provenance-audit.md (25826B)
1 # Provenance & Attribution Audit — `src/content/sheets` 2 3 **Date:** 2026-08-13 4 **Scope:** the 215 hand-curated cheatsheets under `src/content/sheets/`. The `payloads/` and 5 `internal/` mirrors are out of scope — they are already attributed on `/credits` and carry a 6 per-page `PayloadCredit` banner. 7 **Purpose:** find third-party content that is currently republished without credit, so it can be 8 credited. This audit exists to *give* attribution, not to remove content quietly. 9 10 --- 11 12 ## 1. Summary 13 14 | | Count | 15 |---|---| 16 | Sheets in `src/content/sheets/` | 215 | 17 | Sheets carrying `source: "vault:…"` (records vault path only — says nothing about origin) | 204 | 18 | Sheets carrying `source: "repo:…"` (self-declared external origin) | 11 | 19 | Screened as candidates across the two triage phases | 140 | 20 | Escalated to evidence-based adjudication | 5 | 21 | **Attributable (verbatim copy or derived) — action required** | **4** | 22 | Dismissed after adjudication (original commentary) | 1 | 23 | Never entered triage | 75 | 24 25 ### Licence exposure 26 27 | Situation | Sheets | Currently satisfied? | 28 |---|---|---| 29 | MIT upstream — notice must travel with the copy | 2 | **No.** The copyright/permission notice is absent from both sheets and from `/credits`. | 30 | Upstream with **no licence at all** — no grant of rights to copy | 1 unresolved (`awesome-nmap-grep`, a verbatim copy), plus 3 written to the no-copy handling (the ired.team sheets) | **Unresolved for the verbatim copy; satisfied for the ired.team sheets,** which copy no prose and hotlink rather than reproduce. Credit alone still cures nothing. | 31 | Proprietary course material — no redistribution licence | 1 confirmed, 1 further sheet identified during report assembly | **No.** | 32 33 **Bottom line:** four sheets need action. Two are an MIT-notice problem that is fixed by adding 34 credit. Two are *not* fixed by adding credit — one has no licence grant at all, one is proprietary 35 material — and need a keep/link-only/remove decision from you. 36 37 ### Honest statement of coverage 38 39 This is **not** a clean bill of health for the other 211 sheets. 140 sheets were screened and 5 were 40 escalated with hard evidence; the 135 that were screened but not escalated were judged to be generic 41 tool documentation or unattributable command references, which is the correct call for that material 42 (see §5). But **75 sheets never entered triage at all**, and the 11 `repo:`-sourced sheets in §3.4 43 declare a third-party origin in their own frontmatter and were never adjudicated. Treat the counts 44 above as "what has been proven so far", not "what exists". 45 46 --- 47 48 ## 2. Priority table 49 50 Sorted by urgency: no-licence and proprietary first (credit does not resolve them), then 51 notice-requiring licences, then everything already resolved. 52 53 | Sheet | Upstream | Author | License | Status | Action | 54 |---|---|---|---|---|---| 55 | `enumeration/awesome-nmap-grep.md` | [awesome-nmap-grep](https://github.com/leonjza/awesome-nmap-grep) README | Leon Jacobs ([@leonjza](https://github.com/leonjza)) | **None** — no LICENSE file, repo `license` field is `null`, `/license` API returns 404 | **Confirmed verbatim** — byte-for-byte, MD5 `069f471d9d692e02070a12d8ee0792f1`, 271 lines / 8207 bytes, `diff` reports zero differences | **Decide first.** No grant of rights exists, so republication is not permitted by any licence. Options: (a) ask Leon Jacobs for permission, (b) reduce to a short excerpt + credit + link, (c) replace with a link-only stub, (d) remove. Adding a credit line alone does **not** make this compliant. | 56 | `enumeration/lfi.md` | [HTB Academy — File Inclusion module](https://academy.hackthebox.com/course/preview/file-inclusion) end-of-module cheat sheet | Hack The Box | **Proprietary**, all rights reserved | **Confirmed verbatim** — row-for-row identical, incl. the session filename `sess_nhhv8i0o6ua4g88bkdl9u1fdsd` and the full File Inclusion Functions matrix | **Remove or replace with a link.