content-manifest.json (39592B)
1 { 2 "sheets": [ 3 { 4 "source": "vault", 5 "rel": "ActiveDirectory/Active-Directory_cheat_sheet.md", 6 "category": "active-directory", 7 "slug": "active-directory-attacks", 8 "title": "Active Directory Attack Methodology", 9 "description": "End-to-end AD exploitation: enum, roasting, delegation, lateral movement, DCSync, persistence.", 10 "tools": [ 11 "Impacket", 12 "Rubeus", 13 "Mimikatz", 14 "CrackMapExec" 15 ], 16 "tags": [ 17 "active-directory", 18 "methodology", 19 "kerberos", 20 "lateral-movement" 21 ], 22 "difficulty": "advanced", 23 "action": "port", 24 "note": "Consolidated AD attack encyclopedia (1 of 3 consolidated AD sheets); replaces the 78-file AD-Attack catalog." 25 }, 26 { 27 "source": "vault", 28 "rel": "ActiveDirectory/AD_Pentest_Tools_Cheat_Sheet.md", 29 "category": "active-directory", 30 "slug": "ad-pentest-tools", 31 "title": "AD Pentest Tools Workflow", 32 "description": "Tooling-oriented AD engagement workflow with copy-paste commands from enumeration to domain takeover.", 33 "tools": [ 34 "NetExec", 35 "BloodHound", 36 "Impacket", 37 "ldapsearch" 38 ], 39 "tags": [ 40 "active-directory", 41 "tooling", 42 "workflow", 43 "enumeration" 44 ], 45 "difficulty": "advanced", 46 "action": "port", 47 "note": "2nd consolidated AD sheet: tool/command quickref; distinct focus (tools vs techniques)." 48 }, 49 { 50 "source": "vault", 51 "rel": "ActiveDirectory/ACL-ESC-Techniques/_ADCS Attack Methodology Guide.md", 52 "category": "active-directory", 53 "slug": "adcs-attack-methodology", 54 "title": "ADCS Attack Methodology", 55 "description": "ADCS/ESC attack index following Certified Pre-Owned taxonomy: ESC, THEFT, PERSIST, DPERSIST phases.", 56 "tools": [ 57 "Certipy", 58 "Certify" 59 ], 60 "tags": [ 61 "active-directory", 62 "adcs", 63 "esc", 64 "certificates" 65 ], 66 "difficulty": "advanced", 67 "action": "port", 68 "note": "3rd consolidated sheet = single ADCS/ESC index; chosen over the 30-file per-ESC ACL-ESC series." 69 }, 70 { 71 "source": "vault", 72 "rel": "ActiveDirectory/Rubeus.md", 73 "category": "active-directory", 74 "slug": "rubeus", 75 "title": "Rubeus", 76 "description": "Rubeus Kerberos abuse: kerberoast, asreproast, ticket forging, S4U, pass-the-ticket, overpass-the-hash.", 77 "tools": [ 78 "Rubeus" 79 ], 80 "tags": [ 81 "active-directory", 82 "kerberos", 83 "tickets" 84 ], 85 "difficulty": "advanced", 86 "action": "port", 87 "note": "Vault version (25KB/24H2/33code) far richer than Tools/Rubeus-Cheatsheet (8.8KB); single canonical Rubeus." 88 }, 89 { 90 "source": "vault", 91 "rel": "ActiveDirectory/BloodyAD.md", 92 "category": "active-directory", 93 "slug": "bloodyad", 94 "title": "BloodyAD", 95 "description": "BloodyAD LDAP privilege-abuse toolkit: RBCD, shadow creds, DACL edits, password/attribute writes.", 96 "tools": [ 97 "BloodyAD" 98 ], 99 "tags": [ 100 "active-directory", 101 "ldap", 102 "acl-abuse" 103 ], 104 "difficulty": "intermediate", 105 "action": "port", 106 "note": "Vault (30KB/106code) beats repo copy (26KB/41code); dedupe winner." 107 }, 108 { 109 "source": "vault", 110 "rel": "ActiveDirectory/Autobloody.md", 111 "category": "active-directory", 112 "slug": "autobloody", 113 "title": "Autobloody", 114 "description": "autobloody automates BloodyAD privilege-escalation paths from a BloodHound/Neo4j graph, chaining the ACL edges end-to-end to reach a target principal.", 115 "tools": [ 116 "autobloody", 117 "BloodyAD", 118 "BloodHound", 119 "Neo4j" 120 ], 121 "tags": [ 122 "active-directory", 123 "ldap", 124 "acl-abuse" 125 ], 126 "difficulty": "intermediate", 127 "action": "add", 128 "note": "New sheet: two-stage tool (Neo4j Dijkstra pathfinding -> bloodyAD execution) that automates the bloodyAD ACL-edge playbook end-to-end." 129 }, 130 { 131 "source": "repo", 132 "rel": "Active-Directory/Certipy-ad.md", 133 "category": "active-directory", 134 "slug": "certipy", 135 "title": "Certipy", 136 "description": "Certipy ADCS enumeration and ESC exploitation: template abuse, PKINIT, golden certificate, shadow creds.", 137 "tools": [ 138 "Certipy" 139 ], 140 "tags": [ 141 "active-directory", 142 "adcs", 143 "certificates" 144 ], 145 "difficulty": "advanced", 146 "action": "port", 147 "note": "Repo (22.4KB/39code) edges vault copy and the 8KB Tools/Certipy-ADCS; canonical Certipy tool page." 148 }, 149 { 150 "source": "repo", 151 "rel": "Active-Directory/BloodHound-Python_Cheatsheet.md", 152 "category": "active-directory", 153 "slug": "bloodhound", 154 "title": "BloodHound", 155 "description": "BloodHound data collection and analysis with the Python ingestor plus cypher query patterns.", 156 "tools": [ 157 "BloodHound", 158 "bloodhound-python" 159 ], 160 "tags": [ 161 "active-directory", 162 "graph", 163 "enumeration" 164 ], 165 "difficulty": "intermediate", 166 "action": "port", 167 "note": "Richest BloodHound sheet (25.7KB/53code); dedupes vault BH-python, CE-python, Tools/BloodHound and SharpHound." 