{"id":56506,"url":"https://github.com/ByteSnipers/awesome-pentest-cheat-sheets","name":"awesome-pentest-cheat-sheets","description":"Collection of cheat sheets useful for pentesting","projects_count":170,"last_synced_at":"2026-08-01T10:00:25.264Z","repository":{"id":220875991,"uuid":"752811322","full_name":"ByteSnipers/awesome-pentest-cheat-sheets","owner":"ByteSnipers","description":"Collection of cheat sheets useful for pentesting","archived":false,"fork":false,"pushed_at":"2024-06-27T07:56:01.000Z","size":7881,"stargazers_count":662,"open_issues_count":2,"forks_count":55,"subscribers_count":8,"default_branch":"main","last_synced_at":"2026-07-13T08:04:27.328Z","etag":null,"topics":["cheat-sheet","cheat-sheet-pentest","penetration-testing","penetration-testing-tools","pentest","pentest-cheat-sheets","pentesting","pentesting-resources"],"latest_commit_sha":null,"homepage":"https://bytesnipers.com","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"cc0-1.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ByteSnipers.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":".github/CONTRIBUTING.md","funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2024-02-04T21:26:46.000Z","updated_at":"2026-07-12T12:41:21.000Z","dependencies_parsed_at":null,"dependency_job_id":"c5bc37ac-c0d0-4f4f-a459-52ce20925dae","html_url":"https://github.com/ByteSnipers/awesome-pentest-cheat-sheets","commit_stats":null,"previous_names":["bytesnipers/awesome-pentest-cheat-sheets"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/ByteSnipers/awesome-pentest-cheat-sheets","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ByteSnipers%2Fawesome-pentest-cheat-sheets","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ByteSnipers%2Fawesome-pentest-cheat-sheets/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ByteSnipers%2Fawesome-pentest-cheat-sheets/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ByteSnipers%2Fawesome-pentest-cheat-sheets/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ByteSnipers","download_url":"https://codeload.github.com/ByteSnipers/awesome-pentest-cheat-sheets/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ByteSnipers%2Fawesome-pentest-cheat-sheets/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36153085,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"online","status_checked_at":"2026-08-01T02:00:05.789Z","response_time":100,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2024-02-28T07:09:21.344Z","updated_at":"2026-08-01T10:00:25.264Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["🕷️ Web Pentesting","Bug Bounty","📎 Pentest Methodology","Pentest Methodology","Mobile Pentesting","📱 Mobile Pentesting","Learning Platforms","Security Talks and Videos","General cheat sheets","Active Directory","🖥 Security Talks and Videos","Cloud Pentesting","☁️ Cloud Pentesting","Binary Exploitation","Web Pentesting"],"sub_categories":["🗝 Privilege Escalation","Tools Online","Exploitation","Apple","Discovery","🎯 Exploitation","Tools","Write-Ups","Defence Topics","Android","Azure","Kubernetes","Enumeration","🧿 Post-Exploitation","Privilege Escalation","Payloads","Programming","Wireless Hacking","Post-Exploitation"],"readme":"# Awesome Pentest Cheat Sheets [![Awesome](https://awesome.re/badge.svg)](https://github.com/sindresorhus/awesome)\n\nCollection of cheat sheets and check lists useful for security and pentesting. The list contains a huge list of very sorted and selected resources, which can help you to save a lot of time.\n\nThis repo is the updated version from [awesome-pentest-cheat-sheets](https://github.com/coreb1t/awesome-pentest-cheat-sheets).