daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

provenance-audit.md (25826B)


      1 # Provenance & Attribution Audit — `src/content/sheets`
      2 
      3 **Date:** 2026-08-13
      4 **Scope:** the 215 hand-curated cheatsheets under `src/content/sheets/`. The `payloads/` and
      5 `internal/` mirrors are out of scope — they are already attributed on `/credits` and carry a
      6 per-page `PayloadCredit` banner.
      7 **Purpose:** find third-party content that is currently republished without credit, so it can be
      8 credited. This audit exists to *give* attribution, not to remove content quietly.
      9 
     10 ---
     11 
     12 ## 1. Summary
     13 
     14 | | Count |
     15 |---|---|
     16 | Sheets in `src/content/sheets/` | 215 |
     17 | Sheets carrying `source: "vault:…"` (records vault path only — says nothing about origin) | 204 |
     18 | Sheets carrying `source: "repo:…"` (self-declared external origin) | 11 |
     19 | Screened as candidates across the two triage phases | 140 |
     20 | Escalated to evidence-based adjudication | 5 |
     21 | **Attributable (verbatim copy or derived) — action required** | **4** |
     22 | Dismissed after adjudication (original commentary) | 1 |
     23 | Never entered triage | 75 |
     24 
     25 ### Licence exposure
     26 
     27 | Situation | Sheets | Currently satisfied? |
     28 |---|---|---|
     29 | MIT upstream — notice must travel with the copy | 2 | **No.** The copyright/permission notice is absent from both sheets and from `/credits`. |
     30 | Upstream with **no licence at all** — no grant of rights to copy | 1 unresolved (`awesome-nmap-grep`, a verbatim copy), plus 3 written to the no-copy handling (the ired.team sheets) | **Unresolved for the verbatim copy; satisfied for the ired.team sheets,** which copy no prose and hotlink rather than reproduce. Credit alone still cures nothing. |
     31 | Proprietary course material — no redistribution licence | 1 confirmed, 1 further sheet identified during report assembly | **No.** |
     32 
     33 **Bottom line:** four sheets need action. Two are an MIT-notice problem that is fixed by adding
     34 credit. Two are *not* fixed by adding credit — one has no licence grant at all, one is proprietary
     35 material — and need a keep/link-only/remove decision from you.
     36 
     37 ### Honest statement of coverage
     38 
     39 This is **not** a clean bill of health for the other 211 sheets. 140 sheets were screened and 5 were
     40 escalated with hard evidence; the 135 that were screened but not escalated were judged to be generic
     41 tool documentation or unattributable command references, which is the correct call for that material
     42 (see §5). But **75 sheets never entered triage at all**, and the 11 `repo:`-sourced sheets in §3.4
     43 declare a third-party origin in their own frontmatter and were never adjudicated. Treat the counts
     44 above as "what has been proven so far", not "what exists".
     45 
     46 ---
     47 
     48 ## 2. Priority table
     49 
     50 Sorted by urgency: no-licence and proprietary first (credit does not resolve them), then
     51 notice-requiring licences, then everything already resolved.
