What's your favourite guide on security testing?

It’s Tuesday and we’re back with a new article from @restertest

He’s shared a guide on how to use Zap proxy and Zap HUD for Security testing and it got me thinking:

What’s your favourite guide on security testing?

@restertest has done a great job sharing how to use Zap, but there are lots of tools out there that can be used for security testing. What would you recommend?

My favorite “guide” is the disclosed reports and write ups of people.
They contain so much information, not only about vulnerabilities but also about the way a hacker thinks.

Some examples: HackerOne