daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit ae714c7e5ef8f5f3a08601fcd3e4fa2cb3c1d055
parent d1f3335bc7a7af813e54950b0f8b0027596f0317
Author: DAEMON <zer0sec.xp@icloud.com>
Date:   Sat,  3 Oct 2026 18:51:29 +0100

Strip Obsidian vault-renderer artifacts from 21 sheets

The sheets were imported from an Obsidian vault whose renderer understood
two things Astro does not, and both were rendering as literal text on the
live site:

- `ris:<Name>` — Remix Icon tokens, 155 of them across 19 files. 55 sat
  inside headings, so a section titled 'Modes overview' rendered as
  'Modes overview ris:Command' and produced the anchor
  #modes-overview-riscommand. The other 92 were standalone blockquote
  lines containing nothing but the token.
- `+ \`> ABOUT_THIS_NOTE\`` — callout template slots the import never
  filled, showing the slot name to readers.

Also removes a dataviewjs block in cryptography/gpg.md that called
`dv.view("00Meta/Views/NoteBanner")` — Obsidian Dataview machinery that
rendered as a code block exposing internal vault paths.

Removing the tokens changes 55 heading slugs. Nothing links to the
polluted anchors (checked across src/), and the old slugs carried the
icon name as accidental garbage, so the new ones are strictly better.

Separately, shikiConfig gains a langAlias map. Fence languages the sheets
use that Shiki has no grammar for were silently falling back to plaintext
— 23 blocks per build. The capitalised entries (SQL, Javascript, C) come
from the generated payloads/ and internal/ mirrors, where upstream wrote
```SQL and Shiki's lookup is case-sensitive; those files are rewritten by
the sync scripts, so the alias is the only place that fix can live. Two
fallbacks remain by choice: gitignore and smali have no close grammar, so
plaintext is the honest result.

Verified: no ris: token remains anywhere under src/content/sheets, the
build is green, and the Shiki fallback count drops from 23 to 2.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Diffstat:
Mastro.config.mjs | 25+++++++++++++++++++++++++
Msrc/content/sheets/active-directory/attack-37-dcsync-attack.md | 7-------
Msrc/content/sheets/active-directory/attack-38-dcshadow-attack.md | 5-----
Msrc/content/sheets/active-directory/attack-39-ntds-dit-extraction-and-dumping.md | 5-----
Msrc/content/sheets/active-directory/attack-40-zerologon-cve-2020-1472.md | 5-----
Msrc/content/sheets/active-directory/attack-41-petitpotam-cve-2021-36942.md | 5-----
Msrc/content/sheets/active-directory/attack-42-printerbug-spoolsample.md | 5-----
Msrc/content/sheets/active-directory/attack-43-printnightmare-cve-2021-34527.md | 5-----
Msrc/content/sheets/active-directory/attack-44-nopac-sam-the-admin-cve-2021-42278-42287.md | 5-----
Msrc/content/sheets/cryptography/gpg.md | 18++++++------------
Msrc/content/sheets/linux-it/rdp.md | 22++++++++++------------
Msrc/content/sheets/pentest-workflow/alternate-data-streams-guide.md | 2+-
Msrc/content/sheets/pentest-workflow/attack-flow-guide.md | 2+-
Msrc/content/sheets/pentest-workflow/attacking-common-services-guide.md | 4++--
Msrc/content/sheets/pentest-workflow/most-used-commands.md | 8++++----
Msrc/content/sheets/pentest-workflow/network-service-attack-manual.md | 10+++++-----
Msrc/content/sheets/tools/eyewitness.md | 18+++++++-----------
Msrc/content/sheets/tools/internet-archival-guide.md | 29+++++++++--------------------
Msrc/content/sheets/tools/webfuzz.md | 19++++++-------------
Msrc/content/sheets/web/blind-xss-tool-ezxss.md | 19++++++-------------
Msrc/content/sheets/web/blind-xss-tool-interactsh.md | 22++++++----------------
Msrc/content/sheets/web/blind-xss-tool-xss-hunter.md | 19++++++-------------
22 files changed, 94 insertions(+), 165 deletions(-)

diff --git a/astro.config.mjs b/astro.config.mjs @@ -180,6 +180,31 @@ export default defineConfig({ // as terminal output — so there is no second palette to flip to. theme: 'rose-pine-moon', wrap: false, + // Fence languages the sheets actually use, mapped onto grammars Shiki + // ships. Without these the block silently falls back to plaintext, so a + // listing that should be highlighted reads as flat text. + // + // The capitalised three come from the generated mirrors + // (payloads/, internal/) where upstream wrote ```SQL and Shiki's lookup + // is case-sensitive. Those files are rewritten by the sync scripts, so + // the alias is the only place the fix can live. + // + // The rest have no grammar of their own; each is mapped to the closest + // one that reads correctly rather than left to plaintext. `smali` is + // deliberately absent — nothing Shiki ships resembles it, so plaintext + // is the honest result. + langAlias: { + SQL: 'sql', + Javascript: 'javascript', + C: 'c', + conf: 'ini', + svg: 'xml', + yara: 'c', + zeek: 'c', + ldif: 'yaml', + django: 'html', + dataviewjs: 'javascript', + }, }, }, }); diff --git a/src/content/sheets/active-directory/attack-37-dcsync-attack.md b/src/content/sheets/active-directory/attack-37-dcsync-attack.md @@ -20,7 +20,6 @@ DCSync is **the most efficient method for extracting every credential in an Acti The attack works by triggering the `GetNCChanges` RPC function (via the `DRSUAPI` interface) from a non-DC workstation. The target Domain Controller processes this as a legitimate replication request and responds with the requested user's credential material, including **NT hashes, Kerberos AES keys, old password hashes, and password history**. The entire exchange happens over the network using standard RPC — no malware needs to be deployed on the DC, no LSASS memory is accessed, and the NTDS.dit file is never read from disk. > [!info]+ Technical Deep-Dive — DRSUAPI GetNCChanges Flow -> `ris:FileList` > 1. The attacker binds to the DC's **DRSUAPI RPC endpoint** (UUID `e3514235-4b06-11d1-ab04-00c04fc2dcd2`) over TCP 135 → dynamic RPC port > 2. Calls `DRSBind` to establish a replication context handle with the DC > 3. Calls `DRSGetNCChanges` specifying the target account's **Distinguished Name** (or requesting the entire naming context) @@ -205,7 +204,6 @@ SharpKatz.exe --Command dcsync --User krbtgt --Domain corp.local --DomainControl ``` > [!info]+ Command Breakdown — secretsdump.py Flags -> `ris:Command` > 1. **`-just-dc`**: Only perform DCSync (DRSUAPI replication); skip SAM/LSA/DPAPI extraction that requires SMB admin access. Outputs NT hashes + Kerberos keys + cleartext passwords (if reversible encryption enabled) > 2. **`-just-dc-ntlm`**: Same as `-just-dc` but only extract NT hashes (no Kerberos keys). Faster; smaller output files > 3. **`-just-dc-user <user>`**: DCSync only the specified user — single DRSUAPI request, much stealthier than full dump @@ -567,20 +565,17 @@ alert tcp !$DC_SERVERS any -> $DC_SERVERS any ( ### 🛡️ EDR-Specific Detections > [!warning]+ Microsoft Defender for Identity (MDI) -> `ris:Windows` > 1. **"Suspected DCSync attack (replication of directory services)"** — high-confidence alert triggered when a non-DC machine calls DsGetNCChanges > 2. MDI correlates the source IP against registered DC objects in AD — any mismatch triggers the alert > 3. **"Malicious replication request"** — fires when a user account (not machine account) initiates replication > 4. *MDI is considered the gold standard for DCSync detection — it has near-zero false positives in most environments* > [!warning]+ CrowdStrike Falcon -> `ris:Radar` > 1. **"DCSync Credential Dumping"** — detects DRSUAPI GetNCChanges from non-DC endpoints > 2. Falcon monitors RPC traffic and correlates with endpoint process trees > 3. Also detects SharpKatz and Mimikatz in-memory execution via behavioral indicators (AMSI bypass, reflective loading patterns) > [!warning]+ Elastic Security -> `ris:FileList` > 1. Rule: **"Potential Credential Access via DCSync"** — correlates 4662 events with replication GUIDs > 2. Rule: **"Unusual DRSUAPI DsGetNCChanges RPC"** — network-level detection via Packetbeat / Zeek > 3. Kibana detection rule ID: `credential_access_dcsync` @@ -601,7 +596,6 @@ alert tcp !