daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

content-manifest.json (39592B)


      1 {
      2   "sheets": [
      3     {
      4       "source": "vault",
      5       "rel": "ActiveDirectory/Active-Directory_cheat_sheet.md",
      6       "category": "active-directory",
      7       "slug": "active-directory-attacks",
      8       "title": "Active Directory Attack Methodology",
      9       "description": "End-to-end AD exploitation: enum, roasting, delegation, lateral movement, DCSync, persistence.",
     10       "tools": [
     11         "Impacket",
     12         "Rubeus",
     13         "Mimikatz",
     14         "CrackMapExec"
     15       ],
     16       "tags": [
     17         "active-directory",
     18         "methodology",
     19         "kerberos",
     20         "lateral-movement"
     21       ],
     22       "difficulty": "advanced",
     23       "action": "port",
     24       "note": "Consolidated AD attack encyclopedia (1 of 3 consolidated AD sheets); replaces the 78-file AD-Attack catalog."
     25     },
     26     {
     27       "source": "vault",
     28       "rel": "ActiveDirectory/AD_Pentest_Tools_Cheat_Sheet.md",
     29       "category": "active-directory",
     30       "slug": "ad-pentest-tools",
     31       "title": "AD Pentest Tools Workflow",
     32       "description": "Tooling-oriented AD engagement workflow with copy-paste commands from enumeration to domain takeover.",
     33       "tools": [
     34         "NetExec",
     35         "BloodHound",
     36         "Impacket",
     37         "ldapsearch"
     38       ],
     39       "tags": [
     40         "active-directory",
     41         "tooling",
     42         "workflow",
     43         "enumeration"
     44       ],
     45       "difficulty": "advanced",
     46       "action": "port",
     47       "note": "2nd consolidated AD sheet: tool/command quickref; distinct focus (tools vs techniques)."
     48     },
     49     {
     50       "source": "vault",
     51       "rel": "ActiveDirectory/ACL-ESC-Techniques/_ADCS Attack Methodology Guide.md",
     52       "category": "active-directory",
     53       "slug": "adcs-attack-methodology",
     54       "title": "ADCS Attack Methodology",
     55       "description": "ADCS/ESC attack index following Certified Pre-Owned taxonomy: ESC, THEFT, PERSIST, DPERSIST phases.",
     56       "tools": [
     57         "Certipy",
     58         "Certify"
     59       ],
     60       "tags": [
     61         "active-directory",
     62         "adcs",
     63         "esc",
     64         "certificates"
     65       ],
     66       "difficulty": "advanced",
     67       "action": "port",
     68       "note": "3rd consolidated sheet = single ADCS/ESC index; chosen over the 30-file per-ESC ACL-ESC series."
     69     },
     70     {
     71       "source": "vault",
     72       "rel": "ActiveDirectory/Rubeus.md",
     73       "category": "active-directory",
     74       "slug": "rubeus",
     75       "title": "Rubeus",
     76       "description": "Rubeus Kerberos abuse: kerberoast, asreproast, ticket forging, S4U, pass-the-ticket, overpass-the-hash.",
     77       "tools": [
     78         "Rubeus"
     79       ],
     80       "tags": [
     81         "active-directory",
     82         "kerberos",
     83         "tickets"
     84       ],
     85       "difficulty": "advanced",
     86       "action": "port",
     87       "note": "Vault version (25KB/24H2/33code) far richer than Tools/Rubeus-Cheatsheet (8.8KB); single canonical Rubeus."
     88     },
     89     {
     90       "source": "vault",
     91       "rel": "ActiveDirectory/BloodyAD.md",
     92       "category": "active-directory",
     93       "slug": "bloodyad",
     94       "title": "BloodyAD",
     95       "description": "BloodyAD LDAP privilege-abuse toolkit: RBCD, shadow creds, DACL edits, password/attribute writes.",
     96       "tools": [
     97         "BloodyAD"
     98       ],
     99       "tags": [
    100         "active-directory",
    101         "ldap",
    102         "acl-abuse"
    103       ],
    104       "difficulty": "intermediate",
    105       "action": "port",
    106       "note": "Vault (30KB/106code) beats repo copy (26KB/41code); dedupe winner."
    107     },
    108     {
    109       "source": "vault",
    110       "rel": "ActiveDirectory/Autobloody.md",
    111       "category": "active-directory",
    112       "slug": "autobloody",
    113       "title": "Autobloody",
    114       "description": "autobloody automates BloodyAD privilege-escalation paths from a BloodHound/Neo4j graph, chaining the ACL edges end-to-end to reach a target principal.",
    115       "tools": [
    116         "autobloody",
    117         "BloodyAD",
    118         "BloodHound",
    119         "Neo4j"
    120       ],
    121       "tags": [
    122         "active-directory",
    123         "ldap",
    124         "acl-abuse"
    125       ],
    126       "difficulty": "intermediate",
    127       "action": "add",
    128       "note": "New sheet: two-stage tool (Neo4j Dijkstra pathfinding -> bloodyAD execution) that automates the bloodyAD ACL-edge playbook end-to-end."
    129     },
    130     {
    131       "source": "repo",
    132       "rel": "Active-Directory/Certipy-ad.md",
    133       "category": "active-directory",
    134       "slug": "certipy",
    135       "title": "Certipy",
    136       "description": "Certipy ADCS enumeration and ESC exploitation: template abuse, PKINIT, golden certificate, shadow creds.",
    137       "tools": [
    138         "Certipy"
    139       ],
    140       "tags": [
    141         "active-directory",
    142         "adcs",
    143         "certificates"
    144       ],
    145       "difficulty": "advanced",
    146       "action": "port",
    147       "note": "Repo (22.4KB/39code) edges vault copy and the 8KB Tools/Certipy-ADCS; canonical Certipy tool page."