\n\n## Contents\n\n- [Security Talks and Videos](#security-talks-and-videos)\n- [General cheat sheets](#general-cheat-sheets)\n- [Mobile Pentesting](#mobile-pentesting)\n- [Cloud Pentesting](#cloud-pentesting)\n- [Active Directory](#active-directory)\n- [Pentest Methodology](#pentest-methodology)\n- [Privilege Escalation](#privilege-escalation)\n- [Web Pentesting](#web-pentesting)\n- [Binary Exploitation](#binary-exploitation)\n- [Learning Platforms](#learning-platforms)\n- [Bug Bounty](#bug-bounty)\n- [Tools](#tools)\n- [Payloads](#payloads-1)\n- [Programming](#programming)\n\n### Contribution\n\nYour contributions and suggestions are heartily welcome. Please check the [Contributing Guidelines](https://github.com/ByteSnipers/awesome-pentest-cheat-sheets/blob/main/.github/CONTRIBUTING.md) for more details.\n\n## Security Talks and Videos\n\n- [Cybersecurity Conference Directory](https://infosec-conferences.com/site-map/#allevents) - All Cybersecurity, InfoSec \u0026 IT Conferences and Events.\n- [Confsec](https://github.com/cryptax/confsec) - List of Security Events 2024.\n- [InfoCon](https://infocon.org/cons/) - The Hacking Conference Archive.\n- [Awesome Security Talks](https://github.com/PaulSec/awesome-sec-talks) - Curated list of Security Talks and Videos.\n\n## General cheat sheets\n\n- [The Hackers' Choice Tips \u0026 Tricks Cheatsheet](https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet)\n- [Docker Cheat Sheet](https://github.com/wsargent/docker-cheat-sheet)\n- [macOS Command Line Cheat Sheet](https://github.com/herrbischoff/awesome-osx-command-line)\n- [PowerShell Cheat Sheet](https://pen-testing.sans.org/blog/2016/05/25/sans-powershell-cheat-sheet) - SANS PowerShell Cheat Sheet from SEC560 Course [(PDF version)](docs/PowerShellCheatSheet_v41.pdf).\n- [Rawsec's CyberSecurity Inventory](https://inventory.raw.pm/) - An open-source inventory of tools, resources, CTF platforms and Operating Systems about CyberSecurity. ([Source](https://gitlab.com/rawsec/rawsec-cybersecurity-list)).\n- [Regexp Security Cheat Sheet](https://github.com/attackercan/regexp-security-cheatsheet)\n- [Security Cheat Sheets](https://github.com/teamghsoftware/security-cheatsheets) - A collection of security cheat sheets.\n- [Unix Commands Cheat Sheet](https://www.stationx.net/unix-commands-cheat-sheet/)\n- [Linux File Permissions Cheat Sheet](https://www.stationx.net/linux-file-permissions-cheat-sheet/)\n- [DostoevskyLabs' Pentest notes](https://dostoevskylabs.gitbooks.io/dostoevskylabs-pentest-notes/content/) - Pentest Notes collection from DostoevskyLabs.\n- [Thick Client Pentest Checklist](https://github.com/Hari-prasaanth/Thick-Client-Pentest-Checklist) - Pentest Checklist for Thick-Client Penetration Tests.\n- [HauSec's Pentesting Cheat sheet](https://hausec.com/pentesting-cheatsheet/) - Pentest Cheat sheet from HauSec.\n\n## Mobile Pentesting\n\n- [Mobile App Pentest Cheat Sheet](https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet) - Collection of resources on Apple \u0026 iOS Penetration Testing.\n- [Mobexler](https://mobexler.com/) - Customised virtual machine, designed to help in penetration testing of Android \u0026 iOS applications.\n\n### Android\n\n![](https://coderkube.com/wp-content/uploads/2017/10/android-app-development-banner.png).\n\n- [Android Pentest Checklist Xmind](https://xmind.app/m/GkgaYH/#) - Xmind mindmap for Android Penetration Tests.\n- [MASTG](https://github.com/OWASP/owasp-mastg) - OWASP Mobile Application Security Testing Guide [[PDF]](https://github.com/OWASP/owasp-mastg/releases/download/v1.4.0/OWASP_MSTG-v1.4.0.pdf).\n- [Android Pentesting Checklist](https://github.com/Hrishikesh7665/Android-Pentesting-Checklist) - Case-by-case Checklist for Android Pentests.\n- [Android Pentesting Cheat sheet](https://github.com/ivan-sincek/android-penetration-testing-cheat-sheet) - Android Pentesting Resources #1.\n- [HackTricks - Android Pentesting](https://book.hacktricks.xyz/mobile-pentesting/android-app-pentesting) - HackTricks Collection of Android Pentesting.