Free Resources
90+ free cybersecurity infographics for the entire community. No forms to download. Just shared knowledge.
105 of 105 resources
Scan types, techniques, and indicators to identify port scanning on a network.
Key components, roles, and processes inside a Security Operations Center.
Security testing technique using random inputs to discover vulnerabilities.
How EDR and XDR work to detect and respond to endpoint threats.
How buffer overflow attacks work to execute arbitrary code.
Common indicators used to identify phishing emails.
Methods used to crack passwords using brute force, dictionaries and hybrid attacks.
How Slowloris exhausts HTTP connections by keeping them open as long as possible.
How attackers use UPnP/SSDP devices to amplify DDoS traffic.
Functions and methodologies used by Red Teams to simulate real-world attacks.
How to integrate security into CI/CD pipelines and DevOps processes.
How Office documents with malicious macros are used to distribute malware.
How attackers compromise IoT devices and exploit connected networks.
How spyware collects sensitive information and monitors user activity.
How attackers manipulate BGP routes to redirect or intercept internet traffic.
How to gather intelligence using open-source intelligence techniques.
Evasion and concealment techniques using obfuscated JavaScript.
How DKIM protects emails using cryptographic signatures.
How attackers inject malicious SQL queries to compromise databases.
How phishing attacks work and the most common techniques used to deceive users.
How misconfigured subdomains can be hijacked by attackers.
Vulnerability that allows packet fragmentation to bypass security systems.
How attackers overflow switch CAM tables to capture network traffic.
Process for securely managing, auditing, and optimizing firewall rules.
MITRE ATT&CK framework for classifying adversary tactics and techniques.
How attackers exploit JSON Web Token vulnerabilities to escalate privileges.
How C2 channels used by malware and threat actors operate.
How attackers exploit MFA synchronization mechanisms to gain unauthorized access.
DDoS attacks based on reflection and amplification using exposed services.
How VPNs protect communications and privacy over public networks.
How SSO and SAML work to centralize authentication and access management.
How to use Wireshark to capture and analyze network traffic.
Methodologies and phases used in offensive penetration testing.
Common attack vectors against microservices-based architectures.
Architecture and operation of modern artificial intelligence systems.
How brute force attacks against credentials and systems operate.
How cybercriminals use artificial intelligence to automate attacks and fraud.
How attackers compromise websites frequented by targets to distribute malware.
How attackers use reverse proxies to capture credentials and MFA sessions.
Methodologies and techniques used to analyze malware samples.
How fraudulent missed-call scams known as Wangiri operate.
DDoS amplification attacks using exposed Memcached servers.
How attackers force servers to make malicious internal or external requests.
How ransomware attacks operate through encryption and extortion phases.
Methodologies used to collect and analyze digital evidence.
How attackers exploit Broken Object Level Authorization vulnerabilities in APIs.
How attackers exploit insecure direct object references in web applications.
How MFA strengthens authentication using multiple verification factors.
How attackers compromise vendors, libraries and CI/CD pipelines to distribute malware.
Methodology for using Cobalt Strike in attack simulations and penetration testing.
How fileless malware operates in memory to evade traditional detection mechanisms.
How DDoS attacks using amplification through NTP servers work.
Full anatomy of an attack against Active Directory environments, from reconnaissance to exfiltration.
How DDoS attacks targeting applications and HTTP servers work.
How worms automatically spread across networks and vulnerable systems.
How botnets are used to perform distributed denial-of-service attacks.
How attackers use legitimate system tools to avoid detection.
Best practices for creating strong passwords resistant to attacks.
How attackers intercept and manipulate communications between two parties.
How online shopping frauds operate through fake stores and deceptive offers.
Psychological manipulation techniques used to gain unauthorized access.
How analysts proactively search for advanced threats inside organizations.
How DMARC helps prevent email spoofing and phishing.
Techniques used to evade modern EDR and XDR solutions.
How attackers escalate privileges on Linux systems using insecure configurations and vulnerabilities.
How attackers abuse MFA notifications to trick users into granting access.
How attackers overwhelm DNS services using flood-based attacks.
Anatomy of common attacks against modern web applications.
How websites identify users using browser fingerprinting techniques.
How HTTP inconsistencies allow attackers to manipulate proxies and backend servers.
How advanced persistent threats operate inside organizations.
How SYN Flood attacks exhaust resources by overwhelming TCP connections.
How Purple Teams integrate offensive and defensive cybersecurity capabilities.
Roles and responsibilities of Blue Team cybersecurity professionals.
How fraudulent quick-loan apps extort users and steal personal information.
How rootkits hide malicious processes and maintain persistence on compromised systems.
How attackers capture and analyze network traffic to obtain sensitive information.
How Zero Trust continuously validates identities, devices, and access.
How attackers intercept sessions and credentials using AITM attacks.
Common phases attackers use to compromise systems and maintain access.
Threats and attack vectors against Kubernetes containers and clusters.
Common attack vectors targeting modern APIs and REST services.
Common attack vectors against AWS, Azure and GCP infrastructure.
How attackers manipulate DNS responses to redirect users to malicious websites.
Methodologies and techniques used to evade firewall controls and network restrictions.
How attackers inject malicious scripts into vulnerable web applications.
Methodologies used to find vulnerabilities in Bug Bounty programs.
How reflected Cross-Site Scripting works and its most common vectors.
How attackers use fake domains to impersonate brands and steal credentials.
DDoS attacks designed to saturate bandwidth and network capacity.
How attackers manipulate access tokens to escalate privileges or impersonate users.
How to prioritize and classify security incidents effectively.
What MCP is and how it enables AI models to integrate with external tools and systems.
How compromised websites automatically infect users upon visiting them.
How scammers manipulate victims by pretending to be in family emergencies.
How to use advanced search operators for OSINT investigations.
How attackers create fake WiFi hotspots to intercept traffic and credentials.
How SPF validates authorized email sending servers.
How real-time payment systems work and the associated security risks.
How to analyze network traffic to detect threats and anomalies.
How CVE vulnerabilities are discovered, registered and exploited.
How computer viruses operate and spread across systems.
How attackers manipulate prompts to alter the behavior of AI-based systems.
How trojans trick users into installing malicious software disguised as legitimate.
Phases and procedures used to respond to cybersecurity incidents.
Newsletter
We send one email per month with new infographics and cybersecurity trends. No spam, unsubscribe anytime.
Want to learn more?
Visit our academy for specialized cybersecurity training.
Go to AcademyRead the BlogNeed help with your cybersecurity? 💬