168 }, 169 { 170 "source": "repo", 171 "rel": "Active-Directory/Impacket_Cheatsheet.md", 172 "category": "active-directory", 173 "slug": "impacket", 174 "title": "Impacket", 175 "description": "Impacket suite: secretsdump, psexec/wmiexec, GetUserSPNs, ntlmrelayx, ticketer, smbserver and more.", 176 "tools": [ 177 "Impacket" 178 ], 179 "tags": [ 180 "active-directory", 181 "smb", 182 "credentials", 183 "lateral-movement" 184 ], 185 "difficulty": "intermediate", 186 "action": "port", 187 "note": "Repo (22.8KB/84code) beats vault Impacket.md (17KB) and the 8.7KB Tools copy; single canonical Impacket." 188 }, 189 { 190 "source": "vault", 191 "rel": "Tools/Netexec (nxc) Cheat Sheet.md", 192 "category": "active-directory", 193 "slug": "netexec", 194 "title": "NetExec (nxc)", 195 "description": "NetExec/CrackMapExec successor: SMB/WinRM/LDAP/MSSQL sweeps, cred spraying, dumping and modules.", 196 "tools": [ 197 "NetExec", 198 "nxc" 199 ], 200 "tags": [ 201 "active-directory", 202 "smb", 203 "credentials", 204 "enumeration" 205 ], 206 "difficulty": "intermediate", 207 "action": "port", 208 "note": "26.9KB/21H2/50code markdown chosen over the netexec.pdf and 10KB NetExec-Cheatsheet; PDF rewrite unnecessary." 209 }, 210 { 211 "source": "vault", 212 "rel": "Tools/Mimikatz-Cheatsheet.md", 213 "category": "active-directory", 214 "slug": "mimikatz", 215 "title": "Mimikatz", 216 "description": "Mimikatz credential extraction: sekurlsa, LSA dumps, DCSync, pass-the-hash/ticket, golden/silver tickets.", 217 "tools": [ 218 "Mimikatz" 219 ], 220 "tags": [ 221 "active-directory", 222 "credentials", 223 "kerberos" 224 ], 225 "difficulty": "intermediate", 226 "action": "port", 227 "note": "Only Mimikatz sheet; compact but canonical (Mimikatz output is mostly non-code)." 228 }, 229 { 230 "source": "vault", 231 "rel": "ActiveDirectory/Kerberos/Kerberoasting Cheatsheet.md", 232 "category": "active-directory", 233 "slug": "kerberoasting", 234 "title": "Kerberoasting", 235 "description": "Request and crack SPN service tickets: GetUserSPNs, Rubeus, hashcat modes and mitigation notes.", 236 "tools": [ 237 "Impacket", 238 "Rubeus", 239 "Hashcat" 240 ], 241 "tags": [ 242 "active-directory", 243 "kerberos", 244 "cracking" 245 ], 246 "difficulty": "intermediate", 247 "action": "port", 248 "note": "Focused Kerberoasting technique sheet; chosen over the on-host variant and catalog Attack #2." 249 }, 250 { 251 "source": "vault", 252 "rel": "ActiveDirectory/Kerbrute.md", 253 "category": "active-directory", 254 "slug": "kerbrute", 255 "title": "Kerbrute", 256 "description": "Kerbrute Kerberos pre-auth user enumeration and password spraying against a domain controller.", 257 "tools": [ 258 "Kerbrute" 259 ], 260 "tags": [ 261 "active-directory", 262 "kerberos", 263 "enumeration", 264 "spraying" 265 ], 266 "difficulty": "beginner", 267 "action": "port", 268 "note": "Only Kerbrute sheet; distinct user-enum/spray tool." 269 }, 270 { 271 "source": "vault", 272 "rel": "ActiveDirectory/LDAP Search.md", 273 "category": "active-directory", 274 "slug": "ldap-enumeration", 275 "title": "LDAP Enumeration", 276 "description": "Manual ldapsearch queries to enumerate AD: users, groups, computers, ACLs, SPNs and attributes.", 277 "tools": [ 278 "ldapsearch" 279 ], 280 "tags": [ 281 "active-directory", 282 "ldap", 283 "enumeration" 284 ], 285 "difficulty": "intermediate", 286 "action": "port", 287 "note": "Added by critic to fill the LDAP gap; manual query reference distinct from BloodHound/ldapdomaindump automation." 288 }, 289 { 290 "source": "vault", 291 "rel": "Enumeration/Nmap Cheatsheet 2026.md", 292 "category": "enumeration", 293 "slug": "nmap", 294 "title": "Nmap", 295 "description": "Nmap host discovery, port/service/version scanning, timing, output formats and common scan recipes.", 296 "tools": [ 297 "Nmap" 298 ], 299 "tags": [ 300 "enumeration", 301 "port-scanning", 302 "network" 303 ], 304 "difficulty": "beginner", 305 "action": "port", 306 "note": "Canonical Nmap; the 70KB NSE Guide and awesome-nmap-grep are narrower add-ons, dropped for a tight set." 307 }, 308 { 309 "source": "vault", 310 "rel": "Enumeration/rustscan.md", 311 "category": "enumeration", 312 "slug": "rustscan", 313 "title": "RustScan", 314 "description": "RustScan fast port discovery, scripting engine, config and Nmap hand-off patterns.", 315 "tools": [ 316 "RustScan", 317 "Nmap" 318 ], 319 "tags": [ 320 "enumeration", 321 "port-scanning", 322 "network" 323 ], 324 "difficulty": "beginner", 325 "action": "port", 326 "note": "Richest of three RustScan sheets (22.4KB/73code); PDF rewrite unnecessary." 