Pentest-Notes
Collection of Pentest Notes and Cheatsheets
File Explorer
Download Latest Version (.zip)- chapter-1.md
- chapter-2.md
- chapter-3.md
- chapter-4.md
- chapter-5.md
- chapter-6.md
- chapter-7.md
- chapter-8.md
- chapter-9.md
- README.md
- bounties.md
- guides.md
- preparation.md
- network.md
- vulnerability.md
- windows-local.md
- cheatsheet.md
- exploits.md
- prev-escalation.md
- share-files.md
- tty.md
- web.md
- windows.md
- _preparation.md
- _setup.md
- notes.md
- practice-vulnhub.md
- scripts.md
- tools.md
- vuln-software.md
- aws-s3.md
- aws.md
- azuer.md
- _general.md
- _general.md
- bank.md
- bastard.md
- beep.md
- CronOS.md
- grandpa.md
- lame.md
- popcorn.md
- general.md
- hackthebox.md
- command_execution.md
- 0-roles-and-permissions.md
- 1-enumeration.md
- 2-exploitation.md
- 3-command-execution.md
- 4-privilage-escalation.md
- 5-lateral-movement.md
- 6-persistence.md
- 9-defence.md
- 9-pending-references.md
- _general.md
- books.md
- ctf.md
- important-files.md
- tools.md
- glitching.md
- test-conditions.md
- _analysis.md
- _collections.md
- _general.md
- binwalk.md
- bluetooth.md
- busybox.md
- cross-compiling.md
- esp.md
- hacking-atms.md
- hacking-cars.md
- hacking-locks.md
- hacking-printers.md
- hacking-ships.md
- hacking_cameras.md
- hardware.md
- opwnwrt.md
- protocols.md
- qmue.md
- side-channel.md
- tools.md
- uboot.md
- uefi.md
- backdoor.md
- _general.md
- buffer-overflow.md
- commands.md
- fuzzing.md
- kernel-exploitation-linux.md
- kernel-exploitation-windows.md
- lateral-movement.md
- malware.md
- memory-protection.md
- os_windows.md
- payloads.md
- persistance.md
- rop.md
- tool-metasploit.md
- jwt.md
- kerberos.md
- oauth2.md
- go.md
- php.md
- python.md
- regex.md
- rush.md
- _general.md
- _hardning.md
- _tools.md
- file-information.md
- hardware-information.md
- important-files.md
- iptables.md
- netcat.md
- networking.md
- os-information.md
- permissions.md
- privilage-escalation.md
- process-information.md
- searching.md
- services.md
- tcpdump.md
- vi.md
- _defense.md
- anti-virus.md
- downloaders.md
- fileless-attacks.md
- general.md
- pdf-attacks.md
- tools.md
- yara.md
- android.md
- ios.md
- _general.md
- commands.md
- defense.md
- domain-fronting.md
- port-forwarding-and-tunneling.md
- tools.md
- traffic-analysis.md
- wireless.md
- general.md
- tools.md
- general.md
- windows.md
- development.md
- general.md
- modules.md
- remoting.md
- Citrix-1494.md
- DHCP.md
- DNS-53.md
- Finger-79.md
- FTP-21.md
- HTTP-HTTPS-80,443.md
- IMAP-143.md
- IRC-8067.md
- LDAP-389.md
- Memcache.md
- Modbus-502.md
- MySQL-3306.md
- NFS-2049.md
- NTP-123.md
- Oracle-1521.md
- POP3-110.md
- Portmapper-111.md
- PPTP-L2TP-VPN-500,1723.md
- RDP-3389.md
- rlogin-513.md
- RPC.md
- SIP-5060.md
- SMB-Samba-NetBIOS-135-139,445.md
- SMTP-25.md
- SNMP-161.md
- SQL-Server-1433,1434.md
- SSH-22.md
- Telnet-23.md
- TFTP-69.md
- Tor-9001,9030.md
- VNC-5900.md
- WebDev.md
- X11-6000.md
- DNS.md
- email.md
- general.md
- reconng.md
- elf.md
- gdb.md
- setup.md
- general.md
- mitigations.md
- pe.md
- tools.md
- vba.md
- anti-reverse-engineering.md
- arm.md
- c-cpp.md
- dotnet.md
- general.md
- go.md
- java.md
- tools.md
- rfid_nfc.md
- rpi.md