\n\n#### Vulnerable Android Applications\n\n- [InjuredAndroid](https://github.com/B3nac/InjuredAndroid)\n- [Damn vulnerable Bank](https://github.com/rewanthtammana/Damn-Vulnerable-Bank)\n- [InsecureShop](https://github.com/optiv/InsecureShop)\n- [AndroGoat](https://github.com/satishpatnayak/AndroGoat)\n- [Android-Insecurebankv2](https://github.com/dineshshetty/Android-InsecureBankv2)\n- [OVAA](https://github.com/oversecured/ovaa)\n- [DIVA](https://github.com/payatu/diva-android)\n\n### Apple\n\n![](https://uol.de/f/5/_processed_/8/3/csm_apple-banner-min_1588062300375_244697dda3.jpeg)\n\n- [iOS Pentest Checklist](https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet) - Checklist for iOS/IPA Penetration Tests.\n- [Hacktricks iOS Checklist](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting-checklist) -  Another Checklist for iOS/IPA Penetration Tests | Hacktricks Cloud.\n- [PentestGlobal IOS gitbook](https://ios.pentestglobal.com/) - Gitbook about iOS Pentesting.\n- [Can i jailbreak?](https://canijailbreak.com/) - List of each jailbreak needed for each iOS version.\n- [Jailbreaks.app](https://jailbreaks.app/) - Downloads for Odyssey, Taurine Jailbreaks.\n\n## Cloud Pentesting\n\n### Kubernetes\n\n![](https://codefresh.io/wp-content/uploads/2023/07/Intro-to-Kubernetes-blog-b-2.png)\n\n- [Awesome Kubernetes (K8s) Security](https://github.com/magnologan/awesome-k8s-security) - Collection of Kubernetes security resources.\n- [Kubetools](https://collabnix.github.io/kubetools/#security-tools) - Kubernetes security tools.\n- [HackingKubernetes](https://github.com/g3rzi/HackingKubernetes) - Collection of Kubernetes Pentesting Resources.\n- [Kubernetes Goat](https://github.com/madhuakula/kubernetes-goat) - Vulnerable-by-Design cluster environment for training.\n- [KubePwn](https://github.com/alexivkin/kubepwn) - Another Collection of resources about Kubernetes security.\n- [HackTricks - Kubernetes Pentesting](https://cloud.hacktricks.xyz/pentesting-cloud/kubernetes-security) - HackTricks Collection of Kubernetes Pentesting.\n\n##### Kubernetes Pentest Methodology (CyberArk)\n\n- [Part 1](https://cyberark.com/resources/threat-research-blog/kubernetes-pentest-methodology-part-1)\n- [Part 2](https://www.cyberark.com/resources/threat-research-blog/kubernetes-pentest-methodology-part-2)\n- [Part 3](https://www.cyberark.com/resources/threat-research-blog/kubernetes-pentest-methodology-part-3)\n\n### Azure\n\n![](https://www.evozon.com/wp-content/uploads/2017/05/Azure-Banner.png)\n\n- [Awesome Azure Pentest](https://github.com/Kyuu-Ji/Awesome-Azure-Pentest) - A curated list of useful tools and resources for penetration testing and securing Microsofts cloud platform Azure.\n- [HackTricks - Azure Pentesting](https://cloud.hacktricks.xyz/pentesting-cloud/azure-security) - HackTricks Collection of Kubernetes Pentesting.\n\n## Active Directory\n\n![](https://www.bds-solutions.co.uk/wp-content/uploads/2015/10/AD-2012.png)\n\n- [Active Directory Exploitation Cheat Sheet](https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet) - Cheat sheet for Active Directory Exploitation.\n- [OSCP Active Directory Cheat Sheet](https://github.com/brianlam38/OSCP-2022/blob/main/cheatsheet-active-directory.md) - Cheat sheet for Active Directory Attacks used in OSCP.\n- [WADComs](https://wadcoms.github.io/) - Interactive cheat sheet - list of offensive security tools and their respective commands to be used against Windows/AD environments.\n- [HackTricks - Active Directory Pentesting](https://book.hacktricks.xyz/windows-hardening/active-directory-methodology) - HackTricks Collection of Active Directory Pentesting.\n- [GOAD](https://github.com/Orange-Cyberdefense/GOAD) - Vulnerable-by-Design Active Directory environment.\n- [Ultimate BloodHound Guide](https://m4lwhere.medium.com/the-ultimate-guide-for-bloodhound-community-edition-bhce-80b574595acf) - The Ultimate Guide for BloodHound Community Edition (BHCE).