MindMaps πŸ—ΊοΈ

December 22, 2021 Β· View on GitHub

This repository stores and houses various Mindmaps for bug bounty HuntersπŸ§‘β€πŸ¦°, pentestersπŸ§‘β€πŸ¦° and offensive(πŸ”΄)/defensive(πŸ”΅) security ProfessionalsπŸ«‚ provided by me as well as contributed by the communityπŸ§‘πŸ»β€πŸ€β€πŸ§‘πŸ½. Your contributions and suggestions are welcomed.

NameLinkTypeDescriptionAuthor
Bug Hunters MethodologyπŸ”—πŸ”΄This Mindmap explains how to test for bugs on Bug bounty programsJhaddix
Fiding Server side issuesπŸ”—πŸ”΄This mind-map explains how to look for server side issues on your bug-bounty/pentest targetsImran parray
Javascript ReconπŸ”—πŸ”΄How to perform recon on JavaScript filesImran parray
My ReconπŸ”—πŸ”΄This mind-map explains how to look for various server side and client side bugs on Bug bounty programsImran parray
Testing 2FAπŸ”—πŸ”΄How to test 2FA for Bugshackerscrolls
Testing 2FA [2]πŸ”—πŸ”΄How to test 2FA for Bugshackerscrolls
2FA Bypass TechniquesπŸ”—πŸ”΄2FA Bypass TechniquesHarsh Bothra
Android Attacker VectorsπŸ”—πŸ”΄Detailed Mindmap on How to find and exploit Android bugs.hackerscrolls
Testing oAuth for VulnerabilitiesπŸ”—πŸ”΄How to test Oauth for Bugshackerscrolls
Security Assesment MindmapπŸ”—πŸ”΄General security Assessment Mind-mapSopas
Red Teaming Mind Map from The Hacker Playbook 3πŸ”—πŸ”΄Mind-map containing several techniques and approaches used by Red team membersMarcon Lencini
SSRF MindMapπŸ”—πŸ”΄How to test SSRF for Bugshackerscrolls
Code Review MindmapπŸ”—πŸ”΄πŸ”΅Mindmap containing several techniques and approaches that can be used during code reviews.www.amanhardikar.com
Android Application Penetration Testing MindmapπŸ”—πŸ”΄A simple mind-map which explains various test cases around Android Application Penetration TestingHarsh Bothra
Cookie Based Authentication VulnerabilitiesπŸ”—πŸ”΄a comprehensive Mind-map which includes various techniques to test Cookie based authentication mechanism.Harsh Bothra
Tesing JIRA for CVE'sπŸ”—πŸ”΄Detailed Mind-map on How to find and exploit JIRA CVE's.Harsh Bothra
Scope Based TestingπŸ”—πŸ”΄This Mind-map explains how to test for bugs based on the scope of your target.Harsh Bothra
OAuth 2.0 Threat Model Pentesting ChecklistπŸ”—πŸ”΄The following checklist represents a simplified visual alternative to IETF OAuth 2.0 Security Best Current Practice publication combined with various other public resources we found usefull.Binary Brotherhood
Bug Bounty PlatformsπŸ”—πŸ”΄list of bug bounty platform availablefujie gu
Web App PentestπŸ”—πŸ”΄Web application Pentest MindmapDing Jayway
Web App PentestπŸ”—πŸ”΄This mind-map has the list of bugs and the corresponding tools and techniques used to find those bugsNinad Mathpati
Mobile Security MindmapπŸ”—πŸ”΄a comprehensive Mind-map which includes various techniques to test Mobile Application for security issuesAman Hardikar
Web Security Field MindmapπŸ”—πŸ”΄πŸ”΅This mindmap is an combination of Web Attacks, AppSec and Bug Bounty stuffjois
Security Consulting & ImplementationπŸ”—πŸ”΅Security Consulting & Implementation mindmapLawrence Pingree
Information Security Technologies & MarketsπŸ”—πŸ”΄πŸ”΅This Mindmap is an combination of Information Security Technologies & Marketsovens ffdf
Information Security Technologies & MarketsπŸ”—πŸ”΄πŸ”΅This mindmap contains different Information Security Technologies & MarketsJohn Fortner
Nmap Scans MindmapπŸ”—πŸ”΄πŸ”΅This mindmap show how different type of scans can be performed via Nmap ScannerOnly Hacker
Cross Site Request Frogery MindmapπŸ”—πŸ”΄πŸ”΅This mindmap show how different type of security tests can be performed while testing CSRFalexlauerman
Access Control VulnerabilitiesπŸ”—πŸ”΄List of Techniques that can be use to test access control models of an ApplicationPratik Gaikwad
CISO MindMap 2021πŸ”—πŸ”΅is the latest and updated CISO MindMap for 2021 with a number of updates and new recommendations for 2021-22Rafeeq Rehman
Common Vulnerabilites on Forgot Password FunctionalityπŸ”—πŸ”΄List of Test cases that can be perform on an Forgot password functionalities within the web appsHarsh Bothra
Common XML AttacksπŸ”—πŸ”΄In this Mindmap Harsh Bothra Tired to list all the attacks that can be performed on an XML endpoints/servicesHarsh Bothra
Copy of Vulnerability Checklist for SAMLπŸ”—πŸ”΄List of all the Vulnerability that can be tested on SAML Endpoints/ServicesHarsh Bothra
Exploting GrafanaπŸ”—πŸ”΄Possible test cases to Exploit Publicly Avilable Grafa InstanceMuhammad Daffa
FILE READ vulnerabilitiesπŸ”—πŸ”΄Practical strategies for exploiting FILE READ vulnerabilitiesLukasz MikuΕ‚a
The Cyber Guy - ReconπŸ”—πŸ”΄in this mindmap the CyberGuy shares his Recon MethodologytheCyberGuy0
Penetration Testing CertificationsπŸ”—πŸ”΄πŸ”΅in this mindmap Tahar Tries to uncover the list of Certification in the field of Penetration testingMrTaharAmine
Linux Privilege EscalationπŸ”—πŸ”΄this mindmap shows several linux privilege escalation TechniquesSource

Special Thanks to all the authors for publishing these mindmaps πŸ₯³πŸ₯³πŸ₯³