    148     },
    149     {
    150       "source": "repo",
    151       "rel": "Active-Directory/BloodHound-Python_Cheatsheet.md",
    152       "category": "active-directory",
    153       "slug": "bloodhound",
    154       "title": "BloodHound",
    155       "description": "BloodHound data collection and analysis with the Python ingestor plus cypher query patterns.",
    156       "tools": [
    157         "BloodHound",
    158         "bloodhound-python"
    159       ],
    160       "tags": [
    161         "active-directory",
    162         "graph",
    163         "enumeration"
    164       ],
    165       "difficulty": "intermediate",
    166       "action": "port",
    167       "note": "Richest BloodHound sheet (25.7KB/53code); dedupes vault BH-python, CE-python, Tools/BloodHound and SharpHound."
    168     },
    169     {
    170       "source": "repo",
    171       "rel": "Active-Directory/Impacket_Cheatsheet.md",
    172       "category": "active-directory",
    173       "slug": "impacket",
    174       "title": "Impacket",
    175       "description": "Impacket suite: secretsdump, psexec/wmiexec, GetUserSPNs, ntlmrelayx, ticketer, smbserver and more.",
    176       "tools": [
    177         "Impacket"
    178       ],
    179       "tags": [
    180         "active-directory",
    181         "smb",
    182         "credentials",
    183         "lateral-movement"
    184       ],
    185       "difficulty": "intermediate",
    186       "action": "port",
    187       "note": "Repo (22.8KB/84code) beats vault Impacket.md (17KB) and the 8.7KB Tools copy; single canonical Impacket."
    188     },
    189     {
    190       "source": "vault",
    191       "rel": "Tools/Netexec (nxc) Cheat Sheet.md",
    192       "category": "active-directory",
    193       "slug": "netexec",
    194       "title": "NetExec (nxc)",
    195       "description": "NetExec/CrackMapExec successor: SMB/WinRM/LDAP/MSSQL sweeps, cred spraying, dumping and modules.",
    196       "tools": [
    197         "NetExec",
    198         "nxc"
    199       ],
    200       "tags": [
    201         "active-directory",
    202         "smb",
    203         "credentials",
    204         "enumeration"
    205       ],
    206       "difficulty": "intermediate",
    207       "action": "port",
    208       "note": "26.9KB/21H2/50code markdown chosen over the netexec.pdf and 10KB NetExec-Cheatsheet; PDF rewrite unnecessary."
    209     },
    210     {
    211       "source": "vault",
    212       "rel": "Tools/Mimikatz-Cheatsheet.md",
    213       "category": "active-directory",
    214       "slug": "mimikatz",
    215       "title": "Mimikatz",
    216       "description": "Mimikatz credential extraction: sekurlsa, LSA dumps, DCSync, pass-the-hash/ticket, golden/silver tickets.",
    217       "tools": [
    218         "Mimikatz"
    219       ],
    220       "tags": [
    221         "active-directory",
    222         "credentials",
    223         "kerberos"
    224       ],
    225       "difficulty": "intermediate",
    226       "action": "port",
    227       "note": "Only Mimikatz sheet; compact but canonical (Mimikatz output is mostly non-code)."
    228     },
    229     {
    230       "source": "vault",
    231       "rel": "ActiveDirectory/Kerberos/Kerberoasting Cheatsheet.md",
    232       "category": "active-directory",
    233       "slug": "kerberoasting",
    234       "title": "Kerberoasting",
    235       "description": "Request and crack SPN service tickets: GetUserSPNs, Rubeus, hashcat modes and mitigation notes.",
    236       "tools": [
    237         "Impacket",
    238         "Rubeus",
    239         "Hashcat"
    240       ],
    241       "tags": [
    242         "active-directory",
    243         "kerberos",
    244         "cracking"
    245       ],
    246       "difficulty": "intermediate",
    247       "action": "port",
    248       "note": "Focused Kerberoasting technique sheet; chosen over the on-host variant and catalog Attack #2."
    249     },
    250     {
    251       "source": "vault",
    252       "rel": "ActiveDirectory/Kerbrute.md",
    253       "category": "active-directory",
    254       "slug": "kerbrute",
    255       "title": "Kerbrute",
    256       "description": "Kerbrute Kerberos pre-auth user enumeration and password spraying against a domain controller.",
    257       "tools": [
    258         "Kerbrute"
    259       ],
    260       "tags": [
    261         "active-directory",
    262         "kerberos",
    263         "enumeration",
    264         "spraying"
    265       ],
    266       "difficulty": "beginner",
    267       "action": "port",
    268       "note": "Only Kerbrute sheet; distinct user-enum/spray tool."
    269     },
    270     {
    271       "source": "vault",
    272       "rel": "ActiveDirectory/LDAP Search.md",
    273       "category": "active-directory",
    274       "slug": "ldap-enumeration",
    275       "title": "LDAP Enumeration",
    276       "description": "Manual ldapsearch queries to enumerate AD: users, groups, computers, ACLs, SPNs and attributes.",
    277       "tools": [
    278         "ldapsearch"
    279       ],
    280       "tags": [
    281         "active-directory",
    282         "ldap",
    283         "enumeration"
    284       ],
    285       "difficulty": "intermediate",
    286       "action": "port",
    287       "note": "Added by critic to fill the LDAP gap; manual query reference distinct from BloodHound/ldapdomaindump automation."
    288     },
    289     {
    290       "source": "vault",
    291       "rel": "Enumeration/Nmap Cheatsheet 2026.md",
    292       "category": "enumeration",
    293       "slug": "nmap",
    294       "title": "Nmap",
    295       "description": "Nmap host discovery, port/service/version scanning, timing, output formats and common scan recipes.",
    296       "tools": [
    297         "Nmap"
    298       ],
    299       "tags": [
    300         "enumeration",
    301         "port-scanning",
    302         "network"
    303       ],
    304       "difficulty": "beginner",
    305       "action": "port",
    306       "note": "Canonical Nmap; the 70KB NSE Guide and awesome-nmap-grep are narrower add-ons, dropped for a tight set."
