CyberCheatsheets

All tools

142 cheatsheets

Active Directory Attacks

Active

Active Directory attack workflow: enumeration, Kerberoasting, AS-REP roasting, credential dumping, and lateral movement on authorized engagements.

active-directorykerberoslateral-movementpost-exploitation

Aircrack-ng

Wireless

Wi-Fi security auditing suite — capture with airodump-ng, deauth with aireplay-ng, crack WPA with aircrack-ng.

aireplayairodumpwifiwpa

Amass

Reconnaissance

In-depth attack surface mapping and subdomain enumeration via passive and active techniques.

attack-surfacednsosintsubdomain

Arjun

Web

HTTP parameter discovery tool for finding hidden GET and POST parameters.

discoveryparametersrecon

Assetfinder

Reconnaissance

Find domains and subdomains related to a given domain using passive sources (Tom Hudson).

osintpassivesubdomain

Autopsy

Forensics

GUI digital forensics platform built on The Sleuth Kit for disk images, timelines, keyword search, and artifact parsing.

diskguitimeline

AWS CLI

Cloud

Command-line interface for AWS enumeration, credential validation, and misconfiguration discovery during cloud assessments.

awsenumerationiams3

Azure CLI

Cloud

Microsoft Azure command-line tool for subscription, VM, storage, and Entra ID enumeration in cloud pentests.

azureentraenumeration

Bash Scripting

Utilities

Bash scripting syntax and one-liners — variables, loops, conditionals, and text processing for automation and pentesting.

automationbashlinuxscripting

Bettercap

Network

Modern network attack and monitoring framework for ARP/DNS spoofing, sniffing, and credential attacks on authorized LANs.

mitmspoofingwifi

binwalk

Exploitation

Firmware and file analysis tool that scans for embedded files and extracts hidden archives.

carvingfirmwaresteganography

BloodHound

Active

Map Active Directory attack paths from SharpHound/SharpHound data collectors.

acladenumerationgraph

Buffer Overflow

Exploitation

Stack-based buffer overflow workflow: fuzz, find the offset, control EIP, find bad chars, locate a JMP ESP, and get a shell.

binary-exploitationbuffer-overflowoscppwn

Burp Suite

Web

Integrated web proxy and testing platform for intercepting, modifying, and automating HTTP traffic.

intruderproxyrepeaterweb

Censys

Reconnaissance

Internet-wide scan data and certificate intelligence for hosts, services, and attack surface research.

asmcertificatesinternet-scanosint

CeWL

Passwords

Spider a site and build a custom wordlist from discovered words.

osintspiderwebwordlist

checksec

Exploitation

Quick report of binary security mitigations (RELRO, stack canary, NX, PIE, Fortify).

binarycanarymitigationsnx

Chisel

Exploitation

Fast TCP/UDP tunnel over HTTP(S) for pivoting through compromised hosts when SSH is unavailable.

pivotsockstunnel

Command Injection

Web

OS command injection payloads, separators, blind detection, and filter bypasses for achieving RCE on authorized targets.

command-injectioninjectionowasprce

commix

Web

Automated command injection detection and exploitation in web parameters and headers.

command-injectionos-shellrce

CrackMapExec

Active

Swiss-army SMB/WinRM/LDAP/MSSQL tool for AD enumeration and credential testing.

adlateralsmbspray

Crontab

Utilities

Cron syntax reference and commands for scheduling jobs on Linux — plus persistence and privesc angles for pentesters.

croncrontablinuxpersistence

Crunch

Passwords

Generate custom wordlists from charset and length rules.

charsetgeneratormaskswordlist

curl

Utilities

Versatile CLI for HTTP(S), file transfer, headers, and scripting web/API tests during pentests.

apihttptransfer

Dalfox

Web

Fast parameter-based XSS scanner and proof-of-concept generator for web apps.

domreflectedxss

dig

Reconnaissance

DNS lookup utility for querying record types, tracing resolution, and debugging DNSSEC.

dnsrecordstroubleshooting

Dirb

Scanning

Classic web content scanner using wordlists to discover hidden directories and files.

directory-bruteforcelegacyweb

dnsenum

Reconnaissance

Perl DNS enumerator for zone transfers, subdomain brute force, reverse lookups, and WHOIS.

