HackTricks-wiki / hacktricks
Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
View on GitHubAI Architecture Analysis
This repository is indexed by RepoMind. By analyzing HackTricks-wiki/hacktricks in our AI interface, you can instantly generate complete architecture diagrams, visualize control flows, and perform automated security audits across the entire codebase.
Our Agentic Context Augmented Generation (Agentic CAG) engine loads full source files into context on-demand, avoiding the fragmentation of traditional RAG systems. Ask questions about the architecture, dependencies, or specific features to see it in action.
Repository Overview (README excerpt)
Crawler viewHackTricks _Hacktricks logos & motion design by_ _@ppieranacho__._ Run HackTricks Locally Your local copy of HackTricks will be **available at http://localhost:3337** after **STM Cyber** is a great cybersecurity company whose slogan is **HACK THE UNHACKABLE**. They perform their own research and develop their own hacking tools to **offer several valuable cybersecurity services** like pentesting, Red teams and training. You can check their **blog** in **https://blog.stmcyber.com** **STM Cyber** also support cybersecurity open source projects like HackTricks :) --- RootedCON **RootedCON** is the most relevant cybersecurity event in **Spain** and one of the most important in **Europe**. With **the mission of promoting technical knowledge**, this congress is a boiling meeting point for technology and cybersecurity professionals in every discipline. {{#ref}} https://www.rootedcon.com/ {{#endref}} --- Intigriti **Intigriti** is the **Europe's #1** ethical hacking and **bug bounty platform.** **Bug bounty tip**: **sign up** for **Intigriti**, a premium **bug bounty platform created by hackers, for hackers**! Join us at **https://go.intigriti.com/hacktricks** today, and start earning bounties up to **$100,000**! {{#ref}} https://go.intigriti.com/hacktricks {{#endref}} --- Trickest \ Use **Trickest** to easily build and **automate workflows** powered by the world's **most advanced** community tools. Get Access Today: {{#ref}} https://trickest.com/?utm_campaign=hacktrics&utm_medium=banner&utm_source=hacktricks {{#endref}} --- HACKENPROOF Join **HackenProof Discord** server to communicate with experienced hackers and bug bounty hunters! • **Hacking Insights:** Engage with content that delves into the thrill and challenges of hacking • **Real-Time Hack News:** Keep up-to-date with fast-paced hacking world through real-time news and insights • **Latest Announcements:** Stay informed with the newest bug bounties launching and crucial platform updates **Join us on** **Discord** and start collaborating with top hackers today! --- Modern Security – AI & Application Security Training Platform Modern Security delivers **practical AI Security training** with an **engineering-first, hands-on lab approach**. Our courses are built for security engineers, AppSec professionals, and developers who want to **build, break, and secure real AI/LLM-powered applications**. The **AI Security Certification** focuses on real-world skills, including: • Securing LLM and AI-powered applications • Threat modeling for AI systems • Embeddings, vector databases, and RAG security • LLM attacks, abuse scenarios, and practical defenses • Secure design patterns and deployment considerations All courses are **on-demand**, **lab-driven**, and designed around **real-world security tradeoffs**, not just theory. 👉 More details on the AI Security course: https://www.modernsecurity.io/courses/ai-security-certification {{#ref}} https://modernsecurity.io/ {{#endref}} --- SerpApi **SerpApi** offers fast and easy real-time APIs to **access search engine results**. They scrape search engines, handle proxies, solve captchas, and parse all rich structured data for you. A subscription to one of SerpApi’s plans includes access to over 50 different APIs for scraping different search engines, including Google, Bing, Baidu, Yahoo, Yandex, and more.\ Unlike other providers, **SerpApi doesn’t just scrape organic results**. SerpApi responses consistently include all ads, inline images and videos, knowledge graphs, and other elements and features present in the search results. Current SerpApi customers include **Apple, Shopify, and GrubHub**.\ For more information check out their **blog****,** or try an example in their **playground****.**\ You can **create a free account** **here****.** --- 8kSec Academy – In-Depth Mobile Security Courses Learn the technologies and skills required to perform vulnerability research, penetration testing, and reverse engineering to protect mobile applications and devices. **Master iOS and Android security** through our on-demand courses and **get certified**: {{#ref}} https://academy.8ksec.io/ {{#endref}} --- WebSec **WebSec** is a professional cybersecurity company based in **Amsterdam** which helps **protecting** businesses **all over the world** against the latest cybersecurity threats by providing **offensive-security services** with a **modern** approach. WebSec is an intenational security company with offices in Amsterdam and Wyoming. They offer **all-in-one security services** which means they do it all; Pentesting, **Security** Audits, Awareness Trainings, Phishing Campagnes, Code Review, Exploit Development, Security Experts Outsourcing and much more. Another cool thing about WebSec is that unlike the industry average WebSec is **very confident in their skills**, to such an extent that they **guarantee the best quality results**, it states on their website "**If we can't hack it, You don't pay it!**". For more info take a look at their **website** and **blog**! In addition to the above WebSec is also a **committed supporter of HackTricks.** {{#ref}} https://www.youtube.com/watch?v=Zq2JycGDCPM {{#endref}} --- CyberHelmets **Built for the field. Built around you.**\ **Cyber Helmets** develops and delivers effective cybersecurity training built and led by industry experts. Their programs go beyond theory to equip teams with deep understanding and actionable skills, using custom environments that reflect real-world threats. For custom training inquiries, reach out to us **here**. **What sets their training apart:** • Custom-built content and labs • Backed by top-tier tools and platforms • Designed and taught by practitioners {{#ref}} https://cyberhelmets.com/courses/?ref=hacktricks {{#endref}} --- Last Tower Solutions Last Tower Solutions delivers specialized cybersecurity services for **Education** and **FinTech** institutions, with a focus on **penetration testi…