** HTB course material is not licensed for redistribution; credit does not create a licence. Recommended: delete the sheet and link the module, or rewrite from scratch in your own words. | 57 | `active-directory/active-directory-cheat-sheet.md` | [Active-Directory-Exploitation-Cheat-Sheet](https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet) README | Nikos Katsiopis & Nikos Vourdas (S1ckB0y1337) | **MIT** — notice required | **Confirmed verbatim** — the only line dropped from upstream is the authorship notice | **Add credit + reproduce the MIT notice.** Restore the dropped line `This repository was created by Nikos Katsiopis and Nikos Vourdas.` or its equivalent, add the frontmatter fields from §4, and add the MIT text to `/credits`. | 58 | `active-directory/active-directory-attacks.md` | Same upstream (S1ckB0y1337), itself inspired by [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings) | Nikos Katsiopis & Nikos Vourdas; ancestral: Swissky | **MIT** — notice required | **Confirmed derived** — same vault source path as the sheet above; reworded but the DCSync comment, LSA-protection bypass block and "Breaking Forest Trusts" chain track upstream | **Add credit.** Same treatment; mark `upstreamRelation: derived` and name both S1ckB0y1337 and the ancestral PayloadsAllTheThings lineage. | 59 | `web/file-inclusion.md` | HTB Academy — File Inclusion module (per its own `source: "repo:HTB/cheatsheet-file-inclusion.pdf"`) | Hack The Box | **Proprietary** | **Probable derived** — added during report assembly, not by the triage phases. Verified directly: shares the distinctive HTB payload strings with `enumeration/lfi.md` (`?language=./languages/../../../../etc/passwd`, "Bypass appended extension with path truncation (obsolete)", `[./ REPEATED ~2048 times]`) but is reorganised and rewritten with its own prose. | **Assess alongside `enumeration/lfi.md`.** Provenance is not in doubt — the frontmatter declares it. The open question is only whether the rewriting is substantial enough to stand as your own work. If yes, keep with a "based on" credit; if no, treat as `enumeration/lfi.md`. | 60 | `enumeration/cheatsheet-infrastructure-enumeration-tools-1.md` | HTB Academy — Footprinting module (topic scaffolding only) | Hack The Box (topic only) | n/a | **Dismissed** — no third-party expression reproduced; the distinctive sentences return no external source and are self-described as the owner's own additions | **None.** HTB Footprinting is already cited in the file's own References section. Listed here so the dismissal is on the record. | 61 | `exploitation/process-hollowing.md`, `exploitation/dll-injection.md`, `exploitation/thread-execution-hijacking.md` | [ired.team](https://ired.team) / [`mantvydasb/RedTeaming-Tactics-and-Techniques`](https://github.com/mantvydasb/RedTeaming-Tactics-and-Techniques), pinned at `8cdbdd60eb4a8997e689649f3911f7c893e59ed9` | Mantvydas Baranauskas ([@mantvydasb](https://github.com/mantvydasb)) | **None** — no LICENSE file, repo `license` field is `null`, `/license` API returns 404 | **Derived by construction.** No prose copied: these sheets were written fresh against the handling agreed in `docs/superpowers/specs/2026-09-28-ired-team-integration-design.md` §2. Commands, Win32 call sequences and struct offsets are reproduced as technical facts, which upstream's own README disclaims ownership of ("Most of these techniques are discovered by other security researchers and I do not claim their ownership"). The `## Detection` sections are original. | **None outstanding, but the position is conditional.