// Resources
Learning
A curated list of learning platforms, courses, and documentation within cybersecurity.
Hands-on Platforms
CampFire Security
featuredDanish cybersecurity learning platform with courses and workshops aimed at both beginners and experienced security professionals.
Hack The Box
featuredAdvanced pentesting platform with machines, challenges and a structured Academy with courses from beginner to expert.
PentesterLab
featuredHands-on platform focused on web application security. Exercises built around real vulnerabilities such as SQL injection, XSS, XXE and deserialisation.
SagaLabs
featuredDanish cybersecurity platform with hands-on labs and exercises. Focuses on practical learning in network security and hacking.
TryHackMe
featuredBeginner-friendly platform with guided learning rooms covering hacking, networking and defence. Perfect for starting from scratch.
CloudGoat
Rhino Security Labs' deliberately vulnerable AWS environment, deployed into your own account with Terraform. Scenario-based attack paths covering privilege escalation, exposed services and IAM abuse.
crackmes.one
Large community archive of reverse engineering challenges graded by difficulty and platform. The most direct way to build practical RE skill with Ghidra, IDA or radare2.
CryptoHack
Cryptography learned by breaking it. Progressive challenges on block ciphers, RSA, elliptic curves and real-world protocol flaws, with a friendly on-ramp for people without a maths background.
Cryptopals Crypto Challenges
Eight sets of exercises that walk you through implementing and then breaking real cryptographic constructions. Demanding, self-paced, and still the best way to understand why crypto fails in practice.
flAWS.cloud
Scott Piper's classic AWS security challenge. Work through a series of realistic S3, IAM and metadata-service misconfigurations in a live AWS account, one hint at a time.
OffSec PEN-200 (OSCP)
The world's most recognised penetration testing course from Offensive Security. Hands-on lab environment focused on practical exploitation, privilege escalation and report writing.
TCM Security
Practically focused courses in ethical hacking and pentesting. Known for the Practical Ethical Hacking course and affordable pricing.
Application Security
PortSwigger Web Security Academy
featuredFree, in-depth course platform from the creators of Burp Suite. Covers everything in web application security with labs and explanations.
DVWA – Damn Vulnerable Web Application
Classic open source practice app with vulnerabilities across difficulty levels. Perfect for practising SQL injection, brute force, file inclusion and command injection locally.
Hacksplaining
Interactive and visual platform that explains common attack types step by step. Ideal introduction to OWASP Top 10 for both developers and security professionals.
OWASP Web Security Testing Guide
The most comprehensive guide to testing web application security. Covers everything from authentication and session management to API security and encryption.
Snyk Learn
Developer-focused security learning with lessons on vulnerable code in real programming languages. Covers injection, XXE, SSRF, insecure deserialization and much more.
OWASP WebGoat
Deliberately vulnerable web application designed to teach about security flaws in practice. Run locally and learn by exploiting OWASP Top 10 vulnerabilities in a safe environment.
Offensive Security
Exploit Database
featuredThe largest public database of exploits and vulnerable software. Maintained by Offensive Security and used by penetration testers to find known CVE exploits.
Hacking the Cloud
featuredOffensive cloud security encyclopedia covering AWS, Azure, GCP and Kubernetes. Documents concrete attacker techniques and post-exploitation paths — the cloud counterpart to HackTricks.
GTFOBins
Curated list of Unix binaries that can be used to escalate privileges, bypass restrictions or establish reverse shells. Indispensable during Linux privilege escalation.
HackTricks
Comprehensive wiki with techniques, tricks and cheatsheets for penetration testing and CTF. Covers network, Active Directory, cloud, web and much more — used by professionals worldwide.
LOLBAS – Living Off The Land Binaries
The Windows equivalent of GTFOBins. A collection of Windows binaries, scripts and libraries that can be abused by attackers to evade detection and escalate privileges.
PayloadsAllTheThings
Open GitHub repository with a huge collection of payloads and bypasses for use during penetration testing. Covers everything from SQLi and XSS to SSRF, XXE and file upload bypasses.
Defence & Threat Intelligence
Center for Cybersikkerhed (CFCS)
featuredDenmark's national cyber security authority. Publishes the annual "Cybertruslen mod Danmark" threat assessment, sector-specific assessments and practical guidance on NIS2, crisis management and technical hardening. Now part of Styrelsen for Samfundssikkerhed.