- sdr.md
- nmap.md
- port-scanning.md
- vulnerability-scanning.md
- powershell.md
- x86.md
- tools.md
- pentesting.md
- change-password.md
- forgot-password.md
- login.md
- put.md
- register.md
- remember-me.md
- _basics.md
- _defense.md
- _general.md
- _practice.md
- applets.md
- arbitrary-file-upload.md
- browser-exploits.md
- bypass.md
- command-injection.md
- crlf.md
- csrf.md
- discovery.md
- lfi-rfi.md
- open-redirect.md
- password-attacks.md
- php.md
- post-exploitation.md
- sql-injection.md
- ssl-tls.md
- ssrf.md
- tools.md
- toos-burp.md
- xss.md
- _bypass.md
- _defending.md
- _general.md
- _tools.md
- active-directory.md
- api.md
- credential-stealing.md
- domain-previlage-escalation.md
- endpoints.md
- events.md
- hyperv.md
- important-files.md
- previlage-escalation.md
- processes.md
- server-security.md
- services.md
- wmi.md
- README.md
- README.md
- application-whitelisting-bypass-with-wmic-and-xsl.md
- forcing-iexplore.exe-to-load-a-malicious-dll-via-com-abuse.md
- powershell-constrained-language-mode-bypass.md
- powershell-without-powershell.md
- README.md
- t1117-regsvr32-aka-squiblydoo.md
- t1118-installutil.md
- t1170-mshta-code-execution.md
- t1191-cmstp-code-execution.md
- t1196-control-panel-item-code-execution.md
- t1202-forfiles-indirect-command-execution.md
- t1216-signed-script-ce.md
- using-msbuild-to-execute-shellcode-in-c.md
- apc-queue-code-injection.md
- backdooring-a-pe-executable-with-shellcode.md
- backdooring-portable-executables-pe-with-shellcode.md
- dll-injection.md
- early-bird-apc-queue-code-injection.md
- executing-shellcode-with-inline-assembly-in-c-c++.md
- finding-kernel32-base-and-function-addresses-in-shellcode.md
- how-to-hook-windows-api-using-c++.md
- loading-and-executing-shellcode-from-portable-executable-resources.md
- process-doppelganging.md
- process-hollowing-and-pe-image-relocations.md
- process-injection.md
- README.md
- reflective-dll-injection.md
- reflective-shellcode-dll-injection.md
- setwindowhookex-code-injection.md
- shellcode-execution-in-a-local-process-with-queueuserapc-and-nttestalert.md
- dump-credentials-from-lsass-process-using-mimikatz.md
- dumping-and-cracking-mscash-cached-domain-credentials.md
- dumping-credentials-from-lsass.exe-process-memory.md
- dumping-domain-controller-hashes-via-wmic-and-shadow-copy-using-vssadmin.md
- dumping-lsa-secrets.md
- dumping-lsass-passwords-without-mimikatz-minidumpwritedump-av-signature-bypass.md
- forcing-wdigest-to-store-credentials-in-plaintext.md
- network-vs-interactive-logons.md
- ntds.dit-enumeration.md
- reading-dpapi-encrypted-secrets-with-mimikatz-and-c++.md
- README.md
- sam.md
- t1174-password-filter-dll.md
- t1214-credentials-in-registry.md
- av-bypass-with-metasploit-templates.md
- bypassing-cylance-and-other-avs-edrs-by-unhooking-windows-apis.md
- bypassing-ids-signatures-with-simple-reverse-shells.md
- bypassing-windows-defender-one-tcp-socket-away-from-meterpreter-and-cobalt-strike-beacon.md
- commandline-obfusaction.md
- downloading-file-with-certutil.md
- evading-windows-defender-using-classic-c-shellcode-launcher-with-1-byte-change.md
- executing-csharp-assemblies-from-jscript-and-wscript-with-dotnettojscript.md