    307     },
    308     {
    309       "source": "vault",
    310       "rel": "Enumeration/rustscan.md",
    311       "category": "enumeration",
    312       "slug": "rustscan",
    313       "title": "RustScan",
    314       "description": "RustScan fast port discovery, scripting engine, config and Nmap hand-off patterns.",
    315       "tools": [
    316         "RustScan",
    317         "Nmap"
    318       ],
    319       "tags": [
    320         "enumeration",
    321         "port-scanning",
    322         "network"
    323       ],
    324       "difficulty": "beginner",
    325       "action": "port",
    326       "note": "Richest of three RustScan sheets (22.4KB/73code); PDF rewrite unnecessary."
    327     },
    328     {
    329       "source": "vault",
    330       "rel": "Enumeration/ffuf_cheat_sheet.md",
    331       "category": "enumeration",
    332       "slug": "ffuf",
    333       "title": "ffuf",
    334       "description": "ffuf web fuzzing: directory/vhost/parameter discovery, matchers/filters, recursion and wordlists.",
    335       "tools": [
    336         "ffuf"
    337       ],
    338       "tags": [
    339         "enumeration",
    340         "web",
    341         "fuzzing"
    342       ],
    343       "difficulty": "intermediate",
    344       "action": "port",
    345       "note": "37KB/84code markdown beats the FFUF PDF and 8.6KB Tools/Ffuf copy; PDF rewrite unnecessary."
    346     },
    347     {
    348       "source": "vault",
    349       "rel": "Tools/gobuster.md",
    350       "category": "enumeration",
    351       "slug": "gobuster",
    352       "title": "Gobuster",
    353       "description": "Gobuster dir, dns, vhost and s3 brute-forcing modes with wordlist and status-code options.",
    354       "tools": [
    355         "Gobuster"
    356       ],
    357       "tags": [
    358         "enumeration",
    359         "web",
    360         "brute-force"
    361       ],
    362       "difficulty": "beginner",
    363       "action": "port",
    364       "note": "Distinct dir/DNS busting tool; complements ffuf."
    365     },
    366     {
    367       "source": "vault",
    368       "rel": "Tools/Nuclei-Cheatsheet.md",
    369       "category": "enumeration",
    370       "slug": "nuclei",
    371       "title": "Nuclei",
    372       "description": "Nuclei template-based vulnerability scanning: template selection, tags, severity and workflows.",
    373       "tools": [
    374         "Nuclei"
    375       ],
    376       "tags": [
    377         "enumeration",
    378         "scanning",
    379         "vulnerabilities"
    380       ],
    381       "difficulty": "intermediate",
    382       "action": "port",
    383       "note": "Dedicated Nuclei (27.7KB) preferred over the combined Nikto & Nuclei sheet for one clean tool page."
    384     },
    385     {
    386       "source": "vault",
    387       "rel": "Enumeration/WPScan.md",
    388       "category": "enumeration",
    389       "slug": "wpscan",
    390       "title": "WPScan",
    391       "description": "WPScan WordPress enumeration: plugins/themes/users, vuln API tokens and password attacks.",
    392       "tools": [
    393         "WPScan"
    394       ],
    395       "tags": [
    396         "enumeration",
    397         "web",
    398         "wordpress"
    399       ],
    400       "difficulty": "intermediate",
    401       "action": "port",
    402       "note": "WPScan.md (43KB) richer than WPScan 1 (24KB); dedupe winner."
    403     },
    404     {
    405       "source": "vault",
    406       "rel": "Enumeration/SMBMAP.md",
    407       "category": "enumeration",
    408       "slug": "smbmap",
    409       "title": "SMBMap",
    410       "description": "SMBMap share enumeration, permissions mapping, file download/upload and command execution over SMB.",
    411       "tools": [
    412         "SMBMap"
    413       ],
    414       "tags": [
    415         "enumeration",
    416         "smb",
    417         "shares"
    418       ],
    419       "difficulty": "beginner",
    420       "action": "port",
    421       "note": "Canonical SMB share-enum tool page."
    422     },
    423     {
    424       "source": "repo",
    425       "rel": "Enumeration/Shodan_Cheatsheet.md",
    426       "category": "enumeration",
    427       "slug": "shodan",
    428       "title": "Shodan",
    429       "description": "Shodan search filters, dorks, CLI and API workflows for internet-wide asset and service discovery.",
    430       "tools": [
    431         "Shodan"
    432       ],
    433       "tags": [
    434         "enumeration",
    435         "osint",
    436         "recon"
    437       ],
    438       "difficulty": "intermediate",
    439       "action": "port",
    440       "note": "Huge OSINT sheet (44KB/264code); only Shodan reference and a distinct recon angle."
    441     },
    442     {
    443       "source": "vault",
    444       "rel": "Exploitation/sqlmap.md",
    445       "category": "exploitation",
    446       "slug": "sqlmap",
    447       "title": "SQLMap",
    448       "description": "SQLMap automated SQL injection: target flags, techniques, enumeration, dumping and tamper scripts.",
    449       "tools": [
    450         "SQLMap"
    451       ],
    452       "tags": [
    453         "exploitation",
    454         "sql-injection",
    455         "web"
    456       ],
    457       "difficulty": "intermediate",
    458       "action": "port",
    459       "note": "Ultimate SQLMap (29KB) chosen over the 20KB SQLi-testing variant; single canonical sqlmap."
    460     },
    461     {
    462       "source": "vault",
    463       "rel": "Exploitation/Jailbreak - TTY Upgrade.md",
    464       "category": "exploitation",
    465       "slug": "shell-stabilization",
    466       "title": "Shell Stabilization & TTY Upgrades",
    467       "description": "Upgrade dumb shells to full TTYs and escape restricted shells (rbash, jails) with many techniques.",
    468       "tools": [
    469         "python",
    470         "socat",
    471         "stty"
    472       ],
    473       "tags": [
    474         "exploitation",
    475         "shells",
    476         "post-exploitation"
    477       ],
    478       "difficulty": "intermediate",
    479       "action": "port",
    480       "note": "57KB/247code sheet beats the 17KB TTY variant and the tty_shell PDF; PDF rewrite unnecessary."
