I published a browser-readable cheatsheet of the commands and techniques I use most in penetration testing and CTFs.
Contents
Each page collects the steps I actually refer to on engagements and in CTFs.
- Enumeration — the first things to check on a target
- Web attacks — SQLi, XSS, LFI/RFI, SSTI, OS command injection, XXE and more
- CMS — common checks for WordPress, Joomla, Grafana and others
- Shells — getting and stabilising various reverse shells
- Privilege escalation — local privesc on Linux and Windows
About
This started as personal notes, organised into a single site so I can reach it from anywhere. It is not indexed by search engines (noindex), and I add to it over time.