Skip to content

Latest commit

 

History

History
 
 

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 
 
 
 
 

README.md

Yellow - Code and CLI

You do not need to know how to code to be good at security. Many newcomers to the industry are daunted by the prospect of learning to code, which can prevent them from taking the plunge into cybersecurity. Does coding help? Absolutely! However, it is not a prerequisite for success. A foundational level of coding knowledge is perfectly acceptable.

Think of it like learning the basics of a foreign language. Does everyone need 4-5 years to become completely fluent in Spanish before ordering food at your favorite taco restaurant? No! Understanding some of the more common terms and being able to recognize the language when it's used goes a long way.
The same applies to code.

To help with this foundational understanding, many platforms, tools, and projects have been created to make code more approachable. As a security analyst, you are not expected to write complex JavaScript or in-depth PowerShell commands. However, should you be able to recognize them and understand their function? Absolutely! Fortunately, there are tools that can make this process easier.

Secure Coding

Command Shells

{% embed url="https://assets.contentstack.io/v3/assets/blt36c2e63521272fdc/bltea7de5267932e94b/5eb08aafcf88d36e47cf0644/Cheatsheet_SEC301-401_R7.pdf" %}

Bash

{% content-ref url="bash/" %} bash {% endcontent-ref %}

Windows CLI

  • Operator Handbook: Windows_Commands - pg. 328

Powershell

{% content-ref url="powershell/" %} powershell {% endcontent-ref %}

CLI Assistance Tools

  • https://www.commandlinefu.com - An amazing repository of command strings accomplishing different tasks. Simply search the task and see what commands have worked for others.
  • https://explainshell.com/ - Enter a command-line to see the help text that matches each argument
  • cheat.sh - Community-driven command-line cheatsheet tool
  • tldr - Simplified and community-driven man pages with practical examples
  • thefuck - Corrects errors in previous console commands

Code Reference Tools

  • https://stackoverflow.com/ - The world's largest programming Q&A community. An invaluable resource for finding solutions to coding problems and understanding how different code snippets work. If you can't figure out how to code something, start here first.
  • The complete table of ASCII characters, codes, symbols and signs
  • Devhints - One of the largest collections of coding cheatsheets and guides available on the internet.
  • PublicWWW.com - Source code search engine that allows you to search across millions of websites
  • Microsoft Learn - Code Samples - Browse code samples from Microsoft documentation
  • https://ryanstutorials.net/ - A collection of free, introductory tutorials on several technology topics including: Linux command line, Bash scripting, creating and styling webpages with HTML and CSS, counting and converting between different number systems, and writing regular expressions
  • https://www.markdownguide.org/ - Free and open-source reference guide that explains how to use Markdown
  • GitHub Docs - Comprehensive documentation for GitHub, Git, and version control
  • Regex101 - Online regex tester and debugger with explanations
  • Can I Use - Browser compatibility tables for web technologies

{% content-ref url="learn-to-code.md" %} learn-to-code.md {% endcontent-ref %}

Code libraries and collections

Regex

{% content-ref url="regex.md" %} regex.md {% endcontent-ref %}

Decoding Tools

Javascript Decoders

Shellcoding

Shellcode - For those in offensive security

Code Vulnerability Scanning

  • Snyk - CLI and build-time tool to find and fix known vulnerabilities in open-source dependencies. It is one of the most widely adopted tools in DevSecOps. It even has its own conference.
  • Mend (formerly WhiteSource) - Continuous security scanning for open source components in your repositories
  • Brakeman - A static analysis security vulnerability scanner for Ruby on Rails applications
  • Cppcheck - A tool for static C/C++ code analysis
  • SpotBugs - Static analysis tool to find bugs in Java programs (successor to FindBugs)
  • Sobelow - Security-focused static analysis for the Phoenix Framework
  • bandit - Bandit is a tool designed to find common security issues in Python code.
  • Package Hunter - Scan dependencies for potentially malicious code
  • semgrep - Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
  • GGShield - Detect secrets in source code and scan repositories for leaked credentials. GitGuardian is an automated secrets detection and remediation service.
  • puma-scan - Puma Scan is a software security Visual Studio extension that provides real time, continuous source code analysis as development teams write code.
  • https://github.com/deadbits/InsecureProgramming - Examples of insecure programming practices for educational purposes
  • Secure Coding in C/C++
  • Art of software Security Assessment
  • betterscan-ce - Code Scanning/SAST/Static Analysis/Linting using many tools/Scanners with One Report (Code, IaC) - Betterscan Community Edition (CE)
  • Trivy - Comprehensive vulnerability scanner for containers, filesystems, and git repositories
  • Grype - Vulnerability scanner for container images and filesystems
  • OWASP Dependency-Check - Software composition analysis tool that detects publicly disclosed vulnerabilities