    481     },
    482     {
    483       "source": "vault",
    484       "rel": "Tools/meterpreter.md",
    485       "category": "exploitation",
    486       "slug": "metasploit",
    487       "title": "Metasploit Framework",
    488       "description": "msfconsole and Meterpreter workflow: search, exploits, payloads, sessions, post modules, pivoting.",
    489       "tools": [
    490         "Metasploit",
    491         "msfconsole",
    492         "Meterpreter"
    493       ],
    494       "tags": [
    495         "exploitation",
    496         "framework",
    497         "post-exploitation"
    498       ],
    499       "difficulty": "intermediate",
    500       "action": "port",
    501       "note": "48KB markdown covers msfconsole+meterpreter, so the two metasploit PDFs are not rewritten."
    502     },
    503     {
    504       "source": "repo",
    505       "rel": "HTB/cheatsheet-stack-based-buffer-overflows-on-windows-x86.pdf",
    506       "category": "exploitation",
    507       "slug": "buffer-overflow",
    508       "title": "Stack-Based Buffer Overflow (Win x86)",
    509       "description": "Classic Windows x86 stack overflow: fuzzing, EIP control, bad chars, JMP ESP, shellcode.",
    510       "tools": [
    511         "Immunity Debugger",
    512         "mona.py",
    513         "msfvenom"
    514       ],
    515       "tags": [
    516         "exploitation",
    517         "buffer-overflow",
    518         "windows",
    519         "binary"
    520       ],
    521       "difficulty": "advanced",
    522       "action": "rewrite_from_pdf",
    523       "note": "PDF-only classic binary-exploitation topic with no markdown equivalent; worth converting."
    524     },
    525     {
    526       "source": "vault",
    527       "rel": "PrivEsc/PrivEsc - Windows.md",
    528       "category": "privilege-escalation",
    529       "slug": "windows-privesc",
    530       "title": "Windows Privilege Escalation",
    531       "description": "Windows privesc master guide: token/privilege abuse, services, registry, AlwaysInstallElevated, potatoes.",
    532       "tools": [
    533         "winPEAS",
    534         "PowerUp",
    535         "JuicyPotato"
    536       ],
    537       "tags": [
    538         "privilege-escalation",
    539         "windows",
    540         "post-exploitation"
    541       ],
    542       "difficulty": "advanced",
    543       "action": "port",
    544       "note": "118-code master guide chosen over the two other Windows privesc dumps; single canonical page."
    545     },
    546     {
    547       "source": "vault",
    548       "rel": "PrivEsc/Linux PrivEsc Cheat Sheet.md",
    549       "category": "privilege-escalation",
    550       "slug": "linux-privesc",
    551       "title": "Linux Privilege Escalation",
    552       "description": "Linux privesc quick-reference: sudo, SUID/SGID, cron, LD_PRELOAD, LXD, NFS, capabilities and kernel.",
    553       "tools": [
    554         "linPEAS",
    555         "pspy",
    556         "GTFOBins"
    557       ],
    558       "tags": [
    559         "privilege-escalation",
    560         "linux",
    561         "post-exploitation"
    562       ],
    563       "difficulty": "intermediate",
    564       "action": "port",
    565       "note": "Only Linux privesc candidate; dense command-table checklist (0 fenced code because it is a table)."
    566     },
    567     {
    568       "source": "vault",
    569       "rel": "PasswordAttacks/hashcat-cheatsheet.md",
    570       "category": "password-attacks",
    571       "slug": "hashcat",
    572       "title": "Hashcat",
    573       "description": "Hashcat cracking: attack modes, hash-mode selection, rules, masks, wordlists and performance tuning.",
    574       "tools": [
    575         "Hashcat"
    576       ],
    577       "tags": [
    578         "password-attacks",
    579         "cracking",
    580         "hashes"
    581       ],
    582       "difficulty": "intermediate",
    583       "action": "port",
    584       "note": "Structured sheet (11 H2/12 code) preferred over the Tools copy and the raw hashcat-modes table."
    585     },
    586     {
    587       "source": "vault",
    588       "rel": "PasswordAttacks/john-cheatsheet.md",
    589       "category": "password-attacks",
    590       "slug": "john-the-ripper",
    591       "title": "John the Ripper",
    592       "description": "John the Ripper: 2john extractors, formats, wordlist/incremental/rules modes and session control.",
    593       "tools": [
    594         "John the Ripper"
    595       ],
    596       "tags": [
    597         "password-attacks",
    598         "cracking",
    599         "hashes"
    600       ],
    601       "difficulty": "intermediate",
    602       "action": "port",
    603       "note": "13KB markdown beats the john PDF; PDF rewrite unnecessary."
    604     },
    605     {
    606       "source": "repo",
    607       "rel": "Password-Attacks/Password_Attacks_Cheat_Sheet.pdf",
    608       "category": "password-attacks",
    609       "slug": "password-attacks",
    610       "title": "Password Attacks & Brute Forcing",
    611       "description": "Online/offline password attacks: Hydra/Medusa service brute-forcing, spraying, mutations and defaults.",
    612       "tools": [
    613         "Hydra",
    614         "Medusa",
    615         "CrackMapExec"
    616       ],
    617       "tags": [
    618         "password-attacks",
    619         "brute-force",
    620         "spraying"
    621       ],
    622       "difficulty": "intermediate",
    623       "action": "rewrite_from_pdf",
    624       "note": "PDF-only; covers network brute-forcing/spraying not in the hashcat/john offline-cracking sheets."
    625     },
    626     {
    627       "source": "vault",
    628       "rel": "Web/Cross-Site Scripting (XSS) - HTB Cheat Sheet.md",
    629       "category": "web",
    630       "slug": "xss",
    631       "title": "Cross-Site Scripting (XSS)",
    632       "description": "Reflected/stored/DOM XSS discovery, payloads, filter bypass and blind-XSS callbacks.",
    633       "tools": [
    634         "Burp Suite"
    635       ],
    636       "tags": [
    637         "web",
    638         "xss",
    639         "injection"
    640       ],
    641       "difficulty": "intermediate",
    642       "action": "port",
    643       "note": "Main XSS reference; the three blind-XSS tool sheets (ezXSS/Interactsh/XSS Hunter) dropped as too granular."
