01DΛΣMӨП
02Cheatsheets
03Offline search
04Copy-ready
0513 shelves
06Zero fluff
SysOpen notebook/
SearchPagefind · offline/
Sheets264 · curated/
ThemeRosé Pine Dawn/
FieldAD · web · privesc/
MirrorThree upstream trees/
DoctrineTerse, not thin/
Index / operator

Start here.

264 sheets across 13 shelves, plus two full upstream mirrors. The shelves are below; the index itself runs under them.

Offline search Copy-ready Zero fluff
daemon@ref~%vault --status
sheets
264 · curated
shelves
13 · domains
search
offline · fuzzy · no tracking
updated
2026.09 · latest
Quick search / 2026
13 shelves
264 sheets
03 mirrors
Reference transmissions

Terse, tested, kept current.

264 sheets across 13 shelves, each stripped to the commands that matter.

Payloads ↗ Internal ↗ HackTricks ↗ 10 shown
01 FLOW NTFS Alternate Data Streams — Hiding & Finding Hidden Data 2026.09.17 Windows NTFS Alternate Data Streams (ADS): what they are, reading and writing them, finding streams other users hid (dir /r, Get-Item -Stream, streams.exe), Mark-of-the-Web, and a worked HTB example of digging a flag out of a stream. Pentest Workflow · htb · cpts 02 FLOW Potato Attacks — SeImpersonate to SYSTEM 2026.09.17 Windows SeImpersonate → SYSTEM with the whole potato family (PrintSpoofer, GodPotato, JuicyPotatoNG, RoguePotato, EfsPotato, SweetPotato): what each abuses, every useful flag, delivery from MSSQL/IIS/WinRM, and a repeatable field method with an HTB Jeeves worked example. Pentest Workflow · htb · cpts 03 PRIV Windows Privilege Escalation 2026.09.17 Windows privesc master guide: token/privilege abuse, services, registry, AlwaysInstallElevated, potatoes. Privilege Escalation · privilege-escalation · windows 04 FLOW Attacking Common Services — Full Guide 2026.09.16 Detailed CPTS walkthrough for enumerating and exploiting the network services that dominate internal and perimeter networks: FTP, SMB, SQL (MySQL/MSSQL), RDP, DNS, and email (SMTP/POP3/IMAP) — anonymous access, default creds, spraying, misconfigurations, and the module's worked CVEs, framed by the Source → Process → Privileges → Destination model. Pentest Workflow · htb · cpts 05 ENUM feroxbuster 2026.09.15 feroxbuster recursive content discovery — recursion by default, link extraction, response auto-filtering, and rich matchers/filters. Enumeration · enumeration · web 06 CRED Linux Credential & Flag Hunting 2026.09.14 Find flags, passwords, keys and secrets on Linux: find/grep recipes, history files, config secrets, SSH keys and automated tools. Password Attacks · linux · credentials 07 CRED Windows Credential & Flag Hunting 2026.09.14 Find flags, passwords and secrets on Windows — CMD vs PowerShell (Evil-WinRM) syntax, config/registry secrets, PS history, and automated tools. Password Attacks · windows · powershell 08 CRED John the Ripper 2026.09.13 John the Ripper: 2john extractors, formats, wordlist/incremental/rules modes and session control. Password Attacks · password-attacks · cracking 09 AD RustHound-CE 2026.09.13 Cross-platform BloodHound Community Edition collector written in Rust. Fast LDAP-based AD enumeration with pass-the-hash, Kerberos, certificate auth and ADCS-aware output. Active Directory · active-directory · kerberos 10 AD PowerView and PowerUp Deep-Dive 2026.08.29 Comprehensive PowerView domain-enumeration and PowerUp local Windows privilege-escalation reference, with read-only triage, validation, cleanup, and function indexes. Active Directory · active-directory · powerview 11 AD Run as Another User from an Evil-WinRM Session 2026.08.29 You're local admin over WinRM but need to act as a different domain user — spawn processes, tasks, or