Skip to content
HackIndex logo

HackIndex

A structured knowledge base for penetration testers.

Browse by service or platform, or jump straight to an attack phase: Reconnaissance, Enumeration, Exploitation, Privilege Escalation. Find the exact cheatsheet or technique you need.

709+

Cheatsheets, blogs & guides

61+

Services & platforms

63+

CTF writeups

31+

CVEs PoC's

Services & Platforms

Each service contains attack phases and individual technique cheatsheets. This is a horizontally scrolling list of services. You can tab through items.

View all
HTTP/HTTPS icon

HTTP/HTTPS

HTTP/HTTPS pentesting covers recon, enum, vuln discovery, and exploitation of web apps via XSS, SQLi, RCE, LFI, SSRF, JWT flaws, file uploads, and more through to exfil and persistence

Reconnaissance Enumeration Vulnerability Discovery +5 more
Linux icon

Linux

Linux attack reference covering enumeration, privesc via SUID and sudo, shell upgrades, lateral movement via SSH, persistence through cron and systemd, and data exfiltration techniques

Privilege Escalation Post-Exploitation Exploitation +4 more
Windows icon

Windows

Windows pentesting reference covering exploitation, privesc, lateral movement via SMB, WMI and RDP, persistence, AD enumeration, and data exfiltration over HTTP, DNS, and FTP

Privilege Escalation Post-Exploitation Lateral Movement +5 more
Wireless icon

Wireless

Wireless pentesting covering monitor mode setup, passive recon, AP and client enumeration, PMKID capture, WEP/WPA cracking, rogue APs, and post-auth traffic decryption

Setup and Hardware Reconnaissance Enumeration +3 more

Active Directory

Active Directory is Microsoft's directory service for managing users, computers, and policies in Windows networks. It is the central authentication and authorization backbone of most enterprise environments.

Reconnaissance Enumeration Vulnerability Discovery +5 more
AI Platforms icon

AI Platforms

Covers attacking AI systems across recon of endpoints and APIs, threat modeling agent permissions, finding vulns in LLMs and RAG, exploiting AI infra, and poisoning supply chains

Reconnaissance Threat Modeling Vulnerability Discovery +3 more
OSINT icon

OSINT

Open source intelligence platform covering target profiling, identity tracing, corporate and domain mapping, SOCMINT, dark web monitoring, threat actor attribution, and analysis using only publicly available sources

Identity & People Intelligence
FTP icon

FTP

FTP file transfer service. Attackers check banners, anonymous access, writable dirs, cleartext creds, CVEs, and backdoors, then exploit for shells, brute-force, or data exfiltration

Enumeration Vulnerability Discovery Exploitation +1 more

Recent Writeups

Detailed walkthroughs of HTB machines and CTF challenges.

All writeups

Join the HackIndex community

Ask questions, and stay current with techniques.

Join Discord (opens in new tab)