dnssubdomainzone-transfer

dnsrecon

Reconnaissance

Python DNS enumeration tool for records, zone transfers, brute force, and cache snooping.

dnssrvsubdomainzone-transfer

Docker

Cloud

Container runtime CLI for building images, inspecting deployments, and testing container breakout and misconfiguration paths.

containerenumerationescape

DroopeScan

Web

CMS scanner focused on Drupal, Silverstripe, and WordPress plugin enumeration.

cmsdrupalsilverstripe

enum4linux-ng

Scanning

Modern SMB/LDAP/RPC enumerator for Windows and Samba hosts—users, groups, shares, and policies.

active-directoryldapsmbwindows

Ettercap

Network

LAN MITM framework for ARP poisoning, sniffing, and filter-based traffic manipulation on authorized networks.

arpmitmsniffing

Evil-WinRM

Active

WinRM shell and file transfer for post-exploitation on Windows hosts.

lateralshellwindowswinrm

ExifTool

Forensics

Read and write metadata in images, documents, and media — GPS, camera info, author fields, and hidden tags.

imagesmetadatasteganography

Feroxbuster

Scanning

Recursive content discovery tool with smart filtering, backups, and automatic extraction of new URLs.

directory-bruteforcerecursiverustweb

ffuf

Scanning

Fast web fuzzer for directories, parameters, vhosts, and header injection with flexible matchers.

directory-bruteforcefuzzingvhostweb

Fierce

Reconnaissance

DNS reconnaissance tool that locates non-contiguous IP space near target domains.

dnsscansubdomain

file

Exploitation

Identify file types from magic bytes — essential before choosing exploit, extraction, or analysis tools.

binaryforensicsmagic

File Transfer

Utilities

Move files to and from compromised Linux and Windows hosts — HTTP, SMB, netcat, base64, and living-off-the-land binaries.

exfiltrationfile-transferlolbinspentest

Foremost

Forensics

File carving tool that recovers files from disk images by header/footer signatures when filesystem metadata is missing.

carvingdiskrecovery

GDB (GEF / Pwndbg)

Exploitation

GNU debugger for binary analysis with GEF or Pwndbg for heap, registers, and exploit-oriented views.

binarydebuggergefpwndbg

Git

Utilities

Version control CLI for cloning repos, hunting exposed secrets in history, and recovering source during web assessments.

reconsecretsvcs

Gobuster

Scanning

Fast directory, DNS, vhost, and S3 bucket brute-forcer written in Go.

directory-bruteforcednsvhostweb

Google Cloud SDK (gcloud)

Cloud

GCP command-line tool for project enumeration, IAM review, compute instances, and storage access testing.

gcpgcsiam

GPG

Utilities

GnuPG commands for encrypting files, signing, and managing keys — symmetric and public-key workflows.

encryptiongnupggpgpgp

Hash Identifier

Passwords

Interactive helper to guess hash type for cracking tools.

formathashidentificationoffline

Hashcat

Passwords

GPU-accelerated offline password and hash recovery.

crackinggpuhashoffline

hping3

Network

Custom TCP/UDP/ICMP packet crafting for firewall testing, traceroute, and port probing on authorized hosts.

dosfirewallscan

httpx

Scanning

Fast HTTP probe for live URLs, status codes, titles, and tech fingerprinting from host lists.

httpprobingprojectdiscoveryweb

Hydra

Passwords

Parallelized online login brute-forcer for many protocols.

brute-forceloginonlinepasswords

Impacket

Active

Python toolkit for SMB, Kerberos, and Windows protocol attacks.

adkerberosrelaysecrets

John the Ripper

Passwords

Versatile offline password cracker with automatic format detection.

cpucrackinghashoffline

JoomScan

Web

Joomla CMS vulnerability scanner and version or component enumerator.

cmsenumerationjoomla

jq

Utilities

jq command-line JSON processor — filter, transform, and extract fields from API responses and tool output.

apiclijqjson

JWT Attacks

Web

JSON Web Token attacks: alg=none, weak secret cracking, key confusion (RS256→HS256), and claim tampering on authorized targets.

authenticationjson-web-tokenjwtowasp

jwt_tool

Web

JSON Web Token testing for algorithm confusion, weak secrets, and claim tampering.

authenticationcryptojwt

Kerbrute

Active

Fast Kerberos user enumeration and password spraying without LDAP.

