daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

README.md (4400B)


      1 <div align="center">
      2 
      3 # DÆMON//SEC
      4 
      5 **The cheatsheet vault for operators.**
      6 
      7 A curated, glassy vault of the best IT & cybersecurity cheatsheets —
      8 Active Directory, enumeration, exploitation, priv-esc, web, DFIR, and more.
      9 Fast offline search, copy-ready commands, zero fluff.
     10 
     11 🌐 **[cheatsheet.daemon-sec.xyz](https://cheatsheet.daemon-sec.xyz)** · source on [GitLab](https://gitlab.com/DAEMON-404/daemon-sec-cheatsheet)
     12 
     13 `Rose Pine · Apple-glass · cyberpunk` — built with [Astro](https://astro.build) + [Pagefind](https://pagefind.app)
     14 
     15 </div>
     16 
     17 ---
     18 
     19 ## What's inside
     20 
     21 60 hand-picked, modernized cheatsheets across 12 domains:
     22 
     23 | Domain | Domain | Domain |
     24 | ------ | ------ | ------ |
     25 | Active Directory | Enumeration | Exploitation |
     26 | Privilege Escalation | Password Attacks | Web |
     27 | Tunneling & Pivoting | Cryptography | DFIR |
     28 | Tools | Linux & IT | Git & Workflow |
     29 
     30 Each page is stripped of vault-specific syntax, given consistent frontmatter
     31 (tags, tools, difficulty), and refreshed for current tool flags and versions.
     32 
     33 ## Features
     34 
     35 - **Rose Pine** dark theme with a **Rose Pine Dawn** light toggle (respects your system preference).
     36 - **Apple-glass** frosted panels with restrained cyberpunk neon accents.
     37 - Every code block is a **terminal pane** with one-click copy.
     38 - **Instant offline fuzzy search** (`/` or `⌘K`) — no server, no tracking.
     39 - Fully responsive, keyboard-accessible, `prefers-reduced-motion` aware.
     40 
     41 ## Develop
     42 
     43 ```bash
     44 npm install
     45 npm run dev        # local dev server
     46 npm run build      # astro build + pagefind search index -> dist/
     47 npm run preview    # preview the production build
     48 ```
     49 
     50 ## Deploy
     51 
     52 Cloudflare Workers is the only host. It serves `cheatsheet.daemon-sec.xyz`,
     53 configured in `wrangler.jsonc`, and deploys are **manual**:
     54 
     55 ```bash
     56 npm run deploy:workers   # build + .assetsignore + wrangler deploy
     57 ```
     58 
     59 There is no CI deploy. Pushing to `main` publishes nothing on its own, so a
     60 content change is live only once someone runs the command above.
     61 
     62 ## Content structure
     63 
     64 Cheatsheets live in `src/content/sheets/<category>/<slug>.md` with frontmatter:
     65 
     66 ```yaml
     67 ---
     68 title: "Rubeus"
     69 description: "Kerberos abuse toolkit…"
     70 category: active-directory
     71 tags: [kerberos, tickets]
     72 tools: [Rubeus]
     73 difficulty: advanced
     74 updated: "2026-08-09"
     75 ---
     76 ```
     77 
     78 Category slugs, colors, and labels are defined in `src/lib/taxonomy.ts`.
     79 
     80 ## Third-party content
     81 
     82 Two directories are generated mirrors of someone else's work, not ours to
     83 license. Full attribution lives on `/credits`.
     84 
     85 | Path | Upstream | Licence |
     86 | --- | --- | --- |
     87 | `src/content/payloads/` | [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings) (Swissky) | MIT, Copyright (c) 2019 Swissky — see `vendor/PayloadsAllTheThings/LICENSE` |
     88 | `src/content/internal/` | [InternalAllTheThings](https://github.com/swisskyrepo/InternalAllTheThings) (Swissky) | none published upstream; copyright stays with Swissky and its contributors |
     89 
     90 Both are regenerated by `scripts/sync-payloads.py` and `scripts/sync-internal.py`
     91 — don't hand-edit them.
     92 
     93 `scripts/sync-mirrors.sh` drives both of them. Run it bare to see what upstream
     94 has done since the last sync: it clones both upstreams, regenerates the mirrors,
     95 builds and tests the result, and leaves the diff in your working tree without
     96 committing anything.
     97 
     98 ```sh
     99 scripts/sync-mirrors.sh            # sync + validate, commit nothing
    100 scripts/sync-mirrors.sh --commit   # ... and commit, one commit per upstream
    101 scripts/sync-mirrors.sh --push     # ... and push to main, which deploys
    102 ```
    103 
    104 `.github/workflows/sync-mirrors.yml` runs that same script with `--push` daily
    105 at 06:17 UTC, and on demand via **Actions → Sync upstream mirrors → Run
    106 workflow**. Only trees that actually moved get a commit. There is no review
    107 gate, so `npm run build` and `node --test` are the safety net: a sync that
    108 breaks either fails and never lands.
    109 
    110 The sync only lands commits; it does not publish. Because deploys are manual,
    111 run `npm run deploy:workers` after a sync to put the new upstream content live.
    112 
    113 ## Legal
    114 
    115 For **authorized testing, CTFs, and education only**. Know your scope and get
    116 written permission before touching a system you don't own. The maintainers are
    117 not responsible for misuse.
    118 
    119 The site's own code and hand-written cheatsheets are licensed under
    120 [MIT](./LICENSE). That licence does not extend to the mirrored trees above.