README.md (4400B)
1 <div align="center"> 2 3 # DÆMON//SEC 4 5 **The cheatsheet vault for operators.** 6 7 A curated, glassy vault of the best IT & cybersecurity cheatsheets — 8 Active Directory, enumeration, exploitation, priv-esc, web, DFIR, and more. 9 Fast offline search, copy-ready commands, zero fluff. 10 11 🌐 **[cheatsheet.daemon-sec.xyz](https://cheatsheet.daemon-sec.xyz)** · source on [GitLab](https://gitlab.com/DAEMON-404/daemon-sec-cheatsheet) 12 13 `Rose Pine · Apple-glass · cyberpunk` — built with [Astro](https://astro.build) + [Pagefind](https://pagefind.app) 14 15 </div> 16 17 --- 18 19 ## What's inside 20 21 60 hand-picked, modernized cheatsheets across 12 domains: 22 23 | Domain | Domain | Domain | 24 | ------ | ------ | ------ | 25 | Active Directory | Enumeration | Exploitation | 26 | Privilege Escalation | Password Attacks | Web | 27 | Tunneling & Pivoting | Cryptography | DFIR | 28 | Tools | Linux & IT | Git & Workflow | 29 30 Each page is stripped of vault-specific syntax, given consistent frontmatter 31 (tags, tools, difficulty), and refreshed for current tool flags and versions. 32 33 ## Features 34 35 - **Rose Pine** dark theme with a **Rose Pine Dawn** light toggle (respects your system preference). 36 - **Apple-glass** frosted panels with restrained cyberpunk neon accents. 37 - Every code block is a **terminal pane** with one-click copy. 38 - **Instant offline fuzzy search** (`/` or `⌘K`) — no server, no tracking. 39 - Fully responsive, keyboard-accessible, `prefers-reduced-motion` aware. 40 41 ## Develop 42 43 ```bash 44 npm install 45 npm run dev # local dev server 46 npm run build # astro build + pagefind search index -> dist/ 47 npm run preview # preview the production build 48 ``` 49 50 ## Deploy 51 52 Cloudflare Workers is the only host. It serves `cheatsheet.daemon-sec.xyz`, 53 configured in `wrangler.jsonc`, and deploys are **manual**: 54 55 ```bash 56 npm run deploy:workers # build + .assetsignore + wrangler deploy 57 ``` 58 59 There is no CI deploy. Pushing to `main` publishes nothing on its own, so a 60 content change is live only once someone runs the command above. 61 62 ## Content structure 63 64 Cheatsheets live in `src/content/sheets/<category>/<slug>.md` with frontmatter: 65 66 ```yaml 67 --- 68 title: "Rubeus" 69 description: "Kerberos abuse toolkit…" 70 category: active-directory 71 tags: [kerberos, tickets] 72 tools: [Rubeus] 73 difficulty: advanced 74 updated: "2026-08-09" 75 --- 76 ``` 77 78 Category slugs, colors, and labels are defined in `src/lib/taxonomy.ts`. 79 80 ## Third-party content 81 82 Two directories are generated mirrors of someone else's work, not ours to 83 license. Full attribution lives on `/credits`. 84 85 | Path | Upstream | Licence | 86 | --- | --- | --- | 87 | `src/content/payloads/` | [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings) (Swissky) | MIT, Copyright (c) 2019 Swissky — see `vendor/PayloadsAllTheThings/LICENSE` | 88 | `src/content/internal/` | [InternalAllTheThings](https://github.com/swisskyrepo/InternalAllTheThings) (Swissky) | none published upstream; copyright stays with Swissky and its contributors | 89 90 Both are regenerated by `scripts/sync-payloads.py` and `scripts/sync-internal.py` 91 — don't hand-edit them. 92 93 `scripts/sync-mirrors.sh` drives both of them. Run it bare to see what upstream 94 has done since the last sync: it clones both upstreams, regenerates the mirrors, 95 builds and tests the result, and leaves the diff in your working tree without 96 committing anything. 97 98 ```sh 99 scripts/sync-mirrors.sh # sync + validate, commit nothing 100 scripts/sync-mirrors.sh --commit # ... and commit, one commit per upstream 101 scripts/sync-mirrors.sh --push # ... and push to main, which deploys 102 ``` 103 104 `.github/workflows/sync-mirrors.yml` runs that same script with `--push` daily 105 at 06:17 UTC, and on demand via **Actions → Sync upstream mirrors → Run 106 workflow**. Only trees that actually moved get a commit. There is no review 107 gate, so `npm run build` and `node --test` are the safety net: a sync that 108 breaks either fails and never lands. 109 110 The sync only lands commits; it does not publish. Because deploys are manual, 111 run `npm run deploy:workers` after a sync to put the new upstream content live. 112 113 ## Legal 114 115 For **authorized testing, CTFs, and education only**. Know your scope and get 116 written permission before touching a system you don't own. The maintainers are 117 not responsible for misuse. 118 119 The site's own code and hand-written cheatsheets are licensed under 120 [MIT](./LICENSE). That licence does not extend to the mirrored trees above.