adenumkerberosspray

kubectl

Cloud

Kubernetes CLI for cluster enumeration, secret access, and pod exec during authorized K8s penetration tests.

enumerationk8skubernetes

ldapdomaindump

Active

Dump and HTML-report Active Directory LDAP data for offline review.

adenumldaposint

LFI / Path Traversal

Web

Local file inclusion and directory traversal payloads, PHP wrappers, and log-poisoning RCE for authorized testing.

lfiowasppath-traversalrfi

Ligolo-ng

Exploitation

Advanced pivoting via TUN interface and agent — cleaner routing than SOCKS for multi-host internal scans.

pivottuntunnel

Linux Commands

Utilities

Essential Linux command-line reference — files, permissions, processes, networking, and search for everyday and pentest use.

bashclilinuxsysadmin

Linux Privilege Escalation

Exploitation

Enumeration and escalation paths to go from a low-privilege shell to root on Linux during authorized engagements.

enumerationlinuxpost-exploitationprivesc

Maskprocessor

Passwords

Generate candidate passwords from Hashcat-style mask syntax.

generatorhashcatmaskwordlist

Masscan

Scanning

High-speed Internet-scale port scanner for rapid discovery before deeper nmap enumeration.

fast-scannetworkport-scan

Medusa

Passwords

Fast, modular parallel login brute-forcer (Foofus Medusa).

brute-forceonlineparallelpasswords

Metasploit Framework

Exploitation

Modular exploitation framework for scanning, exploiting, and post-exploitation with msfconsole, handlers, and msfvenom.

exploithandlermsfconsolemsfvenom

Mimikatz

Active

Windows credential extraction and Kerberos manipulation (lab-only).

credentialsdcsynclsasssekurlsa

mitmproxy

Web

Interactive TLS-capable HTTP proxy for intercepting, replaying, and scripting web traffic.

interceptionproxytls

msfvenom

Exploitation

Generate and encode standalone payloads (reverse shells, shellcode, MSI/EXE/ELF) for authorized exploitation.

metasploitmsfvenompayloadreverse-shell

Netcat

Network

TCP/UDP connect, listen, and port relay for banners, shells, and file transfer on authorized networks.

ncatnetcatpivotshell

NetExec

Active

Modern CrackMapExec successor for AD protocol abuse and automation.

adcmelateralsmb

ngrok

Exploitation

Expose local services to the internet for reverse shells, webhooks, and phishing callbacks during authorized tests.

callbackreverse-shelltunnel

Nikto

Scanning

Web server scanner for dangerous files, misconfigurations, and outdated software indicators.

cgivulnerability-scanweb

Nmap

Scanning

Network mapper for host discovery, port scanning, service/version detection, and NSE scripting.

enumerationnetworkport-scanservice-detection

nslookup

Reconnaissance

Interactive and non-interactive DNS query tool available on Linux and Windows for basic record lookups.

dnstroubleshootingwindows

Nuclei

Scanning

Template-based fast scanner for CVEs, misconfigs, and exposures across HTTP, DNS, and more.

automationprojectdiscoverytemplatesvulnerability-scan

objdump

Exploitation

Disassemble ELF binaries, inspect sections, symbols, and relocations for exploit development.

disassemblyelfreversing

OpenSSL

Utilities

Cryptography toolkit for certificate inspection, TLS testing, and encoding/hashing in pentests and forensics.

certificatescryptotls

Ophcrack

Passwords

Windows NTLM/LM rainbow-table cracker with GUI and live CD heritage.

ntlmofflinerainbowwindows

OSINT

Reconnaissance

Open-source intelligence workflow: domains, emails, people, breaches, and infrastructure using Google dorks and free OSINT tools.

footprintinginvestigationosintrecon

OWASP ZAP

Web

Open-source web app security proxy with passive/active scanning and automation API.

automationproxyscanner

Pacu

Cloud

AWS exploitation framework with modules for privilege escalation, persistence, and data exfiltration after key compromise.

awsenumerationexploitation

ParamSpider

Web

Mines archived URLs to extract unique parameters for a domain from web archives.

parametersreconwayback

Password Cracking

Passwords

Password cracking workflow: identify the hash, pick the right mode, and crack offline (hashcat/john) or online (hydra) on authorized targets.