loopback PowerShell sessions with alternate credentials. Active Directory · active-directory · lateral-movement 12 TOOL xfreerdp 2026.08.29 FreeRDP command-line RDP client — connection flags, drive redirection, and finding the \tsclient shared folder from a CLI-only Windows session. Tools · tools · rdp 13 WEB Blind XSS to Session Hijacking 2026.08.28 Chaining blind XSS to session hijacking: out-of-band callbacks, cookie/session theft, exfiltration and account takeover. Web · web · xss 14 WEB Command Injection — Filter Bypass 2026.08.28 Bypassing command-injection filters: space, blacklisted-character and blacklisted-command evasion, plus advanced obfuscation. Web · web · command-injection 15 ENUM Common Ports & Services (2026) 2026.08.28 Field reference for common TCP/UDP ports and services — core internet, Windows/AD, web, database and remote-access mappings with confirmation tips. Enumeration · enumeration · port-scanning 16 WEB Dalfox 2026.08.28 Dalfox XSS scanner usage for HTB and AEN: scan modes, pipelines, custom payloads, blind XSS and output handling. Web · web · xss 17 ENUM Nmap NSE Scripts (2026) 2026.08.28 Operator quick reference for selecting, running, constraining and troubleshooting Nmap NSE scripts by category and target service. Enumeration · enumeration · port-scanning 18 PIVOT Socat 2026.08.28 Socat recipes for bind/reverse shells, TCP/UDP relays, TLS-wrapped tunnels, port forwarding and file transfer. Tunneling & Pivoting · tunneling-pivoting · relay 19 GIT The jj Field Guide 2026.08.28 Jujutsu (jj) version control in plain language: the save → bookmark → push ritual, what @ and @- really mean, bookmarks, syncing with GitHub, and undoing anything. Git & Workflow · git · jj 20 PIVOT Ligolo-ng CLI: Routes, Listeners, and Multi-Hop Pivoting 2026.08.25 Ligolo-ng v0.9.x CLI guide covering managed routes, listeners, first pivots, multi-hop tunnels, reverse connections, scanning, and troubleshooting. Tunneling & Pivoting · ligolo-ng · pivoting 21 TOOL dd tool 2026.08.10 ⚠️ Warning: dd can permanently destroy data if used incorrectly. Always double-check your commands, especially the if= (input) and of= (output) parameters. Tools · tools · adcs 22 NIX Find Command 2026.08.10 find /home -iname "*.conf" -type f Linux & IT · linux-it · privilege-escalation 23 GIT Git — Complete Branch & Vault Management Guide 2026.08.10 git init git remote add origin https://github.com/yourusername/your-repo.git Git & Workflow · git-workflow · adcs 24 GIT Git — Move Existing Edits to a New Branch (Railway Site) 2026.08.10 git checkout -b my-new-branch Git & Workflow · git-workflow
Showing 10 of 264 sheets All 13 shelves ↗
Shelves / taxonomy

Pick your vector.

13 shelves, grouped by how you actually reach for them.

Third party / mirrored

Some trees are borrowed.

Three directories are generated from upstream security references: swisskyrepo's PayloadsAllTheThings and InternalAllTheThings, plus an attributed selection from HackTricks. They are searchable offline and every page links back to source. Attribution, modification notes, and licences live on the credits page.

Trees
03
Licence
Upstream
Sync
Scheduled
Edits
None
Read the credits →
Mirror manifest // upstreamswisskyrepo
01payloads/136 files
02internal/176 files
03hacktricks/613 files
04payloads/methodology-and-resources/34 files
05internal/active-directory/72 files
06hacktricks/section/linux-hardening/69 files
Scope
Authorised testing, CTFs and education only. HackTricks-derived pages are also restricted to non-commercial use under CC BY-NC 4.0. Know your scope, and get permission first, before you touch a system.