WeChall is a free online wargame that allows users to practice their hacking skills and learn about various security concepts. It offers a variety of challenges, from easy to hard, that cover different areas of security, such as cryptography, steganography, and web exploitation. WeChall is a great resource for both beginners and experienced hackers to improve their skills and learn from others. It also has a community section where users can discuss and share their experiences, and a ranking system that allows users to compete with each other. Overall, WeChall is an excellent platform for anyone interested in security and hacking to learn and have fun.
FEATURES
SIMILAR TOOLS
A managed code hooking template for .NET assemblies, enabling API hooking, code injection, and runtime manipulation.
Collection of Return-Oriented Programming challenges for practicing exploitation skills.
A tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF) for offensive security purposes.
APT Simulator is a tool for simulating a compromised system on Windows.
A set of YARA rules for identifying files containing sensitive information
A tool for managing multiple reverse shell sessions/clients via terminal with a RESTful API.
A proxy aware C2 framework for penetration testing, red teaming, post-exploitation, and lateral movement with modular format and highly configurable payloads.
An exploration of a new method to abuse DCOM for remote payload execution and lateral movement.
Kali Linux is a specialized Linux distribution for cybersecurity professionals, focusing on penetration testing and security auditing.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.