hashcathasheshydrajohn

Patator

Passwords

Multi-purpose brute-forcer with flexible modules and conditions.

brute-forcemodularonlinepasswords

Pivoting & Tunneling

Network

SSH tunneling, port forwarding, SOCKS proxies, and pivoting with chisel/ligolo to reach internal networks during authorized engagements.

lateral-movementpivotingport-forwardingproxychains

PowerShell

Utilities

PowerShell commands for Windows enumeration, download/execution, and offensive one-liners during authorized engagements.

automationpost-exploitationpowershellscripting

Prowler

Cloud

AWS (and multi-cloud) security assessment tool with hundreds of checks mapped to CIS, PCI, and custom compliance frameworks.

awsciscompliance

Proxychains

Network

Force TCP connections through SOCKS4/5 or HTTP proxies for pivoting during authorized internal assessments.

pivotsockstunnel

pwntools

Exploitation

Python library for exploit development, remote/local process interaction, and ROP/shellcode workflows.

ctfexploit-devpwnpython

Recon-ng

Reconnaissance

Modular reconnaissance framework with workspaces, modules, and API-driven OSINT collectors.

automationframeworkmodularosint

Regex

Utilities

Regular expression syntax reference plus ready-to-use patterns for grepping IPs, hashes, emails, and secrets.

greppattern-matchingregexregular-expressions

Responder

Network

LLMNR/NBT-NS/mDNS poisoner and rogue authentication server for capturing NetNTLM hashes on authorized Windows networks.

hash-capturellmnrnbt-ns

Reverse Shells

Utilities

One-liners and staged payloads for bash, Python, and PowerShell reverse shells during authorized penetration tests.

bashpowershellpythonshell

ROPgadget

Exploitation

Classic ROP gadget finder with --ropchain auto-generation for simple execve/sh chains.

gadgetsret2libcrop

Ropper

Exploitation

ROP gadget search tool supporting ELF/PE with semantic filtering and chain building helpers.

binarygadgetsrop

rpcclient

Network

MS-RPC client for SAMR/LSA enumeration and user management via null or authenticated sessions on authorized domains.

rpcsamrwindows

Rubeus

Active

Kerberos abuse toolkit for ticket requests, roasting, and delegation attacks.

adkerberosroasttickets

RustScan

Scanning

Fast port scanner that pipes discovered ports directly into Nmap for scripting and version detection.

fast-scanport-scanrust

ScoutSuite

Cloud

Multi-cloud security auditing tool that generates HTML reports highlighting misconfigurations and risky permissions.

auditawsazuregcp

SearchSploit

Scanning

Command-line search of Exploit-DB for public exploits, shellcode, and papers by keyword or CVE.

cveexploit-dbresearch

Shodan

Reconnaissance

Search engine for Internet-connected devices, banners, ports, and exposed services via CLI and web.

bannersinternet-scaniotosint

SMB Enumeration

Network

Enumerate SMB: shares, null sessions, users, and versions with nmap, netexec, smbclient, and enum4linux on authorized networks.

enumerationnetbiossharessmb

smbclient

Network

SMB/CIFS client for share enumeration, file access, and null-session testing on authorized Windows hosts.

sharessmbwindows

socat

Network

Bidirectional data relay for shells, port forwarding, and protocol bridging on authorized networks.

pivotrelaytunnel

SpiderFoot

Reconnaissance

OSINT automation platform correlating IPs, domains, emails, breaches, and social data from 200+ modules.

automationcorrelationguiosint

SQL Injection

Web

Manual SQL injection payloads and techniques for detection, UNION extraction, blind, and authentication bypass on authorized targets.

databaseinjectionowaspsqli

sqlmap

Web

Automated SQL injection detection and exploitation for web parameters, headers, and cookies.

databaseinjectionsqli

SSH

Utilities

Secure shell for remote access, port forwarding, SOCKS proxies, and file transfer during authorized engagements.

pivotremotetunnel

sshuttle

Exploitation

Transparent proxy/VPN over SSH — route subnets through a compromised SSH host without modifying sshd config.

pivotsshvpn

SSRF (Server-Side Request Forgery)

Web

Server-side request forgery payloads: cloud metadata access, internal port scanning, filter bypasses, and blind SSRF detection.

cloudinjectionowaspssrf

SSRFmap

Web

SSRF exploitation framework with modules for cloud metadata, port scan, and shell.