$DC_SERVERS any -> $DC_SERVERS any ( *** > [!important]+ Windows Server Version Differences -> `ris:Windows` > 1. **Server 2016+**: Advanced Audit Policy "Audit Directory Service Access" must be explicitly enabled — it's not on by default in all SKUs > 2. **Server 2019+**: Windows Defender Credential Guard protects LSASS but does **NOT** prevent DCSync — DCSync doesn't touch LSASS > 3. **Server 2022**: No new mitigations against DCSync — still relies on ACL auditing and network monitoring @@ -695,7 +689,6 @@ New-NetFirewallRule -DisplayName "Block DRSUAPI from non-DCs" ` ## 🧪 Lab Setup Hints > [!example]+ Minimal Lab for DCSync Practice -> `ris:Command` > 1. **DC**: Windows Server 2019/2022 VM — promote to DC for `lab.local`; create 5-10 test users with varied passwords > 2. **Attacker (Linux)**: Kali/Parrot VM — install Impacket (`pipx install impacket`), NetExec (`pipx install netexec`), bloodyAD > 3. **Attacker (Windows)**: Windows 10/11 VM domain-joined — download Mimikatz, SharpKatz, PowerView, DSInternals diff --git a/src/content/sheets/active-directory/attack-38-dcshadow-attack.md b/src/content/sheets/active-directory/attack-38-dcshadow-attack.md @@ -20,7 +20,6 @@ DCShadow allows an attacker to **register a rogue Domain Controller** in Active The attack was presented at [BlueHat IL 2018](https://www.dcshadow.com/) by Benjamin Delpy (Mimikatz author) and Vincent Le Toux. It works by temporarily registering the attacker's machine as a Domain Controller in Active Directory by creating the required objects in the Configuration partition — specifically an `nTDSDSA` object under `CN=Servers,CN=<Site>,CN=Sites,CN=Configuration` and the corresponding SPN entries (`E3514235-4B06-11D1-AB04-00C04FC2DCD2/<hostname>` for [MS-DRSR](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-drsr/) replication, and `GC/<hostname>` for Global Catalog). Once registered, the rogue DC pushes changes via `DrsReplicaAdd` to force legitimate DCs to pull replication data from the attacker — the changes then propagate across the entire forest as normal multi-master replication. > [!info]+ Technical Deep-Dive — nTDSDSA Registration & Replication Push -> `ris:FileList` > 1. **Phase 1 — DC Registration**: The SYSTEM-context Mimikatz instance creates an `nTDSDSA` object under `CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=local` — this is the object that defines a machine as a Domain Controller > 2. **SPNs Added**: Two critical SPNs are set on the attacker's computer object: > - `E3514235-4B06-11D1-AB04-00C04FC2DCD2/<attacker-hostname>/<domain>` (DRSUAPI replication SPN) @@ -272,20 +271,17 @@ tags: ### 🛡️ EDR-Specific Detections > [!warning]+ Microsoft Defender for Identity (MDI) -> `ris:Windows` > 1. **"Suspected DCShadow attack (domain controller promotion)"** — detects when a non-DC machine registers itself as a Domain Controller > 2. **"Suspected DCShadow attack (domain controller replication request)"** — detects `DrsReplicaAdd` calls from non-DC machines > 3. MDI monitors the Configuration partition in real-time for nTDSDSA object creation > 4. *MDI is the most reliable DCShadow detection tool available — it has specific behavioral detections that SIEM rules alone cannot replicate* > [!warning]+ CrowdStrike Falcon -> `ris:Radar` > 1. **"DCShadow Activity Detected"** — monitors for Mimikatz `lsadump::dcshadow` behavioral patterns > 2. Falcon detects the combination of SYSTEM token manipulation (`!processtoken`) + DRSUAPI RPC server registration > 3. Process tree analysis flags the dual-Mimikatz pattern (two `mimikatz.exe` instances with different token contexts) > [!warning]+ Elastic Security -> `ris:FileList` > 1. Rule: **"Potential DCShadow Activity"** — monitors for nTDSDSA object creation events and SPN modifications containing the DRSUAPI UUID > 2. Rule: **"Active Directory Replication from Anomalous Source"** — correlates replication traffic source IPs against known DC list > 3. *Requires Windows Event Forwarding (WEF) of Configuration partition change events to Elasticsearch* @@ -307,7 +303,6 @@ tags: *** > [!important]+ Windows Server Version Differences -> `ris:Windows` > 1. **Server 2012 R2**: DCShadow works without additional obstacles; minimal replication monitoring by default > 2. **Server 2016+**: Windows Defender Credential Guard does NOT prevent DCShadow (it doesn't interact with LSASS or local credentials) > 3. **Server 2019**: No new DCShadow-specific mitigations; MDI deployment is the primary recommendation diff --git a/src/content/sheets/active-directory/attack-39-ntds-dit-extraction-and-dumping.md b/src/content/sheets/active-directory/attack-39-ntds-dit-extraction-and-dumping.md @@ -18,7 +18,6 @@ source: "vault:ActiveDirectory/AD-Attack/Category-Five/🔵 Attack #39 — NTDS. The `NTDS.dit` file is the **Active Directory database** stored on every Domain Controller at `C:\Windows\NTDS\ntds.dit`. It contains all domain credentials (NT hashes, Kerberos keys, password history) for every account. Unlike DCSync (Attack #37, network-based), NTDS.dit extraction requires **local access to a DC** and involves copying the database file along with the SYSTEM registry hive for decryption. > [!info]+ Technical Deep-Dive — NTDS.dit Database Internals -> `ris:FileList` > 1. NTDS.dit uses the **Extensible Storage Engine (ESE / JET Blue)** database format — the same engine used by Exchange and Windows Search > 2. The database contains multiple tables, but the critical one is the **`datatable`** — it stores all AD objects and their attributes, including the `unicodePwd` (NT hash), `supplementalCredentials` (Kerberos keys, WDigest, cleartext if reversible encryption is enabled), and `lmPwdHistory`/`ntPwdHistory` (password history) > 3. **Encryption layers**: Credential attributes are encrypted with the **Password Encryption Key (PEK)**, which itself is encrypted with the **Boot Key (SYSKEY)** derived from the SYSTEM registry hive (`HKLM\SYSTEM\CurrentControlSet\Control\Lsa\{JD,Skew1,GBG,Data}`) @@ -309,19 +308,16 @@ level: critical ### 🛡️ EDR-Specific Detections > [!warning]+ Microsoft Defender for Identity (MDI) -> `ris:Windows` > 1. **"Suspected NTDS.dit theft"** — detects ntdsutil IFM creation and VSS-based NTDS.dit access patterns > 2. MDI correlates process creation on DCs with known NTDS.dit extraction command patterns > 3. *MDI is less effective for NTDS.dit extraction than for DCSync because the extraction happens locally, not over the network* > [!warning]+ CrowdStrike Falcon -> `ris:Radar` > 1. **"NTDS.dit Credential Dumping"** — behavioral detection for VSS creation followed by ntds.dit file access > 2. **"Volume Shadow Copy Abuse"** — flags vssadmin/diskshadow when combined with file access to sensitive paths > 3. Process tree analysis detects `cmd.exe → vssadmin.exe → copy ntds.dit` chains > [!warning]+ Elastic Security -> `ris:FileList` > 1. Rule: **"NTDS or SAM Database File Copied"** — file event monitoring for ntds.dit copies outside the NTDS directory > 2. Rule: **"Volume Shadow Copy Creation"** — process creation monitoring for vssadmin/diskshadow with shadow creation arguments > 3. Rule: **"Credential Dumping via NTDSutil"** — specific ntdsutil IFM command detection @@ -344,7 +340,6 @@ level: critical *** > [!important]+ Windows Server Version Differences -> `ris:Windows` > 1. **Server 2012 R2**: All extraction methods work; minimal built-in detection > 2. **Server 2016**: vssadmin event logging improved; Sysmon recommended for file-level monitoring > 3. **Server 2019**: Credential Guard protects LSASS but does **NOT** protect NTDS.dit file extraction — the file is a separate attack surface diff --git a/src/content/sheets/active-directory/attack-40-zerologon-cve-2020-1472.md b/src/content/sheets/active-directory/attack-40-zerologon-cve-2020-1472.md @@ -20,7 +20,6 @@ Zerologon is a **critical vulnerability in the [Netlogon Remote Protocol (MS-NRP **CVSS Score: 10.0** — Full unauthenticated domain compromise. > [!info]+ Technical Deep-Dive — AES-CFB8 Cryptographic Flaw -> `ris:FileList` > 1. The [Netlogon protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-nrpc/) uses **AES-CFB8** mode to compute a session key during the `NetrServerAuthenticate3` handshake between a client and a DC > 2. In AES-CFB8, the **Initialization Vector (IV)** should be random — but the Netlogon implementation uses a **fixed all-zero IV** (`ComputeNetlogonCredential` function) > 3. When the **client challenge** is also all zeros, the `ComputeNetlogonCredential` function produces an all-zero session credential with probability **1/256** (~0.39%) @@ -246,19 +245,16 @@ level: high ### 🛡️ EDR-Specific Detections > [!warning]+ Microsoft Defender for Identity (MDI) -> `ris:Windows` > 1. **"Suspected Zerologon exploitation (CVE-2020-1472)"** — high-fidelity alert triggered by anomalous Netlogon authentication patterns > 2. MDI detects the characteristic burst of failed Netlogon authentications followed by a successful authentication with an all-zero session key > 3. **Immediate alert** — MDI classifies this as critical severity with automatic incident creation > [!warning]+ CrowdStrike Falcon -> `ris:Radar` > 1. **"Zerologon Exploitation Detected"** — network-level detection for MS-NRPC manipulation > 2. Falcon correlates Netlogon RPC traffic patterns with CVE-2020-1472 signatures > 3. Process tree analysis for exploit tools (Python scripts, SharpZeroLogon) > [!warning]+ Elastic Security -> `ris:FileList` > 1. Rule: **"Potential Zerologon Attack (CVE-2020-1472)"** — detects burst of Event 5805 entries > 2. Rule: **"DC Machine Account Password Change"** — correlates Event 4742 with DC machine accounts > 3. *Requires Windows Event Forwarding of System and Security logs from DCs* @@ -279,7 +275,6 @@ level: high *** > [!important]+ Windows Server Version & Patch Timeline -> `ris:Windows` > 1. **August 2020**: Initial patch released (KB4565349 for Server 2012 R2/2016/2019) — "Phase 1" allows vulnerable connections with Event 5829 warning > 2. **February 2021**: "Phase 2" enforcement — DCs reject vulnerable Netlogon connections by default (registry `FullSecureChannelProtection = 1`) > 3. **Server 2012 R2**: Vulnerable if unpatched; patch available but may not be installed on legacy systems diff --git a/src/content/sheets/active-directory/attack-41-petitpotam-cve-2021-36942.md b/src/content/sheets/active-directory/attack-41-petitpotam-cve-2021-36942.md @@ -20,7 +20,6 @@ PetitPotam exploits the **[Encrypting File System Remote Protocol (MS-EFSR)](htt PetitPotam was initially **exploitable without authentication** on unpatched DCs, making it an unauthenticated domain compromise vector when combined with ESC8. > [!info]+ Technical Deep-Dive — MS-EFSR RPC Call Flow -> `ris:FileList` > 1. The attacker connects to the target's **MS-EFSR RPC endpoint** — accessible via two named pipes: `\pipe\efsrpc` (direct) and `\pipe\lsarpc` (LSASS-hosted) > 2. The DCERPC interface UUID is `c681d488-d850-11d0-8c52-00c04fd90f7e` (MS-EFSR) > 3. The attacker calls one of several **EFS RPC functions** (see table below) with a UNC path pointing to the attacker's listener (e.g., `\\ATTACKER_IP\share\file`) @@ -251,20 +250,17 @@ level: high ### 🛡️ EDR-Specific Detections > [!warning]+ Microsoft Defender for Identity (MDI) -> `ris:Windows` > 1. **"Suspected NTLM authentication tampering"** — detects NTLM relay patterns including PetitPotam-initiated coercion > 2. **"Suspected NTLM relay attack (Exchange account)"** — broader relay detection that also catches PetitPotam chains > 3. MDI correlates NTLM authentication from DC machine accounts to non-DC targets as suspicious > 4. *Post-2023 MDI updates include specific PetitPotam coercion detection via MS-EFSR pipe monitoring* > [!warning]+ CrowdStrike Falcon -> `ris:Radar` > 1. **"NTLM Coercion Attack Detected"** — behavioral detection for MS-EFSR-triggered NTLM authentication to external hosts > 2. Falcon monitors outbound NTLM from DC machine accounts — any auth to a non-DC is flagged > 3. Process-level detection for PetitPotam.py and Coercer execution on attacker machines within the network > [!warning]+ Elastic Security -> `ris:FileList` > 1. Rule: **"Potential NTLM Coercion via MS-EFSR"** — monitors for EFS pipe access from unusual sources > 2. Rule: **"ADCS Certificate Enrollment for Machine Account"** — detects relay-to-ADCS chain completion > 3. Rule: **"Outbound NTLM from Domain Controller"** — network-level detection for DC-originated NTLM to non-DCs @@ -285,7 +281,6 @@ level: high *** > [!important]+ Windows Server Version & Patch Differences -> `ris:Windows` > 1. **Pre-August 2021**: `EfsRpcOpenFileRaw` callable without authentication — **unauthenticated domain compromise** when paired with ESC8 > 2. **August 2021 patch**: Closes unauthenticated vector for `EfsRpcOpenFileRaw`; other functions still require only low-priv auth > 3. **Server 2016**: Vulnerable; patch available diff --git a/src/content/sheets/active-directory/attack-42-printerbug-spoolsample.md b/src/content/sheets/active-directory/attack-42-printerbug-spoolsample.md @@ -18,7 +18,6 @@ source: "vault:ActiveDirectory/AD-Attack/Category-Five/🔵 Attack #42 — Print The PrinterBug (aka SpoolSample) abuses the **[MS-RPRN (Print System Remote Protocol)](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/)** `RpcRemoteFindFirstPrinterChangeNotificationEx` function to coerce a target machine into authenticating back to an attacker-controlled host. When combined with **Unconstrained Delegation** or **NTLM relay**, this leads to TGT theft or certificate enrollment as the target machine account. > [!info]+ Technical Deep-Dive — MS-RPRN Coercion Mechanism -> `ris:FileList` > 1. The attacker connects to the target's **Print Spooler RPC endpoint** via the `\pipe\spoolss` named pipe (DCERPC interface UUID `12345678-1234-abcd-ef00-0123456789ab`) > 2. The attacker calls `RpcRemoteFindFirstPrinterChangeNotificationEx` (OpNum 69) — this function is designed to allow a client to register for print job notifications from a remote print server > 3. The function accepts a **notification target** parameter — the attacker specifies their own hostname/IP (e.g., `\\ATTACKER_IP`) @@ -259,19 +258,16 @@ level: high ### 🛡️ EDR-Specific Detections > [!warning]+ Microsoft Defender for Identity (MDI) -> `ris:Windows` > 1. **"Suspected NTLM authentication tampering"** — detects NTLM relay following Spooler-coerced authentication > 2. MDI monitors for DC machine accounts authenticating to non-DC endpoints — a key PrinterBug indicator > 3. *MDI does not specifically detect the PrinterBug RPC call itself — it detects the anomalous NTLM authentication that results from it* > [!warning]+ CrowdStrike Falcon -> `ris:Radar` > 1. **"Print Spooler Coercion Attack"** — behavioral detection for spoolss pipe manipulation followed by outbound NTLM > 2. Process tree analysis flags SpoolSample.exe and known coercion tool signatures > 3. Network-level detection for outbound NTLM from DC machine accounts > [!warning]+ Elastic Security -> `ris:FileList` > 1. Rule: **"Print Spooler Named Pipe Access"** — monitors for remote spoolss pipe connections from unusual sources > 2. Rule: **"DC Machine Account Authentication to Non-DC"** — correlates 4624 events with DC machine accounts authenticating to workstations @@ -292,7 +288,6 @@ level: high *** > [!important]+ Windows Server Version Differences -> `ris:Windows` > 1. **Server 2012 R2**: Print Spooler enabled by default; no specific mitigations > 2. **Server 2016**: Print Spooler enabled by default; Microsoft began recommending disabling Spooler on DCs > 3. **Server 2019**: Same as 2016; Print Spooler enabled by default but CIS Benchmarks recommend disabling on DCs diff --git a/src/content/sheets/active-directory/attack-43-printnightmare-cve-2021-34527.md b/src/content/sheets/active-directory/attack-43-printnightmare-cve-2021-34527.md @@ -18,7 +18,6 @@ source: "vault:ActiveDirectory/AD-Attack/Category-Five/🔵 Attack #43 — Print PrintNightmare is a **critical RCE vulnerability** in the Windows Print Spooler service that allows an authenticated user to execute arbitrary code as SYSTEM on any Windows machine with the Print Spooler running — including Domain Controllers. The vulnerability exists in the `RpcAddPrinterDriverEx` function, which doesn't properly validate the caller's permissions before loading a DLL. > [!info]+ Technical Deep-Dive — RpcAddPrinterDriverEx Privilege Bypass -> `ris:FileList` > 1. The [Windows Print Spooler](https://learn.microsoft.com/en-us/windows/win32/printdocs/print-spooler) exposes `RpcAddPrinterDriverEx` (MS-RPRN OpNum 89) to allow remote printer driver installation > 2. The function accepts a `DRIVER_INFO_2` structure containing the path to a DLL file — intended to be a legitimate printer driver > 3. **The vulnerability**: The function checks `SeLoadDriverPrivilege` but the check is **bypassable** — any authenticated user can call the function when `APD_INSTALL_WARNED_DRIVER` (0x8000) flag is set @@ -243,20 +242,17 @@ level: critical ### 🛡️ EDR-Specific Detections > [!warning]+ Microsoft Defender for Identity (MDI) / Defender for Endpoint -> `ris:Windows` > 1. **"Suspicious printer driver installation"** — detects `RpcAddPrinterDriverEx` calls from non-admin users > 2. **"Suspicious DLL loading by spoolsv.exe"** — behavioral detection for Print Spooler loading DLLs from SMB shares or temp directories > 3. Defender for Endpoint has specific PrintNightmare detections that trigger on both the LPE and RCE variants > 4. *Microsoft considers this a high-priority detection — Defender updates within 24 hours of CVE disclosure included signatures* > [!warning]+ CrowdStrike Falcon -> `ris:Radar` > 1. **"PrintNightmare Exploitation Detected"** — high-fidelity behavioral detection for RpcAddPrinterDriverEx exploitation > 2. **"Malicious DLL Loaded by Spooler Service"** — monitors spoolsv.exe DLL loading from non-standard paths > 3. Process tree analysis: `spoolsv.exe → cmd.exe` or `spoolsv.exe → rundll32.exe` = critical alert > [!warning]+ Elastic Security -> `ris:FileList` > 1. Rule: **"PrintNightmare — Suspicious DLL Loaded by Spooler"** — Sysmon Event 7 correlation > 2. Rule: **"Suspicious Child Process of Spooler Service"** — process creation monitoring > 3. Rule: **"Remote Printer Driver Installation"** — network-level detection for remote `RpcAddPrinterDriverEx` calls @@ -279,7 +275,6 @@ level: critical *** > [!important]+ Windows Server Version & Patch Timeline -> `ris:Windows` > 1. **June 2021 (KB5003637)**: CVE-2021-1675 patch — addresses LPE only; RCE still exploitable > 2. **July 2021 (KB5004945)**: Out-of-band emergency patch for CVE-2021-34527 — addresses RCE; but incomplete — researchers