SITE MAP
Every page on Breachfolio.
Looking for something specific? Use this directory of every page on the site, grouped by section. There is also a machine-readable XML sitemap for crawlers.
Home
Cybersecurity
- All cybersecurity guides
- AI & Cybersecurity.
- Cryptography you can actually use.
- CVE vs CVSS: what's the difference?
- Cyber Threat Intelligence (CTI), explained.
- Cybersecurity 101: the words that mean what.
- Digital forensics and DFIR explained.
- Domains vs subdomains: how to enumerate them.
- How a VPN actually works, and what it doesn't hide.
- How networks actually work (without the OSI poster).
- How to actually learn cybersecurity (without burning out on tutorials).
- How to start in cybersecurity: the real roadmap, and where it leads.
- Indicators of Compromise (IOCs) explained.
- Investigate a suspicious domain: a workflow.
- Linux fundamentals for security, the working subset.
- Multi-factor authentication, explained.
- Public Key Infrastructure, explained.
- Red team, blue team, purple team: what each one actually does.
- Registry vs registrar vs ISP vs hosting.
- Shodan and Censys explained.
- Sigma and YARA rules explained.
- SIM swap attacks, explained.
- SOC team roles and tiers explained.
- SOC tools: SIEM, SOAR, EDR and more.
- Social engineering, explained.
- Stateful vs stateless firewalls, and NGFW explained.
- The -INT disciplines: where OSINT fits among them.
- Threat modeling with STRIDE – a worked example.
- TLS certificates and Certificate Transparency, explained.
- What a red team actually does.
- What is a SOC? Security Operations Center.
- What is OSINT? Tools and workflow.
- What is WHOIS and how to read it.
AI
- All AI guides
- 5 prompts for self-study that actually work.
- Agentic AI security: what changes when the LLM can act, not just talk.
- AI and cryptography, explained.
- AI red teaming, from zero.
- Deepfakes, explained.
- LLM vs chatbot vs agent: the difference that actually matters.
- MCP (Model Context Protocol): the new attack surface for developers.
- Prompt injection, explained.
- Run an LLM on your own machine.
- Shadow AI, explained.
- Using LLMs to catch phishing.
Lab
- All lab walkthroughs
- Add a vulnerable target to your lab.
- Build a home cybersecurity lab on one laptop, legally, in 20 minutes.
- Lab 03: a SIEM you can actually read.
- Lab 04 – put a firewall in the middle.
- Lab 05 – see the packets, not just the logs.
- Lab 06 – find out whether your lab actually detects anything.
- Metasploitable 2 walkthrough: a step-by-step exploitation lab.
- What is Metasploitable 2, and why every lab has one.
Compare
- All comparisons
- Bitwarden vs 1Password vs KeePassXC: choosing a password manager in 2026.
- Burp Suite vs Caido: the new proxy that's actually fast.
- Burp Suite vs OWASP ZAP: the proxy that pays its rent.
- Kali Linux vs Parrot OS: the pentest distro you actually live in.
- Metasploit vs Sliver: post-exploitation frameworks in 2026.
- Nmap vs Masscan: accuracy versus raw throughput.
- NordVPN vs Surfshark vs Proton VPN: which one is worth it in 2026.
- Signal vs WhatsApp vs Telegram: which app is actually private in 2026.
- Snort vs Suricata: the other IDS debate.
- Splunk vs Wazuh vs ELK: which SIEM fits your budget.
- Tenable Nessus vs OpenVAS: vulnerability scanners head to head.
- Wireshark vs tcpdump: pick the right tool, then use the other one anyway.
Resources
- All resources
- Common ports, worth memorising.
- Cybersecurity acronyms, decoded.
- Frequently asked questions.
- Linux commands for a security check.
- Linux server hardening checklist: from zero to production.
- Network command glossary: ip, ss, netstat, tcpdump, which one, when.
- OWASP Top 10 (2025): quick reference.
- The first 24 hours of an incident.
- The most recognized cybersecurity certifications, compared.
- The Windows event IDs you actually look at.
News
- All news
- A perfect 10.0 in SimpleHelp puts MSPs back in the supply-chain blast radius
- A vCenter flaw was exploited five days after the patch shipped.
- Adobe patches a Magento flaw that hands over customer accounts
- Anthropic ships Claude Sonnet 5 as the new default – agentic performance near Opus, at Sonnet pricing
- Car screens were infected through their own update channel.
- Cyberattack threatens utterly critical infrastructure in Japan: KFC
- Global Cyber Roundup: Iran Tracking, macOS Malware, and Defense Sector Ransomware
- Government Agencies Falling Victim to Ransomware Daily, Warns Study – High-Stakes Public Impact
- Identity Attacks Overtake Exploits as Top Ransomware Cause
- Inc Ransomware Exploits SonicWall SMA Zero-Days – Full Root Access Achieved via Chaining
- JetBrains patches auth bypass and RCE across Hub, YouTrack, IntelliJ and more
- Microsoft warns of surge in ACR Stealer attacks against enterprise customers
- Progress confirms zero-day vulnerability behind ShareFile disruption – vendor issues patch to restore service
- Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT – Supply Chain Risks Expand
- SharePoint RCE lands on CISA's must-patch list – the bulletin came weeks after the fix
- The Real AI Threat Is Blind Trust – Why Autonomous Execution Without Oversight Is Dangerous
- Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities
- Ukraine Appoints Intelligence Expert as Acting Defense Minister to Strengthen Strategy
Guides
- All guides
- "My child is in trouble and needs money": is that call really them?
- "Your Amazon package could not be delivered": is that text a scam?
- "Your antivirus renewed for $499": do not call the cancellation number
- "Your Apple ID has been locked": check the message without losing your account.
- "Your computer is infected, call this number": the fake tech support scam
- Bank Fraud Department Safe Account Scam: What to Do Now
- Did Google detect suspicious activity? Tell a real security alert from phishing
- Did Netflix ask you to update your payment method? Here's how to verify it.
- How to report a scam website in the United States.
- How to tell if an IRS text message is fake.
- Hurricanes, fires, and earthquakes: how to donate without funding a scammer
- I entered my credit card on a fake website: what to do now.
- Is that job offer real? How to spot fake recruiters, fake checks, and reshipping scams.
- Is the PayPal payment real? How to check "you've been paid" and account alerts.
- Is this domain fake or suspicious? Here's how to check.
- Package Delivery Text Scam: What to Do Right Now
- Someone copied your website. This is the order to shut it down.
- Someone is in your email. This is the order to fix it.
- Someone is threatening to share your photos: what to do right now.
- Someone's impersonating you on Instagram. Here's what to do.
- The app shows profits but will not let you withdraw: how the scam works
- The host wants a direct transfer: how to protect your reservation
- What to do if your messaging account was hacked.
- You sent a photo of your ID. What can really be done with it.
- Your data has already leaked. Here is what you can still do.
Legal & info
This directory is regenerated automatically from the live site on every deploy. If you spot a stale link or a missing page anyway, please get in touch.