learn about active recon, web app attacks and privilege escalation.

Blue

Deploy & hack into a Windows machine, leveraging common misconfigurations issues.

Simple CTF

Beginner level CTF.

Bounty Hacker

A space cowboy-themed boot to root machine.

Free Beginner Red Team Path >Level 3 - Crypto & Hashes with CTF practice

Crack the hash

Cracking hash challenges.

Agent Sudo

You found a secret server located under the deep sea. Your task is to hack inside the server and reveal the truth.

The Cod Caper

A guided room taking you through infiltrating and exploiting a Linux system.

Ice

Deploy & hack into a Windows machine, exploiting a very poorly secured media server.

Lazy Admin

Easy Linux machine to practice your skills.

Basic Pentesting

This is a machine that allows you to practice web app hacking and privilege escalation.

Bypassing UAC

Learn common ways to bypass User Account Control (UAC) in Windows hosts.

Free Beginner Red Team Path >Level 4 - Web

OWASP top 10

Learn about and exploit each of the OWASP Top 10 vulnerabilities; the 10 most critical web security risks.

Inclusion

A beginner-level LFI challenge.

Injection

Walkthrough of OS Command Injection. Demonstrate OS Command Injection and explain how to prevent it on your servers.

Juiceshop

This room uses the OWASP juice shop vulnerable web application to learn how to identify and exploit common web application vulnerabilities.

Overpass

What happens when some broke CompSci students make a password manager.

Year of the Rabbit

Can you hack into the Year of the Rabbit box without falling down a hole.

DevelPy

Boot2root machine for FIT and bsides Guatemala CTF.

Jack of all trades

Boot-to-root originally designed for Securi-Tay 2020.

Bolt

A boot to root Bolt themed machine.

Free Beginner Red Team Path >Level 5 - Reverse Engineering & Pwn

Windows x64 Assembly

Introduction to x64 Assembly on Windows.

CC Ghidra

This room teaches the basics of ghidra.

CC Radare2

This room teaches the basics of radare2.

Reverse Engineering

This room focuses on teaching the basics of assembly through reverse engineering.

Reversing ELF

Room for beginner Reverse Engineering CTF players.

Dumping Router Firmware

Reverse engineering router firmware.

Intro to pwntools

Introduction to popular pwn tools framework.

Pwnkit: CVE-2021-4034

Interactive lab for exploiting and remediating Pwnkit (CVE-2021-4034) in the Polkit package.

Free Beginner Red Team Path >Level 6 - PrivEsc

Sudo Security Bypass

A tutorial room exploring CVE-2019-14287 in the Unix Sudo Program. Room One in the SudoVulns Series.

Sudo Buffer Overflow

A tutorial room exploring CVE-2019-18634 in the Unix Sudo Program. Room Two in the SudoVulns Series.

Windows Privesc Arena

Students will learn how to escalate privileges using a very vulnerable Windows 7 VM.

Linux Privesc Arena

Students will learn how to escalate privileges using a very vulnerable Linux VM.

Windows Privesc

Students will learn how to escalate privileges using a very vulnerable Windows 7 VM.

Blaster

Metasploit Framework to get a foothold.

Ignite

A new start-up has a few security issues with its web server.

Kenobi

Walkthrough on exploiting a Linux machine. Enumerate Samba for shares, manipulate a vulnerable version of proftpd and escalate your privileges with path variable manipulation.

Capture the flag

Another beginner-level CTF challenge.

Pickle Rick

Rick and Morty themed LFI challenge.

Click here to get your red team badge!

https://gist.Github.com/brootware/e30a10dbccf334eb95da7ea59d6f87fe

Free Beginner Blue Team Path >Level 1 - Tools

Introduction to diGital forensics

Intro to DiGital Forensics.

Windows Fundamentals

Intro to Windows.

Nessus

Intro to nessus scan.

Mitre

Intro to Mitre attack framework.

IntroSIEM

Introduction to SIEM.

Yara

Intro to yara for malware analysis.

OpenVAS

Intro to openvas.

Intro to Honeypots

A guided room covering the deployment of honeypots and analysis of botnet activities.

Volatility

Intro to memory analysis with volatility.

Red Line

Learn how to use Redline to perform memory analysis and scan for IOCs on an endpoint.

Autopsy

Use Autopsy to investigate artifacts from a disk image.

Free Beginner Blue Team Path >Level 2 - Security Operations, Incident Response & Threat Hunting

Investigating Windows

A windows machine has been hacked, its your job to go investigate this windows machine and find clues to what the hacker might have done.

Juicy Details

A popular juice shop has been breached! Analyze the logs to see what had happened.

Carnage

Apply your analytical skills to analyze the malicious network traffic using Wireshark.

Squid Game

A CTF room with Squid Game theme.

Splunk Boss of the SOC V1

Part of the Blue Primer series, learn how to use Splunk to search through massive amounts of information.

Splunk Boss of the SOC V2

Splunk analysis vol 2.

Splunk Boss of the SOC V3

Splunk analysis vol 3.

Hunt Conti with Splunk

An Exchange server was compromised with ransomware. Use Splunk to investigate how the attackers compromised the server.

Free Beginner Blue Team Path >Level 3 - Beginner Forensics, Threat Intel & Cryptography

Threat Intelligence 101

Introduction to Cyber Threat Intelligence.

Threat Intelligence Tools

Explore different OSINT tools used to conduct security threat assessments and investigations.