\n- [Windows Red Team Cheat sheet](https://github.com/morph3/Windows-Red-Team-Cheat-Sheet) - Windows for Red Teamers Cheat Sheet ([Moved to wiki](https://notes.morph3.blog/)).\n- [Resource Collection #1](https://github.com/DeanOfCyber/Active-Directory-Penetration-Testing-and-Security) - Collection of Active Directory Pentesting resources #1.\n- [Resource Collection #2](https://github.com/AD-Attacks/Active-Directory-Penetration-Testing) - Collection of Active Directory Pentesting resources #2.\n- [Resource Collection #3](https://github.com/geeksniper/active-directory-pentest) - Collection of Active Directory Pentesting resources #3.\n- [Resource Collection #4](https://github.com/Integration-IT/Active-Directory-Exploitation-Cheat-Sheet) - Collection of Active Directory Pentesting resources #4.\n\n## Pentest Methodology\n\n![](https://blog.rapid7.com/content/images/2018/03/green-metasploit-heart-banner.png)\n\n### Discovery\n\n- [Google Dorks](https://www.exploit-db.com/google-hacking-database) - Google Dorks Hacking Database (Exploit-DB).\n- [Shodan](https://github.com/ByteSnipers/awesome-pentest-cheat-sheets/blob/main/docs/shodan.md) - Shodan is a search engine for finding specific devices, and device types, that exist online.\n- [ZoomEye](http://zoomeye.org) - Zoomeye is a Cyberspace Search Engine recording information of devices, websites, services and components etc.\n- [Amass](https://github.com/OWASP/Amass) - OWASP Network mapping of attack surfaces and external asset discovery using open source information.\n- [Censys](https://search.censys.io/) - Similar to shodan, search engine for specific devices including IoT.\n\n### Enumeration\n\n- [enum4linux-ng](https://github.com/cddmp/enum4linux-ng) - Python tool for enumerating information from Windows/Samba systems.\n- [0xdf - SMB Enumeration](https://0xdf.gitlab.io/2024/03/21/smb-cheat-sheet.html) - 0xdf's SMB Enumeration Cheat Sheet.\n- [OSCP Enumeration Cheat sheet](https://github.com/oncybersec/oscp-enumeration-cheat-sheet) - Cheat sheet for Enumeration for OSCP Certificate.\n- [CrackMapExec Cheatsheet](https://cheatsheet.haax.fr/windows-systems/exploitation/crackmapexec/) - Cheat sheet for CrackMapExec (CME).\n\n### Exploitation\n\n- [Empire Cheat Sheet](https://github.com/HarmJ0y/CheatSheets/blob/master/Empire.pdf) - [Empire](http://www.powershellempire.com) is a PowerShell and Python post-exploitation framework.\n- [Exploit Development Cheat Sheet](https://github.com/ByteSnipers/awesome-pentest-cheat-sheets/blob/main/docs/pentest-exploit-dev-cheatsheet.jpg) - [@ovid](https://twitter.com/ovid)'s exploit development in one picture.\n- [Java Deserialization Cheat Sheet](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet) - A cheat sheet for pentesters about Java Native Binary Deserialization vulnerabilities.\n- [Local File Inclusion (LFI) Cheat Sheet #1](https://highon.coffee/blog/lfi-cheat-sheet/) - Arr0way's LFI Cheat Sheet.\n- [Local File Inclusion (LFI) Cheat Sheet #2](https://www.aptive.co.uk/blog/local-file-inclusion-lfi-testing/) - Aptive's LFI Cheat Sheet.\n- [Metasploit Unleashed](https://www.offensive-security.com/metasploit-unleashed/) - The ultimate guide to the Metasploit Framework.\n- [Metasploit Cheat Sheet](https://www.tunnelsup.com/metasploit-cheat-sheet/) - A quick reference guide [(PNG version)](docs/Metasploit-CheatSheet.png)[(PDF version)](docs/Metasploit-CheatSheet.pdf).\n- [PowerSploit Cheat Sheet](https://github.com/HarmJ0y/CheatSheets/blob/master/PowerSploit.pdf) - [PowerSploit](https://github.com/PowerShellMafia/PowerSploit) is a powershell post-exploitation framework.