OWASP Juice Shop
Modern vulnerable web app with 100+ challenges. Great for web pentesting and secure-coding practice.
A curated command center for penetration testing, red team operations, and system hardening. Every platform free, every tool battle-tested, every technique authorized-use only.
Hand-picked, 100% free platforms used by professional pentesters and red team operators worldwide.
Battle-tested tools used daily by professional red teams — with install notes, usage, and pro tips inside each detail sheet.
All tools are open-source or have generous free tiers. Always verify install instructions on the official repos.
Knowing how to break systems makes you exceptional at hardening them. Production-grade checklists and tooling used by top security teams.
Apply CIS / DISA STIG baselines via Group Policy or LGPO, then layer Defender ASR, BitLocker, and Credential Guard.
A structured, battle-tested methodology with Arsenal tools mapped to each phase. This is how mature operators approach authorized assessments.
Passive and active information gathering. Never skip this — poor recon leads to noisy or failed engagements.
Gaining the first foothold. This phase carries the highest risk of detection.
Establishing reliable access and escalating privileges. Favour living-off-the-land where possible.
Moving through the environment and achieving domain-level objectives (usually DA or equivalent).
Achieving the objectives (data access, ransomware simulation) while maintaining OPSEC.
The most important phase for the client. Professional red teams spend significant time here.
Scenario-based operational playbooks — structured approaches used in real authorized engagements.
A common starting point for mature engagements.
Phase 1 · Initial foothold
Phishing or compromised credential · Responder / LLMNR poisoning · external vuln if in scope
Phase 2 · Situational awareness
BloodHound (SharpHound) · CrackMapExec / netexec · Certipy find
Phase 3 · Privesc & lateral
Rubeus + Certipy · Impacket secretsdump · Sliver / Evil-WinRM
Focused external testing with a bug-bounty mindset.
Recon & discovery
theHarvester + Amass/Subfinder · PortSwigger methodology · Nmap + ffuf/Gobuster
Vulnerability hunting
Burp Suite + OWASP ZAP · SQLMap · business-logic flaws
Exploitation & impact
Chaining vulns · account takeover · data exfil simulation
Demonstrate impact safely, without real destruction.
Access & spread
Establish foothold · map shares & backups · stage simulation payload
Impact (simulated)
Benign canary "encryption" · backup-reachability test · blast-radius mapping
Reporting
Recovery-time insight · detection gaps · resilience recommendations
What to do after initial access in Windows/AD environments.
Credential harvesting
secretsdump.py + Rubeus · SafetyKatz · LSASS techniques
Lateral movement
CrackMapExec / netexec · Impacket (psexec, wmiexec) · Evil-WinRM
Persistence & evasion
Scheduled tasks/services · LOLBins · Sliver / Covenant implants
Hands-on vulnerable environments you can run locally or in-browser for safe practice. Essential for skill development.
Modern vulnerable web app with 100+ challenges. Great for web pentesting and secure-coding practice.
Classic PHP/MySQL vulnerable app. Excellent for learning SQLi, XSS, CSRF and the basics.
Intentionally vulnerable Linux VM. Perfect for Metasploit, enumeration, and post-exploitation.
OWASP project for learning web application security through guided lessons and challenges.
A huge library of community vulnerable VMs. Great for realistic full-scope practice.
Hundreds of free interactive web-security labs, right in the browser. No setup required.
Operational security separates professionals from operators who get burned. Habits, mindset, and practical techniques used by experienced red teams.
Professional-grade templates and assets used by experienced operators. Download, customize, and use in real engagements.
Comprehensive RoE covering scope, authorized techniques, out-of-scope items, communication protocols, and legal protections.
Production-ready checklist aligned with CIS Benchmarks Level 1 & 2. Includes commands and verification steps.
Pre-engagement, during, and post-engagement OPSEC. Covers C2, implants, exfil, and operational security.
Professional structure for red team and pentest reports: executive summary, findings, risk ratings, remediation.
How to run effective purple-team exercises: detection mapping, debrief structure, and improvement tracking.
FORGE exists to advance authorized security testing only. Every resource here assumes you have explicit written permission.
FORGE and its contributors are not responsible for misuse of any information or tools presented. This publication is strictly for educational and professional authorized use.