Rechercher les aide-mémoires
Trouvez des commandes dans tous les outils.
142 results
- Active Directory AttacksActive Directory & Windows
Active Directory attack workflow: enumeration, Kerberoasting, AS-REP roasting, credential dumping, and lateral movement on authorized engagements.
- Aircrack-ngWireless
Wi-Fi security auditing suite — capture with airodump-ng, deauth with aireplay-ng, crack WPA with aircrack-ng.
- AmassReconnaissance & OSINT
In-depth attack surface mapping and subdomain enumeration via passive and active techniques.
- ArjunWeb Application Security
HTTP parameter discovery tool for finding hidden GET and POST parameters.
- AssetfinderReconnaissance & OSINT
Find domains and subdomains related to a given domain using passive sources (Tom Hudson).
- AutopsyForensics & IR
GUI digital forensics platform built on The Sleuth Kit for disk images, timelines, keyword search, and artifact parsing.
- AWS CLICloud & Containers
Command-line interface for AWS enumeration, credential validation, and misconfiguration discovery during cloud assessments.
- Azure CLICloud & Containers
Microsoft Azure command-line tool for subscription, VM, storage, and Entra ID enumeration in cloud pentests.
- Bash ScriptingUtilities & Shells
Bash scripting syntax and one-liners — variables, loops, conditionals, and text processing for automation and pentesting.
- BettercapNetwork & Protocol
Modern network attack and monitoring framework for ARP/DNS spoofing, sniffing, and credential attacks on authorized LANs.
- binwalkExploitation & Payloads
Firmware and file analysis tool that scans for embedded files and extracts hidden archives.
- BloodHoundActive Directory & Windows
Map Active Directory attack paths from SharpHound/SharpHound data collectors.
- Buffer OverflowExploitation & Payloads
Stack-based buffer overflow workflow: fuzz, find the offset, control EIP, find bad chars, locate a JMP ESP, and get a shell.
- Burp SuiteWeb Application Security
Integrated web proxy and testing platform for intercepting, modifying, and automating HTTP traffic.
- CensysReconnaissance & OSINT
Internet-wide scan data and certificate intelligence for hosts, services, and attack surface research.
- CeWLPasswords & Cracking
Spider a site and build a custom wordlist from discovered words.
- checksecExploitation & Payloads
Quick report of binary security mitigations (RELRO, stack canary, NX, PIE, Fortify).
- ChiselExploitation & Payloads
Fast TCP/UDP tunnel over HTTP(S) for pivoting through compromised hosts when SSH is unavailable.
- Command InjectionWeb Application Security
OS command injection payloads, separators, blind detection, and filter bypasses for achieving RCE on authorized targets.
- commixWeb Application Security
Automated command injection detection and exploitation in web parameters and headers.
- CrackMapExecActive Directory & Windows
Swiss-army SMB/WinRM/LDAP/MSSQL tool for AD enumeration and credential testing.
- CrontabUtilities & Shells
Cron syntax reference and commands for scheduling jobs on Linux — plus persistence and privesc angles for pentesters.
- CrunchPasswords & Cracking
Generate custom wordlists from charset and length rules.
- curlUtilities & Shells
Versatile CLI for HTTP(S), file transfer, headers, and scripting web/API tests during pentests.
- DalfoxWeb Application Security
Fast parameter-based XSS scanner and proof-of-concept generator for web apps.
- digReconnaissance & OSINT
DNS lookup utility for querying record types, tracing resolution, and debugging DNSSEC.
- DirbScanning & Enumeration
Classic web content scanner using wordlists to discover hidden directories and files.
- dnsenumReconnaissance & OSINT
Perl DNS enumerator for zone transfers, subdomain brute force, reverse lookups, and WHOIS.
- dnsreconReconnaissance & OSINT
Python DNS enumeration tool for records, zone transfers, brute force, and cache snooping.
- DockerCloud & Containers
Container runtime CLI for building images, inspecting deployments, and testing container breakout and misconfiguration paths.
- DroopeScanWeb Application Security
CMS scanner focused on Drupal, Silverstripe, and WordPress plugin enumeration.
- enum4linux-ngScanning & Enumeration
Modern SMB/LDAP/RPC enumerator for Windows and Samba hosts—users, groups, shares, and policies.
- EttercapNetwork & Protocol
LAN MITM framework for ARP poisoning, sniffing, and filter-based traffic manipulation on authorized networks.
- Evil-WinRMActive Directory & Windows
WinRM shell and file transfer for post-exploitation on Windows hosts.
- ExifToolForensics & IR
Read and write metadata in images, documents, and media — GPS, camera info, author fields, and hidden tags.
- FeroxbusterScanning & Enumeration
Recursive content discovery tool with smart filtering, backups, and automatic extraction of new URLs.
- ffufScanning & Enumeration
Fast web fuzzer for directories, parameters, vhosts, and header injection with flexible matchers.
- FierceReconnaissance & OSINT
DNS reconnaissance tool that locates non-contiguous IP space near target domains.
- fileExploitation & Payloads
Identify file types from magic bytes — essential before choosing exploit, extraction, or analysis tools.
- File TransferUtilities & Shells
Move files to and from compromised Linux and Windows hosts — HTTP, SMB, netcat, base64, and living-off-the-land binaries.
- ForemostForensics & IR
File carving tool that recovers files from disk images by header/footer signatures when filesystem metadata is missing.
- GDB (GEF / Pwndbg)Exploitation & Payloads
GNU debugger for binary analysis with GEF or Pwndbg for heap, registers, and exploit-oriented views.
- GitUtilities & Shells
Version control CLI for cloning repos, hunting exposed secrets in history, and recovering source during web assessments.
- GobusterScanning & Enumeration
Fast directory, DNS, vhost, and S3 bucket brute-forcer written in Go.
- Google Cloud SDK (gcloud)Cloud & Containers
GCP command-line tool for project enumeration, IAM review, compute instances, and storage access testing.
- GPGUtilities & Shells
GnuPG commands for encrypting files, signing, and managing keys — symmetric and public-key workflows.
- Hash IdentifierPasswords & Cracking
Interactive helper to guess hash type for cracking tools.
- HashcatPasswords & Cracking
GPU-accelerated offline password and hash recovery.
- hping3Network & Protocol
Custom TCP/UDP/ICMP packet crafting for firewall testing, traceroute, and port probing on authorized hosts.
- httpxScanning & Enumeration
Fast HTTP probe for live URLs, status codes, titles, and tech fingerprinting from host lists.
Showing first 50. Refine your search to narrow results.