You do not need to know how to code to be good at security. Many newcomers to the industry are daunted by the prospect of learning to code, which can prevent them from taking the plunge into cybersecurity. Does coding help? Absolutely! However, it is not a prerequisite for success. A foundational level of coding knowledge is perfectly acceptable.
Think of it like learning the basics of a foreign language. Does everyone need 4-5 years to become completely fluent in Spanish before ordering food at your favorite taco restaurant? No! Understanding some of the more common terms and being able to recognize the language when it's used goes a long way.
The same applies to code.
To help with this foundational understanding, many platforms, tools, and projects have been created to make code more approachable. As a security analyst, you are not expected to write complex JavaScript or in-depth PowerShell commands. However, should you be able to recognize them and understand their function? Absolutely! Fortunately, there are tools that can make this process easier.
- https://github.com/6mile/DevSecOps-Playbook
- OWASP Secure Coding Practices - Quick reference guide for secure coding practices
- CWE - Common Weakness Enumeration - Community-developed list of software and hardware weakness types
- SANS Secure Coding Resources - Collection of secure coding training and resources
{% embed url="https://assets.contentstack.io/v3/assets/blt36c2e63521272fdc/bltea7de5267932e94b/5eb08aafcf88d36e47cf0644/Cheatsheet_SEC301-401_R7.pdf" %}
{% content-ref url="bash/" %} bash {% endcontent-ref %}
- Operator Handbook: Windows_Commands - pg. 328
{% content-ref url="powershell/" %} powershell {% endcontent-ref %}
- https://www.commandlinefu.com - An amazing repository of command strings accomplishing different tasks. Simply search the task and see what commands have worked for others.
- https://explainshell.com/ - Enter a command-line to see the help text that matches each argument
- cheat.sh - Community-driven command-line cheatsheet tool
- tldr - Simplified and community-driven man pages with practical examples
- thefuck - Corrects errors in previous console commands
- https://stackoverflow.com/ - The world's largest programming Q&A community. An invaluable resource for finding solutions to coding problems and understanding how different code snippets work. If you can't figure out how to code something, start here first.
- The complete table of ASCII characters, codes, symbols and signs
- Devhints - One of the largest collections of coding cheatsheets and guides available on the internet.
- PublicWWW.com - Source code search engine that allows you to search across millions of websites
- Microsoft Learn - Code Samples - Browse code samples from Microsoft documentation
- https://ryanstutorials.net/ - A collection of free, introductory tutorials on several technology topics including: Linux command line, Bash scripting, creating and styling webpages with HTML and CSS, counting and converting between different number systems, and writing regular expressions
- https://www.markdownguide.org/ - Free and open-source reference guide that explains how to use Markdown
- GitHub Docs - Comprehensive documentation for GitHub, Git, and version control
- Regex101 - Online regex tester and debugger with explanations
- Can I Use - Browser compatibility tables for web technologies
{% content-ref url="learn-to-code.md" %} learn-to-code.md {% endcontent-ref %}
- Awesome Lists Collection: Python
- Python-Pentest-Tools
- Pythonidae - Curated collection of scientific programming resources in Python (Note: Repository is archived but still contains valuable references)
- Awesome Lists Collection: PHP
- Awesome Lists Collection: JavaScript
- Awesome Lists Collection: Swift
- Awesome Lists Collection: GO
- Awesome Lists Collection: C
- Awesome Lists Collection: C++
- Awesome Lists Collection: Perl
- Awesome Lists Collection: Rust
- Awesome Lists Collection: Java
- Awesome Lists Collection: HTML5
- Awesome Lists Collection: CSS
- Awesome Lists Collection: DevSecOps
{% content-ref url="regex.md" %} regex.md {% endcontent-ref %}
- CyberChef - Often called the "Cyber Swiss Army Knife," CyberChef is a web-based tool with over 300 functions that can encode/decode, encrypt/decrypt, convert, and parse virtually any data format. You can copy and paste snippets of code for translation or upload entire files. The most useful feature is the "Magic" function, which uses fuzzy logic to automatically detect encoding types and suggest appropriate decoding operations. You can also chain multiple functions together into "Recipes" for complex data transformations.
- https://github.com/mattnotmax/cyberchef-recipes
- https://gist.github.com/michaelder - Cobalt Strike decoding recipes
- Hackvertor - Multi-function Code converter
- String Manipulation tool
- https://encoding.tools - Basic HTML decoding and hash conversion tool
- DCode toolkit - dCode is free and its tools are a valuable help in games, maths, geocaching, puzzles and problems to solve every day!
- quipqiup - Cryptoquip and Cryptogram solver
- Hex to ASCII | Hex to Text converter
- DDecode - Hex, Octal, HTML Decoder
- AES encryption - AES encryption/decryption tool
- Encode/Decode - Google's encoding and decoding tool
- Base64 Decode and Encode - Simple Base64 encoding/decoding tool
- JWT.io - JSON Web Token decoder, verifier, and generator
- de4dot - de4dot is a .NET deobfuscator and unpacker.
- gpp-decrypt - Decrypt the given Group Policy Preferences string
- Online JavaScript beautifier - Beautify, unpack, or de-obfuscate JavaScript and HTML, make JSON/JSONP readable, and more
- UnPacker - Sort and organize JavaScript into properly formatted code for easier analysis
- InfoSec Handlers Diary Blog - Advanced obfuscated JavaScript analysis
- Malware at Stake: JavaScript Obfuscation
- JS NICE: Statistical renaming, Type inference and Deobfuscation
Shellcode - For those in offensive security
- shell-storm - Shellcode database
- cryptam.com: Shellcode Analysis
- Shellcoding for Linux and Windows Tutorial
- Snyk - CLI and build-time tool to find and fix known vulnerabilities in open-source dependencies. It is one of the most widely adopted tools in DevSecOps. It even has its own conference.