found bypasses > 3. **August 2021 (KB5005565)**: Additional hardening — `RestrictDriverInstallationToAdministrators` registry key; Point and Print restrictions diff --git a/src/content/sheets/active-directory/attack-44-nopac-sam-the-admin-cve-2021-42278-42287.md b/src/content/sheets/active-directory/attack-44-nopac-sam-the-admin-cve-2021-42278-42287.md @@ -23,7 +23,6 @@ noPAC (Sam-the-Admin) chains two CVEs to escalate from any domain user to Domain The attacker creates a machine account, renames it to match a DC's `sAMAccountName` (without `$`), requests a TGT, renames it back, then requests a service ticket — the KDC confuses the identity and issues a ticket with DC-level privileges. > [!info]+ Technical Deep-Dive — sAMAccountName Confusion & PAC Bypass -> `ris:FileList` > 1. **Step 1 — Machine Account Creation**: Any domain user can create machine accounts (up to `ms-DS-MachineAccountQuota`, default = 10). The attacker creates a machine account `NOPAC$` > 2. **Step 2 — sAMAccountName Rename** (CVE-2021-42278): The attacker renames `NOPAC$` to `DC01` (removing the `$` suffix). Normally, machine account sAMAccountNames MUST end with `$` — this CVE bypasses that validation > 3. **Step 3 — TGT Request**: The attacker requests a TGT as `DC01` using the machine account's known password. The KDC issues a TGT for `DC01` — the account currently named `DC01` @@ -274,20 +273,17 @@ level: high ### 🛡️ EDR-Specific Detections > [!warning]+ Microsoft Defender for Identity (MDI) -> `ris:Windows` > 1. **"Suspected noPac exploitation (CVE-2021-42278/42287)"** — specific detection for the sAMAccountName rename + TGT request pattern > 2. MDI correlates machine account creation → rename → TGT request → rename-back as a single attack sequence > 3. **"Suspicious machine account name change"** — fires on any machine account sAMAccountName modification that removes the `$` suffix > 4. *MDI added noPAC detection within weeks of the CVE disclosure — high-confidence alerting* > [!warning]+ CrowdStrike Falcon -> `ris:Radar` > 1. **"noPAC/Sam-the-Admin Exploitation"** — behavioral detection for the machine account creation → rename → Kerberos abuse chain > 2. Falcon detects automated exploitation tools (noPac.py, sam-the-admin) via process and network behavioral analysis > 3. Also detects the Kerberos ticket manipulation (S4U2Self with confused identity) > [!warning]+ Elastic Security -> `ris:FileList` > 1. Rule: **"Machine Account sAMAccountName Changed"** — Event 4742 correlation for sAMAccountName attribute modifications > 2. Rule: **"TGT Requested for Account Matching Domain Controller Name"** — Event 4768 correlation > 3. Rule: **"Rapid Machine Account Create-Rename-Delete Pattern"** — temporal correlation of Events 4741→4742→4743 @@ -310,7 +306,6 @@ level: high *** > [!important]+ Windows Server Version & Patch Timeline -> `ris:Windows` > 1. **November 2021 (KB5008102/KB5008380)**: Initial patch released — fixes both CVE-2021-42278 and CVE-2021-42287 > 2. **April 2022**: Enforcement phase — KDC rejects tickets without proper PAC validation > 3. **July 2022**: Full enforcement — PAC validation required; non-patched clients may experience authentication failures diff --git a/src/content/sheets/cryptography/gpg.md b/src/content/sheets/cryptography/gpg.md @@ -11,17 +11,13 @@ source: "vault:Cryptography/GPG - Cheatsheet markdown.md" # GPG -```dataviewjs -await dv.view("00Meta/Views/NoteBanner"); -``` --- -> **Note —** + `> ABOUT_THIS_NOTE` +> **Note —** > Advanced, copy-ready [GnuPG](https://www.gnupg.org/) reference for local key management, signing, encryption, verification, and automation. Examples favour full fingerprints, explicit signing identities, and deliberate recipient lists. Commands were checked against the installed **GnuPG 2.5.21** client. -> **Note —** + `> SAFETY_BOUNDARY` -> `ris:ShieldCheck` +> **Note —** > 1. A fingerprint identifies a key; it is safe to share after independent verification. A private key, passphrase, decrypted data, and private-key backup are not. > 2. Never delete a secret key before an encrypted offline backup and revocation certificate exist. > 3. Keyservers are effectively append-only. Revoking a compromised published key is possible; reliably removing it from all keyservers is not. @@ -43,7 +39,6 @@ gpg --list-keys --keyid-format LONG --with-fingerprint ``` > **Note —** + Why fingerprints matter `fas:Lightbulb` -> `ris:LockPassword` > A short key ID is not a unique trust anchor. Verify a full fingerprint through an independent channel, then use that fingerprint with `--local-user` (`-u`) and `--recipient` (`-r`). ### 2. Sign with a non-default private key @@ -62,8 +57,7 @@ gpg --local-user "$YOUR_FPR" --sign file.pdf gpg --local-user "$YOUR_FPR" --clearsign message.txt ``` -> **Note —** + Signing selection `ris:FileList` -> `ris:Command` +> **Note —** + Signing selection > 1. `--local-user` / `-u` chooses the signing identity and overrides `default-key`. > 2. `--detach-sign` keeps the original file unchanged and is the normal choice for software artifacts. > 3. `--armor` produces portable text output; omit it for compact binary output. @@ -114,12 +108,12 @@ gpg --verify signed-file.gpg gpg --output decrypted-file.pdf --decrypt file.pdf.gpg ``` -> **Note —** + What a successful verification proves `ris:CheckboxCircle` +> **Note —** + What a successful verification proves > A good signature proves that a matching private key signed the bytes you verified. It does **not** establish a real-world identity until you have independently verified the signing key’s fingerprint and trust context. --- -## // DEFAULT_KEY_&_RECIPIENT_CONTROL `ris:LockPassword` +## // DEFAULT_KEY_&_RECIPIENT_CONTROL ### 1. Understand the four settings @@ -207,7 +201,7 @@ fi unset TEST_GNUPGHOME ``` -> **Note —** + Automation rules `ris:Radar` +> **Note —** + Automation rules > Use `--batch`, `--status-fd`, and `--with-colons` for scripts. Do not feed passphrases on the command line; use a controlled pinentry, agent, or a carefully designed file descriptor workflow instead. --- diff --git a/src/content/sheets/linux-it/rdp.md b/src/content/sheets/linux-it/rdp.md @@ -20,8 +20,7 @@ export DOMAIN='DOMAIN' export USER='username' ``` -> [!tip]+ Secure baseline `ris:ShieldCheck` -> `ris:Command` +> [!tip]+ Secure baseline > 1. `/from-stdin:force` prompts before connecting, keeping the password out of shell history and process arguments. > 2. `/cert:tofu` trusts a certificate on the first connection, then rejects an unexpected change. > 3. `+dynamic-resolution` keeps the session usable when the client window is resized. @@ -33,7 +32,7 @@ export USER='username' --- -## // CONNECTION_&_AUTHENTICATION `ris:LockPassword` +## // CONNECTION_&_AUTHENTICATION ### 1. Identity formats @@ -70,8 +69,7 @@ kinit 'user@DOMAIN.EXAMPLE' "$RDP" /v:"$TARGET" /smartcard-logon /sec:nla /cert:tofu ``` -> [!info]+ Authentication notes `ris:FileList` -> `ris:LockPassword` +> [!info]+ Authentication notes > 1. `/sec:nla` explicitly requires Network Level Authentication and disables weaker alternatives. > 2. Kerberos depends on DNS, realm configuration, and clock alignment; inspect the ticket with `klist` before troubleshooting RDP itself. > 3. Smart-card logon activates the local reader; it is distinct from `/smartcard`, which redirects a smart card into an already authenticated remote session. @@ -89,7 +87,7 @@ export NT_HASH='0123456789ABCDEF0123456789ABCDEF' --- -## // TRANSPORT_&_CERTIFICATE_SECURITY `ris:ShieldCheck` +## // TRANSPORT_&_CERTIFICATE_SECURITY | Goal | Option | When to use it | |---|---|---| @@ -115,7 +113,7 @@ export NT_HASH='0123456789ABCDEF0123456789ABCDEF' --- -## // DISPLAY_&_PERFORMANCE `ris:Global` +## // DISPLAY_&_PERFORMANCE ### 1. Display and window controls @@ -160,7 +158,7 @@ export NT_HASH='0123456789ABCDEF0123456789ABCDEF' --- -## // LOCAL_RESOURCE_REDIRECTION `ris:ShareBox` +## // LOCAL_RESOURCE_REDIRECTION ### 1. Clipboard and drives @@ -199,7 +197,7 @@ export NT_HASH='0123456789ABCDEF0123456789ABCDEF' --- -## // GATEWAYS_PROXY_&_REMOTEAPP `ris:GlobalLine` +## // GATEWAYS_PROXY_&_REMOTEAPP ```bash # RD Gateway; omit /p: values so FreeRDP prompts for required credentials @@ -225,12 +223,12 @@ export https_proxy='http://proxy.example.com:3128' /app:program:'||notepad',name:'Notepad' ``` -> [!info]+ Gateway credentials `ris:LockPassword` +> [!info]+ Gateway credentials > A gateway can use credentials different from the target. Keep gateway passwords out of the command line too; FreeRDP prompts when the relevant `/p:` value is omitted. --- -## // SESSION_CONTROL_&_TROUBLESHOOTING `ris:Command` +## // SESSION_CONTROL_&_TROUBLESHOOTING | Symptom or task | Command / response | |---|---| @@ -278,7 +276,7 @@ sdl-freerdp /version xfreerdp /version ``` -> [!success]+ macOS client choice `ris:CheckboxCircle` +> [!success]+ macOS client choice > Use `sdl-freerdp` by default