** Screenshots are **hotlinked** at the pinned SHA and never redistributed — 5 figures on `process-hollowing`, 4 on `thread-execution-hijacking`, 2 on `dll-injection`, each individually credited in its `figcaption`. Hotlinking avoids reproduction; it is not a licence. If Mantvydas Baranauskas objects, the figures and sheets come down. The `/credits` plate names him and links the upstream so that request is easy to make. | 62 63 --- 64 65 ## 3. Special cases 66 67 ### 3.1 Upstream with NO licence file — `enumeration/awesome-nmap-grep.md` 68 69 Stated plainly: **`github.com/leonjza/awesome-nmap-grep` carries no licence.** Verified three ways — 70 `gh api repos/leonjza/awesome-nmap-grep/contents` returns exactly one entry (`README.md`), the 71 `/license` endpoint returns HTTP 404, and the repo metadata `license` field is `null`. Grepping the 72 README for `licen|copyright|author|MIT` returns nothing. 73 74 Default copyright therefore applies: **all rights reserved by the author.** There is no permission to 75 copy, host, or redistribute the file, and no attribution line can manufacture one. This is a 76 *stronger* problem than the MIT precedent, not a weaker one — with MIT you have permission and merely 77 failed to carry the notice; here you have no permission. 78 79 The file is currently a perfect byte-for-byte copy, including the author's own captured terminal 80 output (the macOS `outif lo0` netcat transcript, ephemeral ports 52224/54695/58369, and literal 81 mojibake in a MariaDB banner) and the self-referential phrase "This repository", which is a tell that 82 nothing was modified. 83 84 Your options, honestly ranked: 85 86 1. **Ask.** Open an issue on the repo or email Leon Jacobs asking for permission to mirror with 87 credit. Many authors say yes immediately. Until he does, do not publish a credit line that claims 88 "used with permission" — that would be untrue. 89 2. **Excerpt.** Keep a handful of the grep one-liners with a prominent credit and a link. Short 90 excerpts with attribution are a much smaller ask than a full mirror. 91 3. **Link-only stub.** Replace the body with a description and a link to the upstream repo. 92 4. **Remove.** 93 94 Do **not** simply add a credit banner and leave the full copy up — that fixes the ethics and not the 95 licensing. 96 97 ### 3.2 Proprietary / non-redistributable upstream — the HTB Academy material 98 99 `enumeration/lfi.md` is confirmed as a reproduction of an HTB Academy end-of-module cheat sheet. HTB 100 Academy content is paid, proprietary course material; there is no redistribution licence, and 101 crediting HTB does not create one. `web/file-inclusion.md` derives from the same module. 102 103 The realistic remedy is to link to the module rather than reproduce it, or to rewrite the material in 104 your own words from primary sources (PHP docs, OWASP) so the expression is yours. Note the underlying 105 *techniques* are not ownable — LFI traversal is public knowledge. What is ownable is HTB's particular 106 selection, ordering, table layout and example values, which is exactly what was copied. 107 108 ### 3.3 Copyleft or non-commercial upstreams 109 110 **None found.** No adjudicated sheet traces to a GPL, AGPL, CC-BY-SA or CC-BY-NC source. Nothing in 111 the confirmed set constrains rehosting through share-alike or non-commercial terms. 112 113 ### 3.4 Sheets that declare a third-party origin but were never adjudicated 114 115 Eleven sheets carry `source: "repo:…"` rather than `source: "vault:…"`. These are self-declared 116 imports from an external cheatsheet collection and **none of them appear in the triage results.** 117 This is the largest known gap in the audit. 