     52 
     53 | Sheet | Upstream | Author | License | Status | Action |
     54 |---|---|---|---|---|---|
     55 | `enumeration/awesome-nmap-grep.md` | [awesome-nmap-grep](https://github.com/leonjza/awesome-nmap-grep) README | Leon Jacobs ([@leonjza](https://github.com/leonjza)) | **None** — no LICENSE file, repo `license` field is `null`, `/license` API returns 404 | **Confirmed verbatim** — byte-for-byte, MD5 `069f471d9d692e02070a12d8ee0792f1`, 271 lines / 8207 bytes, `diff` reports zero differences | **Decide first.** No grant of rights exists, so republication is not permitted by any licence. Options: (a) ask Leon Jacobs for permission, (b) reduce to a short excerpt + credit + link, (c) replace with a link-only stub, (d) remove. Adding a credit line alone does **not** make this compliant. |
     56 | `enumeration/lfi.md` | [HTB Academy — File Inclusion module](https://academy.hackthebox.com/course/preview/file-inclusion) end-of-module cheat sheet | Hack The Box | **Proprietary**, all rights reserved | **Confirmed verbatim** — row-for-row identical, incl. the session filename `sess_nhhv8i0o6ua4g88bkdl9u1fdsd` and the full File Inclusion Functions matrix | **Remove or replace with a link.** HTB course material is not licensed for redistribution; credit does not create a licence. Recommended: delete the sheet and link the module, or rewrite from scratch in your own words. |
     57 | `active-directory/active-directory-cheat-sheet.md` | [Active-Directory-Exploitation-Cheat-Sheet](https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet) README | Nikos Katsiopis & Nikos Vourdas (S1ckB0y1337) | **MIT** — notice required | **Confirmed verbatim** — the only line dropped from upstream is the authorship notice | **Add credit + reproduce the MIT notice.** Restore the dropped line `This repository was created by Nikos Katsiopis and Nikos Vourdas.` or its equivalent, add the frontmatter fields from §4, and add the MIT text to `/credits`. |
     58 | `active-directory/active-directory-attacks.md` | Same upstream (S1ckB0y1337), itself inspired by [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings) | Nikos Katsiopis & Nikos Vourdas; ancestral: Swissky | **MIT** — notice required | **Confirmed derived** — same vault source path as the sheet above; reworded but the DCSync comment, LSA-protection bypass block and "Breaking Forest Trusts" chain track upstream | **Add credit.** Same treatment; mark `upstreamRelation: derived` and name both S1ckB0y1337 and the ancestral PayloadsAllTheThings lineage. |
     59 | `web/file-inclusion.md` | HTB Academy — File Inclusion module (per its own `source: "repo:HTB/cheatsheet-file-inclusion.pdf"`) | Hack The Box | **Proprietary** | **Probable derived** — added during report assembly, not by the triage phases. Verified directly: shares the distinctive HTB payload strings with `enumeration/lfi.md` (`?language=./languages/../../../../etc/passwd`, "Bypass appended extension with path truncation (obsolete)", `[./ REPEATED ~2048 times]`) but is reorganised and rewritten with its own prose. | **Assess alongside `enumeration/lfi.md`.** Provenance is not in doubt — the frontmatter declares it. The open question is only whether the rewriting is substantial enough to stand as your own work. If yes, keep with a "based on" credit; if no, treat as `enumeration/lfi.md`. |
     60 | `enumeration/cheatsheet-infrastructure-enumeration-tools-1.md` | HTB Academy — Footprinting module (topic scaffolding only) | Hack The Box (topic only) | n/a | **Dismissed** — no third-party expression reproduced; the distinctive sentences return no external source and are self-described as the owner's own additions | **None.** HTB Footprinting is already cited in the file's own References section. Listed here so the dismissal is on the record. |
     61 | `exploitation/process-hollowing.md`, `exploitation/dll-injection.md`, `exploitation/thread-execution-hijacking.md` | [ired.team](https://ired.team) / [`mantvydasb/RedTeaming-Tactics-and-Techniques`](https://github.com/mantvydasb/RedTeaming-Tactics-and-Techniques), pinned at `8cdbdd60eb4a8997e689649f3911f7c893e59ed9` | Mantvydas Baranauskas ([@mantvydasb](https://github.com/mantvydasb)) | **None** — no LICENSE file, repo `license` field is `null`, `/license` API returns 404 | **Derived by construction.** No prose copied: these sheets were written fresh against the handling agreed in `docs/superpowers/specs/2026-09-28-ired-team-integration-design.md` §2. Commands, Win32 call sequences and struct offsets are reproduced as technical facts, which upstream's own README disclaims ownership of ("Most of these techniques are discovered by other security researchers and I do not claim their ownership"). The `## Detection` sections are original. | **None outstanding, but the position is conditional.** Screenshots are **hotlinked** at the pinned SHA and never redistributed — 5 figures on `process-hollowing`, 4 on `thread-execution-hijacking`, 2 on `dll-injection`, each individually credited in its `figcaption`. Hotlinking avoids reproduction; it is not a licence. If Mantvydas Baranauskas objects, the figures and sheets come down. The `/credits` plate names him and links the upstream so that request is easy to make. |
     62 
     63 ---
     64 
     65 ## 3. Special cases
     66 
     67 ### 3.1 Upstream with NO licence file — `enumeration/awesome-nmap-grep.md`
     68 
     69 Stated plainly: **`github.com/leonjza/awesome-nmap-grep` carries no licence.** Verified three ways —
     70 `gh api repos/leonjza/awesome-nmap-grep/contents` returns exactly one entry (`README.md`), the
     71 `/license` endpoint returns HTTP 404, and the repo metadata `license` field is `null`. Grepping the