    644     },
    645     {
    646       "source": "vault",
    647       "rel": "Web/Phishing Site & Link Identification - Cheat Sheet.md",
    648       "category": "web",
    649       "slug": "phishing-identification",
    650       "title": "Phishing Identification",
    651       "description": "Identify phishing sites and malicious links: URL/domain analysis, indicators and triage workflow.",
    652       "tools": [
    653         "urlscan",
    654         "VirusTotal"
    655       ],
    656       "tags": [
    657         "web",
    658         "phishing",
    659         "osint",
    660         "defense"
    661       ],
    662       "difficulty": "intermediate",
    663       "action": "port",
    664       "note": "Richer than the two phishing PDFs; markdown chosen over rewrite."
    665     },
    666     {
    667       "source": "repo",
    668       "rel": "HTB/cheatsheet-sql-injection-fundamentals.pdf",
    669       "category": "web",
    670       "slug": "sql-injection",
    671       "title": "SQL Injection Fundamentals",
    672       "description": "Manual SQL injection: auth bypass, UNION, error/blind, DB fingerprinting and file read/write.",
    673       "tools": [
    674         "MySQL client"
    675       ],
    676       "tags": [
    677         "web",
    678         "sql-injection",
    679         "injection"
    680       ],
    681       "difficulty": "intermediate",
    682       "action": "rewrite_from_pdf",
    683       "note": "PDF-only manual SQLi complements the automated sqlmap page; distinct angle."
    684     },
    685     {
    686       "source": "repo",
    687       "rel": "HTB/cheatsheet-file-inclusion.pdf",
    688       "category": "web",
    689       "slug": "file-inclusion",
    690       "title": "File Inclusion (LFI/RFI)",
    691       "description": "LFI/RFI exploitation: wrappers, log/wrapper poisoning, RCE, filter bypass and common payloads.",
    692       "tools": [
    693         "curl"
    694       ],
    695       "tags": [
    696         "web",
    697         "lfi",
    698         "rfi",
    699         "injection"
    700       ],
    701       "difficulty": "intermediate",
    702       "action": "rewrite_from_pdf",
    703       "note": "PDF-only; the vault LFI markdown is a 4.8KB stub with 0 code, so rewrite the PDF instead."
    704     },
    705     {
    706       "source": "vault",
    707       "rel": "Web/Curl Document.pdf",
    708       "category": "web",
    709       "slug": "curl",
    710       "title": "cURL",
    711       "description": "cURL for web testing: methods, headers, auth, cookies, proxies, file upload/download and scripting.",
    712       "tools": [
    713         "curl"
    714       ],
    715       "tags": [
    716         "web",
    717         "http",
    718         "tooling"
    719       ],
    720       "difficulty": "beginner",
    721       "action": "rewrite_from_pdf",
    722       "note": "PDF-only staple; vault copy has the correct filename (repo copy is misnamed 'Curk')."
    723     },
    724     {
    725       "source": "vault",
    726       "rel": "Tools/Ligolo-ng Cheat sheet.md",
    727       "category": "tunneling-pivoting",
    728       "slug": "ligolo-ng",
    729       "title": "Ligolo-ng",
    730       "description": "Ligolo-ng tunneling: agent/proxy setup, interface routing, double/multi-hop pivots and listeners.",
    731       "tools": [
    732         "Ligolo-ng"
    733       ],
    734       "tags": [
    735         "pivoting",
    736         "tunneling",
    737         "network"
    738       ],
    739       "difficulty": "intermediate",
    740       "action": "port",
    741       "note": "55KB markdown supersedes the two Ligolo PDFs; PDF rewrite unnecessary."
    742     },
    743     {
    744       "source": "vault",
    745       "rel": "Misc/Tunneling.md",
    746       "category": "tunneling-pivoting",
    747       "slug": "tunneling-tools",
    748       "title": "Tunneling Tools",
    749       "description": "Chisel, socat, plink and SSH tunneling patterns for port forwarding and pivoting through hosts.",
    750       "tools": [
    751         "Chisel",
    752         "socat",
    753         "plink",
    754         "SSH"
    755       ],
    756       "tags": [
    757         "pivoting",
    758         "tunneling",
    759         "port-forwarding"
    760       ],
    761       "difficulty": "advanced",
    762       "action": "port",
    763       "note": "Comprehensive multi-tool tunneling (35KB/93code); chosen over the narrower Pivoting & Tunnelling sheet."
    764     },
    765     {
    766       "source": "vault",
    767       "rel": "Misc/SSH Portfwding with metasploit .md",
    768       "category": "tunneling-pivoting",
    769       "slug": "ssh-tunneling",
    770       "title": "SSH Tunneling & Port Forwarding",
    771       "description": "SSH local/remote/dynamic forwarding and Metasploit route/portfwd pivoting, worked end to end.",
    772       "tools": [
    773         "SSH",
    774         "Metasploit"
    775       ],
    776       "tags": [
    777         "pivoting",
    778         "ssh",
    779         "port-forwarding"
    780       ],
    781       "difficulty": "intermediate",
    782       "action": "port",
    783       "note": "SSH+Metasploit focus distinct from the general tunneling and Ligolo pages."
    784     },
    785     {
    786       "source": "vault",
    787       "rel": "Cryptography/GPG - Cheatsheet markdown.md",
    788       "category": "cryptography",
    789       "slug": "gpg",
    790       "title": "GPG",
    791       "description": "GnuPG keys, encryption/decryption, signing/verification, keyservers, trust and revocation.",
    792       "tools": [
    793         "GPG",
    794         "GnuPG"
    795       ],
    796       "tags": [
    797         "cryptography",
    798         "encryption",
    799         "pgp"
    800       ],
    801       "difficulty": "intermediate",
    802       "action": "port",
    803       "note": "75KB/154code markdown beats both GPG PDFs; PDF rewrite unnecessary."