- file-smuggling-with-html-and-javascript.md
- masquerading-processes-in-userland-through-_peb.md
- README.md
- t1027-obfuscated-powershell-invocations.md
- t1045-software-packing-upx.md
- t1096-alternate-data-streams.md
- t1099-timestomping.md
- t1140-encode-decode-data-with-certutil.md
- t1158-hidden-files.md
- unloading-sysmon-driver.md
- using-native-syscalls-to-bypass-avs-edrs.md
- using-syscalls-directly-from-visual-studio-to-bypass-avs-edrs.md
- detecting-sysmon-on-the-victim-host.md
- dumping-gal-global-address-list-from-outlook-web-application.md
- enumerating-users-without-net-services-without-sc-and-scheduled-tasks-without-schtasks.md
- README.md
- t1010-application-window-discovery.md
- t1087-account-discovery.md
- using-com-to-enumerate-hostname-username-domain-network-drives.md
- payload-delivery-via-dns-using-invoke-powercloud.md
- README.md
- bypassing-malicious-macro-detections-by-defeating-child-parent-process-relationships.md
- inject-macros-from-a-remote-dotm-template-docx-with-macros.md
- phishing-.slk-excel.md
- phishing-embedded-html-forms.md
- phishing-embedded-internet-explorer.md
- phishing-ole-+-lnk.md
- phishing-replacing-embedded-video-with-bogus-payload.md
- phishing-xlm-macro-4.0.md
- README.md
- t1137-office-vba-macros.md
- t1173-dde.md
- netntlmv2-hash-stealing-using-outlook.md
- password-spraying-outlook-web-access-remote-shell.md
- phishing-with-gophish-and-digitalocean.md
- README.md
- t1187-forced-authentication.md
- empire-shells-with-netnltmv2-relaying.md
- lateral-movement-via-smb-relaying-by-abusing-lack-of-smb-signing.md
- lateral-movement-with-psexec.md
- README.md
- simple-tcp-relaying-with-netcat.md
- ssh-tunnelling-port-forwarding.md
- t1028-winrm-for-lateral-movement.md
- t1047-wmi-for-lateral-movement.md
- t1051-shared-webroot.md
- t1076-rdp-hijacking-for-lateral-movement.md
- t1175-distributed-component-object-model.md
- wmi-+-msi-lateral-movement.md
- wmi-+-powershell-desired-state-configuration-lateral-movement.md
- wmi-via-newscheduledtask.md
- office-templates.md
- README.md
- t1013-addmonitor.md
- t1015-sethc.md
- t1035-service-execution.md
- t1053-schtask.md
- t1122-com-hijacking.md
- t1128-netsh-helper-dll.md
- t1130-install-root-certificate.md
- t1131-auth-packages.md
- t1136-create-account.md
- t1138-application-shimming.md
- t1180-screensaver-hijack.md
- t1197-bits-jobs.md
- t1198-trust-provider-hijacking.md
- t1209-hijacking-time-providers.md
- word-library-add-ins.md
- README.md
- t1038-dll-hijacking.md
- t1108-redundant-access.md
- t1134-access-token-manipulation.md
- t1183-image-file-execution-options-injection.md
- unquoted-service-paths.md
- weak-service-permissions.md
- windows-namedpipes-privilege-escalation.md
- automating-red-team-infrastructure-with-terraform.md
- cobalt-strike-101-installation-and-interesting-commands.md
- how-to-setup-modliska-reverse-http-proxy-for-phishing.md
- powershell-empire-101.md
- README.md
- redirectors-forwarders.md
- smtp.md
- spiderfoot-101-with-kali-using-docker.md
- loading-and-executing-shellcode-from-portable-executable-resouces.md
- README.md
- wip.md
- _config.yml
- CNAME
- README.md
- SUMMARY.md
// repository documentation
Was this content helpful?
(0 ratings)