     72 README for `licen|copyright|author|MIT` returns nothing.
     73 
     74 Default copyright therefore applies: **all rights reserved by the author.** There is no permission to
     75 copy, host, or redistribute the file, and no attribution line can manufacture one. This is a
     76 *stronger* problem than the MIT precedent, not a weaker one — with MIT you have permission and merely
     77 failed to carry the notice; here you have no permission.
     78 
     79 The file is currently a perfect byte-for-byte copy, including the author's own captured terminal
     80 output (the macOS `outif lo0` netcat transcript, ephemeral ports 52224/54695/58369, and literal
     81 mojibake in a MariaDB banner) and the self-referential phrase "This repository", which is a tell that
     82 nothing was modified.
     83 
     84 Your options, honestly ranked:
     85 
     86 1. **Ask.** Open an issue on the repo or email Leon Jacobs asking for permission to mirror with
     87    credit. Many authors say yes immediately. Until he does, do not publish a credit line that claims
     88    "used with permission" — that would be untrue.
     89 2. **Excerpt.** Keep a handful of the grep one-liners with a prominent credit and a link. Short
     90    excerpts with attribution are a much smaller ask than a full mirror.
     91 3. **Link-only stub.** Replace the body with a description and a link to the upstream repo.
     92 4. **Remove.**
     93 
     94 Do **not** simply add a credit banner and leave the full copy up — that fixes the ethics and not the
     95 licensing.
     96 
     97 ### 3.2 Proprietary / non-redistributable upstream — the HTB Academy material
     98 
     99 `enumeration/lfi.md` is confirmed as a reproduction of an HTB Academy end-of-module cheat sheet. HTB
    100 Academy content is paid, proprietary course material; there is no redistribution licence, and
    101 crediting HTB does not create one. `web/file-inclusion.md` derives from the same module.
    102 
    103 The realistic remedy is to link to the module rather than reproduce it, or to rewrite the material in
    104 your own words from primary sources (PHP docs, OWASP) so the expression is yours. Note the underlying
    105 *techniques* are not ownable — LFI traversal is public knowledge. What is ownable is HTB's particular
    106 selection, ordering, table layout and example values, which is exactly what was copied.
    107 
    108 ### 3.3 Copyleft or non-commercial upstreams
    109 
    110 **None found.** No adjudicated sheet traces to a GPL, AGPL, CC-BY-SA or CC-BY-NC source. Nothing in
    111 the confirmed set constrains rehosting through share-alike or non-commercial terms.
    112 
    113 ### 3.4 Sheets that declare a third-party origin but were never adjudicated
    114 
    115 Eleven sheets carry `source: "repo:…"` rather than `source: "vault:…"`. These are self-declared
    116 imports from an external cheatsheet collection and **none of them appear in the triage results.**
