daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

taxonomy.ts (2991B)


      1 // Single source of truth for the 14 site domains.
      2 // `accent` maps to a Rose Pine palette token used for the neon edge-glow.
      3 // `tag` is the monospace module label shown on cards ( [AD], [ENUM], ... ).
      4 
      5 export type CategoryDef = {
      6   slug: string;
      7   title: string;
      8   tag: string;
      9   accent: 'iris' | 'foam' | 'love' | 'gold' | 'rose' | 'pine';
     10   blurb: string;
     11 };
     12 
     13 export const CATEGORIES: CategoryDef[] = [
     14   { slug: 'pentest-workflow',     title: 'Pentest Workflow',     tag: 'FLOW',  accent: 'love', blurb: 'CPTS attack-flow playbooks: common services & apps, privesc, web shells, and TTY upgrades.' },
     15   { slug: 'active-directory',     title: 'Active Directory',     tag: 'AD',    accent: 'iris', blurb: 'Kerberos, ADCS, delegation, and domain takeover paths.' },
     16   { slug: 'enumeration',          title: 'Enumeration',          tag: 'ENUM',  accent: 'foam', blurb: 'Port, service, web, and host discovery — mapping the attack surface.' },
     17   { slug: 'osint',                title: 'OSINT',                tag: 'OSINT', accent: 'pine', blurb: 'Open-source investigation: people, places, platforms, imagery, and provenance.' },
     18   { slug: 'exploitation',         title: 'Exploitation',         tag: 'PWN',   accent: 'love', blurb: 'Gaining a foothold: injection, upload, and shell delivery.' },
     19   { slug: 'privilege-escalation', title: 'Privilege Escalation', tag: 'PRIV',  accent: 'gold', blurb: 'From user to root/SYSTEM on Linux and Windows.' },
     20   { slug: 'password-attacks',     title: 'Password Attacks',     tag: 'CRED',  accent: 'rose', blurb: 'Cracking, spraying, and credential recovery.' },
     21   { slug: 'web',                  title: 'Web',                  tag: 'WEB',   accent: 'foam', blurb: 'XSS, injection, and web application testing.' },
     22   { slug: 'tunneling-pivoting',   title: 'Tunneling & Pivoting', tag: 'PIVOT', accent: 'pine', blurb: 'Moving through segmented networks and double pivots.' },
     23   { slug: 'cryptography',         title: 'Cryptography',         tag: 'CRYPTO',accent: 'iris', blurb: 'Hashing, encryption, GPG, and key handling.' },
     24   { slug: 'dfir',                 title: 'DFIR',                 tag: 'DFIR',  accent: 'gold', blurb: 'Forensics, memory, and registry analysis.' },
     25   { slug: 'tools',                title: 'Tools',                tag: 'TOOL',  accent: 'foam', blurb: 'General-purpose offensive tooling and multiplexers.' },
     26   { slug: 'linux-it',             title: 'Linux & IT',           tag: 'NIX',   accent: 'foam', blurb: 'Shell, filesystem, and everyday IT fundamentals.' },
     27   { slug: 'git-workflow',         title: 'Git & Workflow',       tag: 'GIT',   accent: 'rose', blurb: 'Version control and operator workflow.' },
     28 ];
     29 
     30 export const CATEGORY_BY_SLUG: Record<string, CategoryDef> =
     31   Object.fromEntries(CATEGORIES.map((c) => [c.slug, c]));
     32 
     33 export function categoryOf(slug: string): CategoryDef {
     34   return CATEGORY_BY_SLUG[slug] ?? {
     35     slug, title: slug, tag: slug.slice(0, 5).toUpperCase(), accent: 'foam',
     36     blurb: '',
     37   };
     38 }