cloudinternalssrf

Steganography

Forensics

Steganography and hidden-data extraction for CTF and forensics: images, audio, files, and embedded archives.

ctfforensicshidden-dataimage

strings

Exploitation

Extract printable strings from binaries and dumps to find URLs, flags, passwords, and error messages.

binaryforensicsrecon

Subdomain Enumeration

Reconnaissance

Find subdomains via passive sources, DNS brute force, certificate transparency, and permutation — then probe which are live.

attack-surfacebug-bountydnsrecon

Subfinder

Reconnaissance

Fast passive subdomain discovery using curated OSINT sources and API integrations.

osintprojectdiscoverysubdomain

tcpdump

Network

Command-line packet capture and filtering for authorized network analysis and troubleshooting.

capturepcapsniffing

The Sleuth Kit

Forensics

CLI forensic toolkit to analyze disk images — partition tables, inode listing, and file carving without GUI.

clidiskfilesystem

theHarvester

Reconnaissance

OSINT gathering for emails, subdomains, hosts, and employee names from public sources.

breachemailosintsubdomain

tmux

Utilities

Terminal multiplexer for persistent sessions, split panes, and windows — keep shells alive across SSH drops.

multiplexerproductivitysessionsterminal

tplmap

Web

Server-Side Template Injection detection and exploitation for multiple template engines.

rcesstitemplate-injection

Trivy

Cloud

Scanner for container images, filesystems, and IaC (Terraform, K8s) for CVEs and misconfigurations.

containeriacvulnerability

tshark

Network

CLI Wireshark for capture, display filters, and protocol field extraction on authorized traffic.

analysispcapwireshark

Velociraptor

Forensics

Endpoint visibility and digital forensic platform with VQL for hunting, collections, and incident response at scale.

artifacthuntingir

Vim

Utilities

Vim editor commands — modes, motions, editing, search/replace, and the survival basics for editing files on remote shells.

editorproductivityterminalvim

Volatility

Forensics

Memory forensics framework for extracting processes, credentials, and malware artifacts from RAM dumps.

malwarememoryram

wafw00f

Scanning

Identifies Web Application Firewalls in front of targets to tune bypass and testing strategy.

fingerprintwafweb

Wfuzz

Scanning

Python web fuzzer for brute-forcing parameters, directories, and headers with flexible filters.

fuzzingparametersweb

wget

Utilities

Non-interactive downloader for mirroring sites, retrieving payloads, and recursive cloning during recon.

downloadhttpmirror

WhatWeb

Scanning

Web technology fingerprinter identifying CMS, frameworks, plugins, and server headers.

cmsfingerprintweb

Wi-Fi Hacking

Wireless

Wireless attack workflow: monitor mode, recon, WPA/WPA2 handshake capture, deauth, and offline cracking on authorized networks.

aircrack-nghandshakewifiwireless

Windows Commands

Utilities

Windows CMD command reference — files, users, networking, services, and enumeration commands for admins and pentesters.

cmdcommand-lineenumerationsysadmin

Windows Privilege Escalation

Exploitation

Enumeration and escalation paths from a low-privilege Windows user to SYSTEM or Administrator on authorized engagements.

enumerationpost-exploitationprivesctokens

Wireshark Filters

Network

Wireshark display and capture filter syntax for slicing packet captures during analysis and forensics.

display-filterspacket-analysispcaptshark

WPScan

Web

WordPress security scanner for users, plugins, themes, and known vulnerabilities.

cmsenumerationwordpress

x8

Web

Hidden parameter discovery via response status, body, and reflection diffing.

fuzzinghiddenparameters

XSS (Cross-Site Scripting)

Web

Cross-site scripting payloads and filter bypasses for reflected, stored, and DOM-based XSS on authorized targets.

injectionjavascriptowaspweb

XSStrike

Web

Advanced XSS detection with context analysis, fuzzing, and WAF-aware payload generation.

fuzzingwaf-bypassxss

XXE (XML External Entity)

Web

XML External Entity payloads for file read, SSRF, blind out-of-band exfiltration, and denial of service on authorized targets.

injectionowaspwebxml

YARA

Forensics

Pattern matching language to identify malware families, IOCs, and suspicious byte sequences in files and memory.

huntingmalwarerules