DÆMON//SEC
The cheatsheet vault for operators.
A curated, glassy vault of the best IT & cybersecurity cheatsheets — Active Directory, enumeration, exploitation, priv-esc, web, DFIR, and more. Fast offline search, copy-ready commands, zero fluff.
🌐 cheatsheet.daemon-sec.xyz · source on GitLab
Rose Pine · Apple-glass · cyberpunk — built with Astro + Pagefind
What's inside
60 hand-picked, modernized cheatsheets across 12 domains:
| Domain | Domain | Domain |
|---|---|---|
| Active Directory | Enumeration | Exploitation |
| Privilege Escalation | Password Attacks | Web |
| Tunneling & Pivoting | Cryptography | DFIR |
| Tools | Linux & IT | Git & Workflow |
Each page is stripped of vault-specific syntax, given consistent frontmatter (tags, tools, difficulty), and refreshed for current tool flags and versions.
Features
- Rose Pine dark theme with a Rose Pine Dawn light toggle (respects your system preference).
- Apple-glass frosted panels with restrained cyberpunk neon accents.
- Every code block is a terminal pane with one-click copy.
- Instant offline fuzzy search (
/or⌘K) — no server, no tracking. - Fully responsive, keyboard-accessible,
prefers-reduced-motionaware.
Develop
npm install
npm run dev # local dev server
npm run build # astro build + pagefind search index -> dist/
npm run preview # preview the production build
Deploy
Cloudflare Workers is the only host. It serves cheatsheet.daemon-sec.xyz,
configured in wrangler.jsonc, and deploys are manual:
npm run deploy:workers # build + .assetsignore + wrangler deploy
There is no CI deploy. Pushing to main publishes nothing on its own, so a
content change is live only once someone runs the command above.
Content structure
Cheatsheets live in src/content/sheets/<category>/<slug>.md with frontmatter:
---
title: "Rubeus"
description: "Kerberos abuse toolkit…"
category: active-directory
tags: [kerberos, tickets]
tools: [Rubeus]
difficulty: advanced
updated: "2026-08-09"
---
Category slugs, colors, and labels are defined in src/lib/taxonomy.ts.
Third-party content
Two directories are generated mirrors of someone else's work, not ours to
license. Full attribution lives on /credits.
| Path | Upstream | Licence |
|---|---|---|
src/content/payloads/ |
PayloadsAllTheThings (Swissky) | MIT, Copyright (c) 2019 Swissky — see vendor/PayloadsAllTheThings/LICENSE |
src/content/internal/ |
InternalAllTheThings (Swissky) | none published upstream; copyright stays with Swissky and its contributors |
Both are regenerated by scripts/sync-payloads.py and scripts/sync-internal.py
— don't hand-edit them.
scripts/sync-mirrors.sh drives both of them. Run it bare to see what upstream
has done since the last sync: it clones both upstreams, regenerates the mirrors,
builds and tests the result, and leaves the diff in your working tree without
committing anything.
scripts/sync-mirrors.sh # sync + validate, commit nothing
scripts/sync-mirrors.sh --commit # ... and commit, one commit per upstream
scripts/sync-mirrors.sh --push # ... and push to main, which deploys
.github/workflows/sync-mirrors.yml runs that same script with --push daily
at 06:17 UTC, and on demand via Actions → Sync upstream mirrors → Run
workflow. Only trees that actually moved get a commit. There is no review
gate, so npm run build and node --test are the safety net: a sync that
breaks either fails and never lands.
The sync only lands commits; it does not publish. Because deploys are manual,
run npm run deploy:workers after a sync to put the new upstream content live.
Legal
For authorized testing, CTFs, and education only. Know your scope and get written permission before touching a system you don't own. The maintainers are not responsible for misuse.
The site's own code and hand-written cheatsheets are licensed under MIT. That licence does not extend to the mirrored trees above.