327 }, 328 { 329 "source": "vault", 330 "rel": "Enumeration/ffuf_cheat_sheet.md", 331 "category": "enumeration", 332 "slug": "ffuf", 333 "title": "ffuf", 334 "description": "ffuf web fuzzing: directory/vhost/parameter discovery, matchers/filters, recursion and wordlists.", 335 "tools": [ 336 "ffuf" 337 ], 338 "tags": [ 339 "enumeration", 340 "web", 341 "fuzzing" 342 ], 343 "difficulty": "intermediate", 344 "action": "port", 345 "note": "37KB/84code markdown beats the FFUF PDF and 8.6KB Tools/Ffuf copy; PDF rewrite unnecessary." 346 }, 347 { 348 "source": "vault", 349 "rel": "Tools/gobuster.md", 350 "category": "enumeration", 351 "slug": "gobuster", 352 "title": "Gobuster", 353 "description": "Gobuster dir, dns, vhost and s3 brute-forcing modes with wordlist and status-code options.", 354 "tools": [ 355 "Gobuster" 356 ], 357 "tags": [ 358 "enumeration", 359 "web", 360 "brute-force" 361 ], 362 "difficulty": "beginner", 363 "action": "port", 364 "note": "Distinct dir/DNS busting tool; complements ffuf." 365 }, 366 { 367 "source": "vault", 368 "rel": "Tools/Nuclei-Cheatsheet.md", 369 "category": "enumeration", 370 "slug": "nuclei", 371 "title": "Nuclei", 372 "description": "Nuclei template-based vulnerability scanning: template selection, tags, severity and workflows.", 373 "tools": [ 374 "Nuclei" 375 ], 376 "tags": [ 377 "enumeration", 378 "scanning", 379 "vulnerabilities" 380 ], 381 "difficulty": "intermediate", 382 "action": "port", 383 "note": "Dedicated Nuclei (27.7KB) preferred over the combined Nikto & Nuclei sheet for one clean tool page." 384 }, 385 { 386 "source": "vault", 387 "rel": "Enumeration/WPScan.md", 388 "category": "enumeration", 389 "slug": "wpscan", 390 "title": "WPScan", 391 "description": "WPScan WordPress enumeration: plugins/themes/users, vuln API tokens and password attacks.", 392 "tools": [ 393 "WPScan" 394 ], 395 "tags": [ 396 "enumeration", 397 "web", 398 "wordpress" 399 ], 400 "difficulty": "intermediate", 401 "action": "port", 402 "note": "WPScan.md (43KB) richer than WPScan 1 (24KB); dedupe winner." 403 }, 404 { 405 "source": "vault", 406 "rel": "Enumeration/SMBMAP.md", 407 "category": "enumeration", 408 "slug": "smbmap", 409 "title": "SMBMap", 410 "description": "SMBMap share enumeration, permissions mapping, file download/upload and command execution over SMB.", 411 "tools": [ 412 "SMBMap" 413 ], 414 "tags": [ 415 "enumeration", 416 "smb", 417 "shares" 418 ], 419 "difficulty": "beginner", 420 "action": "port", 421 "note": "Canonical SMB share-enum tool page." 422 }, 423 { 424 "source": "repo", 425 "rel": "Enumeration/Shodan_Cheatsheet.md", 426 "category": "enumeration", 427 "slug": "shodan", 428 "title": "Shodan", 429 "description": "Shodan search filters, dorks, CLI and API workflows for internet-wide asset and service discovery.", 430 "tools": [ 431 "Shodan" 432 ], 433 "tags": [ 434 "enumeration", 435 "osint", 436 "recon" 437 ], 438 "difficulty": "intermediate", 439 "action": "port", 440 "note": "Huge OSINT sheet (44KB/264code); only Shodan reference and a distinct recon angle." 441 }, 442 { 443 "source": "vault", 444 "rel": "Exploitation/sqlmap.md", 445 "category": "exploitation", 446 "slug": "sqlmap", 447 "title": "SQLMap", 448 "description": "SQLMap automated SQL injection: target flags, techniques, enumeration, dumping and tamper scripts.", 449 "tools": [ 450 "SQLMap" 451 ], 452 "tags": [ 453 "exploitation", 454 "sql-injection", 455 "web" 456 ], 457 "difficulty": "intermediate", 458 "action": "port", 459 "note": "Ultimate SQLMap (29KB) chosen over the 20KB SQLi-testing variant; single canonical sqlmap." 460 }, 461 { 462 "source": "vault", 463 "rel": "Exploitation/Jailbreak - TTY Upgrade.md", 464 "category": "exploitation", 465 "slug": "shell-stabilization", 466 "title": "Shell Stabilization & TTY Upgrades", 467 "description": "Upgrade dumb shells to full TTYs and escape restricted shells (rbash, jails) with many techniques.", 468 "tools": [ 469 "python", 470 "socat", 471 "stty" 472 ], 473 "tags": [ 474 "exploitation", 475 "shells", 476 "post-exploitation" 477 ], 478 "difficulty": "intermediate", 479 "action": "port", 480 "note": "57KB/247code sheet beats the 17KB TTY variant and the tty_shell PDF; PDF rewrite unnecessary." 