    117 This is the largest known gap in the audit.
    118 
    119 | Sheet | Declared source | Note |
    120 |---|---|---|
    121 | `web/file-inclusion.md` | `repo:HTB/cheatsheet-file-inclusion.pdf` | Assessed in §2 — HTB, probable derived |
    122 | `web/sql-injection.md` | `repo:HTB/cheatsheet-sql-injection-fundamentals.pdf` | HTB Academy module cheat sheet; also mentions hackthebox in-body |
    123 | `tools/file-transfers.md` | `repo:HTB/cheatsheet-file-transfers.pdf` | HTB Academy module cheat sheet |
    124 | `exploitation/buffer-overflow.md` | `repo:HTB/cheatsheet-stack-based-buffer-overflows-on-windows-x86.pdf` | HTB Academy module cheat sheet |
    125 | `password-attacks/password-attacks.md` | `repo:Password-Attacks/Password_Attacks_Cheat_Sheet.pdf` | Not labelled HTB, but contains `InlaneFreight` — HTB's lab domain — which is a strong HTB tell |
    126 | `cryptography/openssl.md` | `repo:Misc/openssl-cheatsheet.pdf` | Origin of the PDF unknown |
    127 | `linux-it/chmod.md` | `repo:Linux/chmod-cheatsheet.pdf` | Origin of the PDF unknown |
    128 | `active-directory/impacket.md` | `repo:Active-Directory/Impacket_Cheatsheet.md` | Origin unknown; "Cheatsheet" filenames of this shape usually come from a named author |
    129 | `active-directory/certipy.md` | `repo:Active-Directory/Certipy-ad.md` | Origin unknown |
    130 | `active-directory/bloodhound.md` | `repo:Active-Directory/BloodHound-Python_Cheatsheet.md` | Origin unknown |
    131 | `enumeration/shodan.md` | `repo:Enumeration/Shodan_Cheatsheet.md` | Origin unknown |
    132 
    133 Four of these name HTB explicitly and a fifth carries HTB's lab domain — the same proprietary-source
    134 problem as §3.2, five more times over. **Recommend a follow-up pass over these eleven before shipping
    135 any attribution changes**, since the frontmatter has effectively already admitted the provenance and
    136 only the upstream identity and degree of copying remain to be established.
    137 
    138 One mitigation worth recording: the `pdf:` frontmatter field exists in the schema and
    139 `src/pages/sheets/[...slug].astro` will embed a PDF viewer for it, but **no sheet currently sets
    140 `pdf:` and `public/pdfs/` does not exist** — so the source PDFs themselves are not being
    141 redistributed. Only the transcribed markdown is.
    142 
    143 ### 3.5 Disagreements or thin evidence
    144 
    145 - **No two-agent disagreement occurred.** All five adjudications were unanimous.
    146 - **Thinnest evidence in the confirmed set:** `active-directory/active-directory-attacks.md`. It is
    147   reworded rather than copied, so the case rests on shared vault provenance with the confirmed sheet
    148   plus matching distinctive comment strings and section chains — strong, but a step below the
    149   byte-for-byte proof behind the other three. `derived` is the right label; do not describe it as a
    150   verbatim copy.
    151 - **`web/file-inclusion.md` is my own addition**, found while assembling this report, and has not
    152   been through the two triage phases. I verified the shared HTB strings directly; I have **not**
    153   compared it against the HTB PDF line by line. Confidence: high that HTB is the source (its own
    154   frontmatter says so), moderate on whether it is "derived" versus genuinely rewritten.
    155 - **Nothing was flagged on `licenseRequiresNotice` grounds without checking the actual upstream
    156   licence.** In one case the earlier triage assumed MIT for `awesome-nmap-grep` and that assumption
    157   was wrong — the repo has no licence — which is why §3.1 is more serious than a missing credit line.
    158 
    159 ---
    160 
    161 ## 4. Recommended mechanism
    162 
    163 The site already has a working attribution pattern for the mirrors. Extend it to `sheets` rather than
    164 inventing anything new.
    165 
    166 ### 4.1 Schema — `src/content.config.ts`
    167 
    168 Add to the `sheets` collection schema (after the existing `source` field on line 24). Keep `source`
    169 as-is; it records the vault path and is orthogonal.
    170 
    171 ```ts
    172     source: z.string().optional(),
    173 
    174     // --- Third-party attribution ---------------------------------------
    175     // Set together. `upstreamRelation` gates the whole block: if it is
    176     // present, the rest is required (enforced by superRefine below).
