An interactive offensive-security reference suite

🏠 HomeAdaptixAI AttacksBloodHoundCertipyCloudContainersEvilginxHashcatImpacketKaliLotLMetasploitMethodologyNetExecOSINTOT / ICSReconRTFM CommandsScenariosTools DatabaseTTP / ATT&CKWeb & API

This site was created as a quick reference guide for Red Teamers, Purple Teamers, and security professionals who need fast access to commonly used tools, commands, and techniques during an engagement. The goal is to provide a centralized resource that helps operators quickly find useful syntax, references, and examples without having to search across multiple notes, repositories, or documentation sources.

The content is intended to support common Red Team and Purple Team activities, including reconnaissance, enumeration, privilege escalation, lateral movement, credential access, persistence testing, detection validation, and cleanup. It is designed to be practical, easy to navigate, and useful in real-world engagement scenarios where time and accuracy matter.

👾
AdaptixC2
Listeners, beacon generation, BOFs, tunneling & pivoting for the AdaptixC2 framework.
37 entries
🤖
AI / LLM Attacks
Prompt injection, jailbreaks, RAG & agent abuse, model/data extraction — OWASP LLM Top 10 & MITRE ATLAS.
64 techniques
🐾
BloodHound Queries
Cypher query library — AD, Azure & AD CS, plus Jamf, GitHub & Okta.
637 queries
🔑
Certipy
AD CS enumeration & abuse — ESC1-ESC16, certificate requests, PKINIT auth, shadow credentials & golden certs.
31 entries
☁️
Cloud Attacks
AWS, Azure / Entra ID & GCP — recon, cred access, IAM privesc, lateral movement, persistence & exfil.
57 techniques
Containers & K8s
Docker & Kubernetes attack and hardening — enumeration, escapes, RBAC abuse, secrets & cloud metadata.
40 entries
🦊
Evilginx
MITM reverse-proxy phishing — phishlets, lures, credential & session-cookie capture for MFA-bypass testing.
29 entries
🔑
Hashcat Cheat Sheet
Hash modes, attack modes, masks, rules, methodology & command examples.
136 entries
🤖
Impacket Modules
Every Impacket example script — remote exec, secretsdump, Kerberos, NTLM relay & more.
63 modules
🐔
Kali Linux
Setup, tool metapackages, services, recon/web/wireless/cracking tool categories & customization.
38 entries
🌴
Living off the Land
Operate with built-in OS binaries & trusted tools — recon, execution, cred access, lateral, persistence, exfil.
33 steps
💥
Metasploit Framework
msfconsole, msfvenom, Meterpreter, modules, pivoting & post-exploitation.
46 entries
🎓
Methodology
Penetration testing, red teaming & purple teaming — definitions, workflows, frameworks, engagement lifecycle & reporting.
81 entries
🧰
NetExec (nxc)
Multi-protocol AD assessment — enumeration, password spraying, credential dumping, execution & modules.
36 entries
🔎
OSINT Steps
Passive reconnaissance methodology — domains, infra, people, breaches, code & geo, step by step.
32 steps
🏭
OT / ICS Security
Red teaming operational technology — Purdue model, ICS protocols, tools & TTPs (ATT&CK for ICS). Safety-first.
92 entries
🔍
Recon
Windows & Linux host, network & AD enumeration commands with details & ATT&CK mapping.
55 commands
📖
RTFM Commands
Red Team Field Manual v2 reference — Windows, *NIX, networking, tools & more.
1353 commands
🧮
Scenario Builder
Interactive: assemble a red/purple-team engagement scenario — objective, adversary, ROE & an ordered ATT&CK plan. Save, print & export.
interactive
🛠️
Tools Database
Offensive security tooling — recon to exfiltration & AI red teaming, mapped to MITRE ATT&CK.
406 tools
🧩
TTP / ATT&CK Matrix
Full MITRE ATT&CK Enterprise matrix — procedures, kill-chain view & a custom chain builder.
703 techniques
🕸
Web & API Testing
Web & API pentest — recon, auth, injection, access control, SSRF/XXE, GraphQL & more.
47 entries

⚙ Appearance

Theme Presets

Custom Colors

Background
Card
Accent
Border
Text

Typography

Size
14px
Font

Layout

Density
Card Radius
10px
Card Border
Grid Gap
1rem
Min Card Width
340px
Hover Shadow
0.4
Animations
Show Header