481 }, 482 { 483 "source": "vault", 484 "rel": "Tools/meterpreter.md", 485 "category": "exploitation", 486 "slug": "metasploit", 487 "title": "Metasploit Framework", 488 "description": "msfconsole and Meterpreter workflow: search, exploits, payloads, sessions, post modules, pivoting.", 489 "tools": [ 490 "Metasploit", 491 "msfconsole", 492 "Meterpreter" 493 ], 494 "tags": [ 495 "exploitation", 496 "framework", 497 "post-exploitation" 498 ], 499 "difficulty": "intermediate", 500 "action": "port", 501 "note": "48KB markdown covers msfconsole+meterpreter, so the two metasploit PDFs are not rewritten." 502 }, 503 { 504 "source": "repo", 505 "rel": "HTB/cheatsheet-stack-based-buffer-overflows-on-windows-x86.pdf", 506 "category": "exploitation", 507 "slug": "buffer-overflow", 508 "title": "Stack-Based Buffer Overflow (Win x86)", 509 "description": "Classic Windows x86 stack overflow: fuzzing, EIP control, bad chars, JMP ESP, shellcode.", 510 "tools": [ 511 "Immunity Debugger", 512 "mona.py", 513 "msfvenom" 514 ], 515 "tags": [ 516 "exploitation", 517 "buffer-overflow", 518 "windows", 519 "binary" 520 ], 521 "difficulty": "advanced", 522 "action": "rewrite_from_pdf", 523 "note": "PDF-only classic binary-exploitation topic with no markdown equivalent; worth converting." 524 }, 525 { 526 "source": "vault", 527 "rel": "PrivEsc/PrivEsc - Windows.md", 528 "category": "privilege-escalation", 529 "slug": "windows-privesc", 530 "title": "Windows Privilege Escalation", 531 "description": "Windows privesc master guide: token/privilege abuse, services, registry, AlwaysInstallElevated, potatoes.", 532 "tools": [ 533 "winPEAS", 534 "PowerUp", 535 "JuicyPotato" 536 ], 537 "tags": [ 538 "privilege-escalation", 539 "windows", 540 "post-exploitation" 541 ], 542 "difficulty": "advanced", 543 "action": "port", 544 "note": "118-code master guide chosen over the two other Windows privesc dumps; single canonical page." 545 }, 546 { 547 "source": "vault", 548 "rel": "PrivEsc/Linux PrivEsc Cheat Sheet.md", 549 "category": "privilege-escalation", 550 "slug": "linux-privesc", 551 "title": "Linux Privilege Escalation", 552 "description": "Linux privesc quick-reference: sudo, SUID/SGID, cron, LD_PRELOAD, LXD, NFS, capabilities and kernel.", 553 "tools": [ 554 "linPEAS", 555 "pspy", 556 "GTFOBins" 557 ], 558 "tags": [ 559 "privilege-escalation", 560 "linux", 561 "post-exploitation" 562 ], 563 "difficulty": "intermediate", 564 "action": "port", 565 "note": "Only Linux privesc candidate; dense command-table checklist (0 fenced code because it is a table)." 566 }, 567 { 568 "source": "vault", 569 "rel": "PasswordAttacks/hashcat-cheatsheet.md", 570 "category": "password-attacks", 571 "slug": "hashcat", 572 "title": "Hashcat", 573 "description": "Hashcat cracking: attack modes, hash-mode selection, rules, masks, wordlists and performance tuning.", 574 "tools": [ 575 "Hashcat" 576 ], 577 "tags": [ 578 "password-attacks", 579 "cracking", 580 "hashes" 581 ], 582 "difficulty": "intermediate", 583 "action": "port", 584 "note": "Structured sheet (11 H2/12 code) preferred over the Tools copy and the raw hashcat-modes table." 585 }, 586 { 587 "source": "vault", 588 "rel": "PasswordAttacks/john-cheatsheet.md", 589 "category": "password-attacks", 590 "slug": "john-the-ripper", 591 "title": "John the Ripper", 592 "description": "John the Ripper: 2john extractors, formats, wordlist/incremental/rules modes and session control.", 593 "tools": [ 594 "John the Ripper" 595 ], 596 "tags": [ 597 "password-attacks", 598 "cracking", 599 "hashes" 600 ], 601 "difficulty": "intermediate", 602 "action": "port", 603 "note": "13KB markdown beats the john PDF; PDF rewrite unnecessary." 604 }, 605 { 606 "source": "repo", 607 "rel": "Password-Attacks/Password_Attacks_Cheat_Sheet.pdf", 608 "category": "password-attacks", 609 "slug": "password-attacks", 610 "title": "Password Attacks & Brute Forcing", 611 "description": "Online/offline password attacks: Hydra/Medusa service brute-forcing, spraying, mutations and defaults.", 612 "tools": [ 613 "Hydra", 614 "Medusa", 615 "CrackMapExec" 616 ], 617 "tags": [ 618 "password-attacks", 619 "brute-force", 620 "spraying" 621 ], 622 "difficulty": "intermediate", 623 "action": "rewrite_from_pdf", 624 "note": "PDF-only; covers network brute-forcing/spraying not in the hashcat/john offline-cracking sheets." 