This is a repo for pentest cheat sheets which I have found useful!!
- https://pentestbook.six2dez.com/others/web-checklist is pentest
#Checklist
. - https://github.com/trimstray/the-book-of-secret-knowledge#hackingpenetration-testing-toc is a complete cheatsheet.
#CheatSheet
- https://github.com/enaqx/awesome-pentest is a complete cheatsheet.
#CheatSheet
- https://github.com/enaqx/awesome-pentest for Pentest cheatsheet.
#CheatSheet
- https://github.com/riramar/Web-Attack-Cheat-Sheet for Pentest cheatsheet.
#CheatSheet
- https://github.com/swisskyrepo/PayloadsAllTheThings for various attacks paloads.
#attackPayloads
- https://github.com/tennc/webshell for collection of web shells.
#webshells
- https://portswigger.net/web-security/cross-site-scripting/cheat-sheet for XSS cheat sheets.
#XSS
- https://github.com/Walidhossain010/WAF-bypass-xss-payloads for XSS payloads for bypassing WAFs.
#XSS #WAF
- https://book.hacktricks.xyz/pentesting-web/file-upload for file upload cheat sheets.
#fileUpload
- https://github.com/modzero/mod0BurpUploadScanner for upload scanner for burp.
#uploadScanner
- https://book.hacktricks.xyz/windows/windows-local-privilege-escalation/dpapi-extracting-passwords for DPAPI - Extracting Passwords.
#Crypto
- https://www.beyondtrust.com/resources/glossary/pass-the-hash-pth-attack for Pass-the-Hash(PtH) Attack.
#Crypto
- https://www.acunetix.com/blog/articles/tls-vulnerabilities-attacks-final-part/ for TLS Vulnerabilities.
#TLS
- https://www.cloudinsidr.com/content/known-attack-vectors-against-tls-implementation-vulnerabilities/ for Attack vectors against TLS.
#TLS
- https://cheatsheetseries.owasp.org/cheatsheets/REST_Security_Cheat_Sheet.html for REST Security Cheat Sheet.
#API
- https://owasp.org/www-project-api-security/ for API testing.
#API
- https://blog.nvisium.com/angular-for-pentesters-part-1 is Angular And AngularJS For Pentesters.
#Angular
- https://portswigger.net/web-security/websockets for WebSocket Pentesting.
#WebSocket
- https://cheatsheetseries.owasp.org/cheatsheets/REST_Security_Cheat_Sheet.html for REST API Pentesting.
#REST_API
- https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS for CORS.
#CORS
- https://github.com/cipher387/Dorks-collections-list/ for Dorks.
#Dork
- https://github.com/gquere/pwn_jenkins for Pentesting Jenkins.
#Jenkins
- https://many-passwords.github.io/ for collection of default passwords.
#default #password
- https://github.com/arainho/awesome-api-security for API PenTest.
#API #Pentest
- https://github.com/juliocesarfort/public-pentesting-reports for PenTesting report samples.
#Report
- https://cure53.de/ for pentest reports of popular applications.
#reports #popular_apps
1.https://deepscan.io/demo/ for statically analyzing JS, VUE, and React code. #staticAnalysis
- http://www.pentest-standard.org/index.php/PTES_Technical_Guidelines for pentest methodology.
#methodology
These websites are recommended for learning to Pentest.
- https://www.hackthebox.eu/
- https://tryhackme.com/
- https://www.root-me.org/
- https://github.com/Ignitetechnologies/HackTheBox-CTF-Writeups
HackTheBox CTF Cheatsheet
- https://github.com/PowerShellMafia/PowerSploit
- https://www.cobaltstrike.com/help-beacon
- https://github.com/GhostPack/Seatbelt
- https://github.com/cobbr/SharpSploit
- https://github.com/med0x2e/RT-EWS
- https://github.com/med0x2e/GadgetToJScript
- https://github.com/SecureAuthCorp/impacket
- https://github.com/Kevin-Robertson/InveighZero
- https://github.com/denandz/KeeFarce
- https://github.com/med0x2e/NET-Assembly-Inject-Remote
- https://github.com/med0x2e/NoAmci/
- https://github.com/GhostPack/Rubeus
- https://github.com/GhostPack/SafetyKatz
- https://github.com/IllidanS4/SharpUtils/
- https://github.com/hoangprod/AndrewSpecial
- https://github.com/rasta-mouse/RuralBishop
- https://github.com/fullhunt/log4j-scan
CVE-2021-44228 - Apache Log4j RCE Scanner
#log4j