118 119 | Sheet | Declared source | Note | 120 |---|---|---| 121 | `web/file-inclusion.md` | `repo:HTB/cheatsheet-file-inclusion.pdf` | Assessed in §2 — HTB, probable derived | 122 | `web/sql-injection.md` | `repo:HTB/cheatsheet-sql-injection-fundamentals.pdf` | HTB Academy module cheat sheet; also mentions hackthebox in-body | 123 | `tools/file-transfers.md` | `repo:HTB/cheatsheet-file-transfers.pdf` | HTB Academy module cheat sheet | 124 | `exploitation/buffer-overflow.md` | `repo:HTB/cheatsheet-stack-based-buffer-overflows-on-windows-x86.pdf` | HTB Academy module cheat sheet | 125 | `password-attacks/password-attacks.md` | `repo:Password-Attacks/Password_Attacks_Cheat_Sheet.pdf` | Not labelled HTB, but contains `InlaneFreight` — HTB's lab domain — which is a strong HTB tell | 126 | `cryptography/openssl.md` | `repo:Misc/openssl-cheatsheet.pdf` | Origin of the PDF unknown | 127 | `linux-it/chmod.md` | `repo:Linux/chmod-cheatsheet.pdf` | Origin of the PDF unknown | 128 | `active-directory/impacket.md` | `repo:Active-Directory/Impacket_Cheatsheet.md` | Origin unknown; "Cheatsheet" filenames of this shape usually come from a named author | 129 | `active-directory/certipy.md` | `repo:Active-Directory/Certipy-ad.md` | Origin unknown | 130 | `active-directory/bloodhound.md` | `repo:Active-Directory/BloodHound-Python_Cheatsheet.md` | Origin unknown | 131 | `enumeration/shodan.md` | `repo:Enumeration/Shodan_Cheatsheet.md` | Origin unknown | 132 133 Four of these name HTB explicitly and a fifth carries HTB's lab domain — the same proprietary-source 134 problem as §3.2, five more times over. **Recommend a follow-up pass over these eleven before shipping 135 any attribution changes**, since the frontmatter has effectively already admitted the provenance and 136 only the upstream identity and degree of copying remain to be established. 137 138 One mitigation worth recording: the `pdf:` frontmatter field exists in the schema and 139 `src/pages/sheets/[...slug].astro` will embed a PDF viewer for it, but **no sheet currently sets 140 `pdf:` and `public/pdfs/` does not exist** — so the source PDFs themselves are not being 141 redistributed. Only the transcribed markdown is. 142 143 ### 3.5 Disagreements or thin evidence 144 145 - **No two-agent disagreement occurred.** All five adjudications were unanimous. 146 - **Thinnest evidence in the confirmed set:** `active-directory/active-directory-attacks.md`. It is 147 reworded rather than copied, so the case rests on shared vault provenance with the confirmed sheet 148 plus matching distinctive comment strings and section chains — strong, but a step below the 149 byte-for-byte proof behind the other three. `derived` is the right label; do not describe it as a 150 verbatim copy. 151 - **`web/file-inclusion.md` is my own addition**, found while assembling this report, and has not 152 been through the two triage phases. I verified the shared HTB strings directly; I have **not** 153 compared it against the HTB PDF line by line. Confidence: high that HTB is the source (its own 154 frontmatter says so), moderate on whether it is "derived" versus genuinely rewritten. 155 - **Nothing was flagged on `licenseRequiresNotice` grounds without checking the actual upstream 156 licence.** In one case the earlier triage assumed MIT for `awesome-nmap-grep` and that assumption 157 was wrong — the repo has no licence — which is why §3.1 is more serious than a missing credit line. 158 159 --- 160 161 ## 4. Recommended mechanism 162 163 The site already has a working attribution pattern for the mirrors. Extend it to `sheets` rather than 164 inventing anything new. 165 166 ### 4.1 Schema — `src/content.config.ts` 167 168 Add to the `sheets` collection schema (after the existing `source` field on line 24). Keep `source` 169 as-is; it records the vault path and is orthogonal. 