CyberCheatsheets

All tools

14 cheatsheets in Network & Protocol

Bettercap

Network

Modern network attack and monitoring framework for ARP/DNS spoofing, sniffing, and credential attacks on authorized LANs.

mitmspoofingwifi

Ettercap

Network

LAN MITM framework for ARP poisoning, sniffing, and filter-based traffic manipulation on authorized networks.

arpmitmsniffing

hping3

Network

Custom TCP/UDP/ICMP packet crafting for firewall testing, traceroute, and port probing on authorized hosts.

dosfirewallscan

Netcat

Network

TCP/UDP connect, listen, and port relay for banners, shells, and file transfer on authorized networks.

ncatnetcatpivotshell

Pivoting & Tunneling

Network

SSH tunneling, port forwarding, SOCKS proxies, and pivoting with chisel/ligolo to reach internal networks during authorized engagements.

lateral-movementpivotingport-forwardingproxychains

Proxychains

Network

Force TCP connections through SOCKS4/5 or HTTP proxies for pivoting during authorized internal assessments.

pivotsockstunnel

Responder

Network

LLMNR/NBT-NS/mDNS poisoner and rogue authentication server for capturing NetNTLM hashes on authorized Windows networks.

hash-capturellmnrnbt-ns

rpcclient

Network

MS-RPC client for SAMR/LSA enumeration and user management via null or authenticated sessions on authorized domains.

rpcsamrwindows

SMB Enumeration

Network

Enumerate SMB: shares, null sessions, users, and versions with nmap, netexec, smbclient, and enum4linux on authorized networks.

enumerationnetbiossharessmb

smbclient

Network

SMB/CIFS client for share enumeration, file access, and null-session testing on authorized Windows hosts.

sharessmbwindows

socat

Network

Bidirectional data relay for shells, port forwarding, and protocol bridging on authorized networks.

pivotrelaytunnel

tcpdump

Network

Command-line packet capture and filtering for authorized network analysis and troubleshooting.

capturepcapsniffing

tshark

Network

CLI Wireshark for capture, display filters, and protocol field extraction on authorized traffic.

analysispcapwireshark

Wireshark Filters

Network

Wireshark display and capture filter syntax for slicing packet captures during analysis and forensics.

display-filterspacket-analysispcaptshark