// the find
jhaddix/pentest-bookmarks
a collection of handy bookmarks
A Firefox bookmarks export from Jason Haddix, organized into categories like OSINT, web vectors, exploitation, and cheatsheets for penetration testers. It's a link dump, not code or a tool — useful only as a starting-point reading list for someone building a pentest methodology.
Categorization maps cleanly onto actual pentest workflow phases (recon, exploitation, web vectors, post-exploitation), which makes it easy to scan for a specific need. Early traction from a recognized name in the field (HP Fortify's pentest lead at the time) means the initial link set had real vetting behind it, not just scraped search results.
Last meaningful update was over a decade ago — the README itself admits half the sections 'need work' or are unparsed, and that was true before the project went dormant, so link rot is now severe. Distribution is a raw Firefox bookmarks HTML file plus a Google Code wiki page, with no JSON/markdown export, no dedup, and no dead-link checking, so you can't programmatically consume or audit it. No commits or structural changes since 2023 despite 350 forks, meaning nobody picked up maintenance — any fork is likely just as stale as upstream.