Pwnversity
Cybersecurity knowledge, from 0 to root. Offense, defense, cloud, forensics, GRC and much more.
258 cards24 areasSpanish / English
Table of contents
Section titled “Table of contents”Start here
Section titled “Start here” Fundamentals Methodology, networking, Linux, Windows, HTTP, crypto and building your lab.
Recon & OSINT Map the target's surface without touching it: OSINT, subdomains, fingerprinting.
Offense — attack surfaces
Section titled “Offense — attack surfaces” Web Hacking SQLi, XSS, SSRF, deserialization and all of OWASP, done by hand.
Network & Services Enumeration, protocol attacks, pivoting and lateral movement.
Cloud AWS, Azure and GCP: IAM, metadata, buckets and privilege escalation.
Mobile Android and iOS: static/dynamic analysis and control bypasses.
Wireless & Radio WiFi, Bluetooth and RF: capture, cracking and proximity attacks.
Offense — systems & binaries
Section titled “Offense — systems & binaries” Linux — Post-exploitation Privilege escalation, persistence and SUID/capabilities abuse.
Windows & Active Directory Kerberos, ACL abuse, lateral movement and full domain compromise.
Binary Exploitation & Reversing Stack, heap, ROP and reversing from scratch, register by register.
Malware & Evasion C2, obfuscation and EDR evasion —and how the blue team hunts it.
Cryptography Real-world failures: padding oracle, ECB, JWT and weak PRNGs.
Social Engineering & Phishing Pretexting, phishing campaigns and infrastructure.
Defense, response & intel
Section titled “Defense, response & intel” Defense & Blue Team Hardening, detection and defense in depth.
DFIR — Forensics & Response Incident response and disk, memory and network forensics.
Threat Intelligence CTI, IOCs, MITRE ATT&CK and threat hunting.
DevSecOps & AppSec Secure SDLC, SAST/DAST, secrets and CI/CD security.
OT/ICS & IoT SCADA, industrial protocols and device security.
AI & Security OWASP LLM Top 10, prompt injection and adversarial ML.
Governance, practice & career
Section titled “Governance, practice & career” GRC & Compliance ISO 27001, NIST, risk management and compliance.
Bug Bounty Methodology Workflow, triage and maximizing impact and payouts.
CTF & Practice CTF methodology and platforms to train on.
Certifications & Career Roadmaps, OSCP/CRTP and how to grow in the field.
Tooling Burp, nmap, ffuf, BloodHound and the rest of the arsenal.