Platforms
Browse all platforms. Each platform contains attack phases with individual technique guides and cheatsheets.
Linux
→Linux attack reference covering enumeration, privesc via SUID and sudo, shell upgrades, lateral movement via SSH, persistence through cron and systemd, and data exfiltration techniques
Windows
→Windows pentesting reference covering exploitation, privesc, lateral movement via SMB, WMI and RDP, persistence, AD enumeration, and data exfiltration over HTTP, DNS, and FTP
Wireless
→Wireless pentesting covering monitor mode setup, passive recon, AP and client enumeration, PMKID capture, WEP/WPA cracking, rogue APs, and post-auth traffic decryption
Active Directory
→Active Directory is Microsoft's directory service for managing users, computers, and policies in Windows networks. It is the central authentication and authorization backbone of most enterprise environments.
AI Platforms
→Covers attacking AI systems across recon of endpoints and APIs, threat modeling agent permissions, finding vulns in LLMs and RAG, exploiting AI infra, and poisoning supply chains
OSINT
→Open source intelligence platform covering target profiling, identity tracing, corporate and domain mapping, SOCMINT, dark web monitoring, threat actor attribution, and analysis using only publicly available sources
AWS
→Enumeration, exploitation, and post-exploitation techniques targeting AWS environments. Covers IAM abuse, metadata service, S3 misconfigurations, credential harvesting, and lateral movement across accounts and services.