on macOS. The Homebrew formula builds the SDL client, while its `xfreerdp` client requires a running X11 server and otherwise produces a `$DISPLAY` error. --- diff --git a/src/content/sheets/pentest-workflow/alternate-data-streams-guide.md b/src/content/sheets/pentest-workflow/alternate-data-streams-guide.md @@ -13,7 +13,7 @@ source: "vault:NTFS ADS tradecraft" [← Windows PrivEsc cheat sheet](/sheets/pentest-workflow/privilege-escalation) · [Workflow dashboard](/sheets/pentest-workflow/attack-flow-dashboard) · [Windows PrivEsc master guide](/sheets/privilege-escalation/windows-privesc) · [← Potato Attacks guide](/sheets/pentest-workflow/potato-attacks-guide) -# NTFS Alternate Data Streams — Hiding & Finding Hidden Data `ris:FileList` +# NTFS Alternate Data Streams — Hiding & Finding Hidden Data > [!dashboard] What this is > NTFS Alternate Data Streams (ADS) let a file carry extra content that a normal directory listing never shows. On offense, that's a place to stage a payload off a directory listing and strip Mark-of-the-Web before you run it — a trick usually paired with the [Potato Attacks guide](/sheets/pentest-workflow/potato-attacks-guide) once you've got a privileged shell. On the other side of the same coin, it's where CTF flags, credentials, and second-stage tooling get hidden, and where a downloaded file's origin gets recorded — so knowing how to *find* a stream matters as much as knowing how to hide one. They're a legitimate NTFS feature, quietly used (and abused) for both since Windows NT. diff --git a/src/content/sheets/pentest-workflow/attack-flow-guide.md b/src/content/sheets/pentest-workflow/attack-flow-guide.md @@ -26,7 +26,7 @@ source: "vault:Pentest Attack Flow/Companion Guides/Attack-Flow-Guide.md" ## // THE_GOLDEN_RULES -> [!tip]+ `> MINDSET` +> [!tip] > 1. **Enumerate, don't guess.** Every box rewarded reading the loot (PDFs, notes, README, git history, images) over exploit-hunting. > 2. **New identity = restart enumeration.** Cracked a hash / reset a password / read a cred? Re-run BloodHound *as that principal*, re-spray it across SMB+WinRM, re-check ADCS. Boxes chain 4-7 identities. > 3. **Clock skew kills Kerberos** → `sudo ntpdate -u $DC` before every Kerberos/certipy step. diff --git a/src/content/sheets/pentest-workflow/attacking-common-services-guide.md b/src/content/sheets/pentest-workflow/attacking-common-services-guide.md @@ -117,7 +117,7 @@ export WEBKIT_FORCE_SANDBOX=0 && evolution # if it dies with a bwrap sandbox e --- -## 2 · The concept of attacks `ris:FileList` +## 2 · The concept of attacks Rather than memorising per-protocol exploits in isolation, decompose any vulnerability into four categories. The same cycle reappears for CoreFTP, SMBGhost, BlueKeep, subdomain takeover, and the OpenSMTPD RCE — once you can place a technique in this frame, spotting the analogue on a service you've never touched gets much faster. @@ -162,7 +162,7 @@ OWASP's **A05:2021 – Security Misconfiguration** doubles as an offensive check --- -## 4 · Finding sensitive information `ris:FileList` +## 4 · Finding sensitive information Attacking common services is detective work: a single, apparently insignificant thing found on one service is frequently the key to a completely different one. The canonical worked chain from the module makes the point — an *empty file* is the whole foothold: diff --git a/src/content/sheets/pentest-workflow/most-used-commands.md b/src/content/sheets/pentest-workflow/most-used-commands.md @@ -54,7 +54,7 @@ The order I actually work a box. Windows/AD path is the spine, web/Linux detours </div> </figure> -> [!tip]+ `> THE_LOOP` (what to do first, then again) +> [!tip] (what to do first, then again) > 1. **Every time you get new creds or a new hash** → re-run BloodHound as that principal, re-spray across SMB/WinRM, and re-check ADCS with certipy. New identity = new outbound control. > 2. **Every shell** → run the "First 5 Commands" for the OS immediately (`whoami /all` / `sudo -l`). > 3. **Kerberos error?** → 99% clock skew. Re-run `ntpdate`. See Phase 0. @@ -91,7 +91,7 @@ Quick map of the CPTS-prep list to the primary skill each one drills (so I know ## // PHASE_0 — SETUP (do this first, every AD box) -> [!warning]+ `> CLOCK_SKEW` — the #1 Kerberos killer +> [!warning] — the #1 Kerberos killer > Kerberos rejects auth if your clock differs from the DC by more than ~5 min. Sync **before** any Kerberos/certipy/getTGT step, and again if a box's time drifts. > ```bash > sudo ntpdate -u $TARGET # classic, quickest @@ -341,7 +341,7 @@ cat hosts | sudo tee -a /etc/hosts+ ## // CRACKING -> [!example]+ `> HASHCAT_MODES` +> [!example] > | Hash | Mode | Command | > |---|---|---| > | NetNTLMv2 (Responder) | 5600 | `hashcat -m 5600 hash rockyou.txt` | @@ -681,7 +681,7 @@ cat hosts | sudo tee -a /etc/hosts+ ## // REFERENCES -> [!info]+ `> WRITEUP_SOURCES` (used to build the workflow) +> [!info] (used to build the workflow) > - Fluffy, TombWatcher, Redelegate, VulnCicada, Media, Pov, Snoopy, Authority, StreamIO — [0xdf](https://0xdf.gitlab.io/) > - [Certipy Wiki — ESC techniques](https://github.com/ly4k/Certipy/wiki) > - [The Hacker Recipes — AD](https://www.thehacker.recipes/) diff --git a/src/content/sheets/pentest-workflow/network-service-attack-manual.md b/src/content/sheets/pentest-workflow/network-service-attack-manual.md @@ -80,7 +80,7 @@ sudo nmap -Pn -n -sU -sV -p53 -oA "$EVIDENCE/udp-services" "$IP" > [!tip] Interpret the whole response > A certificate subject can disclose a host or domain. An NTLM challenge can disclose the NetBIOS domain. An SMTP banner may name the mail product. SMB signing status determines whether an NTLM relay path is plausible. Save those details before authentication changes what the service returns. -## 2 · Model the attack path `ris:FileList` +## 2 · Model the attack path The source module uses four questions for any vulnerability. This guide renames them as an operator worksheet: @@ -199,7 +199,7 @@ On Windows, use `sqlcmd` for MSSQL and `mysql.exe` for MySQL. DBeaver is useful Once credentials work, an IMAP-capable client such as Evolution can search headers, bodies, and attachments more reliably than a raw socket session. Record server, port, TLS mode, and authentication method. Avoid synchronising an entire mailbox when a scoped server-side search will answer the question. -## 4 · Test configuration before exploits `ris:FileList` +## 4 · Test configuration before exploits The same four configuration failures recur across all of these protocols: @@ -1031,7 +1031,7 @@ The fastest path through a multi-service host is a state machine. Each new ident Do not import flags or dynamic lab credentials into the cheatsheet. The learning objective is the chain and its evidence, not a static answer from one spawned target. -## 13 · Failure analysis `ris:BugLine` +## 13 · Failure analysis | Symptom | Likely cause | Check | |---|---|---| @@ -1046,7 +1046,7 @@ Do not import flags or dynamic lab credentials into the cheatsheet. The learning | AXFR fails against one server | transfer policy differs per NS | test each authoritative nameserver | | FTP transfer corrupts an archive | ASCII transfer mode | repeat in `binary` mode and compare hashes | -## 14 · Proof, cleanup, and reporting `ris:FileList` +## 14 · Proof, cleanup, and reporting ### Minimal proof ladder @@ -1102,7 +1102,7 @@ Write each finding around the complete path: | Open relay | `nmap -p25 --script smtp-open-relay $IP` | | NetNTLMv2 crack | `hashcat -m 5600 capture.txt wordlist.txt` | -## 16 · CVE and condition index `ris:GlobalLine` +## 16 · CVE and condition index | Issue | Service | Required condition | Safe validation stance | |---|---|---|---| diff --git a/src/content/sheets/tools/eyewitness.md b/src/content/sheets/tools/eyewitness.md @@ -38,7 +38,7 @@ Related notes: Nuclei-Cheatsheet · Ffuf-Cheatsheet · webfuzz · NetExec-Cheats --- -## Summary `ris:Eye` +## Summary [EyeWitness](https://github.com/RedSiege/EyeWitness) takes screenshots of HTTP(S) targets, records response headers/source, and attempts to flag known default credentials. It is useful after host/URL discovery (nmap, httpx, masscan) when you need a visual triage of large web attack surfaces. Modern builds use **Chromium/Chrome + Selenium**, install into an isolated **Python venv**, and support text URL lists, Nmap/Nessus XML, single-URL mode, and resume via SQLite (`ew.db`). @@ -50,7 +50,7 @@ Related notes: Nuclei-Cheatsheet · Ffuf-Cheatsheet · webfuzz · NetExec-Cheats --- -## Project Status & Alternatives `ris:Radar` +## Project Status & Alternatives | Tool | Status (as of 2026) | Notes | |---|---|---| @@ -106,7 +106,6 @@ Related notes: Nuclei-Cheatsheet · Ffuf-Cheatsheet · webfuzz · NetExec-Cheats ## Installation `fas:Screwdriver` > **Note —** + [EyeWitness](https://github.com/RedSiege/EyeWitness) Overview -> `ris:GlobalLine` > Chromium-based HTTP screenshot and reporting