Cheatsheets
Command reference
Growing, one command at a time. Each entry covers how it actually shows up in engagements, a link to an established reference, and the specific invocations worth remembering.
Recon & OSINT
Shodan
Shodan search syntax for finding internet-facing devices and services by fingerprint, and PWNMI's top queries for real engagements.
theHarvester
theHarvester commands for OSINT recon — pulling emails, subdomains, and names from public sources, and PWNMI's top invocations for real engagements.
Curl
The curl invocations worth memorizing for manual HTTP testing — inspecting headers, crafting raw API requests, and seeing exactly what's sent and received when something's behaving unexpectedly.
Gobuster
Gobuster's directory, DNS, and vhost enumeration modes, with the extension-matching flags that catch the backup files and forgotten configs a default wordlist run misses.
Nmap
Nmap commands for recon — host discovery, full-port version scans, and the NSE vulnerability-detection scripts worth running before anything else touches the target.
Web Application Testing
Burp Suite
Burp Suite shortcuts, scope configuration, and lesser-used tabs beyond Proxy and Repeater, and PWNMI's top workflows for web application testing.
Nikto
Nikto's automated web server vulnerability scan, plus the port and SSL flags needed once Nmap has already told you what's actually listening.
Ffuf
Ffuf commands for directory, parameter, and vhost fuzzing, including the response-size filter that saves a scan from drowning in false positives on targets that fake a 200 for every path.
Sqlmap
Sqlmap's core workflow — confirming injection against a parameter, then enumerating databases, tables, and data once it's confirmed.
Credential Attacks
BloodHound
Collect an Active Directory's full user, group, computer, and ACL graph with one authenticated command, then let BloodHound's Neo4j-backed graph find the shortest path to Domain Admin instead of hunting for it by hand.
NetExec
NetExec (formerly CrackMapExec) commands for spraying and validating credentials across a subnet over SMB, and telling a domain hit apart from local admin reuse.
Hashcat
GPU-accelerated hash cracking with hashcat — dictionary, rule-based, and mask/brute-force attacks, and which mode to reach for once a plain wordlist run comes up empty.
Hydra
Hydra commands for testing credentials against SSH, FTP, and other network services — including the password-spray pattern that's far less likely to trigger a lockout than a full brute-force matrix.
John the Ripper
John the Ripper for offline hash cracking — the NTLM format flag you'll need constantly against Windows/AD targets, plus the rule-based mangling that turns a near-miss wordlist into a crack.
Exploitation & Post-Exploitation
Python3
The python3 one-liners and invocations that come up constantly on an engagement — reverse shells, TTY upgrades, quick file serving, and running PoC exploit scripts.
GTFOBins
How to use GTFOBins to turn a reachable Unix binary into a shell, a file read/write primitive, or privilege escalation — and PWNMI's most-cited example entries.
LOLBAS
How to use LOLBAS to find signed, pre-installed Windows binaries that can execute, download, or bypass controls — GTFOBins' Windows counterpart — and PWNMI's most-cited example entries.
Impacket Suite
The core Impacket scripts beyond secretsdump.py — Kerberoasting, AS-REP roasting, ticket handling, and remote execution against Windows and Active Directory targets.
secretsdump.py
Impacket's secretsdump.py for pulling SAM, LSA, and NTDS.dit secrets from a single host or an entire domain controller — plaintext, pass-the-hash, or a straight DCSync.
Socat
Socat for port relays and upgrading a raw shell into a fully interactive TTY with job control and signal handling — the step past a plain nc listener.
Msfconsole (Metasploit)
Finding, selecting, and configuring Metasploit modules from msfconsole — searching the module database by platform and keyword instead of scrolling blind, through to post-exploitation.
Netcat
Netcat listeners, reverse shells, and file transfer one-liners — including the named-pipe shell that works regardless of whether the target's netcat build still supports -e.
Pivoting & Tunneling
Proxychains
Running tools that have no native proxy support through a SOCKS pivot with proxychains — including the SYN-scan limitation that trips people up the first time they try it against Nmap.
Chisel
Chisel commands for tunneling through a firewall that only allows outbound HTTP — turning a compromised host with no listening ports into a reverse SOCKS proxy or port forward back to your attack box.
SSH (Tunneling & Pivoting)
SSH's three forwarding modes — local, remote, and dynamic — for reaching internal services, exposing a compromised host back to yourself, or turning a single connection into a full SOCKS pivot.
Traffic & Analysis
Tcpdump
Tcpdump capture and filter syntax — isolating traffic by interface, port, or host, and the fastest way to confirm whether a reverse shell callback actually landed.
Tshark
Tshark commands for command-line packet capture and analysis, and PWNMI's top invocations for red team and blue team use.
Hardware & Firmware
Lab Infrastructure
Python Virtual Environments
Isolating a PoC or tool's exact pip dependencies from system Python and from every other tool's dependencies, and PWNMI's top invocations for lab and engagement work.
Git
Git commands for cloning lab environments and PoC repos, tracking your own engagement notes and tooling, and a real recon technique against exposed .git directories.
Docker
Docker and Docker Compose commands for building and running isolated lab environments, and PWNMI's top invocations for lab work.