CyberDefenders
featuredBlue team labs built on real forensic artefacts — packet captures, memory images and disk images from genuine intrusions. Strongest option for moving toward a DFIR or incident response role.
LetsDefend
featuredBlue team training platform that simulates a real SOC. Work actual alerts in a mock SIEM, triage incidents and practise the analyst workflow rather than just reading about it.
MITRE ATT&CK
featuredGlobally recognised knowledge base of attack techniques and tactics used by threat actors. An indispensable reference for threat modelling and SOC work.
SektorCERT
featuredThe CERT for Denmark's critical infrastructure sectors, operating a sensor network across member organisations. Publishes threat assessments and incident reports — including the 2023 report on the attacks against the Danish energy sector.
ANY.RUN
Interactive malware sandbox you can click around in while the sample detonates. Free tier gives access to a large public archive of analysed samples and their behaviour.
Atomic Red Team
Red Canary's library of small, portable tests mapped to MITRE ATT&CK techniques. Run them to verify your detections actually fire — the practical bridge between ATT&CK as a reference and ATT&CK as coverage you can prove.
Blue Team Labs Online
Gamified defensive challenges covering incident response, digital forensics, threat hunting and reverse engineering. Purely blue team — no red team content mixed in.
DKCERT
The Danish research and education network CERT, run by DeiC. Publishes advisories, the annual trend report on Danish cyber security incidents, and accessible write-ups of current vulnerabilities.
Malware-Traffic-Analysis.net
Brad Duncan's long-running archive of real malware packet captures with guided exercises. The standard free resource for learning to read malicious network traffic in Wireshark.
Sigma
Vendor-neutral signature format for SIEM detection rules, with a large open rule repository. Write a detection once and convert it to Splunk, Sentinel, Elastic or whatever you actually run.
The DFIR Report
In-depth threat intelligence reports and real-world incident response case studies covering malware, ransomware, and adversary techniques.
Standards & Documentation
OWASP
featuredOpen source project with guidelines, documentation and resources on web security. OWASP Top 10 is the standard reference for web vulnerabilities.
OWASP ASVS
featuredThe Application Security Verification Standard — a tiered list of concrete security requirements for applications. The requirements counterpart to the WSTG's testing guidance, and a practical basis for security acceptance criteria.
OWASP Cheat Sheet Series
Concise, actionable guidance on specific defensive topics — password storage, session management, input validation, deserialisation and dozens more. The fastest answer to "how should we actually implement this safely".
Governance, Risk and Compliance
ENISA
featuredThe EU Agency for Cybersecurity. Source material for NIS2, the Cyber Resilience Act and EU certification schemes, plus the annual Threat Landscape report. The reference point when Danish requirements trace back to EU law.
GRC Labs Blog
Aron Lange's blog on Governance, Risk and Compliance with practical insight into risk management, compliance frameworks and security policies.
CTF
Videos & Blogs
IppSec
YouTube channel with detailed walkthroughs of Hack The Box machines. One of the best ways to learn pentesting methodology. Searchable across every video at ippsec.rocks.
LiveOverflow
YouTube channel and blog with in-depth videos on CTF solutions, reverse engineering and bug bounty. Excellent for understanding low-level security.
Security Podcasts
Darknet Diaries
featuredJack Rhysider's award-winning podcast about true stories from the dark side of the internet — hackers, data breaches, cybercrime and state-sponsored attacks. One of the best introductions to infosec.
SANS Internet Stormcast
featuredDaily 5-minute podcast from SANS Internet Storm Center covering the latest threats, vulnerabilities and security news. Perfect for staying up to date on a daily basis.
Malicious Life
Podcast from Cybereason telling the true stories behind major cyberattacks and security incidents. In-depth research and well-crafted narrative about APT groups and cybercrime.
Risky Business
Weekly podcast with Patrick Gray interviewing the most influential voices in the security industry. Focus on current events, policy and trends in cybersecurity.
Security Now
Long-running weekly podcast with Steve Gibson and Leo Laporte going deep on technical security topics — encryption, protocols, vulnerabilities and current attacks.
Smashing Security
Weekly podcast with Graham Cluley and Carole Theriault covering the latest cybersecurity news with humour and insight. A great mix of serious content and entertainment.
Know a resource that's missing?
Create a new markdown file in src/content/learning/ and open a pull request.