\n- [PowerView 2.0 Tricks](https://gist.github.com/HarmJ0y/3328d954607d71362e3c)\n- [PowerView 3.0 Tricks](https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993)\n- [PHP htaccess Injection Cheat Sheet](https://github.com/sektioneins/pcc/wiki/PHP-htaccess-injection-cheat-sheet) - PHP htaccess Injection Cheat Sheet by PHP Secure Configuration Checker.\n- [Reverse Shell Cheat Sheet #1](http://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet) - Pentestmonkey Reverse Shell Cheat Sheet.\n- [Reverse Shell Cheat Sheet #2](https://highon.coffee/blog/reverse-shell-cheat-sheet) - Arr0way's  Reverse Shell Cheat Sheet.\n- [SQL Injection Cheat Sheet](https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet) - Netsparker's SQL Injection Cheat Sheet.\n- [SQLite3 Injection Cheat Sheet](http://atta.cked.me/home/sqlite3injectioncheatsheet)\n\n### Post-Exploitation\n\n- [Awesome Windows Post Exploitation](https://github.com/emilyanncr/Windows-Post-Exploitation) - Collection of resources for Windows Post-Exploitation.\n- [HackTricks - Post Exploitation](https://book.hacktricks.xyz/todo/post-exploitation) - HackTricks Collection of Post-Exploitation.\n\n### Privilege Escalation\n\n#### Learn Privilege Escalation\n\n- [Windows / Linux Local Privilege Escalation Workshop](https://github.com/sagishahar/lpeworkshop) - The Privilege Escalation Workshop covers all known (at the time) attack vectors of local user privilege escalation on both Linux and Windows operating systems and includes slides, videos, test VMs.\n\u003cimg src=\"https://pbs.twimg.com/media/DAZsE2VUQAA_bpZ.jpg\"\u003e.\n\n#### ![](images/linux.svg) Linux Privilege Escalation\n\n- [Basic Linux Privilege Escalation](https://blog.g0tmi1k.com/2011/08/basic-linux-privilege-escalation/) - Linux Privilege Escalation by [@g0tmi1k](https://twitter.com/g0tmi1k).\n- [linux-exploit-suggester.sh](https://github.com/mzet-/linux-exploit-suggester) - Linux privilege escalation auditing tool written in bash (updated).\n- [Linux_Exploit_Suggester.pl](https://github.com/PenturaLabs/Linux_Exploit_Suggester) - Linux Exploit Suggester written in Perl (last update 3 years ago).\n- [Linux_Exploit_Suggester.pl v2](https://github.com/jondonas/linux-exploit-suggester-2) - Next-generation exploit suggester based on Linux_Exploit_Suggester (updated).\n- [Linux Soft Exploit Suggester](https://github.com/belane/linux-soft-exploit-suggester) - Linux-soft-exploit-suggester finds exploits for all vulnerable software in a system helping with the privilege escalation. It focuses on software packages instead of Kernel vulnerabilities.\n- [checksec.sh](https://github.com/slimm609/checksec.sh) - Bash script to check the properties of executables (like PIE, RELRO, PaX, Canaries, ASLR, Fortify Source).\n- [linuxprivchecker.py](http://www.securitysift.com/download/linuxprivchecker.py) - This script is intended to be executed locally on a Linux box to enumerate basic system info and search for common privilege escalation vectors such as world writable files, misconfigurations, clear-text passwords and applicable exploits (@SecuritySift).\n- [LinEnum](https://github.com/rebootuser/LinEnum) - This tool is great at running through a heap of things you should check on a Linux system in the post exploit process. This include file permissions, cron jobs if visible, weak credentials etc.(@Rebootuser).\n- [linPEAS](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS) - LinPEAS - Linux Privilege Escalation Awesome Script. Check the Local Linux Privilege Escalation checklist from [book.hacktricks.xyz](https://book.hacktricks.xyz).\n- [MimiPenguin](https://github.com/huntergregal/mimipenguin) - A tool to dump the login password from the current linux desktop user. Adapted from the idea behind the popular Windows tool mimikatz. .\n\n#### ![](images/Windows.svg) Windows Privilege Escalation\n\n- [PowerUp](https://github.com/PowerShellMafia/PowerSploit/tree/master/Privesc) - Excellent powershell script for checking of common Windows privilege escalation vectors. Written by [harmj0y](https://twitter.com/harmj0y) [(direct link)](https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Privesc/PowerUp.ps1).