tool with default-credential categorisation. > 1. Accepts URL lists and Nmap/Nessus XML. > 2. Isolates Python deps in `eyewitness-venv/`. @@ -129,7 +128,6 @@ python Python/EyeWitness.py --single https://example.com ``` > **Note —** + Install Breakdown -> `ris:FileList` > 1. **setup.sh / setup.ps1**: creates `eyewitness-venv/`, installs Selenium stack, pulls Chromium/ChromeDriver. > 2. **Always activate the venv** — running system Python will miss deps / hit PEP 668 errors. > 3. **Docker**: still marked “in development” upstream — prefer native install for labs. @@ -137,7 +135,7 @@ python Python/EyeWitness.py --single https://example.com --- -## Basic Usage `ris:Command` +## Basic Usage ```bash source eyewitness-venv/bin/activate @@ -153,7 +151,6 @@ python Python/EyeWitness.py --web -x nmap_http.xml -d ./ew-nmap --threads 8 --ti ``` > **Note —** + Command Breakdown -> `ris:FileList` > 1. **--web**: Selenium HTTP screenshot engine (required action). > 2. **-f / -x / --single**: mutually exclusive-style inputs — provide at least one. > 3. **-d**: fixed output path; omit to get a timestamped folder in CWD. @@ -161,7 +158,7 @@ python Python/EyeWitness.py --web -x nmap_http.xml -d ./ew-nmap --threads 8 --ti --- -## Input Formats `ris:FileList` +## Input Formats ```bash # urls.txt — one URL or host per line @@ -185,7 +182,7 @@ python Python/EyeWitness.py -f urls.txt --validate-urls -d ./ew-validate --- -## Timing, Proxy & Browser Options `ris:Global` +## Timing, Proxy & Browser Options ```bash python Python/EyeWitness.py --web -f urls.txt -d ./ew-slow \ @@ -197,7 +194,6 @@ python Python/EyeWitness.py --web -f urls.txt -d ./ew-slow \ ``` > **Note —** + Tuning Breakdown -> `ris:FileList` > 1. **--threads**: lower on low-RAM boxes; EyeWitness may auto-reduce based on memory. > 2. **--timeout / --max-retries**: slow lab links and flaky VPN paths. > 3. **--proxy-***: send browser traffic through Burp (`http`) or SOCKS. @@ -241,7 +237,7 @@ Example config keys (from upstream README): --- -## Output Layout `ris:FileList` +## Output Layout | Path | Contents | |---|---| @@ -255,7 +251,7 @@ Categories commonly include High Value, CMS, network devices, etc., plus default --- -## Practical Recipes `ris:Command` +## Practical Recipes ```bash # 1) httpx live hosts → EyeWitness diff --git a/src/content/sheets/tools/internet-archival-guide.md b/src/content/sheets/tools/internet-archival-guide.md @@ -132,7 +132,6 @@ ffmpeg -hwaccel auto -i YOUR_INPUT_FILE.anything \ ``` > [!info]+ CRF Quality Guide -> `ris:FileList` > 1. **CRF 18** = near-lossless — use for archival masters > 2. **CRF 22** = good quality — default for most archiving > 3. **CRF 28** = smaller file, visible quality loss — throwaway clips only @@ -193,7 +192,7 @@ ffmpeg -i input.mp4 -i metadata.txt -map_metadata 1 -c copy output.mp4 --- -### Online Video Archiving (No Command Line) `ris:GlobalLine` +### Online Video Archiving (No Command Line) | Tool | URL | Notes | |---|---|---| @@ -207,7 +206,7 @@ ffmpeg -i input.mp4 -i metadata.txt -map_metadata 1 -c copy output.mp4 --- -## Part 3 — Screenshots & Full-Page Captures `ris:Eye` +## Part 3 — Screenshots & Full-Page Captures ### Platform Quick Reference @@ -241,12 +240,11 @@ ffmpeg -i input.mp4 -i metadata.txt -map_metadata 1 -c copy output.mp4 --- -## Part 4 — Platform-Specific Archiving `ris:Radar` +## Part 4 — Platform-Specific Archiving ### Twitter / X > [!warning]+ Twitter/X requires login for most content — breaks most archivers -> `ris:Radar` > Methods in order of reliability: > 1. **Nitter mirror → archive.today**: Replace `twitter.com`/`x.com` with `nitter.poast.org`, feed to archive.ph > 2. **GhostArchive** directly on x.com URL — works intermittently @@ -264,7 +262,6 @@ ffmpeg -i input.mp4 -i metadata.txt -map_metadata 1 -c copy output.mp4 ### Reddit > [!info]+ Reddit Archiving -> `ris:FileList` > 1. Always use **old.reddit.com** URLs — `reddit.com` → `old.reddit.com`. archive.today handles old Reddit layout far better. > 2. **Unddit** for deleted posts/comments: replace `reddit.com` with `unddit.com` in any URL → [unddit.com](https://unddit.com) > 3. **Full user post history**: use PRAW (Python Reddit API Wrapper) to iterate profile pages and submit each to archive.today. *See `scripts/reddit_archive_user.py`.* @@ -274,7 +271,6 @@ ffmpeg -i input.mp4 -i metadata.txt -map_metadata 1 -c copy output.mp4 ### Discord > [!info]+ [DiscordChatExporter](https://github.com/Tyrrrz/DiscordChatExporter) — Standard Discord archiving tool -> `ris:ShareBox` > Exports Discord servers, channels, and DMs to HTML (with images), JSON, CSV, or TXT. GUI + CLI versions. > 1. Requires your Discord auth token (browser DevTools → Network tab → Authorization header) > 2. GUI version is straightforward; CLI supports bulk and automated export @@ -285,7 +281,6 @@ DiscordChatExporter.Cli exportguild --guild SERVERID --token YOUR_TOKEN --output ``` > [!warning]+ Discord CDN URLs Expire -> `ris:Radar` > `cdn.discordapp.com` image URLs are publicly accessible without login, but Discord periodically rotates/expires them. Archive immediately after finding them. --- @@ -293,7 +288,6 @@ DiscordChatExporter.Cli exportguild --guild SERVERID --token YOUR_TOKEN --output ### Instagram > [!info]+ Instagram Archiving Methods -> `ris:GlobalLine` > Instagram requires login for most content. Working methods: > 1. **View profiles without account**: [picuki.com](https://picuki.com), [imgsed.com](https://imgsed.com), [dumpor.com](https://dumpor.com) → then feed URL to archive.today > 2. **Download posts/reels**: [Instaloader](https://instaloader.github.io) (`instaloader profile USERNAME`), JDownloader, [SnapInsta](https://snapinsta.app), [igram.io](https://igram.io) @@ -314,7 +308,6 @@ yt-dlp https://www.tiktok.com/@user/video/VIDEOID ``` > [!warning]+ yt-dlp profile scraping is broken for TikTok -> `ris:Radar` > Individual videos still work. For profile-level scraping, use [Geranium's scraper-helper](https://github.com/GeraniumKF/scraper-helper) or [Cobalt](https://cobalt.tools). --- @@ -338,7 +331,6 @@ yt-dlp --ignore-errors --continue \ > [Filmot](https://filmot.com) indexes YouTube subtitle data including from removed videos. Search by keywords to find videos no longer publicly visible — extremely useful for tracking deleted content. > [!info]+ YouTube Comment Archiving -> `ris:FileList` > No third-party site currently preserves full comment sections. Use the [YouTube Data API v3](https://developers.google.com/youtube/v3) (free API key) to download all comments from a video programmatically. *See `scripts/youtube_comment_archiver.py`.* --- @@ -346,7 +338,6 @@ yt-dlp --ignore-errors --continue \ ### Other Platforms > [!info]+ Platform Reference Table -> `ris:FileList` > > | Platform | Tool / Method | > |---|---| @@ -384,7 +375,6 @@ yt-dlp --ignore-errors --continue \ > ``` > [!info]+ [Bellingcat Auto Archiver](https://github.com/bellingcat/auto-archiver) -> `ris:Radar` > Professional-grade automated archiving. Takes URLs from spreadsheets, Telegram, or other sources and archives to archive.org, Google Drive, S3, etc. with verification metadata. Used by journalists and OSINT researchers. > [!info]+ Archiving Entire Wikis and Forums @@ -410,7 +400,7 @@ yt-dlp --ignore-errors --continue \ --- -## Part 6 — OSINT & Account Finding `ris:Radar` +## Part 6 — OSINT & Account Finding | Tool | URL | Use For | |---|---|---| @@ -430,7 +420,7 @@ python3 -m maigret username --- -## Part 7 — File Hosting for Large Files `ris:ShareBox` +## Part 7 — File Hosting for Large Files > [!tip]+ File Hosting Priority Order > `fas:Lightbulb` @@ -443,7 +433,7 @@ python3 -m maigret username --- -## Part 8 — Un-Redacting & Recovering Obscured Content `ris:Eye` +## Part 8 — Un-Redacting & Recovering Obscured Content ### Recovering Poorly Redacted Text @@ -455,7 +445,7 @@ python3 -m maigret username > 3. Try **Contrast** at maximum > 4. If the black bar is a separate layer (common in quick edits), select and delete the layer -### Recovering Deleted Content `ris:Radar` +### Recovering Deleted Content | Method | Where to Look | |---|---| @@ -467,7 +457,7 @@ python3 -m maigret username --- -## Part 9 — Expanded: Cookie Extraction for Archiving `ris:LockPassword` +## Part 9 — Expanded: Cookie Extraction for Archiving Many archiving tasks require authenticated sessions. The cleanest method is exporting cookies from your browser. @@ -489,14 +479,13 @@ Many archiving tasks require authenticated sessions. The cleanest method is expo > 4. Use with: `yt-dlp --cookies cookies.txt URL` > [!warning]+ Cookie Security -> `ris:Radar` > 1. Never share your cookies.txt file — it grants full session access to your accounts > 2. Delete exported cookie files after use > 3. Use throwaway accounts for archiving sensitive content --- -## Part 10 — Expanded: VTT Subtitle Processing `ris:FileList` +## Part 10 — Expanded: VTT Subtitle Processing Auto-generated subtitles from yt-dlp are invaluable for searching long videos and streams. diff --git a/src/content/sheets/tools/webfuzz.md b/src/content/sheets/tools/webfuzz.md @@ -24,14 +24,13 @@ webfuzz -h # sanity check ``` > [!warning]+ Vault-mounted caveat -> `ris:Radar` > 1. The tool lives on the Cryptomator vault, so the symlink only resolves while that vault is **mounted**. > 2. To use it even when the vault is locked, copy the `webfuzz/` folder to somewhere permanent (e.g. `~/tools/webfuzz`) and repoint the symlink there. > 3. *The script resolves its own real path, so a symlink still finds its bundled wordlists.