Knowledge Garden
  • Home
  • Notes
  • CTF Writeups
  • Blog
  • About

Notes Explorer

1. eJPT
1. Assessment Methodologies
Active & Passive Recon
Active recon
Passive Recon
MetaSploit
!ntro MSF
Armitage
MSF Auxiliary Module
msfvenom⚕️
Payloads
Services
HTTP (80)
Apache Tomcat
Directory Listing
HTTP
php
rejetto HFS (80)
Word Press
!ntro Services
01-FTP (21)⬇️
02-SSH (22)
03-SMTP (25)
04-WebDAV (80,443)
05-Microsoft IIS (80,443)
06-DNS (53)
07-NetBIOS (137,138,139)
08-SNMP (161)
09-SMB (445)
10-Rsync 873
11-MSSQL (1433)
12-MySQL (3306)
13-NFS (2049)
14-RDP (3389)
15-WinRM (5985,5986)
Services
Shells
Bind Shells
meterpreter
Reverse Shells
webshell
Tools
Brute Force
Hashcat
John The Ripper
Directory bruteforce
Dirb
GoBuster
wfuzz
nmap
Scan Types
Ping Sweeping
netdiscover
nmap 👁️
Useful Scans
PrivEsc Tools
UACMe
wesng
To Exploit WebDAV
Cadaver
Davtest
Binwalk
crackmapexec
Hydra
John the Ripper
Nessus
Netcat
Powershell Empire
Tools
WordLists
Wordlists
2. Host Exploitation
AV Evasion
AV Evasion Techniques
Shellter
Exploits
Compiling Exploits
Exploitation
Linux
Exploits & Vulnerability
CVE-2014-6271 (ShellShock) Bash
Linux
Linux Exploit Suggester
Linux Password Hashes
Misplaced Passwords
Windows
Credential Dumping
Credential Dumping
Kiwi
MimiKatz
NTLM
Unattended Installation
Exploits & Vulnerability
CVE-2017-0144 (EternalBlue) SMB
CVE-2019-0708 (BlueKeep) RDP
Pass-The-Hash
SMB PsExec
Access Tokens
Alternate Data Streams
Persistence
Windows
Windows Exploits Suggester
Windows Services 🪟
2. Host Exploitation
3. Network PenTesting
SMB Relay Attack
4. Post Exploitation
1. Linux
Linux Persistence
Persistence via Cronjobs
Persistence via SSH or backdoor user
Privilege Escalation
Dangerous SUID binaries
find
Shell permissions
Change root pass in shadow file
Cron Jobs
Dangerous SUID Binaries to Look For
LinEnum & LinPEAS
PrivEsc Linux Cheat Sheet
SUID SGID
Vulnerabilities
chkrootkit v(0.5)
Ubuntu 18.04 privesc
1. Linux
Dump Linux Hashes
Enumerating LINUX Information
Linux Post-Exploitation Modules
Tmux
2. Windows
Privilege Escalation
!ntro Win PrivEsc
PrivEscCheck
UAC
2. Windows
Enumerating WINDOWS information
JAWS
KeyLogging
Windows Post-Exploitation Modules
3. Pivoting
Port Forwarding
What is Pivoting
Cleaning artifacts
Linux
Clear bash history
Windows
Clear Windows Event Log
4. Post Exploitation
Transfer files to Windows & Linux Targets
5. Web Pentesting
HTTP Request & Response
curl
HTTP Request Methods
HTTP Response Component
Glossary
ZAP
Exam Notes
All Hosts
Machine3 (52)
Machine5 (63)
Machine6 (67)
THM Rooms
WINSERVER-01 (50)
WINSERVER-02 (51)
WINSERVER-03 (55)
zCTF Solves
Cheat Sheets
2. SOC L1
4n6
Cheatsheets
Registry_4n6
Malware Analysis
Sandboxes
Static Analysis
KAPE
Volatility
Brim
Brim Introduction
Brim Queries
Email Analysis
Email Security
C2 over SMTP
DKIM (DomainKeys Identified Mail)
DMARC (Domain-Based Message Authentication Reporting and Conformance)
S-MIME (Secure-Multipurpose Internet Mail Extensions)
SPF (Sender Policy Framework)
Phishing Prevention
Phishing Prevention Intro
Social Engineering
Email Phishing Tools
Phishing🎣
Email Body Analysis
Email Header Analysis Tools
Malware Sandbox
EZTools
EvtxEcmd
SysmonView
Timeline Explorer
Incidents Playbooks
1- Ransomware Playbook
2- Phishing Playbook
5- Other Playbooks
Snort
Basic Rules
Snort Introduction
TShark
TShark Advanced Filtering
TShark Basics
TShark CLI Features
Wireshark
1- IP Filters
11- Matching Filters
12- SMTP
2- TCP & UDP Filters
3- HTTP-S & DNS Analysis
4- Nmap Scans
5- ARP Filters
6- DHCP Filters
7- NetBIOS & Kerberos
8- ICMP Filters
9- FTP Filters
WireShark
Brim vs Wireshark vs Zeek
Malware Traffic Analysis
tcpdump
3. eCIR
Glossary
Playbooks in SOC
Incident Handling vs Incident Response
HTB machines
Soulmate
  1. Notes
  2. 1. eJPT
  3. 4. Post Exploitation
  4. 1. Linux
  5. Privilege Escalation
  6. PrivEsc Linux Cheat Sheet

Everything Cheat Sheet: https://github.com/Ignitetechnologies/Linux-Privilege-Escalation

SUID Cheat Sheet:

https://cheatsheet.haax.fr/linux-systems/privilege-escalation/suid/

GTFOBins

https://gtfobins.github.io/