Welcome to z-r0crypt
Not sure where to begin? This page guides you to the most relevant content based on your interests.
I’m Preparing for OSCP (PEN-200)
Best starting point: Foundation building, Linux privilege escalation, network penetration testing
Recommended reading order:
-
Cryptography Fundamentals
- Cryptography I - Week 1
- Cryptography I - Week 2 Part 1
- Why: OSCP includes network security fundamentals
-
Linux Post-Exploitation
- SSSD-Extract Tool
- Why: Active Directory on Linux is a real attack vector
-
Methodology & Planning
- HTB Machines for OSEP Preparation (applies to OSCP too)
- Why: Understand structured approach to penetration testing
Estimated time: 2-3 hours reading + practice labs
I’m Preparing for OSWE (Web-300)
Best starting point: Web application security, exploit development, code review
Recommended reading order:
-
Web Security Fundamentals
- Dangerous PHP Functions
- Why: Understanding dangerous patterns in code
-
OSWE/AWAE Preparation Guide
- OSWE/AWAE Preparation
- Why: Comprehensive exam prep reference
-
Advanced Concepts
- Cryptography I - Week 2 Part 2
- Why: Understanding encryption modes for web security
Estimated time: 3-4 hours reading + hands-on AWAE lab
I’m Preparing for OSEP (PEN-300)
Best starting point: Red teaming, advanced exploitation, active directory attacks
Recommended reading order:
-
Start with the Curated List
- HTB Machines for OSEP Preparation
- Why: This directly maps HTB machines to PEN-300 topics
-
Tool Development
- SSSD-Extract Tool
- Why: Understanding practical exploitation tool building
-
Cryptography Deep Dive
- Cryptography I Series
- Why: OSEP includes cryptographic attacks
Estimated time: 4-5 hours reading + HTB practice
I’m Interested in Web Application Security
Best starting point: Understanding vulnerabilities, code review, exploitation techniques
Recommended reading order:
-
Understanding Dangerous Patterns
-
OSWE Preparation (Advanced)
-
Related Posts in Category
I’m Interested in Cryptography
Best starting point: Cryptography theory, practical applications, attacks
Recommended reading order:
-
Start with Fundamentals
-
Advanced Topics
-
Explore More
Why read these? Stanford’s Cryptography I course by Dan Boneh is industry-leading. These notes summarize the essentials and explain practical implications.
I’m Learning to Reverse Engineer & Exploit
Best starting point: Assembly, binary exploitation, CTF challenges
Recommended reading order:
-
Get Hands-On with Challenges
- Microcorruption CTF Tutorial
- Why: Learn by doing in a safe environment
-
Complement with Theory
I’m Interested in Red Teaming & Post-Exploitation
Best starting point: Tool development, practical techniques, attack chains
Recommended reading order:
-
Practical Tool Deep-Dive
-
Attack Chain Planning
-
Explore More
I Want a Full Reading Path
Complete learning journey (in order):
-
Foundations (2 weeks)
- Cryptography I - Week 1
- Cryptography I - Week 2 Part 1
- Dangerous PHP Functions
-
Intermediate (2 weeks)
- Cryptography I - Week 2 Part 2
- OSWE/AWAE Preparation
- SSSD-Extract Tool
-
Hands-On (ongoing)
- Microcorruption CTF Tutorial (practice)
- HTB Machines for OSEP (practice with real machines)
-
Advanced (as you progress)
- All Red Team posts
- All Web Security posts
All Posts by Category
- Red Team — Penetration testing, post-exploitation, adversarial techniques
- Web Security — Web application exploitation and defense
- Cryptography — Cryptographic theory and attacks
- Exploit Development — Building and understanding exploits
- CTF — Capture the flag walkthroughs and techniques
- Tools — Open-source security tools and utilities
How to Use This Site
- Browse by category — Find content related to your specific interest
- Read the posts — Each post is self-contained and thoroughly researched
- Follow the recommendations above — If you’re prepping for a cert, follow the reading path
- Explore tags — Click tags to find related content across posts
- Check back regularly — New posts are added regularly covering emerging topics
Questions?
Found an error? Have a topic suggestion? Want to discuss something?
Happy learning!