01DΛΣMӨП
02Cheatsheets
03Offline search
04Copy-ready
0513 shelves
06Zero fluff
Index / operator
Start here.
264 sheets across 13 shelves, plus two full upstream mirrors. The shelves are below; the index itself runs under them.
Offline search Copy-ready Zero fluff
daemon@ref~%vault --status
- sheets
- 264 · curated
- shelves
- 13 · domains
- search
- offline · fuzzy · no tracking
- updated
- 2026.09 · latest
Quick search / 2026
- 13 shelves
- 264 sheets
- 03 mirrors
Reference transmissions
Terse, tested, kept current.
264 sheets across 13 shelves, each stripped to the commands that matter.
01 FLOW NTFS Alternate Data Streams — Hiding & Finding Hidden Data 2026.09.17 Windows NTFS Alternate Data Streams (ADS): what they are, reading and writing them, finding streams other users hid (dir /r, Get-Item -Stream, streams.exe), Mark-of-the-Web, and a worked HTB example of digging a flag out of a stream. Pentest Workflow · htb · cpts 02 FLOW Potato Attacks — SeImpersonate to SYSTEM 2026.09.17 Windows SeImpersonate → SYSTEM with the whole potato family (PrintSpoofer, GodPotato, JuicyPotatoNG, RoguePotato, EfsPotato, SweetPotato): what each abuses, every useful flag, delivery from MSSQL/IIS/WinRM, and a repeatable field method with an HTB Jeeves worked example. Pentest Workflow · htb · cpts 03 PRIV Windows Privilege Escalation 2026.09.17 Windows privesc master guide: token/privilege abuse, services, registry, AlwaysInstallElevated, potatoes. Privilege Escalation · privilege-escalation · windows 04 FLOW Attacking Common Services — Full Guide 2026.09.16 Detailed CPTS walkthrough for enumerating and exploiting the network services that dominate internal and perimeter networks: FTP, SMB, SQL (MySQL/MSSQL), RDP, DNS, and email (SMTP/POP3/IMAP) — anonymous access, default creds, spraying, misconfigurations, and the module's worked CVEs, framed by the Source → Process → Privileges → Destination model. Pentest Workflow · htb · cpts 05 ENUM feroxbuster 2026.09.15 feroxbuster recursive content discovery — recursion by default, link extraction, response auto-filtering, and rich matchers/filters. Enumeration · enumeration · web 06 CRED Linux Credential & Flag Hunting 2026.09.14 Find flags, passwords, keys and secrets on Linux: find/grep recipes, history files, config secrets, SSH keys and automated tools. Password Attacks · linux · credentials 07 CRED Windows Credential & Flag Hunting 2026.09.14 Find flags, passwords and secrets on Windows — CMD vs PowerShell (Evil-WinRM) syntax, config/registry secrets, PS history, and automated tools. Password Attacks · windows · powershell 08 CRED John the Ripper 2026.09.13 John the Ripper: 2john extractors, formats, wordlist/incremental/rules modes and session control. Password Attacks · password-attacks · cracking 09 AD RustHound-CE 2026.09.13 Cross-platform BloodHound Community Edition collector written in Rust. Fast LDAP-based AD enumeration with pass-the-hash, Kerberos, certificate auth and ADCS-aware output. Active Directory · active-directory · kerberos 10 AD PowerView and PowerUp Deep-Dive 2026.08.29 Comprehensive PowerView domain-enumeration and PowerUp local Windows privilege-escalation reference, with read-only triage, validation, cleanup, and function indexes. Active Directory · active-directory · powerview 11 AD Run as Another User from an Evil-WinRM Session 2026.08.29 You're local admin over WinRM but need to act as a different domain user — spawn processes, tasks, or loopback PowerShell sessions with alternate credentials. Active Directory · active-directory · lateral-movement 12 TOOL xfreerdp 2026.08.29 FreeRDP command-line RDP client — connection flags, drive redirection, and finding the \tsclient shared