625 }, 626 { 627 "source": "vault", 628 "rel": "Web/Cross-Site Scripting (XSS) - HTB Cheat Sheet.md", 629 "category": "web", 630 "slug": "xss", 631 "title": "Cross-Site Scripting (XSS)", 632 "description": "Reflected/stored/DOM XSS discovery, payloads, filter bypass and blind-XSS callbacks.", 633 "tools": [ 634 "Burp Suite" 635 ], 636 "tags": [ 637 "web", 638 "xss", 639 "injection" 640 ], 641 "difficulty": "intermediate", 642 "action": "port", 643 "note": "Main XSS reference; the three blind-XSS tool sheets (ezXSS/Interactsh/XSS Hunter) dropped as too granular." 644 }, 645 { 646 "source": "vault", 647 "rel": "Web/Phishing Site & Link Identification - Cheat Sheet.md", 648 "category": "web", 649 "slug": "phishing-identification", 650 "title": "Phishing Identification", 651 "description": "Identify phishing sites and malicious links: URL/domain analysis, indicators and triage workflow.", 652 "tools": [ 653 "urlscan", 654 "VirusTotal" 655 ], 656 "tags": [ 657 "web", 658 "phishing", 659 "osint", 660 "defense" 661 ], 662 "difficulty": "intermediate", 663 "action": "port", 664 "note": "Richer than the two phishing PDFs; markdown chosen over rewrite." 665 }, 666 { 667 "source": "repo", 668 "rel": "HTB/cheatsheet-sql-injection-fundamentals.pdf", 669 "category": "web", 670 "slug": "sql-injection", 671 "title": "SQL Injection Fundamentals", 672 "description": "Manual SQL injection: auth bypass, UNION, error/blind, DB fingerprinting and file read/write.", 673 "tools": [ 674 "MySQL client" 675 ], 676 "tags": [ 677 "web", 678 "sql-injection", 679 "injection" 680 ], 681 "difficulty": "intermediate", 682 "action": "rewrite_from_pdf", 683 "note": "PDF-only manual SQLi complements the automated sqlmap page; distinct angle." 684 }, 685 { 686 "source": "repo", 687 "rel": "HTB/cheatsheet-file-inclusion.pdf", 688 "category": "web", 689 "slug": "file-inclusion", 690 "title": "File Inclusion (LFI/RFI)", 691 "description": "LFI/RFI exploitation: wrappers, log/wrapper poisoning, RCE, filter bypass and common payloads.", 692 "tools": [ 693 "curl" 694 ], 695 "tags": [ 696 "web", 697 "lfi", 698 "rfi", 699 "injection" 700 ], 701 "difficulty": "intermediate", 702 "action": "rewrite_from_pdf", 703 "note": "PDF-only; the vault LFI markdown is a 4.8KB stub with 0 code, so rewrite the PDF instead." 704 }, 705 { 706 "source": "vault", 707 "rel": "Web/Curl Document.pdf", 708 "category": "web", 709 "slug": "curl", 710 "title": "cURL", 711 "description": "cURL for web testing: methods, headers, auth, cookies, proxies, file upload/download and scripting.", 712 "tools": [ 713 "curl" 714 ], 715 "tags": [ 716 "web", 717 "http", 718 "tooling" 719 ], 720 "difficulty": "beginner", 721 "action": "rewrite_from_pdf", 722 "note": "PDF-only staple; vault copy has the correct filename (repo copy is misnamed 'Curk')." 723 }, 724 { 725 "source": "vault", 726 "rel": "Tools/Ligolo-ng Cheat sheet.md", 727 "category": "tunneling-pivoting", 728 "slug": "ligolo-ng", 729 "title": "Ligolo-ng", 730 "description": "Ligolo-ng tunneling: agent/proxy setup, interface routing, double/multi-hop pivots and listeners.", 731 "tools": [ 732 "Ligolo-ng" 733 ], 734 "tags": [ 735 "pivoting", 736 "tunneling", 737 "network" 738 ], 739 "difficulty": "intermediate", 740 "action": "port", 741 "note": "55KB markdown supersedes the two Ligolo PDFs; PDF rewrite unnecessary." 742 }, 743 { 744 "source": "vault", 745 "rel": "Misc/Tunneling.md", 746 "category": "tunneling-pivoting", 747 "slug": "tunneling-tools", 748 "title": "Tunneling Tools", 749 "description": "Chisel, socat, plink and SSH tunneling patterns for port forwarding and pivoting through hosts.", 750 "tools": [ 751 "Chisel", 752 "socat", 753 "plink", 754 "SSH" 755 ], 756 "tags": [ 757 "pivoting", 758 "tunneling", 759 "port-forwarding" 760 ], 761 "difficulty": "advanced", 762 "action": "port", 763 "note": "Comprehensive multi-tool tunneling (35KB/93code); chosen over the narrower Pivoting & Tunnelling sheet." 764 }, 765 { 766 "source": "vault", 767 "rel": "Misc/SSH Portfwding with metasploit .md", 768 "category": "tunneling-pivoting", 769 "slug": "ssh-tunneling", 770 "title": "SSH Tunneling & Port Forwarding", 771 "description": "SSH local/remote/dynamic forwarding and Metasploit route/portfwd pivoting, worked end to end.", 772 "tools": [ 773 "SSH", 774 "Metasploit" 775 ], 776 "tags": [ 777 "pivoting", 778 "ssh", 779 "port-forwarding" 780 ], 781 "difficulty": "intermediate", 782 "action": "port", 783 "note": "SSH+Metasploit focus distinct from the general tunneling and Ligolo pages." 784 }, 785 { 786 "source": "vault", 787 "rel": "Cryptography/GPG - Cheatsheet markdown.md", 788 "category": "cryptography", 789 "slug": "gpg", 790 "title": "GPG", 791 "description": "GnuPG keys, encryption/decryption, signing/verification, keyservers, trust and revocation.", 792 "tools": [ 793 "GPG", 794 "GnuPG" 795 ], 796 "tags": [ 797 "cryptography", 798 "encryption", 799 "pgp" 800 ], 801 "difficulty": "intermediate", 802 "action": "port", 803 "note": "75KB/154code markdown beats both GPG PDFs; PDF rewrite unnecessary." 