Hacking Articles
21K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
Secret Alternatives for DevSecOps Engineer.pdf
17.5 MB
Secret Alternatives for DevSecOps Engineer
Container Security Labs.pdf
39.4 MB
Container Security Labs
โค2
๐—›๐—ง๐—ง๐—ฃ_๐—ฅ๐—ฒ๐—พ๐˜‚๐—ฒ๐˜€๐˜_๐—ฆ๐—บ๐˜‚๐—ด๐—ด๐—น๐—ถ๐—ป๐—ด_๐—ง๐—ต๐—ฒ_๐—ฆ๐—ถ๐—น๐—ฒ๐—ป๐˜_๐—ฃ๐—ฟ๐—ผ๐˜๐—ผ๐—ฐ๐—ผ๐—น_๐—ช๐—ฎ๐—ฟ.pdf
6.3 MB
๐—›๐—ง๐—ง๐—ฃ ๐—ฅ๐—ฒ๐—พ๐˜‚๐—ฒ๐˜€๐˜ ๐—ฆ๐—บ๐˜‚๐—ด๐—ด๐—น๐—ถ๐—ป๐—ด ๐—ง๐—ต๐—ฒ ๐—ฆ๐—ถ๐—น๐—ฒ๐—ป๐˜ ๐—ฃ๐—ฟ๐—ผ๐˜๐—ผ๐—ฐ๐—ผ๐—น ๐—ช๐—ฎ๐—ฟ
โค1
๐˜‹๐˜ข๐˜ต๐˜ข_๐˜š๐˜ฆ๐˜ค๐˜ถ๐˜ณ๐˜ช๐˜ต๐˜บ_๐˜ธ๐˜ช๐˜ต๐˜ฉ๐˜ช๐˜ฏ_๐˜ˆ๐˜_๐˜Œ๐˜ฏ๐˜ท๐˜ช๐˜ณ๐˜ฐ๐˜ฏ๐˜ฎ๐˜ฆ๐˜ฏ๐˜ต๐˜ด.pdf
1.4 MB
๐˜‹๐˜ข๐˜ต๐˜ข ๐˜š๐˜ฆ๐˜ค๐˜ถ๐˜ณ๐˜ช๐˜ต๐˜บ ๐˜ธ๐˜ช๐˜ต๐˜ฉ๐˜ช๐˜ฏ ๐˜ˆ๐˜ ๐˜Œ๐˜ฏ๐˜ท๐˜ช๐˜ณ๐˜ฐ๐˜ฏ๐˜ฎ๐˜ฆ๐˜ฏ๐˜ต๐˜ด
๐Ÿ”ฅ Ethical Hacking Proactive Training โ€“ Live & Practical ๐Ÿ”ฅ

Ready to build real-world cybersecurity skills with hands-on experience?

๐Ÿš€ Ignite Technologies brings you a comprehensive Ethical Hacking Proactive Training Program designed with live sessions and core practical exposure โ€” at an affordable price.

๐Ÿ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

๐Ÿ’ฌ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

๐Ÿ“ง Email:
info@ignitetechnologies.in

๐ŸŽฏ Book Your Demo Session Today!

๐Ÿ“˜ What Youโ€™ll Learn:

โœ… Introduction to Ethical Hacking
โœ… Old School Learning Methodology
โœ… Networking Fundamentals
โœ… Reconnaissance (Footprinting, Scanning & Enumeration)
โœ… System Hacking
โœ… Post Exploitation & Persistence
โœ… Web Server Penetration Testing
โœ… Website Hacking Techniques
โœ… Malware Threats & Analysis
โœ… Wireless Network Security
โœ… Cryptography & Steganography
โœ… Sniffing Attacks
โœ… Denial of Service (DoS)
โœ… Evading IDS, Firewalls & Honeypots
โœ… Social Engineering Techniques
โœ… Mobile Platform Security

๐Ÿ’ก Whether you're a beginner or looking to strengthen your penetration testing skills, this training is structured to provide practical knowledge aligned with real-world attack scenarios.

Limited seats available. Secure yours now.
โค1๐Ÿ‘1
โค1๐Ÿ‘1
โค1๐Ÿ‘1
โค1
โค3
โค2๐Ÿ‘1
โค3
๐Ÿš€ OSEP Exam Practice Training (Online) โ€“ Registration Open!

Ready to level up your offensive security & red team skills?

Join Ignite Technologiesโ€™ CTF-Based OSEP Practice Program and train in a real-world attack-driven environment designed for serious cybersecurity professionals.

