CyberCheatsheets

Scanning & Enumeration

Active probing: ports, services, vulnerability templates, and directory discovery.

Dirb

Scanning

Classic web content scanner using wordlists to discover hidden directories and files.

directory-bruteforcelegacyweb

enum4linux-ng

Scanning

Modern SMB/LDAP/RPC enumerator for Windows and Samba hosts—users, groups, shares, and policies.

active-directoryldapsmbwindows

Feroxbuster

Scanning

Recursive content discovery tool with smart filtering, backups, and automatic extraction of new URLs.

directory-bruteforcerecursiverustweb

ffuf

Scanning

Fast web fuzzer for directories, parameters, vhosts, and header injection with flexible matchers.

directory-bruteforcefuzzingvhostweb

Gobuster

Scanning

Fast directory, DNS, vhost, and S3 bucket brute-forcer written in Go.

directory-bruteforcednsvhostweb

httpx

Scanning

Fast HTTP probe for live URLs, status codes, titles, and tech fingerprinting from host lists.

httpprobingprojectdiscoveryweb

Masscan

Scanning

High-speed Internet-scale port scanner for rapid discovery before deeper nmap enumeration.

fast-scannetworkport-scan

Nikto

Scanning

Web server scanner for dangerous files, misconfigurations, and outdated software indicators.

cgivulnerability-scanweb

Nmap

Scanning

Network mapper for host discovery, port scanning, service/version detection, and NSE scripting.

enumerationnetworkport-scanservice-detection

Nuclei

Scanning

Template-based fast scanner for CVEs, misconfigs, and exposures across HTTP, DNS, and more.

automationprojectdiscoverytemplatesvulnerability-scan

RustScan

Scanning

Fast port scanner that pipes discovered ports directly into Nmap for scripting and version detection.

fast-scanport-scanrust

SearchSploit

Scanning

Command-line search of Exploit-DB for public exploits, shellcode, and papers by keyword or CVE.

cveexploit-dbresearch

wafw00f

Scanning

Identifies Web Application Firewalls in front of targets to tune bypass and testing strategy.

fingerprintwafweb

Wfuzz

Scanning

Python web fuzzer for brute-forcing parameters, directories, and headers with flexible filters.

fuzzingparametersweb

WhatWeb

Scanning

Web technology fingerprinter identifying CMS, frameworks, plugins, and server headers.

cmsfingerprintweb