804 }, 805 { 806 "source": "repo", 807 "rel": "Misc/openssl-cheatsheet.pdf", 808 "category": "cryptography", 809 "slug": "openssl", 810 "title": "OpenSSL", 811 "description": "OpenSSL: keys, CSRs, certs, x509 inspection, PEM/DER conversion, s_client and encryption.", 812 "tools": [ 813 "OpenSSL" 814 ], 815 "tags": [ 816 "cryptography", 817 "tls", 818 "certificates" 819 ], 820 "difficulty": "intermediate", 821 "action": "rewrite_from_pdf", 822 "note": "PDF-only crypto staple with no markdown equivalent." 823 }, 824 { 825 "source": "vault", 826 "rel": "HashingAndEncrypting/Hashing cheat sheet .md", 827 "category": "cryptography", 828 "slug": "hashing", 829 "title": "Hashing & Hash Identification", 830 "description": "Compute and identify hashes (md5/sha/NTLM), encodings, and pick the right cracking mode.", 831 "tools": [ 832 "hashid", 833 "hash-identifier", 834 "openssl" 835 ], 836 "tags": [ 837 "cryptography", 838 "hashing", 839 "identification" 840 ], 841 "difficulty": "beginner", 842 "action": "port", 843 "note": "Only manual-hashing sheet; complements GPG/OpenSSL and feeds the password-cracking pages." 844 }, 845 { 846 "source": "vault", 847 "rel": "DFIR/Forensics Cheatsheet.md", 848 "category": "dfir", 849 "slug": "forensics", 850 "title": "Digital Forensics", 851 "description": "Cross-platform DFIR reference: acquisition, triage, artifacts, timelines and analysis commands.", 852 "tools": [ 853 "Autopsy", 854 "Sleuth Kit", 855 "plaso" 856 ], 857 "tags": [ 858 "dfir", 859 "forensics", 860 "incident-response" 861 ], 862 "difficulty": "intermediate", 863 "action": "port", 864 "note": "Broadest DFIR sheet (73KB/60code); general forensics anchor." 865 }, 866 { 867 "source": "vault", 868 "rel": "DFIR/Volitility3 .md", 869 "category": "dfir", 870 "slug": "volatility", 871 "title": "Volatility 3", 872 "description": "Volatility 3 Windows memory forensics: processes, network, injection, hashes and plugin workflow.", 873 "tools": [ 874 "Volatility 3" 875 ], 876 "tags": [ 877 "dfir", 878 "memory-forensics", 879 "malware" 880 ], 881 "difficulty": "advanced", 882 "action": "port", 883 "note": "Only Volatility sheet; core memory-forensics tool." 884 }, 885 { 886 "source": "vault", 887 "rel": "DFIR/REDmd - Quick Cheat sheet.md", 888 "category": "dfir", 889 "slug": "recmd", 890 "title": "RECmd Registry Forensics", 891 "description": "RECmd registry analysis workflow: batch files, keys of interest and evidence extraction.", 892 "tools": [ 893 "RECmd", 894 "Registry Explorer" 895 ], 896 "tags": [ 897 "dfir", 898 "registry", 899 "windows" 900 ], 901 "difficulty": "advanced", 902 "action": "port", 903 "note": "Quick cheat/workflow variant chosen over the longer RECmd FullGuide; one canonical RECmd page." 904 }, 905 { 906 "source": "vault", 907 "rel": "Tools/Tshark.md", 908 "category": "dfir", 909 "slug": "tshark", 910 "title": "TShark", 911 "description": "TShark CLI packet capture and analysis: filters, fields, follow streams and extraction for triage.", 912 "tools": [ 913 "TShark", 914 "Wireshark" 915 ], 916 "tags": [ 917 "dfir", 918 "network-forensics", 919 "pcap" 920 ], 921 "difficulty": "intermediate", 922 "action": "port", 923 "note": "Network-traffic analysis rep for DFIR; preferred over the narrower pcap-credential-extraction sheet." 924 }, 925 { 926 "source": "vault", 927 "rel": "Tools/CMD-Powershell Cheat Sheet.md", 928 "category": "tools", 929 "slug": "windows-cmd-powershell", 930 "title": "Windows CMD & PowerShell", 931 "description": "Windows pentest command reference: recon, users/groups, networking, downloads and PowerShell one-liners.", 932 "tools": [ 933 "cmd", 934 "PowerShell" 935 ], 936 "tags": [ 937 "windows", 938 "post-exploitation", 939 "commands" 940 ], 941 "difficulty": "intermediate", 942 "action": "port", 943 "note": "71KB/161code superset; dedupes the standalone Powershell.md." 944 }, 945 { 946 "source": "vault", 947 "rel": "Tools/fscan.md", 948 "category": "tools", 949 "slug": "fscan", 950 "title": "fscan", 951 "description": "fscan all-in-one intranet scanner: host/port discovery, service brute-forcing and vuln checks.", 952 "tools": [ 953 "fscan" 954 ], 955 "tags": [ 956 "scanning", 957 "enumeration", 958 "internal" 959 ], 960 "difficulty": "intermediate", 961 "action": "port", 962 "note": "Distinct all-in-one internal scanner (43KB)." 