    804     },
    805     {
    806       "source": "repo",
    807       "rel": "Misc/openssl-cheatsheet.pdf",
    808       "category": "cryptography",
    809       "slug": "openssl",
    810       "title": "OpenSSL",
    811       "description": "OpenSSL: keys, CSRs, certs, x509 inspection, PEM/DER conversion, s_client and encryption.",
    812       "tools": [
    813         "OpenSSL"
    814       ],
    815       "tags": [
    816         "cryptography",
    817         "tls",
    818         "certificates"
    819       ],
    820       "difficulty": "intermediate",
    821       "action": "rewrite_from_pdf",
    822       "note": "PDF-only crypto staple with no markdown equivalent."
    823     },
    824     {
    825       "source": "vault",
    826       "rel": "HashingAndEncrypting/Hashing cheat sheet .md",
    827       "category": "cryptography",
    828       "slug": "hashing",
    829       "title": "Hashing & Hash Identification",
    830       "description": "Compute and identify hashes (md5/sha/NTLM), encodings, and pick the right cracking mode.",
    831       "tools": [
    832         "hashid",
    833         "hash-identifier",
    834         "openssl"
    835       ],
    836       "tags": [
    837         "cryptography",
    838         "hashing",
    839         "identification"
    840       ],
    841       "difficulty": "beginner",
    842       "action": "port",
    843       "note": "Only manual-hashing sheet; complements GPG/OpenSSL and feeds the password-cracking pages."
    844     },
    845     {
    846       "source": "vault",
    847       "rel": "DFIR/Forensics Cheatsheet.md",
    848       "category": "dfir",
    849       "slug": "forensics",
    850       "title": "Digital Forensics",
    851       "description": "Cross-platform DFIR reference: acquisition, triage, artifacts, timelines and analysis commands.",
    852       "tools": [
    853         "Autopsy",
    854         "Sleuth Kit",
    855         "plaso"
    856       ],
    857       "tags": [
    858         "dfir",
    859         "forensics",
    860         "incident-response"
    861       ],
    862       "difficulty": "intermediate",
    863       "action": "port",
    864       "note": "Broadest DFIR sheet (73KB/60code); general forensics anchor."
    865     },
    866     {
    867       "source": "vault",
    868       "rel": "DFIR/Volitility3 .md",
    869       "category": "dfir",
    870       "slug": "volatility",
    871       "title": "Volatility 3",
    872       "description": "Volatility 3 Windows memory forensics: processes, network, injection, hashes and plugin workflow.",
    873       "tools": [
    874         "Volatility 3"
    875       ],
    876       "tags": [
    877         "dfir",
    878         "memory-forensics",
    879         "malware"
    880       ],
    881       "difficulty": "advanced",
    882       "action": "port",
    883       "note": "Only Volatility sheet; core memory-forensics tool."
    884     },
    885     {
    886       "source": "vault",
    887       "rel": "DFIR/REDmd - Quick Cheat sheet.md",
    888       "category": "dfir",
    889       "slug": "recmd",
    890       "title": "RECmd Registry Forensics",
    891       "description": "RECmd registry analysis workflow: batch files, keys of interest and evidence extraction.",
    892       "tools": [
    893         "RECmd",
    894         "Registry Explorer"
    895       ],
    896       "tags": [
    897         "dfir",
    898         "registry",
    899         "windows"
    900       ],
    901       "difficulty": "advanced",
    902       "action": "port",
    903       "note": "Quick cheat/workflow variant chosen over the longer RECmd FullGuide; one canonical RECmd page."
    904     },
    905     {
    906       "source": "vault",
    907       "rel": "Tools/Tshark.md",
    908       "category": "dfir",
    909       "slug": "tshark",
    910       "title": "TShark",
    911       "description": "TShark CLI packet capture and analysis: filters, fields, follow streams and extraction for triage.",
    912       "tools": [
    913         "TShark",
    914         "Wireshark"
    915       ],
    916       "tags": [
    917         "dfir",
    918         "network-forensics",
    919         "pcap"
    920       ],
    921       "difficulty": "intermediate",
    922       "action": "port",
    923       "note": "Network-traffic analysis rep for DFIR; preferred over the narrower pcap-credential-extraction sheet."
    924     },
    925     {
    926       "source": "vault",
    927       "rel": "Tools/CMD-Powershell Cheat Sheet.md",
    928       "category": "tools",
    929       "slug": "windows-cmd-powershell",
    930       "title": "Windows CMD & PowerShell",
    931       "description": "Windows pentest command reference: recon, users/groups, networking, downloads and PowerShell one-liners.",
    932       "tools": [
    933         "cmd",
    934         "PowerShell"
    935       ],
    936       "tags": [
    937         "windows",
    938         "post-exploitation",
    939         "commands"
    940       ],
    941       "difficulty": "intermediate",
    942       "action": "port",
    943       "note": "71KB/161code superset; dedupes the standalone Powershell.md."
    944     },
    945     {
    946       "source": "vault",
    947       "rel": "Tools/fscan.md",
    948       "category": "tools",
    949       "slug": "fscan",
    950       "title": "fscan",
    951       "description": "fscan all-in-one intranet scanner: host/port discovery, service brute-forcing and vuln checks.",
    952       "tools": [
    953         "fscan"
    954       ],
    955       "tags": [
    956         "scanning",
    957         "enumeration",
    958         "internal"
    959       ],
    960       "difficulty": "intermediate",
    961       "action": "port",
    962       "note": "Distinct all-in-one internal scanner (43KB)."
