Free Resources
90+ free cybersecurity infographics for the entire community. No forms to download. Just shared knowledge.
98 of 98 resources
How websites identify users using browser fingerprinting techniques.
Full anatomy of an attack against Active Directory environments, from reconnaissance to exfiltration.
How attackers intercept sessions and credentials using AITM attacks.
Common attack vectors targeting modern APIs and REST services.
Anatomy of common attacks against modern web applications.
How advanced persistent threats operate inside organizations.
How attackers exploit Broken Object Level Authorization vulnerabilities in APIs.
Threats and attack vectors against Kubernetes containers and clusters.
Common attack vectors against AWS, Azure and GCP infrastructure.
How attackers compromise IoT devices and exploit connected networks.
Evasion and concealment techniques using obfuscated JavaScript.
How attackers exploit JSON Web Token vulnerabilities to escalate privileges.
How attackers use reverse proxies to capture credentials and MFA sessions.
How attackers compromise vendors, libraries and CI/CD pipelines to distribute malware.
How CVE vulnerabilities are discovered, registered and exploited.
Common attack vectors against microservices-based architectures.
Techniques used to evade modern EDR and XDR solutions.
How C2 channels used by malware and threat actors operate.
How attackers abuse MFA notifications to trick users into granting access.
Psychological manipulation techniques used to gain unauthorized access.
Methods used to crack passwords using brute force, dictionaries and hybrid attacks.
How attackers use fake domains to impersonate brands and steal credentials.
How phishing attacks work and the most common techniques used to deceive users.
How attackers manipulate prompts to alter the behavior of AI-based systems.
How attackers manipulate BGP routes to redirect or intercept internet traffic.
How DDoS attacks using amplification through NTP servers work.
DDoS attacks based on reflection and amplification using exposed services.
How botnets are used to perform distributed denial-of-service attacks.
How DDoS attacks targeting applications and HTTP servers work.
How attackers overwhelm DNS services using flood-based attacks.
DDoS amplification attacks using exposed Memcached servers.
How Slowloris exhausts HTTP connections by keeping them open as long as possible.
How attackers use UPnP/SSDP devices to amplify DDoS traffic.
How SYN Flood attacks exhaust resources by overwhelming TCP connections.
DDoS attacks designed to saturate bandwidth and network capacity.
How attackers manipulate DNS responses to redirect users to malicious websites.
How attackers create fake WiFi hotspots to intercept traffic and credentials.
How attackers overflow switch CAM tables to capture network traffic.
How attackers intercept and manipulate communications between two parties.
How attackers capture and analyze network traffic to obtain sensitive information.
Common indicators used to identify phishing emails.
How attackers exploit MFA synchronization mechanisms to gain unauthorized access.
How attackers compromise websites frequented by targets to distribute malware.
How attackers inject malicious scripts into vulnerable web applications.
How reflected Cross-Site Scripting works and its most common vectors.
How compromised websites automatically infect users upon visiting them.
How HTTP inconsistencies allow attackers to manipulate proxies and backend servers.
How attackers exploit insecure direct object references in web applications.
How attackers inject malicious SQL queries to compromise databases.
How attackers manipulate access tokens to escalate privileges or impersonate users.
How attackers force servers to make malicious internal or external requests.
How misconfigured subdomains can be hijacked by attackers.
How real-time payment systems work and the associated security risks.
Roles and responsibilities of Blue Team cybersecurity professionals.
How Purple Teams integrate offensive and defensive cybersecurity capabilities.
Functions and methodologies used by Red Teams to simulate real-world attacks.
How online shopping frauds operate through fake stores and deceptive offers.
How scammers manipulate victims by pretending to be in family emergencies.
How fraudulent missed-call scams known as Wangiri operate.
How fraudulent quick-loan apps extort users and steal personal information.
How cybercriminals use artificial intelligence to automate attacks and fraud.
What MCP is and how it enables AI models to integrate with external tools and systems.
Architecture and operation of modern artificial intelligence systems.
How fileless malware operates in memory to evade traditional detection mechanisms.
How worms automatically spread across networks and vulnerable systems.
How attackers use legitimate system tools to avoid detection.
How ransomware attacks operate through encryption and extortion phases.
How rootkits hide malicious processes and maintain persistence on compromised systems.
How spyware collects sensitive information and monitors user activity.
How trojans trick users into installing malicious software disguised as legitimate.
How Office documents with malicious macros are used to distribute malware.
How computer viruses operate and spread across systems.
Methodologies and techniques used to analyze malware samples.
How to use Wireshark to capture and analyze network traffic.
How to analyze network traffic to detect threats and anomalies.
How brute force attacks against credentials and systems operate.
Methodologies used to find vulnerabilities in Bug Bounty programs.
Common phases attackers use to compromise systems and maintain access.
MITRE ATT&CK framework for classifying adversary tactics and techniques.
How to prioritize and classify security incidents effectively.
How to integrate security into CI/CD pipelines and DevOps processes.
How to use advanced search operators for OSINT investigations.
Methodologies used to collect and analyze digital evidence.
How to gather intelligence using open-source intelligence techniques.
Methodologies and phases used in offensive penetration testing.
How attackers escalate privileges on Linux systems using insecure configurations and vulnerabilities.
Process for securely managing, auditing, and optimizing firewall rules.
Phases and procedures used to respond to cybersecurity incidents.
How analysts proactively search for advanced threats inside organizations.
How Zero Trust continuously validates identities, devices, and access.
Best practices for creating strong passwords resistant to attacks.
How DKIM protects emails using cryptographic signatures.
How DMARC helps prevent email spoofing and phishing.
How SPF validates authorized email sending servers.
How MFA strengthens authentication using multiple verification factors.
How SSO and SAML work to centralize authentication and access management.
How VPNs protect communications and privacy over public networks.
Methodologies and techniques used to evade firewall controls and network restrictions.
Newsletter
We send one email per month with new infographics and cybersecurity trends. No spam, unsubscribe anytime.
Want to learn more?
Visit our academy for specialized cybersecurity training.
Go to AcademyRead the BlogNeed help with your cybersecurity? 💬