963 }, 964 { 965 "source": "vault", 966 "rel": "Tools/EyeWitness-Cheatsheet.md", 967 "category": "tools", 968 "slug": "eyewitness", 969 "title": "EyeWitness", 970 "description": "EyeWitness bulk web/RDP/VNC screenshotting and reporting for rapid visual recon.", 971 "tools": [ 972 "EyeWitness" 973 ], 974 "tags": [ 975 "recon", 976 "screenshots", 977 "web" 978 ], 979 "difficulty": "beginner", 980 "action": "port", 981 "note": "Only screenshot-recon tool sheet." 982 }, 983 { 984 "source": "vault", 985 "rel": "ActiveDirectory/Snaffler.md", 986 "category": "tools", 987 "slug": "snaffler", 988 "title": "Snaffler", 989 "description": "Snaffler share-crawling for credentials, keys and sensitive files across SMB with tuning rules.", 990 "tools": [ 991 "Snaffler" 992 ], 993 "tags": [ 994 "credentials", 995 "shares", 996 "enumeration" 997 ], 998 "difficulty": "intermediate", 999 "action": "port", 1000 "note": "Rich share/credential hunting tool (28KB/38code)." 1001 }, 1002 { 1003 "source": "vault", 1004 "rel": "ActiveDirectory/SharpSploit.md", 1005 "category": "tools", 1006 "slug": "sharpsploit", 1007 "title": "SharpSploit", 1008 "description": "SharpSploit .NET post-exploitation library: execution, credentials, enumeration and evasion APIs.", 1009 "tools": [ 1010 "SharpSploit" 1011 ], 1012 "tags": [ 1013 "post-exploitation", 1014 "dotnet", 1015 "offensive" 1016 ], 1017 "difficulty": "advanced", 1018 "action": "port", 1019 "note": "Rich .NET tradecraft sheet (28KB); distinct from GUI/CLI tools." 1020 }, 1021 { 1022 "source": "vault", 1023 "rel": "Tools/NTLM-Kerberos-Relay-Cheatsheet.md", 1024 "category": "tools", 1025 "slug": "ntlm-kerberos-relay", 1026 "title": "NTLM & Kerberos Relay", 1027 "description": "Coercion and relay attacks: ntlmrelayx/Responder targets, ADCS/LDAP relay and Kerberos relaying.", 1028 "tools": [ 1029 "ntlmrelayx", 1030 "Responder", 1031 "Coercer" 1032 ], 1033 "tags": [ 1034 "relay", 1035 "ntlm", 1036 "kerberos", 1037 "coercion" 1038 ], 1039 "difficulty": "advanced", 1040 "action": "port", 1041 "note": "Consolidated relay/coercion reference; complements Impacket without duplicating it." 1042 }, 1043 { 1044 "source": "vault", 1045 "rel": "Tools/Cobalt-Strike-Cheatsheet.md", 1046 "category": "tools", 1047 "slug": "cobalt-strike", 1048 "title": "Cobalt Strike", 1049 "description": "Cobalt Strike operator reference: beacon commands, listeners, pivoting and post-exploitation.", 1050 "tools": [ 1051 "Cobalt Strike" 1052 ], 1053 "tags": [ 1054 "c2", 1055 "post-exploitation", 1056 "red-team" 1057 ], 1058 "difficulty": "advanced", 1059 "action": "port", 1060 "note": "Only C2 reference; command-light because CS is GUI-driven, but fills a real gap." 1061 }, 1062 { 1063 "source": "repo", 1064 "rel": "HTB/cheatsheet-file-transfers.pdf", 1065 "category": "tools", 1066 "slug": "file-transfers", 1067 "title": "File Transfers", 1068 "description": "Move files to/from targets on Windows/Linux: HTTP, SMB, certutil, base64, nc and living-off-the-land.", 1069 "tools": [ 1070 "certutil", 1071 "wget", 1072 "nc", 1073 "smbserver" 1074 ], 1075 "tags": [ 1076 "post-exploitation", 1077 "file-transfer", 1078 "windows", 1079 "linux" 1080 ], 1081 "difficulty": "intermediate", 1082 "action": "rewrite_from_pdf", 1083 "note": "PDF-only essential technique with no markdown equivalent; high-value convert." 1084 }, 1085 { 1086 "source": "vault", 1087 "rel": "Linux/Find Command.md", 1088 "category": "linux-it", 1089 "slug": "linux-find", 1090 "title": "Linux find Command", 1091 "description": "find recipes: by name/type/time/perm/size, SUID hunting, exec actions and pruning noisy paths.", 1092 "tools": [ 1093 "find" 1094 ], 1095 "tags": [ 1096 "linux", 1097 "cli", 1098 "search" 1099 ], 1100 "difficulty": "intermediate", 1101 "action": "port", 1102 "note": "Canonical find sheet; dedupes the broader File & Directory Search sheet." 1103 }, 1104 { 1105 "source": "repo", 1106 "rel": "Linux/chmod-cheatsheet.pdf", 1107 "category": "linux-it", 1108 "slug": "chmod", 1109 "title": "chmod & File Permissions", 1110 "description": "Linux permission model: symbolic/octal chmod, chown, umask, SUID/SGID/sticky bits explained.", 1111 "tools": [ 1112 "chmod", 1113 "chown", 1114 "umask" 1115 ], 1116 "tags": [ 1117 "linux", 1118 "permissions", 1119 "cli" 1120 ], 1121 "difficulty": "beginner", 1122 "action": "rewrite_from_pdf", 1123 "note": "PDF-only IT staple named in the brief; no markdown equivalent." 