Blue hat

Good guys

Blue hats are defense-oriented ethical security researchers

Red hat

Good guys

Red hats are offense-oriented ethical security researchers

Green hat

Good guys

Green hats are ethical security researchers who are still learning and maturing their tradecraft

Purple hat

Good guys

Purple hats are ethical security researchers that practice both offensive and defensive security tradecrafts

White hat

Rarely a bad guy

White hats are "hackers" who place a high regard on laws, morals, and/or ethics during their operations. White hat hackers typically work with proactive respect to the law during their research efforts

Grey hat

Sometimes a bad guy

Grey hats are "hackers" who perform technically illicit actions during their operations to achieve success regardless of their means or motive, but infrequently target without cause. Think "Robin Hood Complex"

Black hat

Always a bad guy

Black hats are "hackers" who intentfully seek to commit eCrime acts in part of, or as a whole of their operations. Ransomware actors are black hats, as an example

Our knowledgebase includes court case reviews and write-ups, documentation on a selection of offensive and defensive CyberTools, and much more!

Got something to add to it? Submit it in a Pull Request, and we'll accept it if it's high quality.


Analyzing files?

Use these tools and platforms for file analysis - they come highly recommended.

A new malware sandbox, developed with scaling in mind from the start. Triage is Hatching’s new and revolutionary malware sandboxing solution. It leverages a unique architecture, developed with scaling in mind from the start. Triage can scale up to 500.000 analyses per day, an unprecedented number for a sandboxing service.



Relyze seamlessly integrates interactive software reverse engineering and analysis, boasting features such as loading PE and ELF binaries for in-depth structural exploration and symbol-rich analysis. It offers versatile code analysis across x86, x64, and ARM architectures, empowering users to reconstruct control flow, resolve indirect calls, and unveil stack variables. Its interactive environment enables dynamic modifications and annotations, fostering a deep understanding of code-data relationships through interactive graphs.

Cursor IDE

AI-first Code Editor that lets you build software faster in an editor designed for pair-programming with AI. Supports both Cursor account creation, but also OpenAI API Keys if you have a billing method already linked to your OpenAI account.


Atom Editor

A free and open-source, but since killed, text and source code editor for macOS, Linux, and Windows with support for plug-ins written in JavaScript, and embedded Git Control.


Google Earth Pro

Google Earth Pro on desktop is free for users with advanced feature needs. Import and export GIS data, and go back in time with historical imagery. Available on PC, Mac, or Linux.



Maltego is the all-in-one tool for link analysis, offering real-time data mining and information gathering, as well as the representation of this information on a node-based graph, making patterns and multiple order connections between said information easily identifiable.