๐Ÿ”— Register Now
https://forms.gle/bowpX9TGEs41GDG99

๐Ÿ’ฌ WhatsApp
https://wa.me/message/HIOPPNENLOX6F1

๐Ÿ“ง Email
info@ignitetechnologies.in

๐Ÿ“š Training Modules

๐Ÿš€ Introduction
๐Ÿ” Advanced Information Gathering
๐ŸŽฏ Initial Access & Client-Side Attacks
๐Ÿ›ก Bypassing Security Controls
๐ŸชŸ Windows Privilege Escalation
๐Ÿง Linux Privilege Escalation
๐Ÿงญ Active Directory Enumeration
๐Ÿ” Lateral Movement
๐Ÿฐ Active Directory Attacks
๐ŸŒ Web Application Attacks
๐Ÿ•ณ Tunneling & Pivoting
๐Ÿงฌ Post-Exploitation & Persistence
๐Ÿฅท Defense Evasion & OPSEC
๐Ÿงช Custom Malware & Tool Development
๐Ÿ’ฅ Advanced Exploitation
๐Ÿ“ Reporting & Documentation

๐ŸŽฏ Ideal for professionals preparing for advanced offensive security certifications and red team roles.

โš ๏ธ Limited Seats Available โ€“ Register Now!
โค3
๐Ÿ” Credential Dumping โ€“ Red Team Cheatsheet

๐Ÿ”ฅ Telegram: https://t.me/hackinarticles

A practical Credential Dumping reference guide for Red Teamers, Penetration Testers, and Security Researchers.
This cheatsheet explains multiple credential access techniques used during post-exploitation and Active Directory attacks.

โšก๏ธ Topics Covered:

๐Ÿ“ก Wireless Credential Extraction
๐Ÿ—‚ Group Policy Preferences (GPP) Passwords
๐Ÿ”‘ Windows Credential Manager
๐Ÿง  WDigest Credential Storage
๐Ÿงฉ Security Support Provider (SSP)
๐Ÿ—„ SAM Database Extraction
๐Ÿ“ฆ Installed Applications Credential Discovery
๐Ÿข NTDS.dit Domain Credential Dumping
๐ŸŽฃ Phishing Windows Credentials
๐Ÿ›ก Local Security Authority (LSA / LSASS.EXE) Dumping
๐Ÿ“‹ Clipboard Credential Leakage
๐Ÿ” DCSync Attack
๐Ÿ” LAPS Password Extraction
๐Ÿ’พ Domain Cached Credentials
โš™๏ธ Fake Services Credential Capture
๐Ÿ”“ Windows Autologon Password
๐Ÿงฌ Internal Monologue Attack
๐Ÿ”‘ Reversible Password Encryption
๐Ÿ‘ฅ Group Managed Service Accounts (gMSA)
๐Ÿ“ Active Directory User Comment Credential Leakage

๐ŸŽฏ Useful for Red Team operations, Active Directory assessments, and post-exploitation phases.

๐Ÿ”— GitHub Repository:
https://github.com/Ignitetechnologies/Credential-Dumping
โค3
๐ŸชŸ Windows Privilege Escalation โ€“ Red Team Cheatsheet

๐Ÿ”ฅ Telegram: https://t.me/hackinarticles

A practical Windows Privilege Escalation reference guide for Red Teamers, Penetration Testers, and Security Researchers.
Learn common techniques used to escalate privileges from low-privileged user to SYSTEM or Domain Admin during real-world assessments.

โšก๏ธ Topics Covered:

๐Ÿ”“ AlwaysInstallElevated Misconfiguration
๐Ÿ—„ SeBackupPrivilege Abuse
๐ŸŒ DnsAdmins โ†’ Domain Admin Escalation
๐ŸŽญ SeImpersonatePrivilege Exploitation
๐Ÿ’พ HiveNightmare Vulnerability
๐Ÿ” Registry Run Keys (Logon Autostart Execution)
๐Ÿ“‚ Startup Folder Persistence
๐Ÿ”‘ Stored Credentials (Runas)
โš™๏ธ Weak Registry Permissions
๐Ÿงพ Unquoted Service Path
๐Ÿ–ฅ Insecure GUI Applications
๐Ÿ›  Weak Service Permissions
โฑ๏ธ Scheduled Task / Job Abuse (T1053.005)
๐Ÿงฌ Kernel Exploits
๐Ÿ‘ค SamAccountSpoofing (CVE-2021-42278)
๐Ÿ–จ SpoolFool Exploit
๐Ÿ–จ PrintNightmare Vulnerability
๐Ÿ‘ฅ Server Operators โ†’ Privilege Escalation

๐ŸŽฏ Useful for Windows post-exploitation, Active Directory attacks, and Red Team operations.

๐Ÿ”— GitHub Repository:
https://github.com/Ignitetechnologies/Windows-Privilege-Escalation
โค1๐Ÿ‘1
๐Ÿง  Cyber Security Mindmaps & Cheat Sheet

๐Ÿ”ฅ Telegram: https://t.me/hackinarticles

A curated collection of Cyber Security Mindmaps designed to help students, pentesters, and security professionals visualize tools, technologies, frameworks, and attack methodologies in a structured way.

These mindmaps simplify complex cybersecurity concepts and create a clear learning roadmap from beginner to advanced levels.