Misc Tools

Automation

  • Ansible - Open-source automation tool for configuration management, application deployment, and task automation
  • Terraform - Infrastructure as code tool for building, changing, and versioning infrastructure

Grok

  • Grok Debugger - Online grok pattern tester (Note: Availability may vary; consider using Kibana's built-in Grok Debugger as an alternative)
  • Grok Constructor - Alternative web-based grok pattern builder and tester

Hashes

  • Hashcalc - A fast and easy-to-use calculator that computes message digests, checksums, and HMACs for files, text, and hex strings. It offers a choice of 13 of the most popular hash and checksum algorithms.
  • Md5 Decrypt & Encrypt - More than 10.000.000.000 hashes - Handy tool for hash lookups. Can save some time over brute forcing.
  • CrackStation - Free hash lookup database with billions of hashes
  • hashcat - Advanced password recovery utility supporting numerous hash types

Hex Editors

  • HexEd.it - Browser-based online and offline hex editing
  • Hexinator - Powerful free hex editor
  • shed - shed (Simple Hex Editor) is an easy application for viewing and editing files in text mode, using ncurses.
  • Bless - Gtk# Hex Editor
  • ImHex - Modern, feature-rich hex editor with pattern language support for reverse engineering

Debugger

  • edb-debugger - edb is a graphical cross platform x86/x86-64 debugger.
  • ollydbg - OllyDbg is a 32-bit assembler level analysing debugger for Microsoft Windows. Emphasis on binary code analysis makes it particularly useful in cases where source is unavailable.
  • openocd - OpenOCD aims to provide debugging, in-system programming and boundary-scan testing for embedded target devices.
  • gdb - GDB/PEDA - GDB is a command-line debugger for Linux that is essential for analyzing and exploiting Linux binaries. Python Exploit Development Assistant (PEDA) is an open-source extension to GDB that enhances its usability with additional features for exploit development.
    • Pattern - When looking for buffer overflows, one of the key components is identifying at which point the return pointer is overwritten. To help identify this location, PEDA can generate patterns that can be used as input to identify the exact offset.
    • Ropsearch - Searches for return-oriented programming (ROP) gadgets in memory that can be used for ROP-based exploits.
    • Searchmem|find - These commands can be used to search for structures and strings in memory. A typical use case is searching for strings like '/bin/sh' for ret2libc payloads.
    • Skeleton - Generates a Python skeleton script that can be used as a template for creating exploit code.
    • Vmmap - Displays a table listing all memory regions of the binary, including read, write, and execute permissions for each section.
      ◇ https://github.com/longld/peda
    • Install PEDA
# git clone https://github.com/longld/peda.git ~/peda
# echo "source ~/peda/peda.py" >> ~/.gdbinit
  • GEF (GDB Enhanced Features) - Modern GDB extension with additional features for exploit developers and reverse engineers
  • pwndbg - Another popular GDB plugin designed for exploit development and reverse engineering
  • radare2 - Advanced open-source framework for reverse engineering and analyzing binaries
  • Ghidra - NSA's open-source software reverse engineering framework

Legacy/Deprecated Tools

Note: The following tools are no longer actively maintained or have been superseded by newer alternatives. They are listed here for reference purposes only.

  • FindBugs - Legacy static analysis tool for Java (replaced by SpotBugs)
  • Frhed - Older hex editor for Windows (consider using ImHex or HexEd.it instead)
  • NRE Labs - Network automation learning platform (project has been discontinued)

Honorable Mention

  • Ciphey - Fully automated decryption/decoding/cracking tool using natural language processing & artificial intelligence, along with some common sense.
  • Replit - Collaborative, in-browser IDE to code in 50+ languages.
  • bytecode-viewer - An advanced lightweight Java bytecode viewer, GUI Java decompiler, GUI bytecode editor, and much more.
  • jq - Lightweight and flexible command-line JSON processor
  • yq - Command-line YAML, JSON, and XML processor
  • ShellCheck - Static analysis tool for shell scripts to find bugs and improve code quality