daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

DÆMON//SEC

The cheatsheet vault for operators.

A curated, glassy vault of the best IT & cybersecurity cheatsheets — Active Directory, enumeration, exploitation, priv-esc, web, DFIR, and more. Fast offline search, copy-ready commands, zero fluff.

🌐 cheatsheet.daemon-sec.xyz · source on GitLab

Rose Pine · Apple-glass · cyberpunk — built with Astro + Pagefind


What's inside

60 hand-picked, modernized cheatsheets across 12 domains:

Domain Domain Domain
Active Directory Enumeration Exploitation
Privilege Escalation Password Attacks Web
Tunneling & Pivoting Cryptography DFIR
Tools Linux & IT Git & Workflow

Each page is stripped of vault-specific syntax, given consistent frontmatter (tags, tools, difficulty), and refreshed for current tool flags and versions.

Features

Develop

npm install
npm run dev        # local dev server
npm run build      # astro build + pagefind search index -> dist/
npm run preview    # preview the production build

Deploy

Cloudflare Workers is the only host. It serves cheatsheet.daemon-sec.xyz, configured in wrangler.jsonc, and deploys are manual:

npm run deploy:workers   # build + .assetsignore + wrangler deploy

There is no CI deploy. Pushing to main publishes nothing on its own, so a content change is live only once someone runs the command above.

Content structure

Cheatsheets live in src/content/sheets/<category>/<slug>.md with frontmatter:

---
title: "Rubeus"
description: "Kerberos abuse toolkit…"
category: active-directory
tags: [kerberos, tickets]
tools: [Rubeus]
difficulty: advanced
updated: "2026-08-09"
---

Category slugs, colors, and labels are defined in src/lib/taxonomy.ts.

Third-party content

Two directories are generated mirrors of someone else's work, not ours to license. Full attribution lives on /credits.

Path Upstream Licence
src/content/payloads/ PayloadsAllTheThings (Swissky) MIT, Copyright (c) 2019 Swissky — see vendor/PayloadsAllTheThings/LICENSE
src/content/internal/ InternalAllTheThings (Swissky) none published upstream; copyright stays with Swissky and its contributors

Both are regenerated by scripts/sync-payloads.py and scripts/sync-internal.py — don't hand-edit them.

scripts/sync-mirrors.sh drives both of them. Run it bare to see what upstream has done since the last sync: it clones both upstreams, regenerates the mirrors, builds and tests the result, and leaves the diff in your working tree without committing anything.

scripts/sync-mirrors.sh            # sync + validate, commit nothing
scripts/sync-mirrors.sh --commit   # ... and commit, one commit per upstream
scripts/sync-mirrors.sh --push     # ... and push to main, which deploys

.github/workflows/sync-mirrors.yml runs that same script with --push daily at 06:17 UTC, and on demand via Actions → Sync upstream mirrors → Run workflow. Only trees that actually moved get a commit. There is no review gate, so npm run build and node --test are the safety net: a sync that breaks either fails and never lands.

The sync only lands commits; it does not publish. Because deploys are manual, run npm run deploy:workers after a sync to put the new upstream content live.

Legal

For authorized testing, CTFs, and education only. Know your scope and get written permission before touching a system you don't own. The maintainers are not responsible for misuse.

The site's own code and hand-written cheatsheets are licensed under MIT. That licence does not extend to the mirrored trees above.