170 171 ```ts 172 source: z.string().optional(), 173 174 // --- Third-party attribution --------------------------------------- 175 // Set together. `upstreamRelation` gates the whole block: if it is 176 // present, the rest is required (enforced by superRefine below). 177 upstreamName: z.string().optional(), // "Active Directory Exploitation Cheat Sheet" 178 upstreamUrl: z.string().url().optional(), // canonical upstream location 179 upstreamAuthor: z.string().optional(), // "Nikos Katsiopis & Nikos Vourdas (S1ckB0y1337)" 180 upstreamLicense: z // SPDX id, or the two honest non-ids 181 .enum([ 182 'MIT', 'BSD-2-Clause', 'BSD-3-Clause', 'Apache-2.0', 183 'CC-BY-4.0', 'CC-BY-SA-4.0', 'GPL-3.0-only', 184 'none', // upstream publishes NO licence — no grant of rights 185 'proprietary', // course material, vendor docs, all rights reserved 186 ]) 187 .optional(), 188 upstreamRelation: z.enum(['verbatim', 'derived', 'inspired']).optional(), 189 // Verbatim copyright line to reproduce, e.g. "Copyright (c) 2020 Nikos Katsiopis". 190 // Required for MIT/BSD/Apache — this is the notice the licence says must travel. 191 upstreamNotice: z.string().optional(), 192 // Rights status for licences that grant nothing on their own. 193 upstreamPermission: z.enum(['licensed', 'granted', 'pending', 'none']).optional(), 194 ``` 195 196 …and close the object with a `superRefine` so a half-filled credit fails the build instead of 197 shipping a misleading banner: 198 199 ```ts 200 }).superRefine((d, ctx) => { 201 if (!d.upstreamRelation) return; 202 for (const f of ['upstreamName', 'upstreamUrl', 'upstreamAuthor', 'upstreamLicense'] as const) { 203 if (!d[f]) ctx.addIssue({ code: 'custom', path: [f], message: `${f} is required when upstreamRelation is set` }); 204 } 205 const noticeRequired = ['MIT', 'BSD-2-Clause', 'BSD-3-Clause', 'Apache-2.0']; 206 if (d.upstreamLicense && noticeRequired.includes(d.upstreamLicense) && !d.upstreamNotice) { 207 ctx.addIssue({ code: 'custom', path: ['upstreamNotice'], message: `${d.upstreamLicense} requires the copyright notice to be reproduced` }); 208 } 209 if ((d.upstreamLicense === 'none' || d.upstreamLicense === 'proprietary') && !d.upstreamPermission) { 210 ctx.addIssue({ code: 'custom', path: ['upstreamPermission'], message: 'set upstreamPermission — this licence grants no redistribution right on its own' }); 211 } 212 }), 213 ``` 214 215 Note `defineCollection` schemas accept a `ZodEffects` from `superRefine`, but the object must be 216 built before `.superRefine()` is chained — keep the existing `z.object({ … })` and chain onto it. 217 218 ### 4.2 Per-sheet banner — new `src/components/SheetCredit.astro` 219 220 Model it on `src/components/PayloadCredit.astro` and reuse the same class names (`patt-credit`, 221 `patt-badge`, `patt-credit__text`, `patt-lic`, `patt-src`) so no new CSS is needed. 222 223 ```astro 224 --- 225 import Icon from './Icon.astro'; 226 import { url } from '../lib/url'; 227 interface Props { 228 name: string; upstreamUrl: string; author: string; 229 license: string; relation: 'verbatim' | 'derived' | 'inspired'; 230 notice?: string; permission?: string; 231 } 232 const { name, upstreamUrl, author, license, relation, notice, permission } = Astro.props; 233 const verb = relation === 'verbatim' ? 'Reproduced from' 234 : relation === 'derived' ? 'Derived from' 235 : 'Based on'; 236 const warn = license === 'none' || license === 'proprietary'; 237 --- 238 <aside class="patt-credit" aria-label="Attribution" data-warn={warn ? '' : null}> 239 <span class="patt-badge">{relation}</span> 240 <span class="patt-credit__text"> 241 {verb} <a href={upstreamUrl} target="_blank" rel="noopener">{name}</a> by <strong>{author}</strong> 242 <span class="patt-lic"> 243 {license === 'none' ? 