    963     },
    964     {
    965       "source": "vault",
    966       "rel": "Tools/EyeWitness-Cheatsheet.md",
    967       "category": "tools",
    968       "slug": "eyewitness",
    969       "title": "EyeWitness",
    970       "description": "EyeWitness bulk web/RDP/VNC screenshotting and reporting for rapid visual recon.",
    971       "tools": [
    972         "EyeWitness"
    973       ],
    974       "tags": [
    975         "recon",
    976         "screenshots",
    977         "web"
    978       ],
    979       "difficulty": "beginner",
    980       "action": "port",
    981       "note": "Only screenshot-recon tool sheet."
    982     },
    983     {
    984       "source": "vault",
    985       "rel": "ActiveDirectory/Snaffler.md",
    986       "category": "tools",
    987       "slug": "snaffler",
    988       "title": "Snaffler",
    989       "description": "Snaffler share-crawling for credentials, keys and sensitive files across SMB with tuning rules.",
    990       "tools": [
    991         "Snaffler"
    992       ],
    993       "tags": [
    994         "credentials",
    995         "shares",
    996         "enumeration"
    997       ],
    998       "difficulty": "intermediate",
    999       "action": "port",
   1000       "note": "Rich share/credential hunting tool (28KB/38code)."
   1001     },
   1002     {
   1003       "source": "vault",
   1004       "rel": "ActiveDirectory/SharpSploit.md",
   1005       "category": "tools",
   1006       "slug": "sharpsploit",
   1007       "title": "SharpSploit",
   1008       "description": "SharpSploit .NET post-exploitation library: execution, credentials, enumeration and evasion APIs.",
   1009       "tools": [
   1010         "SharpSploit"
   1011       ],
   1012       "tags": [
   1013         "post-exploitation",
   1014         "dotnet",
   1015         "offensive"
   1016       ],
   1017       "difficulty": "advanced",
   1018       "action": "port",
   1019       "note": "Rich .NET tradecraft sheet (28KB); distinct from GUI/CLI tools."
   1020     },
   1021     {
   1022       "source": "vault",
   1023       "rel": "Tools/NTLM-Kerberos-Relay-Cheatsheet.md",
   1024       "category": "tools",
   1025       "slug": "ntlm-kerberos-relay",
   1026       "title": "NTLM & Kerberos Relay",
   1027       "description": "Coercion and relay attacks: ntlmrelayx/Responder targets, ADCS/LDAP relay and Kerberos relaying.",
   1028       "tools": [
   1029         "ntlmrelayx",
   1030         "Responder",
   1031         "Coercer"
   1032       ],
   1033       "tags": [
   1034         "relay",
   1035         "ntlm",
   1036         "kerberos",
   1037         "coercion"
   1038       ],
   1039       "difficulty": "advanced",
   1040       "action": "port",
   1041       "note": "Consolidated relay/coercion reference; complements Impacket without duplicating it."
   1042     },
   1043     {
   1044       "source": "vault",
   1045       "rel": "Tools/Cobalt-Strike-Cheatsheet.md",
   1046       "category": "tools",
   1047       "slug": "cobalt-strike",
   1048       "title": "Cobalt Strike",
   1049       "description": "Cobalt Strike operator reference: beacon commands, listeners, pivoting and post-exploitation.",
   1050       "tools": [
   1051         "Cobalt Strike"
   1052       ],
   1053       "tags": [
   1054         "c2",
   1055         "post-exploitation",
   1056         "red-team"
   1057       ],
   1058       "difficulty": "advanced",
   1059       "action": "port",
   1060       "note": "Only C2 reference; command-light because CS is GUI-driven, but fills a real gap."
   1061     },
   1062     {
   1063       "source": "repo",
   1064       "rel": "HTB/cheatsheet-file-transfers.pdf",
   1065       "category": "tools",
   1066       "slug": "file-transfers",
   1067       "title": "File Transfers",
   1068       "description": "Move files to/from targets on Windows/Linux: HTTP, SMB, certutil, base64, nc and living-off-the-land.",
   1069       "tools": [
   1070         "certutil",
   1071         "wget",
   1072         "nc",
   1073         "smbserver"
   1074       ],
   1075       "tags": [
   1076         "post-exploitation",
   1077         "file-transfer",
   1078         "windows",
   1079         "linux"
   1080       ],
   1081       "difficulty": "intermediate",
   1082       "action": "rewrite_from_pdf",
   1083       "note": "PDF-only essential technique with no markdown equivalent; high-value convert."
   1084     },
   1085     {
   1086       "source": "vault",
   1087       "rel": "Linux/Find Command.md",
   1088       "category": "linux-it",
   1089       "slug": "linux-find",
   1090       "title": "Linux find Command",
   1091       "description": "find recipes: by name/type/time/perm/size, SUID hunting, exec actions and pruning noisy paths.",
   1092       "tools": [
   1093         "find"
   1094       ],
   1095       "tags": [
   1096         "linux",
   1097         "cli",
   1098         "search"
   1099       ],
   1100       "difficulty": "intermediate",
   1101       "action": "port",
   1102       "note": "Canonical find sheet; dedupes the broader File & Directory Search sheet."
   1103     },
   1104     {
   1105       "source": "repo",
   1106       "rel": "Linux/chmod-cheatsheet.pdf",
   1107       "category": "linux-it",
   1108       "slug": "chmod",
   1109       "title": "chmod & File Permissions",
   1110       "description": "Linux permission model: symbolic/octal chmod, chown, umask, SUID/SGID/sticky bits explained.",
   1111       "tools": [
   1112         "chmod",
   1113         "chown",
   1114         "umask"
   1115       ],
   1116       "tags": [
   1117         "linux",
   1118         "permissions",
   1119         "cli"
   1120       ],
   1121       "difficulty": "beginner",
   1122       "action": "rewrite_from_pdf",
   1123       "note": "PDF-only IT staple named in the brief; no markdown equivalent."