    177     upstreamName: z.string().optional(),        // "Active Directory Exploitation Cheat Sheet"
    178     upstreamUrl: z.string().url().optional(),   // canonical upstream location
    179     upstreamAuthor: z.string().optional(),      // "Nikos Katsiopis & Nikos Vourdas (S1ckB0y1337)"
    180     upstreamLicense: z                          // SPDX id, or the two honest non-ids
    181       .enum([
    182         'MIT', 'BSD-2-Clause', 'BSD-3-Clause', 'Apache-2.0',
    183         'CC-BY-4.0', 'CC-BY-SA-4.0', 'GPL-3.0-only',
    184         'none',        // upstream publishes NO licence — no grant of rights
    185         'proprietary', // course material, vendor docs, all rights reserved
    186       ])
    187       .optional(),
    188     upstreamRelation: z.enum(['verbatim', 'derived', 'inspired']).optional(),
    189     // Verbatim copyright line to reproduce, e.g. "Copyright (c) 2020 Nikos Katsiopis".
    190     // Required for MIT/BSD/Apache — this is the notice the licence says must travel.
    191     upstreamNotice: z.string().optional(),
    192     // Rights status for licences that grant nothing on their own.
    193     upstreamPermission: z.enum(['licensed', 'granted', 'pending', 'none']).optional(),
    194 ```
    195 
    196 …and close the object with a `superRefine` so a half-filled credit fails the build instead of
    197 shipping a misleading banner:
    198 
    199 ```ts
    200   }).superRefine((d, ctx) => {
    201     if (!d.upstreamRelation) return;
    202     for (const f of ['upstreamName', 'upstreamUrl', 'upstreamAuthor', 'upstreamLicense'] as const) {
    203       if (!d[f]) ctx.addIssue({ code: 'custom', path: [f], message: `${f} is required when upstreamRelation is set` });
    204     }
    205     const noticeRequired = ['MIT', 'BSD-2-Clause', 'BSD-3-Clause', 'Apache-2.0'];
    206     if (d.upstreamLicense && noticeRequired.includes(d.upstreamLicense) && !d.upstreamNotice) {
    207       ctx.addIssue({ code: 'custom', path: ['upstreamNotice'], message: `${d.upstreamLicense} requires the copyright notice to be reproduced` });
    208     }
    209     if ((d.upstreamLicense === 'none' || d.upstreamLicense === 'proprietary') && !d.upstreamPermission) {
    210       ctx.addIssue({ code: 'custom', path: ['upstreamPermission'], message: 'set upstreamPermission — this licence grants no redistribution right on its own' });
    211     }
    212   }),
    213 ```
    214 
    215 Note `defineCollection` schemas accept a `ZodEffects` from `superRefine`, but the object must be
    216 built before `.superRefine()` is chained — keep the existing `z.object({ … })` and chain onto it.
    217 
    218 ### 4.2 Per-sheet banner — new `src/components/SheetCredit.astro`
    219 
    220 Model it on `src/components/PayloadCredit.astro` and reuse the same class names (`patt-credit`,
    221 `patt-badge`, `patt-credit__text`, `patt-lic`, `patt-src`) so no new CSS is needed.