'no licence' : license} 244 {notice && <> · {notice}</>} 245 {permission === 'granted' && <> · used with permission</>} 246 · <a href={url('credits')}>credits</a> 247 </span> 248 </span> 249 <a class="patt-src" href={upstreamUrl} target="_blank" rel="noopener" aria-label="View upstream source"> 250 <Icon name="github" style="width:15px;height:15px;" /> source 251 </a> 252 </aside> 253 ``` 254 255 Render it in `src/pages/sheets/[...slug].astro`, inside `<article class="prose" data-pagefind-body>` 256 immediately **before** the existing `{pdfHref && …}` block (currently around line 59), so the credit 257 sits above the content and above the fold: 258 259 ```astro 260 {d.upstreamUrl && ( 261 <SheetCredit 262 name={d.upstreamName!} upstreamUrl={d.upstreamUrl} author={d.upstreamAuthor!} 263 license={d.upstreamLicense!} relation={d.upstreamRelation!} 264 notice={d.upstreamNotice} permission={d.upstreamPermission} 265 /> 266 )} 267 ``` 268 269 Add the import next to the existing `Icon` import at the top of that file. 270 271 ### 4.3 Credits page — `src/pages/credits.astro` 272 273 Two changes. 274 275 **(a) Fix the currently-inaccurate paragraph.** Lines 96–101 say sheets "credit their upstream source 276 in frontmatter where applicable" — today none of them do. Replace with a statement of what is 277 actually true once the fields land. 278 279 **(b) Add a "Third-party cheatsheets" section** between the existing 280 `<h2>The DÆMON//SEC cheatsheets</h2>` block and `<h2>This site</h2>`, driven by a new helper in 281 `src/lib/sheets.ts`: 282 283 ```ts 284 // src/lib/sheets.ts 285 export async function attributedSheets() { 286 const all = await getCollection('sheets'); 287 const withCredit = all.filter((e) => e.data.upstreamUrl); 288 const byUpstream = new Map<string, { data: any; sheets: typeof withCredit }>(); 289 for (const e of withCredit) { 290 const k = e.data.upstreamUrl!; 291 if (!byUpstream.has(k)) byUpstream.set(k, { data: e.data, sheets: [] }); 292 byUpstream.get(k)!.sheets.push(e); 293 } 294 return [...byUpstream.values()].sort((a, b) => a.data.upstreamName.localeCompare(b.data.upstreamName)); 295 } 296 ``` 297 298 The section should render, per upstream: name + link, author, licence, relation, the sheets that 299 derive from it (linked via `sheetHref`), and — for MIT/BSD/Apache — the **full licence text**, using 300 the same `<figure class="code-pane">` treatment already used for the Swissky MIT block at lines 301 67–73. That full-text block is what actually discharges the MIT obligation that "the above copyright 302 notice and this permission notice shall be included in all copies or substantial portions"; a link 303 alone is weaker. 304 305 For `upstreamLicense: 'none'` and `'proprietary'` entries the section should say so in plain language 306 rather than listing a licence — mirroring the honest wording already used for InternalAllTheThings on 307 line 86 ("the repository publishes no LICENSE file, so no licence is claimed or implied here"), which 308 is a good precedent and should be the template. 309 310 ### 4.4 Frontmatter to apply, per sheet 311 312 Paste-ready, assuming you keep the sheets. For the two that need a rights decision first, the block 313 is written as it would be *after* permission is obtained — do not commit those until it is. 314 315 `src/content/sheets/active-directory/active-directory-cheat-sheet.md`: 316 317 ```yaml 318 upstreamName: "Active Directory Exploitation Cheat Sheet" 319 upstreamUrl: "https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet" 320 upstreamAuthor: "Nikos Katsiopis & Nikos Vourdas (S1ckB0y1337)" 321 upstreamLicense: "MIT" 322 upstreamRelation: "verbatim" 323 upstreamNotice: "Copyright (c) 2020 Nikos Katsiopis" 324 upstreamPermission: "licensed" 325 ``` 326 327 Also restore