1124 }, 1125 { 1126 "source": "vault", 1127 "rel": "macOS/macOS Terminal Tweaks Cheat Sheet.md", 1128 "category": "linux-it", 1129 "slug": "macos-terminal", 1130 "title": "macOS Terminal Tweaks", 1131 "description": "Hidden macOS terminal/defaults tweaks and productivity commands for the CLI.", 1132 "tools": [ 1133 "defaults", 1134 "zsh" 1135 ], 1136 "tags": [ 1137 "macos", 1138 "terminal", 1139 "productivity" 1140 ], 1141 "difficulty": "beginner", 1142 "action": "port", 1143 "note": "IT staple; dedupes the identical root-level copy (uses the macOS/ path)." 1144 }, 1145 { 1146 "source": "vault", 1147 "rel": "Misc/tmux.md", 1148 "category": "linux-it", 1149 "slug": "tmux", 1150 "title": "tmux", 1151 "description": "tmux sessions, windows, panes, copy mode and config bindings for terminal multiplexing.", 1152 "tools": [ 1153 "tmux" 1154 ], 1155 "tags": [ 1156 "linux", 1157 "terminal", 1158 "productivity" 1159 ], 1160 "difficulty": "beginner", 1161 "action": "port", 1162 "note": "IT staple named in the brief." 1163 }, 1164 { 1165 "source": "vault", 1166 "rel": "Git/git-cheatsheet.md", 1167 "category": "git-workflow", 1168 "slug": "git", 1169 "title": "Git", 1170 "description": "Everyday Git: staging, commits, remotes, log/diff, stash, merge/rebase and recovery.", 1171 "tools": [ 1172 "git" 1173 ], 1174 "tags": [ 1175 "git", 1176 "version-control", 1177 "workflow" 1178 ], 1179 "difficulty": "beginner", 1180 "action": "port", 1181 "note": "Most comprehensive Git sheet (31KB/46code); core Git reference." 1182 }, 1183 { 1184 "source": "vault", 1185 "rel": "Git/Branches Expanded.md", 1186 "category": "git-workflow", 1187 "slug": "git-branching", 1188 "title": "Git Branching", 1189 "description": "Branch workflows: create/switch, track remotes, merge vs rebase, and moving edits between branches.", 1190 "tools": [ 1191 "git" 1192 ], 1193 "tags": [ 1194 "git", 1195 "branching", 1196 "workflow" 1197 ], 1198 "difficulty": "intermediate", 1199 "action": "port", 1200 "note": "Best-structured branching deep-dive (9 H2); dedupes Branches.md and the Vault-management branch guide." 1201 }, 1202 { 1203 "source": "vault", 1204 "rel": "Git/Resetting.md", 1205 "category": "git-workflow", 1206 "slug": "git-reset", 1207 "title": "Git Reset & Undo", 1208 "description": "Undo work safely: reset soft/mixed/hard, restore, revert, reflog recovery and stash rescue.", 1209 "tools": [ 1210 "git" 1211 ], 1212 "tags": [ 1213 "git", 1214 "undo", 1215 "recovery" 1216 ], 1217 "difficulty": "intermediate", 1218 "action": "port", 1219 "note": "Distinct undo/recovery focus not covered by the main Git sheet." 1220 }, 1221 { 1222 "source": "local", 1223 "rel": "smtp-user-enum + swaks + nmap smtp-enum-users", 1224 "category": "enumeration", 1225 "slug": "smtp-user-enum", 1226 "title": "SMTP User Enumeration", 1227 "description": "smtp-user-enum, swaks and nmap smtp-enum-users \u2014 VRFY/EXPN/RCPT enumeration, open-relay checks, manual SMTP probing.", 1228 "tools": [ 1229 "smtp-user-enum", 1230 "swaks", 1231 "Nmap" 1232 ], 1233 "tags": [ 1234 "enumeration", 1235 "smtp", 1236 "email" 1237 ], 1238 "difficulty": "beginner", 1239 "action": "add", 1240 "note": "New sheet: written after installing smtp-user-enum/swaks on the attacker Mac; nmap smtp-enum-users already bundled." 1241 }, 1242 { 1243 "source": "local", 1244 "rel": "amass v5.1.1", 1245 "category": "enumeration", 1246 "slug": "amass", 1247 "title": "Amass", 1248 "description": "OWASP Amass v5 subdomain enumeration and attack-surface mapping \u2014 enum, ASN/CIDR discovery, reading results out of its graph database.", 1249 "tools": [ 1250 "Amass" 1251 ], 1252 "tags": [ 1253 "enumeration", 1254 "osint", 1255 "recon", 1256 "dns" 1257 ], 1258 "difficulty": "intermediate", 1259 "action": "add", 1260 "note": "New sheet: v5 rewrote the CLI (OAM graph DB, engine subcommand, intel folded into enum) vs the v3/v4-era commands still shown in passive-external-recon.md." 1261 }, 1262 { 1263 "source": "local", 1264 "rel": "dorkforge 1.0.0", 1265 "category": "enumeration", 1266 "slug": "google-dorking", 1267 "title": "Google Dorking", 1268 "description": "Search-engine operators as a recon primitive \u2014 full operator reference, the gotchas that silently break dorks, recipes by objective, cross-engine translation, OPSEC, and blue-team defence.", 1269 "tools": [ 1270 "Google", 1271 "Bing", 1272 "DuckDuckGo", 1273 "Yandex", 1274 "GitHub", 1275 "Shodan", 1276 "dorkforge" 1277 ], 1278 "tags": [ 1279 "enumeration", 1280 "osint", 1281 "recon", 1282 "google-dorking", 1283 "dorks", 1284 "passive" 1285 ], 1286 "difficulty": "beginner", 1287 "action": "add", 1288 "note": "New sheet: expands the single dork table in passive-external-recon.md into a full reference, and ships the dorkforge.py companion script under public/downloads/enumeration/." 1289 } 1290 ] 1291 }