Martryohka doll

Beginner file analysis challenge.

The Glory of the Garden

Beginner image analysis challenge.

Packets Primer

Beginner packet analysis challenge.

Wireshark doo doo doo

Beginner packet analysis challenge.

Wireshark two two two

Beginner packet analysis challenge.

Trivial flag transfer protocol

Beginner packet analysis challenge.

What Lies within

Beginner decoding analysis challenge.

Illumination

Medium level forensics challenge.

Emo

Medium level forensics challenge.

Obsecure

Medium level forensics challenge.

Intel101 Challenge

Medium level Threat Intel challenge.

Introduction to Cryptohack

Medium level cryptography challenge.

Free Beginner Blue Team Path >Level 4 - Memory & Disk Forensics

Sleuthkit Intro

Medium level disk forensics challenge.

Reminiscent

Medium level disk forensics challenge.

Hunter - Windows Disk Image Forensics

Medium level disk forensics challenge.

Spotlight - Mac Disk Image Forensics

Medium level disk forensics challenge.

Ulysses - Linux Disk Image Forensics

Medium level disk forensics challenge.

Banking Troubles - Windows Memory Image Forensics

Medium level memory forensics challenge.

Detect Log4J

Medium level disk forensics challenge.

Free Beginner Blue Team Path >Level 5 - Malware and Reverse Engineering

History of Malware

Intro to malware history.

Malware Introduction

Intro to malware.

Basic Malware Reverse Engineering

Intro to malware RE.

Intro Windows Reversing

Intro to Windows RE.

Windows x64 Assembly

Introduction to x64 Assembly on Windows.

JVM reverse engineering

Learn Reverse Engineering for Java Virtual Machine bytecode.

Get PDF (Malicious Document)

Reversing PDF malware.

Click here to get your blue team badge!

https://gist.Github.com/brootware/62b76a84aaa8d6f55c82f6f329ad6d2d

Bonus CTF practice and Latest CVEs

Bandit

Aimed at absolute beginners and teaches the basics of remote server access.

Natas

Teaches the basics of serverside web-security.

Post Exploitation Basics

Learn the basics of post-exploitation and maintaining access with mimikatz, bloodhound, powerview and msfvenom.

In 2 lists

Smag Grotto

An obsecure boot to root machine.

Dogcat

I made a website where you can look at pictures of dogs and/or cats! Exploit a PHP application via LFI and break out of a Docker container.

Buffer Overflow Prep

Practice stack-based buffer overflows.

Break out the cage

Help Cage bring back his acting career and investigate the nefarious going on of his agent.

Lian Yu

A beginner-level security challenge.

Insecure Kubernetes

Exploiting Kubernetes by leveraging a Grafana LFI vulnerability.

The Great Escape (Docker)

Escaping Docker container.

Solr Exploiting Log4j

Explore CVE-2021-44228, a vulnerability in log4j affecting almost all software under the sun.

Spring4Shell

Interactive lab for exploiting Spring4Shell (CVE-2022-22965) in the Java Spring Framework.

Most Recent threats

Learn about the latest industry threats. Get hands-on experience identifying, exploiting, and mitigating critical vulnerabilities.

Bonus Windows

Attacktive Directory

Learn about 99% of Corporate networks that run off of AD.

In 2 lists

Retro

Breaking out of the retro-themed box.

Blue Print

Hack into this Windows machine and escalate your privileges to Administrator.

Anthem

Exploit a Windows machine in this beginner-level challenge.

Relevant

Penetration Testing Challenge.

Extremely Hard Rooms to do

Ra

You have found WindCorp's internal network and their Domain Controller. Pwn the network.

CCT2019

Legacy challenges from the US Navy Cyber Competition Team 2019 Assessment sponsored by US TENTH Fleet.

Theseus

The first installment of the SuitGuy series of very hard challenges.

IronCorp

Get access to Iron Corp's system.

Carpe Diem 1

Recover your client's encrypted files before the ransomware timer runs out.

Borderlands

Compromise a perimeter host and pivot through this network.

Jeff

Hack into Jeff's web server.

Year of the Owl

Owl-themed boot to root machine.

Anonymous Playground

Want to become part of Anonymous? They have a challenge for you.

EnterPrize

Enterprise-themed network to hack into.

Racetrack Bank

It's time for another heist.

Python Playground

Use python to pwn this room.

See category
94

Awesome-Selfhosted

awesome-selfhosted/awesome-selfhosted

A list of Free Software network services and web applications which can be hosted on your own servers

Fresh★ 323k1312 entriesPushed yesterday
91

Awesome Privacy

lissy93/awesome-privacy

🦄 A curated list of privacy & security-focused software and services

Fresh★ 9.9k459 entriesPushed today
89

Awesome Bug Bounty Tools

vavkamil/awesome-bugbounty-tools

A curated list of various bug bounty tools

Fresh★ 6.3k400 entriesPushed yesterday
88

android-security-awesome

ashishb/android-security-awesome

A collection of android security related resources

Fresh★ 9.7k233 entriesPushed 2 days ago
88

Awesome Hacker Search Engines

edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Fresh★ 11k563 entriesPushed 27 days ago
87

Awesome Web Security

qazbnm456/awesome-web-security

🐶 A curated list of Web Security materials and resources.

Fresh★ 14k368 entriesPushed 15 days ago