\n- [PowerUp Cheat Sheet](https://github.com/HarmJ0y/CheatSheets/blob/master/PowerUp.pdf)\n- [Windows Exploit Suggester](https://github.com/GDSSecurity/Windows-Exploit-Suggester) - Tool for detection of missing security patches on the windows operating system and mapping with the public available exploits.\n- [Sherlock](https://github.com/rasta-mouse/Sherlock) - PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities.\n- [Watson](https://github.com/rasta-mouse/Watson) - Enumerate missing KBs and suggest exploits for useful Privilege Escalation vulnerabilities.\n- [Precompiled Windows Exploits](https://github.com/abatchy17/WindowsExploits) - Collection of precompiled Windows exploits.\n- [Metasploit Modules](https://github.com/rapid7/metasploit-framework)\n  - post/multi/recon/local_exploit_suggester - suggests local meterpreter exploits that can be used.\n  - post/windows/gather/enum_patches - helps to identify any missing patches.\n\n## Web Pentesting\n\n![](https://142972.fs1.hubspotusercontent-na1.net/hubfs/142972/sql-injection-hero.png)\n- [OWASP Web Security Testing Guide](https://owasp.org/www-project-web-security-testing-guide/v42/)\n- [Web Pentest Checklist](https://pentestbook.six2dez.com/others/web-checklist) - Checklist for Web Application Penetration Tests.\n- [SQL Injection Cheatsheet](https://portswigger.net/web-security/sql-injection/cheat-sheet) - PortSwigger SQL Injection Cheat Sheet.\n- [Cross-Site-Scripting Cheat sheet](https://portswigger.net/web-security/cross-site-scripting/cheat-sheet) - PortSwigger Cross-Site-Scripting (XSS) Cheat sheet.\n- [Google CSP Evaluator](https://csp-evaluator.withgoogle.com) - Google's CSP Evaluator [Chrome Extension](https://chromewebstore.google.com/detail/csp-evaluator/fjohamlofnakbnbfjkohkbdigoodcejf)\n- [Awesome Web Hacking](https://github.com/infoslack/awesome-web-hacking) - Collection of resources for Web Pentesting #1.\n- [Awesome Web Security](https://github.com/qazbnm456/awesome-web-security) - Collection of resources for Web Pentesting #2.\n\n##### Payloads\n\n- [XSS Polyglot Payloads #1](https://github.com/0xsobky/HackVault/wiki/Unleashing-an-Ultimate-XSS-Polyglot) - Unleashing an Ultimate XSS Polyglot list by 0xsobky.\n- [XSS Polyglot Payloads #2](http://polyglot.innerht.ml/) - [@filedescriptor](https://twitter.com/filedescriptor)'s XSS.\n- [Browser's-XSS-Filter-Bypass-Cheat-Sheet](https://github.com/masatokinugawa/filterbypass/wiki/Browser's-XSS-Filter-Bypass-Cheat-Sheet) - Excellent List of working XSS bypasses running on the latest version of Chrome, Safari, Edge created by Masato Kinugawa.\n\n##### Labs\n\n- [PortSwigger Web Penetration Testing Labs](https://portswigger.net/web-security/all-labs)\n\n## Binary Exploitation\n\n![](https://64.media.tumblr.com/cae273ceb708b68e270d66c30e8a42a3/tumblr_inline_pekyt8seIo1sjxwjp_1280.png).\n- [Binary Exploitation Red Team Notes](https://www.ired.team/offensive-security/code-injection-process-injection/binary-exploitation) - Ired.team notes for Binary Exploitation.\n- [Binary Exploitation Notes](https://ir0nstone.gitbook.io/notes) - Ir0nstone's Binary Exploitation Notes.\n- [Sticky Notes Binary Exploitation](https://exploit-notes.hdks.org/exploit/binary-exploitation/) - Sticky Notes colletion for Binary Exploitation.\n- [checksec.py](https://github.com/Wenzel/checksec.py/) - Cross-Platform CheckSec Tool for checking binary security properties.\n- [HackTricks - Binary Exploitation](https://book.hacktricks.xyz/binary-exploitation/basic-binary-exploitation-methodology) - HackTricks Collection of Binary Exploitation.\n- [Liveoverflow - Binary Exploitation](https://www.youtube.com/playlist?list=PLhixgUqwRTjxglIswKp9mpkfPNfHkzyeN) - LiveOverflow's Binary Exploitation YouTube playlist.