* --- -## Modes overview `ris:Command` +## Modes overview | Mode | Fuzzes | Minimal command | |---|---|---| @@ -48,7 +47,7 @@ webfuzz -h # sanity check --- -## Content discovery `ris:ShareBox` +## Content discovery ```bash # Directories: URL/FUZZ @@ -68,13 +67,12 @@ webfuzz dir -u http://10.10.10.10/ -e .php,.txt,.html -R --depth 2 ``` > [!info]+ ffuf equivalent -> `ris:Command` > `webfuzz dir -u http://t/` becomes > `ffuf -w <list>:FUZZ -u http://t/FUZZ -ic -c` (plus an auto `-fs` only if the server soft-404s). --- -## Sub-domains and VHosts `ris:GlobalLine` +## Sub-domains and VHosts ```bash # Public sub-domains via real DNS (note: public academy example uses https) @@ -88,7 +86,6 @@ webfuzz vhost -u http://10.129.203.101/ -d inlanefreight.local -w namelist.txt ``` > [!example]+ What the vhost auto-`-fs` replaces -> `ris:Scan2` > The raw command you used to type: > ```bash > ffuf -w namelist.txt:FUZZ -u http://10.129.203.101/ -H 'Host:FUZZ.inlanefreight.local' -fs 15157 @@ -97,7 +94,7 @@ webfuzz vhost -u http://10.129.203.101/ -d inlanefreight.local -w namelist.txt --- -## Parameter and value fuzzing `ris:LockPassword` +## Parameter and value fuzzing ```bash # GET parameter NAME: /admin/admin.php?FUZZ=key @@ -114,7 +111,6 @@ webfuzz value -u http://t/a.php -p user --method GET -w /path/users.txt ``` > [!info]+ Command Breakdown -> `ris:FileList` > 1. **`--value`** (getparam/postparam) sets the placeholder value sent with each fuzzed name; default is `key`. > 2. **`-p / --param`** (value mode) is the fixed parameter name whose value you are brute-forcing. > 3. **`--range A-B`** writes a numeric wordlist `A..B` to `webfuzz-out/` and uses it — the classic `for i in $(seq 1 1000)` trick, built in. @@ -122,7 +118,7 @@ webfuzz value -u http://t/a.php -p user --method GET -w /path/users.txt --- -## PHP-filter base64 LFI (the Dante trick) `ris:KnifeBlood` +## PHP-filter base64 LFI (the Dante trick) ```bash # One command: wrap, match PHP source, then auto curl + base64 -d every hit @@ -130,14 +126,12 @@ webfuzz lfi -u 'http://172.16.1.10/nav.php?page=FUZZ' --resource /var/www/html/w ``` > [!success]+ What this automates -> `ris:Key` > 1. Rewrites `FUZZ` into `php://filter/read=convert.base64-encode/resource=/var/www/html/wordpress/FUZZ`. > 2. Adds `-mc all -mr PD9waH -fs 0` — `PD9waH` is base64 for `<?ph`, so only **real PHP source** matches and empty responses are dropped. > 3. For every hit it `curl`s the URL, base64-decodes it, and saves the source to `webfuzz-out/decoded/`. > 4. Scans the decoded files and prints any **URLs** and **DB creds / secrets** — i.e. the URL you are hunting for pops out on its own. > [!example]+ The raw commands it replaces (straight from the Dante notes) -> `ris:Command` > ```bash > ffuf -w raft-medium-files.txt:FUZZ \ > -u "http://172.16.1.10/nav.php?page=php://filter/read=convert.base64-encode/resource=/var/www/html/wordpress/FUZZ" \ @@ -180,7 +174,6 @@ webfuzz lfi -u 'http://t/nav.php?page=FUZZ' --resource /var/www/ --no-decode | `-v` | verbose (full URLs) · `--no-color` plain output | > [!info]+ Output -> `ris:FileList` > 1. Live ffuf output plus a clean hit summary. > 2. Machine-readable results at `webfuzz-out/<mode>-<timestamp>.json`. > 3. LFI loot (decoded source) at `webfuzz-out/decoded/`. @@ -214,7 +207,7 @@ webfuzz value -u http://admin.academy.htb:PORT/admin/admin.php -p id --range 1-1 --- -## Try it offline (no target) `ris:Global` +## Try it offline (no target) ```bash cd /Volumes/bmdrbeKUVgvV/Cybersecurity/Code/webfuzz/.selftest diff --git a/src/content/sheets/web/blind-xss-tool-ezxss.md b/src/content/sheets/web/blind-xss-tool-ezxss.md @@ -10,7 +10,7 @@ source: "vault:Web/Blind XSS Tool - ezXSS.md" --- # Blind XSS Tool — ezXSS `fas:ClipboardList` -## Summary `ris:Eye` +## Summary [ezXSS](https://github.com/ssl/ezXSS) is a self-hosted blind-XSS platform for generating probes, receiving browser reports, managing notifications, and controlling how evidence is stored. Its Docker deployment can configure the database and obtain a TLS certificate automatically. For HTB use, keep public registration disabled, allowlist only the active lab domains, minimise collected data, and leave persistent-session features disabled unless a specific authorised lab objective requires them. @@ -23,7 +23,7 @@ source: "vault:Web/Blind XSS Tool - ezXSS.md" --- -## Conceptual Information `ris:GlobalLine` +## Conceptual Information ### When to Use ezXSS @@ -52,7 +52,7 @@ source: "vault:Web/Blind XSS Tool - ezXSS.md" --- -## Prerequisites `ris:FileList` +## Prerequisites | Requirement | Recommendation | Check | |---|---|---| @@ -74,7 +74,7 @@ source: "vault:Web/Blind XSS Tool - ezXSS.md" --- -## Commands and Implementation `ris:Command` +## Commands and Implementation ### 1. Preflight the Host @@ -87,7 +87,6 @@ docker compose version ``` > [!info]+ Preflight Breakdown -> `ris:Radar` > 1. DNS should match the VPS public address. > 2. Ports `80` and `443` should be available unless an intentional reverse proxy owns them. > 3. Docker and Compose must both respond before cloning ezXSS. @@ -102,7 +101,6 @@ docker compose config --services ``` > [!info]+ Command Breakdown -> `ris:Command` > 1. **Official repository**: The project installation wiki uses `ssl/ezXSS`. > 2. **Clean baseline**: Record local changes before updates. > 3. **Compose validation**: Prints the service names and detects obvious configuration problems. @@ -128,7 +126,6 @@ useMailAlerts=false ``` > [!info]+ Environment Breakdown -> `ris:LockPassword` > 1. **`dbPassword`**: Replace the example with a unique random password; never commit `.env`. > 2. **`autoInstallCertificate=true`**: Enables the Docker certificate workflow when DNS and ports are ready. > 3. **`domain`**: Must match the public hostname used by payloads and TLS. @@ -170,7 +167,6 @@ docker compose logs --tail=150 7. Leave custom JavaScript, automatic spidering, and persistent mode disabled. > [!success]+ Expected Result -> `ris:Key` > 1. `/manage/install` is no longer exposed after successful setup. > 2. The management panel requires the new administrator credentials. > 3. A self-test callback from an isolated page appears in the reports view. @@ -227,7 +223,6 @@ For a confirmed double-quoted attribute context: | Local/session storage | Browser-side application data | Collect only when the lab objective requires it | > [!success]+ Evidence Handling -> `ris:Key` > 1. Correlate the report to its payload name, field, account, and time. > 2. Export only the minimum evidence needed for the HTB write-up. > 3. Remove stored lab payloads where the application permits. @@ -261,7 +256,7 @@ For a confirmed double-quoted attribute context: --- -## Operations and Lifecycle `ris:FileList` +## Operations and Lifecycle ### Logs and Health @@ -272,7 +267,6 @@ docker stats --no-stream ``` > [!info]+ Operational Checks -> `ris:FileList` > 1. Inspect all services first, then add a service name to narrow the logs. > 2. Watch disk and database growth when screenshots, DOM, or duplicate reports are enabled. > 3. Disable unused notifications and advanced features rather than leaving failing integrations active. @@ -308,7 +302,6 @@ docker compose logs --tail=100 ``` > [!info]+ Update Breakdown -> `ris:Command` > 1. Back up the database and `.env` first. > 2. Review release notes and `.env.example` changes before restarting. > 3. Re-run a self-test probe after the upgrade. @@ -335,7 +328,7 @@ docker compose down --volumes --- -## Troubleshooting `ris:FileList` +## Troubleshooting > [!failure]+ “You did not setup your config file yet” > `fas:CircleXmark` diff --git a/src/content/sheets/web/blind-xss-tool-interactsh.md b/src/content/sheets/web/blind-xss-tool-interactsh.md @@ -10,7 +10,7 @@ source: "vault:Web/Blind XSS Tool - Interactsh.md" --- # Blind XSS Tool — Interactsh `fas:ClipboardList` -## Summary `ris:Eye` +## Summary [Interactsh](https://github.com/projectdiscovery/interactsh) generates unique out-of-band interaction domains and reports DNS, HTTP, SMTP, LDAP, and other callbacks. For blind XSS, it is a fast way to determine whether an unseen browser resolved or requested a unique address. It is lighter than XSS Hunter or ezXSS, but it does not automatically provide the same screenshots, DOM captures, or browser-specific evidence. @@ -23,7 +23,7 @@ source: "vault:Web/Blind XSS Tool - Interactsh.md" --- -## Conceptual Information `ris:GlobalLine` +## Conceptual Information ### What Interactsh Proves @@ -45,7 +45,6 @@ source: "vault:Web/Blind XSS Tool - Interactsh.md" | Raw callback visible over the HTB VPN | Python HTTP server or Netcat from the main XSS note | > [!info]+ Correlation Model -> `ris:FileList` > 1. The client generates a unique domain containing a correlation identifier and nonce. > 2. The server records interactions for that identifier. > 3. The client polls and decrypts or displays matching events. @@ -56,7 +55,6 @@ source: "vault:Web/Blind XSS Tool - Interactsh.md" ## Tools Overview `fas:Screwdriver` > [!info]+ [Interactsh Web Client](https://app.interactsh.com) Overview -> `ris:GlobalLine` > 1. Browser-based dashboard with no local installation. > 2. Stores session state in browser storage. > 3. Best for a quick, non-sensitive HTB callback test. @@ -68,14 +66,13 @@ source: "vault:Web/Blind XSS Tool - Interactsh.md" > 3. Best for reproducible lab notes and long-running polling. > [!info]+ Interactsh Server Overview -> `ris:Radar` > 1. Self-hosted DNS and application-protocol interaction collector. > 2. Requires a dedicated domain, nameserver delegation, a public server, and careful exposure controls. > 3. Best when public shared infrastructure is unsuitable or unreliable. --- -## Commands and Implementation `ris:Command` +## Commands and Implementation ### 1. Hosted Web Client — Fastest Start @@ -117,7 +114,6 @@ UNIQUE_CORRELATION_ID.oast.example ``` > [!info]+ Session Breakdown -> `ris:FileList` > 1. **`-sf interactsh-htb.session`**: Saves the client session so polling can resume after interruption. > 2. The displayed hostname is unique to this session; copy it exactly. > 3. Keep the session file private because it associates the client with its interactions. @@ -130,7 +126,6 @@ interactsh-client -auth ``` > [!info]+ Authentication Note -> `ris:LockPassword` > 1. Follow the interactive prompt and use your own ProjectDiscovery Cloud Platform API key. > 2. Do not paste API keys into command history or the Obsidian vault. > 3. Public-server authentication is separate from a token used by a protected self-hosted server. @@ -174,7 +169,6 @@ content-type: text/html; charset=utf-8 ``` > [!success]+ Expected Result -> `ris:Key` > 1. The client reports a DNS lookup and an HTTP request for `/self-test`. > 2. The event time, protocol, source address, and request metadata appear. > 3. If only DNS appears, inspect TLS, routing, and HTTP service availability before planting the HTB payload. @@ -236,7 +230,6 @@ Replace `UNIQUE_DOMAIN` and the label with values from the active session. | Raw request | Evidence of the exact callback; may contain sensitive values if the payload included them | > [!success]+ Minimum HTB Evidence -> `ris:Key` > 1. Screenshot or export the interaction with its unique label and timestamp. > 2. Save the request that planted the payload. > 3. State whether evidence was DNS-only, resource loading, or JavaScript-created HTTP. @@ -244,7 +237,7 @@ Replace `UNIQUE_DOMAIN` and the label with values from the active session. --- -## Optional Self-Hosting `ris:Global` +## Optional Self-Hosting > [!important]+ Self-Hosting Requirements > `fas:TriangleExclamation` @@ -271,7 +264,6 @@ dig A ns2.oast.YOUR_DOMAIN +short ``` > [!success]+ Expected DNS Result -> `ris:Key` > 1. The delegated nameservers are returned for the OAST domain. > 2. Both nameserver hosts resolve to the intended server address. > 3. Do not start payload testing until delegation is consistent externally. @@ -321,7 +313,6 @@ interactsh-client -server oast.YOUR_DOMAIN -token SELF_HOSTED_CLIENT_TOKEN ``` > [!info]+ Client Connection -> `ris:LockPassword` > 1. **`-server`**: Overrides the rotating public server list. > 2. **`-token`**: Authenticates to a protected self-hosted server. > 3. Store the token in a protected configuration file or secret manager rather than shell history. @@ -344,7 +335,7 @@ interactsh-server \ --- -## Operations and Lifecycle `ris:FileList` +## Operations and Lifecycle ### Logs and Session Output @@ -353,7 +344,6 @@ interactsh-client -sf interactsh-htb.session -json -o interactions.jsonl ``` > [!info]+ Output Breakdown -> `ris:FileList` > 1. **`-json`**: Produces structured interaction records. > 2. **`-o`**: Writes events to the named file. > 3. Protect the session and JSONL files because request headers and callback paths may be sensitive. @@ -394,7 +384,7 @@ docker pull projectdiscovery/interactsh-client:latest --- -## Troubleshooting `ris:FileList` +## Troubleshooting > [!failure]+ No Interaction Appears > `fas:CircleXmark` diff --git a/src/content/sheets/web/blind-xss-tool-xss-hunter.md b/src/content/sheets/web/blind-xss-tool-xss-hunter.md @@ -10,7 +10,7 @@ source: "vault:Web/Blind XSS Tool - XSS Hunter.md" --- # Blind XSS Tool — XSS Hunter `fas:ClipboardList` -## Summary `ris:Eye` +## Summary [XSS Hunter Express](https://github.com/mandatoryprogrammer/xsshunter-express) is a self-hosted blind-XSS reporting platform. When its generated probe executes in an unseen HTB browser, the platform can record the vulnerable URI, origin, referrer, user agent, non-`HttpOnly` cookies, page DOM, screenshots, and request metadata. Use it when a simple DNS or HTTP callback is insufficient and the lab requires evidence from an administrator-facing or asynchronous rendering path. @@ -23,7 +23,7 @@ source: "vault:Web/Blind XSS Tool - XSS Hunter.md" --- -## Conceptual Information `ris:GlobalLine` +## Conceptual Information ### When to Use XSS Hunter @@ -52,7 +52,7 @@ source: "vault:Web/Blind XSS Tool - XSS Hunter.md" --- -## Prerequisites `ris:FileList` +## Prerequisites | Requirement | Minimum or recommendation | Check | |---|---|---| @@ -73,7 +73,7 @@ source: "vault:Web/Blind XSS Tool - XSS Hunter.md" --- -## Commands and Implementation `ris:Command` +## Commands and Implementation ### 1. Verify DNS and Ports @@ -84,7 +84,6 @@ sudo ss -lntp '( sport = :80 or sport = :443 )' ``` > [!info]+ Preflight Breakdown -> `ris:Radar` > 1. **`dig`**: The hostname should resolve to the VPS public address. > 2. **Public IP check**: Confirms the address expected in DNS. > 3. **`ss`**: Output should be empty before XSS Hunter starts unless a planned reverse proxy owns the ports. @@ -99,7 +98,6 @@ docker compose config --services ``` > [!info]+ Command Breakdown -> `ris:Command` > 1. **Repository**: Uses the original XSS Hunter Express repository because its current Compose file contains the documented production hostname, TLS, SMTP, storage, and database settings. > 2. **`git status --short`**: Establishes a clean baseline before configuration edits. > 3. **`docker compose config --services`**: Validates the Compose file and prints the actual service names before startup. @@ -133,7 +131,6 @@ docker compose config >/dev/null ``` > [!info]+ Configuration Breakdown -> `ris:FileList` > 1. The copy provides a local rollback reference without exposing secrets elsewhere. > 2. **`docker compose config`** resolves the configuration and fails on malformed YAML or missing values. > 3. Do not commit the configured Compose file if it contains credentials. @@ -163,7 +160,6 @@ docker compose logs --tail=100 xsshunterexpress ``` > [!success]+ Expected Result -> `ris:Key` > 1. The services show a running state. > 2. `https://x.YOUR_DOMAIN/admin/` presents the control-panel login. > 3. TLS is valid for the configured hostname. @@ -213,7 +209,6 @@ For a quoted attribute context, break out only after confirming the quote type: | Responsible request | Injection request when supported | Requires compatible tooling or metadata | > [!success]+ Evidence Standard -> `ris:Key` > 1. Correlate the callback to the unique field and timestamp. > 2. Save only the evidence needed to prove the lab objective. > 3. Report the affected role and page separately from the injecting account. @@ -221,7 +216,7 @@ For a quoted attribute context, break out only after confirming the quote type: --- -## Operations and Lifecycle `ris:FileList` +## Operations and Lifecycle ### Logs and Health @@ -233,7 +228,6 @@ docker stats --no-stream ``` > [!info]+ Operational Checks -> `ris:FileList` > 1. Application logs expose TLS, configuration, callback, and startup errors. > 2. Database logs expose storage and authentication failures. > 3. Resource checks are important on the project's minimum-size VPS. @@ -271,7 +265,6 @@ docker compose ps ``` > [!info]+ Update Breakdown -> `ris:Command` > 1. Back up first and review upstream release notes or repository changes. > 2. **`--ff-only`** refuses an unexpected merge. > 3. **`--build`** rebuilds the application image from the updated source. @@ -299,7 +292,7 @@ docker compose down --volumes --- -## Troubleshooting `ris:FileList` +## Troubleshooting > [!failure]+ Certificate Issuance Fails > `fas:CircleXmark`