    222 
    223 ```astro
    224 ---
    225 import Icon from './Icon.astro';
    226 import { url } from '../lib/url';
    227 interface Props {
    228   name: string; upstreamUrl: string; author: string;
    229   license: string; relation: 'verbatim' | 'derived' | 'inspired';
    230   notice?: string; permission?: string;
    231 }
    232 const { name, upstreamUrl, author, license, relation, notice, permission } = Astro.props;
    233 const verb = relation === 'verbatim' ? 'Reproduced from'
    234            : relation === 'derived'  ? 'Derived from'
    235            :                           'Based on';
    236 const warn = license === 'none' || license === 'proprietary';
    237 ---
    238 <aside class="patt-credit" aria-label="Attribution" data-warn={warn ? '' : null}>
    239   <span class="patt-badge">{relation}</span>
    240   <span class="patt-credit__text">
    241     {verb} <a href={upstreamUrl} target="_blank" rel="noopener">{name}</a> by <strong>{author}</strong>
    242     <span class="patt-lic">
    243       {license === 'none' ? 'no licence' : license}
    244       {notice && <> · {notice}</>}
    245       {permission === 'granted' && <> · used with permission</>}
    246       · <a href={url('credits')}>credits</a>
    247     </span>
    248   </span>
    249   <a class="patt-src" href={upstreamUrl} target="_blank" rel="noopener" aria-label="View upstream source">
    250     <Icon name="github" style="width:15px;height:15px;" /> source
    251   </a>
    252 </aside>
    253 ```
    254 
    255 Render it in `src/pages/sheets/[...slug].astro`, inside `<article class="prose" data-pagefind-body>`
    256 immediately **before** the existing `{pdfHref && …}` block (currently around line 59), so the credit
    257 sits above the content and above the fold:
    258 
    259 ```astro
    260 {d.upstreamUrl && (
    261   <SheetCredit
    262     name={d.upstreamName!} upstreamUrl={d.upstreamUrl} author={d.upstreamAuthor!}
    263     license={d.upstreamLicense!} relation={d.upstreamRelation!}
    264     notice={d.upstreamNotice} permission={d.upstreamPermission}
    265   />
    266 )}
    267 ```
    268 
    269 Add the import next to the existing `Icon` import at the top of that file.
    270 
    271 ### 4.3 Credits page — `src/pages/credits.astro`
    272 
    273 Two changes.
    274 
    275 **(a) Fix the currently-inaccurate paragraph.** Lines 96–101 say sheets "credit their upstream source
    276 in frontmatter where applicable" — today none of them do. Replace with a statement of what is
    277 actually true once the fields land.
    278 
    279 **(b) Add a "Third-party cheatsheets" section** between the existing
    280 `<h2>The DÆMON//SEC cheatsheets</h2>` block and `<h2>This site</h2>`, driven by a new helper in
    281 `src/lib/sheets.ts`:
    282 
    283 ```ts
    284 // src/lib/sheets.ts
    285 export async function attributedSheets() {
    286   const all = await getCollection('sheets');
    287   const withCredit = all.filter((e) => e.data.upstreamUrl);
    288   const byUpstream = new Map<string, { data: any; sheets: typeof withCredit }>();
    289   for (const e of withCredit) {
    290     const k = e.data.upstreamUrl!;
    291     if (!byUpstream.has(k)) byUpstream.set(k, { data: e.data, sheets: [] });
    292     byUpstream.get(k)!.sheets.push(e);
    293   }
    294   return [...byUpstream.values()].sort((a, b) => a.data.upstreamName.localeCompare(b.data.upstreamName));
    295 }
    296 ```
    297 
    298 The section should render, per upstream: name + link, author, licence, relation, the sheets that
    299 derive from it (linked via `sheetHref`), and — for MIT/BSD/Apache — the **full licence text**, using
    300 the same `<figure class="code-pane">` treatment already used for the Swissky MIT block at lines
    301 67–73. That full-text block is what actually discharges the MIT obligation that "the above copyright
    302 notice and this permission notice shall be included in all copies or substantial portions"; a link
    303 alone is weaker.
    304 
    305 For `upstreamLicense: 'none'` and `'proprietary'` entries the section should say so in plain language
    306 rather than listing a licence — mirroring the honest wording already used for InternalAllTheThings on
    307 line 86 ("the repository publishes no LICENSE file, so no licence is claimed or implied here"), which
    308 is a good precedent and should be the template.
    309 
    310 ### 4.4 Frontmatter to apply, per sheet
    311 
    312 Paste-ready, assuming you keep the sheets. For the two that need a rights decision first, the block
    313 is written as it would be *after* permission is obtained — do not commit those until it is.