folder from a CLI-only Windows session. Tools · tools · rdp 13 WEB Blind XSS to Session Hijacking 2026.08.28 Chaining blind XSS to session hijacking: out-of-band callbacks, cookie/session theft, exfiltration and account takeover. Web · web · xss 14 WEB Command Injection — Filter Bypass 2026.08.28 Bypassing command-injection filters: space, blacklisted-character and blacklisted-command evasion, plus advanced obfuscation. Web · web · command-injection 15 ENUM Common Ports & Services (2026) 2026.08.28 Field reference for common TCP/UDP ports and services — core internet, Windows/AD, web, database and remote-access mappings with confirmation tips. Enumeration · enumeration · port-scanning 16 WEB Dalfox 2026.08.28 Dalfox XSS scanner usage for HTB and AEN: scan modes, pipelines, custom payloads, blind XSS and output handling. Web · web · xss 17 ENUM Nmap NSE Scripts (2026) 2026.08.28 Operator quick reference for selecting, running, constraining and troubleshooting Nmap NSE scripts by category and target service. Enumeration · enumeration · port-scanning 18 PIVOT Socat 2026.08.28 Socat recipes for bind/reverse shells, TCP/UDP relays, TLS-wrapped tunnels, port forwarding and file transfer. Tunneling & Pivoting · tunneling-pivoting · relay 19 GIT The jj Field Guide 2026.08.28 Jujutsu (jj) version control in plain language: the save → bookmark → push ritual, what @ and @- really mean, bookmarks, syncing with GitHub, and undoing anything. Git & Workflow · git · jj 20 PIVOT Ligolo-ng CLI: Routes, Listeners, and Multi-Hop Pivoting 2026.08.25 Ligolo-ng v0.9.x CLI guide covering managed routes, listeners, first pivots, multi-hop tunnels, reverse connections, scanning, and troubleshooting. Tunneling & Pivoting · ligolo-ng · pivoting 21 TOOL dd tool 2026.08.10 ⚠️ Warning: dd can permanently destroy data if used incorrectly. Always double-check your commands, especially the if= (input) and of= (output) parameters. Tools · tools · adcs 22 NIX Find Command 2026.08.10 find /home -iname "*.conf" -type f Linux & IT · linux-it · privilege-escalation 23 GIT Git — Complete Branch & Vault Management Guide 2026.08.10 git init git remote add origin https://github.com/yourusername/your-repo.git Git & Workflow · git-workflow · adcs 24 GIT Git — Move Existing Edits to a New Branch (Railway Site) 2026.08.10 git checkout -b my-new-branch Git & Workflow · git-workflow
Showing 10 of 264 sheets All 13 shelves ↗
Shelves / taxonomy
Pick your vector.
13 shelves, grouped by how you actually reach for them.
0138 sheets Pentest Workflow 02134 sheets Active Directory 0321 sheets Enumeration 044 sheets Exploitation 052 sheets Privilege Escalation 065 sheets Password Attacks 0712 sheets Web 087 sheets Tunneling & Pivoting 093 sheets Cryptography 104 sheets DFIR 1119 sheets Tools 129 sheets Linux & IT 136 sheets Git & Workflow
Third party / mirrored
Some trees are borrowed.
Three directories are generated from upstream security references: swisskyrepo's PayloadsAllTheThings and InternalAllTheThings, plus an attributed selection from HackTricks. They are searchable offline and every page links back to source. Attribution, modification notes, and licences live on the credits page.
- Trees
- 03
- Licence
- Upstream
- Sync
- Scheduled
- Edits
- None
Mirror manifest // upstreamswisskyrepo
01payloads/136 files
02internal/176 files
03hacktricks/613 files
04payloads/methodology-and-resources/34 files
05internal/active-directory/72 files
06hacktricks/section/linux-hardening/69 files
Scope
Authorised testing, CTFs and education only. HackTricks-derived pages are also restricted to
non-commercial use under CC BY-NC 4.0. Know your scope, and get permission first,
before you touch a system.