โšก๏ธ What Youโ€™ll Find:

๐Ÿง  Burp Suite
๐ŸŒ Censys
โ˜๏ธ Cloud Security Framework
๐Ÿ“ฆ Container Security
โš”๏ธ Crackmapexec
๐Ÿ’€ Cyber Hack
๐ŸŽฏ Cyber Security Attack
๐Ÿ›ก Cybersec Technologies
โš™๏ธ DevOps
๐Ÿณ Docker CheatSheet
๐Ÿงฌ Empire
๐Ÿ”Ž Enumeration
๐Ÿš€ Feroxbuster
๐ŸฆŠ Firefox Pentest Addons
๐Ÿงพ Forensics
๐Ÿ” GitHub Dorks
๐ŸŒ Google Dorks
๐Ÿ”Ž Google Search Operators
โš™๏ธ GTFOBins
๐ŸŽฎ HTB
๐ŸŒ HTTP Status Code
๐Ÿ“ก ICMP
๐Ÿงฌ IDA Pro
๐Ÿ“œ ISO Control
๐Ÿ›  Impacket
๐Ÿ”‘ John
๐Ÿ’ฃ Metasploit
๐Ÿง  Mimikatz
๐ŸŽฏ MITRE ATT&CK
๐Ÿ“ก Nmap
๐Ÿ•ต๏ธ OSINT
๐Ÿ“‚ OWASP
๐Ÿ” Privacy Tools
๐Ÿ’ฐ Ransomware
๐ŸŽฏ Red Team Dorks
๐ŸŒ SSRF Tools
๐Ÿ›ก Security 360
โš™๏ธ Security Automation
๐Ÿ”Ž Search Engine for Pentester
๐ŸŒ Shodan
๐ŸŽญ Social Engineering
๐Ÿ’‰ Sqlmap
๐ŸŒ Subdomain Enumeration
๐Ÿ“ก Tcpdump
๐Ÿงฐ Tools
๐ŸŽฏ TryHackMe
๐Ÿ“ก Tshark
๐Ÿ” Vulnerability Scanners
๐Ÿงช VulnHub
๐Ÿณ Web App Docker
๐ŸชŸ Windows Privileges
๐Ÿ“ถ Wireless Pentest Tools
๐Ÿฆˆ Wireshark
๐Ÿ’ฅ XSS Tools
๐Ÿšจ Zero-Day CVEs (2023)
๐Ÿ“ก Aircrack
โšก๏ธ FFUF
๐Ÿ”Ž Gobuster
๐Ÿ”‘ Hashcat
๐ŸŒ HTTPX
๐Ÿ’ฃ Hydra
๐Ÿ” Medusa
๐Ÿ“œ NIST
๐ŸŽฏ Wfuzz

๐ŸŽฏ Useful for students, bug bounty hunters, red teamers, and cybersecurity professionals building a structured learning roadmap.

๐Ÿ”— GitHub Repository:
https://github.com/Ignitetechnologies/Mindmap
โค6
๐Ÿšจ Credential Dumping: LAPS Abuse

๐Ÿ”ฅ Telegram: https://t.me/hackinarticles
โœด๏ธ Twitter: https://x.com/hackinarticles

In Windows environments, Local Administrator Password Solution (LAPS) stores local administrator passwords inside Active Directory attributes. If an attacker gains permission to read these attributes, they can retrieve the credentials and perform lateral movement across the network.

โšก๏ธ Key Tools for LAPS Enumeration & Dumping
๐Ÿ›  Impacket
โš”๏ธ NXC Tool
๐Ÿ PyLaps
๐Ÿ“ฆ LAPSDumper
๐Ÿฉธ BloodyAD
๐Ÿ”Ž ldapsearch
๐Ÿ’ฃ Metasploit: ldap_query
๐Ÿ”— impacket-ntlmrelayx
๐Ÿ–ฅ ldap_shell
๐Ÿ“œ PowerShell
๐ŸŒ NetTools
๐Ÿ’Ž SharpLAPS
๐Ÿš€ Metasploit: enum_laps
๐Ÿง  PowerView

๐Ÿ“– Article: https://www.hackingarticles.in/credential-dumping-laps/
โค1
๐Ÿšจ Credential Dumping: Phishing Windows Credentials

๐Ÿ”ฅ Telegram: https://t.me/hackinarticles
โœด๏ธ Twitter: https://x.com/hackinarticles

Phishing attacks are commonly used to capture Windows credentials by tricking users into entering their login details on malicious prompts or fake login screens. Once obtained, attackers can reuse these credentials to gain unauthorized access and move laterally inside the network.

โšก๏ธ Key Tools Used for Windows Credential Phishing
๐Ÿ›  Metasploit Framework
๐ŸŽฃ phish_windows_credentials
๐Ÿ–ฅ FakeLogonScreen
๐Ÿ” SharpLocker
โš”๏ธ PowerShell Empire
๐Ÿ“ฆ Collection/prompt
๐Ÿž Collection/toasted
๐Ÿ’‰ Koadic
๐Ÿ“ฉ Password_box
๐Ÿ“œ PowerShell
๐Ÿงช Invoke-CredentialsPhish.ps1
๐Ÿ”‘ Invoke-LoginPrompt.ps1
๐ŸŽญ Lockphish

๐Ÿ“– Article: https://www.hackingarticles.in/credential-dumping-phishing-windows-credentials/