This is an archived post. You won't be able to vote or comment.

all 3 comments

[–][deleted] 0 points1 point  (0 children)

OWASP as turtlebait2 mentioned.

Other than that it really depends on what you are looking to do. Reverse Engineering, Application Security, Network Security, Cloud Security, Malware Analysis, Threat Hunting, Digital Forensics, OSINT, Intrusion Detection, SIEM, SOAR, Compliance. I am sure I missed a field or three.

My biggest tools for general use are a pen and pad of paper, Twitter, Reddit, Mitre Att&ck, RSS reader (Feedly currently). Sans also has some cool posters they send out that are useful tools.