Essential commands for scanning, enumeration, exploitation, and privilege escalation.
Nmap, RustScan, Autorecon, network discovery and port scanning commands
Directory busting, web scanning, gobuster, feroxbuster, nikto, wpscan
SMBclient, smbmap, NetExec (nxc), enum4linux, share enumeration
One-liners for Bash, Netcat, PHP, Python, PowerShell, and TTY upgrades
wget, curl, PowerShell, certutil, SMB server, and more
SUID, sudo, cron, capabilities, kernel exploits, LinPEAS
Token impersonation, service misconfig, Potato exploits, WinPEAS
BloodHound, Kerberoasting, Pass-the-Hash, lateral movement
AMSI bypass, CLM bypass, AppLocker evasion, LOLBins, Defender evasion
XSS, SQLi, SSRF, file upload, 403 bypass, WAF evasion, OWASP Top 10
Hashcat, John, Hydra, password spraying, hash cracking
XSS, SQLi, SSRF, XXE, deserialization, SSTI, request smuggling, auth bypass
Cobalt Strike, C2 infrastructure, OPSEC, lateral movement, AD attacks, persistence
Comprehensive exam-focused reference: methodology, scanning, service enumeration, web attacks, Active Directory, Linux/Windows privesc, shells, file transfers, pivoting, and password attacks. Everything you need on exam day.