Practitioner-grade cybersecurity content
Technical playbooks, war stories, and how-to-think guides — written by practitioners, anchored to the Indian context.
Want structured, step-by-step learning instead? Explore the Academy (guided courses) or the AI security hub.
Latest articles
Most recent practitioner playbooks across every track. Filter by topic in the sidebar, or use search.
BloodHound — Install, Use, Optimise (2026)
Active Directory attack-path graph tool — finds the shortest path from a low-priv user to Domain Admin.
Hacking Tools 2026Metasploit Framework — Install, Use, Optimise (2026)
The exploit framework — 4000+ exploits, post-exploitation modules, payload generators. Default starting point for hands-on exploitation.
Hacking Tools 2026Nuclei — Install, Use, Optimise (2026)
Template-based vulnerability scanner — 8000+ community templates covering CVEs, exposures, misconfigurations.
Hacking Tools 2026WPScan — Install, Use, Optimise (2026)
WordPress-specific vulnerability scanner — versions, plugins, themes, user enumeration, and CVE matching.
Hacking Tools 2026sqlmap — Install, Use, Optimise (2026)
Automatic SQL injection detection and exploitation — the canonical tool for proving SQLi to a developer.
Hacking Tools 2026ffuf — Install, Use, Optimise (2026)
Fast Go-based web fuzzer — directory busting, parameter discovery, virtual host enumeration. Fastest in class.
Hacking Tools 2026OWASP ZAP — Install, Use, Optimise (2026)
The free, open-source Burp alternative — full proxy + scanner + automation framework, maintained by OWASP/Checkmarx.
Hacking Tools 2026Burp Suite — Install, Use, Optimise (2026)
PortSwigger's industry-standard web application testing proxy — Pro is the bug-bounty hunter's default tool.
Hacking Tools 2026Maltego — Install, Use, Optimise (2026)
Visual link-analysis platform for OSINT — graph relationships between people, domains, IPs, and infrastructure.
Hacking Tools 2026Shodan CLI — Install, Use, Optimise (2026)
Command-line client for Shodan, the search engine for internet-connected devices and exposed services.