   1124     },
   1125     {
   1126       "source": "vault",
   1127       "rel": "macOS/macOS Terminal Tweaks Cheat Sheet.md",
   1128       "category": "linux-it",
   1129       "slug": "macos-terminal",
   1130       "title": "macOS Terminal Tweaks",
   1131       "description": "Hidden macOS terminal/defaults tweaks and productivity commands for the CLI.",
   1132       "tools": [
   1133         "defaults",
   1134         "zsh"
   1135       ],
   1136       "tags": [
   1137         "macos",
   1138         "terminal",
   1139         "productivity"
   1140       ],
   1141       "difficulty": "beginner",
   1142       "action": "port",
   1143       "note": "IT staple; dedupes the identical root-level copy (uses the macOS/ path)."
   1144     },
   1145     {
   1146       "source": "vault",
   1147       "rel": "Misc/tmux.md",
   1148       "category": "linux-it",
   1149       "slug": "tmux",
   1150       "title": "tmux",
   1151       "description": "tmux sessions, windows, panes, copy mode and config bindings for terminal multiplexing.",
   1152       "tools": [
   1153         "tmux"
   1154       ],
   1155       "tags": [
   1156         "linux",
   1157         "terminal",
   1158         "productivity"
   1159       ],
   1160       "difficulty": "beginner",
   1161       "action": "port",
   1162       "note": "IT staple named in the brief."
   1163     },
   1164     {
   1165       "source": "vault",
   1166       "rel": "Git/git-cheatsheet.md",
   1167       "category": "git-workflow",
   1168       "slug": "git",
   1169       "title": "Git",
   1170       "description": "Everyday Git: staging, commits, remotes, log/diff, stash, merge/rebase and recovery.",
   1171       "tools": [
   1172         "git"
   1173       ],
   1174       "tags": [
   1175         "git",
   1176         "version-control",
   1177         "workflow"
   1178       ],
   1179       "difficulty": "beginner",
   1180       "action": "port",
   1181       "note": "Most comprehensive Git sheet (31KB/46code); core Git reference."
   1182     },
   1183     {
   1184       "source": "vault",
   1185       "rel": "Git/Branches Expanded.md",
   1186       "category": "git-workflow",
   1187       "slug": "git-branching",
   1188       "title": "Git Branching",
   1189       "description": "Branch workflows: create/switch, track remotes, merge vs rebase, and moving edits between branches.",
   1190       "tools": [
   1191         "git"
   1192       ],
   1193       "tags": [
   1194         "git",
   1195         "branching",
   1196         "workflow"
   1197       ],
   1198       "difficulty": "intermediate",
   1199       "action": "port",
   1200       "note": "Best-structured branching deep-dive (9 H2); dedupes Branches.md and the Vault-management branch guide."
   1201     },
   1202     {
   1203       "source": "vault",
   1204       "rel": "Git/Resetting.md",
   1205       "category": "git-workflow",
   1206       "slug": "git-reset",
   1207       "title": "Git Reset & Undo",
   1208       "description": "Undo work safely: reset soft/mixed/hard, restore, revert, reflog recovery and stash rescue.",
   1209       "tools": [
   1210         "git"
   1211       ],
   1212       "tags": [
   1213         "git",
   1214         "undo",
   1215         "recovery"
   1216       ],
   1217       "difficulty": "intermediate",
   1218       "action": "port",
   1219       "note": "Distinct undo/recovery focus not covered by the main Git sheet."
   1220     },
   1221     {
   1222       "source": "local",
   1223       "rel": "smtp-user-enum + swaks + nmap smtp-enum-users",
   1224       "category": "enumeration",
   1225       "slug": "smtp-user-enum",
   1226       "title": "SMTP User Enumeration",
   1227       "description": "smtp-user-enum, swaks and nmap smtp-enum-users \u2014 VRFY/EXPN/RCPT enumeration, open-relay checks, manual SMTP probing.",
   1228       "tools": [
   1229         "smtp-user-enum",
   1230         "swaks",
   1231         "Nmap"
   1232       ],
   1233       "tags": [
   1234         "enumeration",
   1235         "smtp",
   1236         "email"
   1237       ],
   1238       "difficulty": "beginner",
   1239       "action": "add",
   1240       "note": "New sheet: written after installing smtp-user-enum/swaks on the attacker Mac; nmap smtp-enum-users already bundled."
   1241     },
   1242     {
   1243       "source": "local",
   1244       "rel": "amass v5.1.1",
   1245       "category": "enumeration",
   1246       "slug": "amass",
   1247       "title": "Amass",
   1248       "description": "OWASP Amass v5 subdomain enumeration and attack-surface mapping \u2014 enum, ASN/CIDR discovery, reading results out of its graph database.",
   1249       "tools": [
   1250         "Amass"
   1251       ],
   1252       "tags": [
   1253         "enumeration",
   1254         "osint",
   1255         "recon",
   1256         "dns"
   1257       ],
   1258       "difficulty": "intermediate",
   1259       "action": "add",
   1260       "note": "New sheet: v5 rewrote the CLI (OAM graph DB, engine subcommand, intel folded into enum) vs the v3/v4-era commands still shown in passive-external-recon.md."
   1261     },
   1262     {
   1263       "source": "local",
   1264       "rel": "dorkforge 1.0.0",
   1265       "category": "enumeration",
   1266       "slug": "google-dorking",
   1267       "title": "Google Dorking",
   1268       "description": "Search-engine operators as a recon primitive \u2014 full operator reference, the gotchas that silently break dorks, recipes by objective, cross-engine translation, OPSEC, and blue-team defence.",
   1269       "tools": [
   1270         "Google",
   1271         "Bing",
   1272         "DuckDuckGo",
   1273         "Yandex",
   1274         "GitHub",
   1275         "Shodan",
   1276         "dorkforge"
   1277       ],
   1278       "tags": [
   1279         "enumeration",
   1280         "osint",
   1281         "recon",
   1282         "google-dorking",
   1283         "dorks",
   1284         "passive"
   1285       ],
   1286       "difficulty": "beginner",
   1287       "action": "add",
   1288       "note": "New sheet: expands the single dork table in passive-external-recon.md into a full reference, and ships the dorkforge.py companion script under public/downloads/enumeration/."
   1289     }
   1290   ]
   1291 }