- Mend (formerly WhiteSource) - Continuous security scanning for open source components in your repositories
- Brakeman - A static analysis security vulnerability scanner for Ruby on Rails applications
- Cppcheck - A tool for static C/C++ code analysis
- SpotBugs - Static analysis tool to find bugs in Java programs (successor to FindBugs)
- Sobelow - Security-focused static analysis for the Phoenix Framework
- bandit - Bandit is a tool designed to find common security issues in Python code.
- Package Hunter - Scan dependencies for potentially malicious code
- semgrep - Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
- GGShield - Detect secrets in source code and scan repositories for leaked credentials. GitGuardian is an automated secrets detection and remediation service.
- puma-scan - Puma Scan is a software security Visual Studio extension that provides real time, continuous source code analysis as development teams write code.
- https://github.com/deadbits/InsecureProgramming - Examples of insecure programming practices for educational purposes
- Secure Coding in C/C++
- Art of software Security Assessment
- betterscan-ce - Code Scanning/SAST/Static Analysis/Linting using many tools/Scanners with One Report (Code, IaC) - Betterscan Community Edition (CE)
- Trivy - Comprehensive vulnerability scanner for containers, filesystems, and git repositories
- Grype - Vulnerability scanner for container images and filesystems
- OWASP Dependency-Check - Software composition analysis tool that detects publicly disclosed vulnerabilities
- Ansible - Open-source automation tool for configuration management, application deployment, and task automation
- Terraform - Infrastructure as code tool for building, changing, and versioning infrastructure
- Grok Debugger - Online grok pattern tester (Note: Availability may vary; consider using Kibana's built-in Grok Debugger as an alternative)
- Grok Constructor - Alternative web-based grok pattern builder and tester
- Hashcalc - A fast and easy-to-use calculator that computes message digests, checksums, and HMACs for files, text, and hex strings. It offers a choice of 13 of the most popular hash and checksum algorithms.
- Md5 Decrypt & Encrypt - More than 10.000.000.000 hashes - Handy tool for hash lookups. Can save some time over brute forcing.
- CrackStation - Free hash lookup database with billions of hashes
- hashcat - Advanced password recovery utility supporting numerous hash types
- HexEd.it - Browser-based online and offline hex editing
- Hexinator - Powerful free hex editor
- shed - shed (Simple Hex Editor) is an easy application for viewing and editing files in text mode, using ncurses.
- Bless - Gtk# Hex Editor
- ImHex - Modern, feature-rich hex editor with pattern language support for reverse engineering
- edb-debugger - edb is a graphical cross platform x86/x86-64 debugger.
- ollydbg - OllyDbg is a 32-bit assembler level analysing debugger for Microsoft Windows. Emphasis on binary code analysis makes it particularly useful in cases where source is unavailable.
- openocd - OpenOCD aims to provide debugging, in-system programming and boundary-scan testing for embedded target devices.
- gdb - GDB/PEDA - GDB is a command-line debugger for Linux that is essential for analyzing and exploiting Linux binaries. Python Exploit Development Assistant (PEDA) is an open-source extension to GDB that enhances its usability with additional features for exploit development.
- Pattern - When looking for buffer overflows, one of the key components is identifying at which point the return pointer is overwritten. To help identify this location, PEDA can generate patterns that can be used as input to identify the exact offset.
- Ropsearch - Searches for return-oriented programming (ROP) gadgets in memory that can be used for ROP-based exploits.
- Searchmem|find - These commands can be used to search for structures and strings in memory. A typical use case is searching for strings like '/bin/sh' for ret2libc payloads.
- Skeleton - Generates a Python skeleton script that can be used as a template for creating exploit code.
- Vmmap - Displays a table listing all memory regions of the binary, including read, write, and execute permissions for each section.
◇ https://github.com/longld/peda - Install PEDA
# git clone https://github.com/longld/peda.git ~/peda
# echo "source ~/peda/peda.py" >> ~/.gdbinit
- GEF (GDB Enhanced Features) - Modern GDB extension with additional features for exploit developers and reverse engineers
- pwndbg - Another popular GDB plugin designed for exploit development and reverse engineering
- radare2 - Advanced open-source framework for reverse engineering and analyzing binaries
- Ghidra - NSA's open-source software reverse engineering framework
Note: The following tools are no longer actively maintained or have been superseded by newer alternatives. They are listed here for reference purposes only.
- FindBugs - Legacy static analysis tool for Java (replaced by SpotBugs)
- Frhed - Older hex editor for Windows (consider using ImHex or HexEd.it instead)
- NRE Labs - Network automation learning platform (project has been discontinued)
- Ciphey - Fully automated decryption/decoding/cracking tool using natural language processing & artificial intelligence, along with some common sense.
- Replit - Collaborative, in-browser IDE to code in 50+ languages.
- bytecode-viewer - An advanced lightweight Java bytecode viewer, GUI Java decompiler, GUI bytecode editor, and much more.
- jq - Lightweight and flexible command-line JSON processor
- yq - Command-line YAML, JSON, and XML processor
- ShellCheck - Static analysis tool for shell scripts to find bugs and improve code quality