    314 
    315 `src/content/sheets/active-directory/active-directory-cheat-sheet.md`:
    316 
    317 ```yaml
    318 upstreamName: "Active Directory Exploitation Cheat Sheet"
    319 upstreamUrl: "https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet"
    320 upstreamAuthor: "Nikos Katsiopis & Nikos Vourdas (S1ckB0y1337)"
    321 upstreamLicense: "MIT"
    322 upstreamRelation: "verbatim"
    323 upstreamNotice: "Copyright (c) 2020 Nikos Katsiopis"
    324 upstreamPermission: "licensed"
    325 ```
    326 
    327 Also restore the authorship line that was dropped from the upstream README body.
    328 
    329 `src/content/sheets/active-directory/active-directory-attacks.md`:
    330 
    331 ```yaml
    332 upstreamName: "Active Directory Exploitation Cheat Sheet"
    333 upstreamUrl: "https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet"
    334 upstreamAuthor: "Nikos Katsiopis & Nikos Vourdas (S1ckB0y1337); ancestral source: Swissky / PayloadsAllTheThings"
    335 upstreamLicense: "MIT"
    336 upstreamRelation: "derived"
    337 upstreamNotice: "Copyright (c) 2020 Nikos Katsiopis"
    338 upstreamPermission: "licensed"
    339 ```
    340 
    341 `src/content/sheets/enumeration/awesome-nmap-grep.md` — **only after Leon Jacobs agrees**:
    342 
    343 ```yaml
    344 upstreamName: "awesome-nmap-grep"
    345 upstreamUrl: "https://github.com/leonjza/awesome-nmap-grep"
    346 upstreamAuthor: "Leon Jacobs (@leonjza)"
    347 upstreamLicense: "none"
    348 upstreamRelation: "verbatim"
    349 upstreamPermission: "granted"   # ONLY once actually granted; use "pending" until then
    350 ```
    351 
    352 `src/content/sheets/enumeration/lfi.md` and `src/content/sheets/web/file-inclusion.md` — recommended
    353 outcome is removal or rewrite, not a credit block. If you keep them pending a decision, set
    354 `upstreamLicense: "proprietary"` and `upstreamPermission: "none"` so the banner states the position
    355 honestly and the build does not let it be forgotten.
    356 
    357 ### 4.5 Suggested order of work
    358 
    359 1. Decide the rights questions (§3.1, §3.2) — they may change what gets published at all.
    360 2. Land the schema + component + credits section with the two MIT sheets. That closes the known
    361    compliance gap and creates the mechanism.
    362 3. Run the follow-up pass over the eleven `repo:`-sourced sheets in §3.4.
    363 4. Consider triaging the 75 sheets that never entered triage.
    364 
    365 ---
    366 
    367 ## 5. Explicitly excluded
    368 
    369 The audit deliberately did **not** flag:
    370 
    371 - **The 135 screened-but-not-escalated sheets.** These are command references, tool-flag listings and
    372   syntax tables. `nmap -sV`, `hashcat -m 1000`, `impacket-secretsdump` invocations and the like are
    373   facts about tools, not authorship — they look identical everywhere because there is only one way to
    374   write them. Documenting a public tool is not evidence of copying, and flagging on that basis would
    375   have produced a list too noisy to act on.
    376 - **`enumeration/cheatsheet-infrastructure-enumeration-tools-1.md`**, which reached adjudication and
    377   was cleared. Its distinctive sentences ("This is cleaner than the grep | cut | awk chain in the
    378   original notes", "Expired subdomains are often forgotten by admins") return no external source and
    379   are self-described as the owner's own additions. The crt.sh + `jq` pipeline, `dig` record queries
    380   and Shodan filters are generic recon idioms nobody owns, and the one genuine third-party input —
    381   the HTB Footprinting module's topic scaffolding — is already cited in the file's own References
    382   section. This is what a correct dismissal looks like.
    383 - **The 47 sheets that already carry a `## References` / `## Credits` / `## Sources` section.** These
    384   were not treated as suspicious; existing citation is evidence of good faith, not of copying.
    385 - **Shared technique, structure and terminology.** Kerberoasting is Kerberoasting, and every AD
    386   cheatsheet covers enumeration → roasting → delegation → lateral movement in roughly that order,
    387   because that is the order of the attack. Only *expression* — specific prose, specific example
    388   values, specific selection and layout — was treated as attributable.
    389 
    390 Four sheets out of 215 were flagged. That ratio is the point: the audit looked hard at 140 and found
    391 a small, specific, actionable set rather than blanket-flagging a vault of public security notes.