\n- [PwnTools Cheat sheet](https://gist.github.com/anvbis/64907e4f90974c4bdd930baeb705dedf) - Cheat sheet for PwnTools python library.\n- [pwndbg Cheat sheet](https://drive.google.com/file/d/16t9MV8KTFXK7oX_CzXhmDdaVnjT8IYM4/view) - Cheat sheet for pwndbg GDB plug-in.\n- [GDB PEDA Cheat sheet](https://github.com/kibercthulhu/gdb-peda-cheatsheet/blob/master/gdb-peda%20cheatsheet.pdf) - Cheat sheet for PEDA GDB plug-in.\n\n## Learning Platforms\n\n![](https://www.crest-approved.org/wp-content/uploads/2022/11/htb-header.png)\n\n#### Online\n\n- [Hack The Box :: Penetration Testing Labs](https://www.hackthebox.eu) - Leading penetration testing training labs platform.\n- [TryHackMe](https://tryhackme.com/) - Free online platform for learning cyber security \u0026 penetration testing.\n- [OWASP Vulnerable Web Applications Directory Project (Online)](https://owasp.org/www-project-vulnerable-web-applications-directory/#div-online) - List of online available vulnerable applications for learning purposes.\n- [Pentestit labs](https://lab.pentestit.ru) - Hands-on Pentesting Labs (OSCP style).\n- [Root-me.org](https://www.root-me.org) - Hundreds of challenges are available to train yourself in different and not simulated environments.\n\n#### Off-Line\n\n- [Vulnhub.com](https://www.vulnhub.com) - Vulnerable By Design VMs for practical 'hands-on' experience in digital security.\n- [Damn Vulnerable Xebia Training Environment](https://github.com/davevs/dvxte) - Docker Container including several vurnerable web applications (DVWA,DVWServices, DVWSockets, WebGoat, Juiceshop, Railsgoat, django.NV, Buggy Bank, Mutilidae II and more).\n- [OWASP Vulnerable Web Applications Directory Project (Offline)](https://owasp.org/www-project-vulnerable-web-applications-directory/#div-offline) - List of offline available vulnerable applications for learning purposes.\n- [Vulnerable SOAP Web Service](https://github.com/anil-yelken/Vulnerable-Soap-Service) - Vulnerable SOAP web service lab environment.\n- [Vulnerable Flask Web App](https://github.com/anil-yelken/Vulnerable-Flask-App) - Vulnerable Flask Web App lab environment.\n\n## Bug Bounty\n\n![](https://www.tataplay.com/assets/images/bug-bounty/banner-desktop.png)\n\n- [Awesome BugBounty Tools](https://github.com/vavkamil/awesome-bugbounty-tools) - A curated list of various bug bounty tools.\n- [bug-bounty-platforms](https://github.com/disclose/bug-bounty-platforms) - Open-Sourced Collection of Bug Bounty Platforms.\n- [m0chan - Bug Bounty Methodology](https://m0chan.github.io/2019/12/17/Bug-Bounty-Cheetsheet.html) - m0chan's Bug Bounty Methodology Collection.\n- [NahamSec - Resources for Beginners](https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters) - NahamSec's Resources for Beginner Bug Bounty Hunters Collection.\n- [AllAboutBugBounty](https://github.com/daffainfo/AllAboutBugBounty?tab=readme-ov-file) - BugBounty notes gathered from various sources.\n- [Bug-Bounty-Resources](https://github.com/Tikam02/Bug-Bounty-Resources) - Collection of Bug Bounty Resources #1.\n- [Bug-Bounty-Resources](https://github.com/AnLoMinus/Bug-Bounty) - Collection of Bug Bounty Resources #2.\n\n#### Free video courses\n\n- [Ryan John Bug Bounty Playlist](https://www.youtube.com/watch?v=wMO_My5gsDI\u0026list=PLtZtNPs3fJyDUJttw2sJVU69IKfqY7XPn) - Collection of Ryan John's BugBounty videos ([11h Full Course Video](https://www.youtube.com/watch?v=TTw-EY7F1rM)).\n- [LiveOverFlow Bug Bounty Playlist](https://www.youtube.com/watch?v=LrLJuyAdoAg\u0026list=PLhixgUqwRTjxKYsPTegCyL5adZaq5eILt) - Collection of LiveOverflow's Bug bounty videos.\n\n#### Podcasts\n\n- [BBRE Podcast](https://www.youtube.com/watch?v=CfE0-GZk4v8\u0026list=PLvxs_epf2X91Dn3pWeRxPQSV6SWvWqDE3\u0026index=2) - Bug Bounty Reports Explained Podcast.