Some resources are from unethical sources. (pirate sites, cracked software, etc) Everything here will have a legitimate source, as well as a “alternative” source for you to explore at your own discretion.
The lab mindset is about isolation, repeatability, and good notes. Everything else is just tools.
What you will find here
A little bit of everything you would need to get started.
- Tools: Core kit + optional tracks.
- Software: Hypervisors, base OS, and workflow helpers.
- Learning: Curated resources and practice paths.
- Starter packs: Downloadable bundles.
Tools
Start with the core kit. Add specialized tools only when you need them.
> Core toolkit (start here)
One disassembler, one debugger, one packet tool, one instrumentation layer.
Core toolkit (start here)
One disassembler, one debugger, one packet tool, one instrumentation layer.
Ghidra
Full suite with decompiler and scripting.
IDA Pro
Industry standard disassembler and debugger.
Binary Ninja
Modern UI with strong analysis workflows.
x64dbg
Go-to user mode debugger for Windows.
WinDbg Preview
Microsoft debugger for kernel and user mode.
Frida
Dynamic instrumentation and live hooks.
Wireshark
Packet capture and deep protocol analysis.
ImHex
Hex editor with patterns and plugins.
> Specialized tracks
Add these when you need firmware, mobile, or web focus.
Specialized tracks
Add these when you need firmware, mobile, or web focus.
Firmware + file analysis
Binwalk
Firmware extraction and analysis tooling.
YARA
Pattern matching for malware triage.
010 Editor
Hex editor with binary templates.
Managed + mobile
dnSpyEx
.NET decompiler and debugger.
JADX
Android DEX decompiler and viewer.
MobSF
Mobile app static + dynamic analysis.
JEB Decompiler
Commercial decompiler for mobile RE.
Web + red team
Software
> Lab foundation
Pick a hypervisor + base OS + one analysis VM.
Lab foundation
Pick a hypervisor + base OS + one analysis VM.
VMware Workstation
Reliable desktop virtualization.
VirtualBox
Free VM host with snapshots.
Hyper-V
Built-in Windows hypervisor.
Windows 11
Great for WinDbg, .NET, and tooling.
Ubuntu
General-purpose Linux base.
FLARE-VM
Malware analysis environment.
REMnux
Linux distro for malware analysis.
> Workflow + automation
Keep lab builds reproducible and notes organized.
Workflow + automation
Keep lab builds reproducible and notes organized.
Learning resources
> Learning resources
Small, high-signal picks to avoid overwhelm.
Learning resources
Small, high-signal picks to avoid overwhelm.
MITRE ATT&CK
Tactics, techniques, and detection ideas.
PortSwigger Web Security Academy
Hands-on labs for web testing and Burp skills.
OpenSecurityTraining2
Deep-dive RE, OS, and low-level training.
pwn.college
Interactive binary exploitation and RE exercises.
TryHackMe
Guided learning tracks for red team basics.
> Practice targets
Intentionally vulnerable apps and labs.
Practice targets
Intentionally vulnerable apps and labs.
Suggested starter packs
> Starter pack downloads
Swap in your preferred links once the zips are ready.
Starter pack downloads
Swap in your preferred links once the zips are ready.
Downloadable bundles you can swap out as your lab grows. Point the links to MediaFire, Dropbox, or Drive once you have the zips ready.
Hardware + lab interfaces
> Bench + field gear
Interfaces, probes, and RF tools.
Bench + field gear
Interfaces, probes, and RF tools.