the authorship line that was dropped from the upstream README body. 328 329 `src/content/sheets/active-directory/active-directory-attacks.md`: 330 331 ```yaml 332 upstreamName: "Active Directory Exploitation Cheat Sheet" 333 upstreamUrl: "https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet" 334 upstreamAuthor: "Nikos Katsiopis & Nikos Vourdas (S1ckB0y1337); ancestral source: Swissky / PayloadsAllTheThings" 335 upstreamLicense: "MIT" 336 upstreamRelation: "derived" 337 upstreamNotice: "Copyright (c) 2020 Nikos Katsiopis" 338 upstreamPermission: "licensed" 339 ``` 340 341 `src/content/sheets/enumeration/awesome-nmap-grep.md` — **only after Leon Jacobs agrees**: 342 343 ```yaml 344 upstreamName: "awesome-nmap-grep" 345 upstreamUrl: "https://github.com/leonjza/awesome-nmap-grep" 346 upstreamAuthor: "Leon Jacobs (@leonjza)" 347 upstreamLicense: "none" 348 upstreamRelation: "verbatim" 349 upstreamPermission: "granted" # ONLY once actually granted; use "pending" until then 350 ``` 351 352 `src/content/sheets/enumeration/lfi.md` and `src/content/sheets/web/file-inclusion.md` — recommended 353 outcome is removal or rewrite, not a credit block. If you keep them pending a decision, set 354 `upstreamLicense: "proprietary"` and `upstreamPermission: "none"` so the banner states the position 355 honestly and the build does not let it be forgotten. 356 357 ### 4.5 Suggested order of work 358 359 1. Decide the rights questions (§3.1, §3.2) — they may change what gets published at all. 360 2. Land the schema + component + credits section with the two MIT sheets. That closes the known 361 compliance gap and creates the mechanism. 362 3. Run the follow-up pass over the eleven `repo:`-sourced sheets in §3.4. 363 4. Consider triaging the 75 sheets that never entered triage. 364 365 --- 366 367 ## 5. Explicitly excluded 368 369 The audit deliberately did **not** flag: 370 371 - **The 135 screened-but-not-escalated sheets.** These are command references, tool-flag listings and 372 syntax tables. `nmap -sV`, `hashcat -m 1000`, `impacket-secretsdump` invocations and the like are 373 facts about tools, not authorship — they look identical everywhere because there is only one way to 374 write them. Documenting a public tool is not evidence of copying, and flagging on that basis would 375 have produced a list too noisy to act on. 376 - **`enumeration/cheatsheet-infrastructure-enumeration-tools-1.md`**, which reached adjudication and 377 was cleared. Its distinctive sentences ("This is cleaner than the grep | cut | awk chain in the 378 original notes", "Expired subdomains are often forgotten by admins") return no external source and 379 are self-described as the owner's own additions. The crt.sh + `jq` pipeline, `dig` record queries 380 and Shodan filters are generic recon idioms nobody owns, and the one genuine third-party input — 381 the HTB Footprinting module's topic scaffolding — is already cited in the file's own References 382 section. This is what a correct dismissal looks like. 383 - **The 47 sheets that already carry a `## References` / `## Credits` / `## Sources` section.** These 384 were not treated as suspicious; existing citation is evidence of good faith, not of copying. 385 - **Shared technique, structure and terminology.** Kerberoasting is Kerberoasting, and every AD 386 cheatsheet covers enumeration → roasting → delegation → lateral movement in roughly that order, 387 because that is the order of the attack. Only *expression* — specific prose, specific example 388 values, specific selection and layout — was treated as attributable. 389 390 Four sheets out of 215 were flagged. That ratio is the point: the audit looked hard at 140 and found 391 a small, specific, actionable set rather than blanket-flagging a vault of public security notes.