\n- [Critical Thinking Podcast](https://www.youtube.com/watch?v=t6cTvajgYsM\u0026list=PLO-h_HEvT1ysKxfLkI-uk3_vxzxoUHCD7) - Critical Thinking Bug Bounty Podcast.\n\n### Other resources\n\n### Tools\n\n- [Nmap Cheat Sheet](https://github.com/ByteSnipers/awesome-pentest-cheat-sheets/blob/main/docs/nmap.md)\n- [SQLmap Cheat Sheet](https://github.com/ByteSnipers/awesome-pentest-cheat-sheets/blob/main/docs/sqlmap-cheatsheet-1.0-SDB.pdf)\n- [SQLmap Tamper Scripts](https://forum.bugcrowd.com/t/sqlmap-tamper-scripts-sql-injection-and-waf-bypass/423) - SQLmap Tamper Scripts General/MSSQL/MySQL.\n- [VIM Cheatsheet](https://i.imgur.com/YLInLlY.png)\n- [Wireshark Display Filters](https://github.com/ByteSnipers/awesome-pentest-cheat-sheets/blob/main/docs/Wireshark_Display_Filters.pdf) - Filters for the best sniffing tool.\n\n### Tools Online\n\n- [revshells.com](https://www.revshells.com) - Reverse shell payload generator ([Source code](https://github.com/0dayCTF/reverse-shell-generator)).\n- [Segfault](https://www.thc.org/segfault) - Segfault: Free disposable root servers (by [@THC](https://www.thc.org/)).\n- [suip.biz](https://suip.biz) - Various free online pentesting tools like nmap, wpscan, sqlmap.\n- [XSS'OR Encoder/Decoder](http://xssor.io/#ende) - Online Decoder/Encoder for testing purposes (@evilcos).\n- [WebGun](https://brutelogic.com.br/webgun/) - WebGun, XSS Payload Creator (@brutelogic).\n- [Hackvertor](https://hackvertor.co.uk) - Tool to convert various encodings and generate attack vectors (@garethheyes).\n- [JSFiddle](https://jsfiddle.net) - Test and share XSS payloads, [Example PoC](https://jsfiddle.net/xqjpsh65/).\n\n### Payloads\n\n- [Fuzzdb](https://github.com/fuzzdb-project/fuzzdb) - Dictionary of attack patterns and primitives for black-box application testing Polyglot Challenge with submitted solutions.\n- [SecList](https://github.com/danielmiessler/SecLists) - A collection of multiple types of lists used during security assessments. List types include usernames, passwords, URLs, sensitive data grep strings, fuzzing payloads, and many more.\n\n### Write-Ups\n\n- [Bug Bounty Reference](https://github.com/ngalongc/bug-bounty-reference) - Huge list of bug bounty write-up that is categorized by the bug type (SQLi, XSS, IDOR, etc.).\n- [Write-Ups for CTF challenges](https://ctftime.org/writeups)\n- [Facebook Bug Bounties](https://www.facebook.com/notes/phwd/facebook-bug-bounties/707217202701640) - Categorized Facebook Bug Bounties write-ups.\n\n### Wireless Hacking\n\n#### Tools\n\n- [wifite2](https://github.com/coreb1t/wifite2) - Full automated WiFi security testing script .\n\n### Defence Topics\n\n- [Docker Security Cheat Sheet](https://container-solutions.com/content/uploads/2015/06/15.06.15_DockerCheatSheet_A2.pdf) - The following tips should help you to secure a container based system [(PDF version)](docs/DockerCheatSheet.pdf).\n- [Windows Domain Hardening](https://github.com/PaulSec/awesome-windows-domain-hardening) - A curated list of awesome Security Hardening techniques for Windows.\n\n### Programming\n\n- [JavaScript Cheat Sheet](https://github.com/coodict/javascript-in-one-pic) - Learn JavaScript in one picture [(Online version)](https://git.io/Js-pic) [(PNG version)](docs/js-in-one-pic.png).\n- [Python Cheat Sheet #1](https://github.com/siyuanzhao/python3-in-one-pic) - Learn python3 in one picture [(PNG version)](docs/python-3-in-one-pic.png).\n- [Python Cheat Sheet #2 ](https://github.com/coodict/python3-in-one-pic) - Learn python3 in one picture [Online version](https://git.io/Coo-py3) [PNG version](docs/py3-in-one-pic.png).\n- [Python Snippets Cheat Sheet](https://github.com/ByteSnipers/awesome-pentest-cheat-sheets/blob/main/docs/python-snippets.md) - List of helpful re-usable code snippets in Python.\n","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/bytesnipers%2Fawesome-pentest-cheat-sheets/projects"}