Links
40 links across 5 groups: where the hardware comes from, what we read, and where to go and practise. Every one is checked periodically — tell us in Discord if you find a dead one.
Hardware & tool vendors
Where the kit on the gadgets page actually comes from. Lab401 is the usual European source; most of the rest ship direct.
- Lab401 European supplier for RFID, NFC, Flipper, Hak5 and general offensive hardware.
- Hak5 WiFi Pineapple, Rubber Ducky, Bash Bunny, Shark Jack and the rest of the classics.
- Flipper Zero The pocket multi-tool for sub-GHz, NFC, RFID, IR and GPIO.
- Espressif Makers of the ESP32 family, including the 5 GHz-capable ESP32-C5.
- Lilygo ESP32 boards that arrive with screens and batteries already attached.
- M5Stack Stackable ESP32 modules — the Cardputer and M5StickC are field-usable as-is.
- Great Scott Gadgets HackRF One and other open hardware from Michael Ossmann.
- Nuand bladeRF — full-duplex SDR with a serious FPGA.
- NooElec RTL-SDR dongles, upconverters, filters and antennas.
- KrakenRF KrakenSDR — five coherent receivers for direction finding and passive radar.
- SB Components HackyPi and a long tail of Pi and RP2040 accessories.
- Adafruit Components, dev boards and some of the best hardware documentation anywhere.
- Kode Dot Pocket ESP32 device with AMOLED touchscreen and an add-on hacking module.
- DevKitty Whisker — the open-source ESP32-S3 hacking console.
News & analysis
What we read to stay current. Breaking-news sites first, analysis and long-form after.
- The Hacker News High-volume breaking security news.
- BleepingComputer Ransomware, breaches and malware coverage — usually first to the detail.
- Krebs on Security Brian Krebs on cybercrime, with the investigative depth nobody else bothers with.
- Dark Reading Enterprise-facing security news and analysis.
- SecurityWeek Industry news, vulnerabilities and threat research.
- Risky Business The weekly podcast and newsletter — opinionated, and usually right.
- Schneier on Security Bruce Schneier on cryptography, policy and security economics.
- The Daily Swig / PortSwigger Research Web security news and original research from the Burp people.
Training & practice
Where to build the skills. Start with the guided platforms, graduate to the wargames, then play CTFs with us.
- TryHackMe Guided rooms and learning paths — the gentlest on-ramp.
- Hack The Box Boxes, Pro Labs and a genuinely hard endgame.
- PortSwigger Web Security Academy Free, thorough, and the best web-security training available at any price.
- OverTheWire The classic wargames. Bandit first, always.
- picoCTF Beginner-friendly CTF challenges that stay available year-round.
- Root-Me Hundreds of challenges across every category.
- CryptoHack Cryptography, taught by breaking it.
- pwn.college University-grade binary exploitation and systems security.
- VulnHub Downloadable vulnerable VMs for offline practice.
- PentesterLab Hands-on web exploitation exercises with real CVEs.
- CTFtime The CTF calendar, ratings and team pages. Ours is linked from /ctf.
References & databases
The lookups you end up with open in a tab permanently.
- MITRE ATT&CK The tactics and techniques matrix everything is mapped to now.
- Exploit-DB Public exploit archive, maintained by OffSec.
- NVD The US National Vulnerability Database — CVE detail and CVSS scoring.
- Have I Been Pwned Breach exposure lookup for addresses and domains.
Danish security
Local context. We are a Danish team and a good deal of our threat intelligence work is aimed at the Danish threat landscape specifically.
- Center for Cybersikkerhed (CFCS) The Danish national cyber security centre — threat assessments and advisories.
- CERT.dk Danish incident response and coordination.
- Digitaliseringsministeriet Danish digitalisation ministry — policy and national digital strategy.