TRAINING RESOURCES
Curated learning resources mapped to real skills, certifications, and Arsenal tools. Every resource builds the analyst mindset first — tools second.
New for 2026: Quantum cryptography labs, AI-driven OSINT automation, and cyberpunk red team scenarios. All resources are mapped to real client work and internal FLLC training. No fake links—every lab, tool, and guide is live or in-repo.
All offensive security resources are provided for authorized penetration testing and defensive security research only. Applying techniques from these materials against systems you don't own is illegal.
Enterprise-grade REST API for global flight tracking, predictive analytics, and historical data. Used by airlines, airports, and cyber intelligence teams for deep-dive flight research, anomaly detection, and real-time alerting.
Open-source API for real-time and historical air traffic, ADS-B, and Mode S data. Integrate with Python, R, or MATLAB for custom analytics, anomaly detection, and airspace security research.
API for accessing up-to-date Two-Line Element (TLE) sets for all tracked satellites. Enables real-time satellite tracking, orbital prediction, and integration with custom visualization tools.
API for accessing the global SatNOGS network: receive, decode, and analyze satellite signals from space using SDR and open hardware. Integrate with custom analytics and visualization tools for deep space OSINT.
FAA's official Unmanned Aircraft Systems (UAS) portal: drone registration, airspace authorizations, and real-time UAS facility maps. Essential for drone pilots and airspace OSINT.
ESA’s open data portal: satellite imagery, Earth observation, and mission telemetry. European counterpart to NASA’s open data, with unique datasets for global space OSINT.
Track every Starlink satellite in real time, visualize orbits, and analyze constellation growth. Essential for space nerds, telecom OSINT, and global internet research.
NASA’s interactive 3D visualization platform for planets, missions, and spacecraft. Explore the solar system, track missions, and visualize real-time data in a browser.
Enterprise-grade API for global flight tracking, historical data, and predictive analytics. Used by airlines, airports, and intelligence analysts for deep-dive flight research.
The definitive source for satellite orbital elements (TLEs), launch logs, and space situational awareness. Used by NASA, NORAD, and amateur astronomers worldwide.
Global, open-source network of satellite ground stations. Receive, decode, and analyze satellite signals from space using SDR and open hardware. Join the nerd revolution in space OSINT!
Track satellites, ISS, Starlink, and astronomical events. Visualize passes, flares, and orbits with interactive sky charts. Essential for space OSINT and amateur astronomy.
Massive, community-driven database of aircraft, tail numbers, airline fleets, and photos. Used for tail number research, fleet tracking, and aviation OSINT investigations.
Free online book covering practical Python automation — file system operations, web scraping, PDF manipulation, Excel automation, and scheduling. Foundational reading before moving to security scripting. Insider tip: Combine with OSINT APIs and automate deep data mining for real-world cyber investigations.
Harvard's structured Python introduction with problem sets, automated grading, and a certificate of completion. Rigorous academic framework with real programming challenges from day one.
PowerShell as a security operations language: Active Directory administration, WMI queries, event log analysis, incident response automation, and tradecraft used by both red and blue teams. Insider: Learn to script AD enumeration and lateral movement like a real-world red teamer. Combine with BloodHound for graph-based attack path mapping.
Free, project-based Ruby curriculum from fundamentals through object-oriented design. Ruby's clean syntax makes it ideal for rapid tool prototyping and is the language underpinning Metasploit modules.
Free SSH-based wargame series teaching security concepts through progressive challenges. Bandit teaches Linux command-line fundamentals; Narnia covers memory corruption; Leviathan, Natas, and Krypton cover escalating topics.
Official FAA data portal: live flight tracking, NOTAMs, aircraft registry, drone zone, and safety incident databases. The backbone for all US aviation OSINT and regulatory research.
The nerdiest, most open global flight tracking platform. Real-time, unfiltered aircraft positions, military and private jet tracking, and historical flight data. No censorship, no paywall.
Track satellites, ISS, and space debris in real time. Includes TLE data, orbital predictions, and ground track visualization. Integrate with Python for custom space OSINT workflows.
Open-source platform and API for real-time and historical air traffic, ADS-B, and Mode S data. Integrate with Python, R, or MATLAB for custom analytics and visualizations.
NASA’s official open data portal: satellite imagery, mission telemetry, space weather, and APIs for everything from Mars rover photos to asteroid tracking. The ultimate nerd resource for space OSINT and research.
Free web hacking playground with structured missions covering JavaScript manipulation, server-side vulnerabilities, app logic flaws, and cryptography. Legal sandbox environment for offensive web techniques.
OffSec's standalone lab environment with beginner through advanced Linux and Windows machines. Play tier is free; Practice tier ($19/mo) provides full-difficulty machines matching OSCP exam complexity. Insider: Use these labs to build a personal arsenal of custom exploits and post-exploitation scripts. Document every step for your cyberpunk portfolio.
OffSec's flagship penetration testing course. 800+ page PDF, 17+ hours of video, and lab access to 70+ vulnerable machines. Culminates in the 24-hour OSCP practical exam — the gold-standard entry cert for pentesters.
Free, world-class web application security training from the makers of Burp Suite. 220+ interactive labs covering every OWASP category plus advanced topics: HTTP request smuggling, OAuth attacks, and GraphQL injection.
ASU-backed binary exploitation training platform covering program misuse, shellcoding, memory corruption, format strings, return-oriented programming, and kernel exploits. Docker-based dojo environment.
Free, comprehensive video course covering all Network+ domains: OSI model, TCP/IP, subnetting, routing protocols, wireless, network security, and troubleshooting. Foundational requirement before any network security work.
Hands-on lab for quantum-safe encryption, lattice-based cryptography, and post-quantum key exchange. Includes real-world attack/defense scenarios and code samples.
Automate OSINT collection, threat feed aggregation, and anomaly detection using AI. Includes live code, Jupyter notebooks, and integration with FURIOS-INT feeds. Insider: Use LLMs to correlate threat actor TTPs, automate dark web scraping, and build your own cyberpunk threat intelligence engine.
Immersive red team labs with cyberpunk scenarios: AI adversaries, quantum firewalls, and live attack/defense. Includes CTFs, writeups, and Discord integration.
Professor Dan Boneh's rigorous cryptography course from Stanford. Covers stream ciphers, block ciphers, MACs, authenticated encryption, public-key cryptography, and digital signatures with mathematical rigor.
Adam Shostack's definitive guide on STRIDE threat modeling, data flow diagrams, attack trees, and security design review. Required reading for anyone producing architecture-level security assessments.
Michael Bazzell's comprehensive OSINT methodology guide, updated annually. Covers people searches, social media intelligence, image analysis, domain research, email tracing, and custom search tools.
Advanced study of Ring-0 kernel logic and recursive world-building compilers. CyberOS architecture for modern cybersecurity simulation and SOC operations.
Official CISA Cybersecurity Evaluation Tool documentation. Mapping enterprise assets to NIST and federal compliance standards.