Hacking Articles
21K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
Social Engineering Attack Cheat Sheet

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Social Engineering is a technique used to manipulate people into revealing confidential information or performing actions that compromise security. It is commonly used as an initial access vector in many cyber attacks.

⚑️ Common Social Engineering Attacks

🎣 Phishing
πŸ“± Smishing (SMS Phishing)
πŸ“ž Vishing (Voice Phishing)
🎭 Pretexting
🎁 Baiting
πŸͺ€ Quid Pro Quo
πŸ‘€ Shoulder Surfing
πŸ—‘ Dumpster Diving
πŸ§‘β€πŸ’» Impersonation
πŸ”— Malicious Links

Understanding these techniques helps security professionals and organizations identify, prevent, and mitigate social engineering attacks.

πŸ“š Social Engineering Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Social%20Engineering
πŸ‘1
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) – Enroll Now! πŸš€

Looking to strengthen your practical penetration testing skills and boost your confidence before the OSCP+ exam?

Join Ignite Technologies’ Exclusive Capture The Flag (CTF) Practice Program β€” designed to simulate real exam scenarios and real-world attack environments.

πŸ”— Register Here:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š What You’ll Cover:

🧠 Introduction to Exam Strategy & Methodology
🌐 Information Gathering & Enumeration
🧱 Vulnerability Scanning & Analysis
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks & Credential Exploitation
🧠 Tunneling & Pivoting Techniques
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits Effectively
πŸ“‹ Professional Report Writing

🎯 This training is ideal for:
β€’ OSCP+ aspirants
β€’ CTF players aiming to go professional
β€’ Pentesters wanting structured exam practice
β€’ Security professionals strengthening real-world attack skills

Limited seats available. Prepare smart. Hack ethically. πŸš€
❀2πŸ‘1
Shodan Cheat Sheet for Pentesters

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Shodan is a powerful search engine that discovers internet-connected devices such as servers, routers, webcams, IoT devices, and industrial systems. Unlike Google that indexes websites, Shodan indexes devices, services, and open ports across the internet. ()

⚑️ Useful Shodan Search Filters

πŸ”Ž port:22
🌍 country:US
🏒 org:"Amazon"
πŸ’» os:Windows
πŸ“¦ product:Apache
🌐 hostname:example.com
πŸ“‘ net:192.168.1.0/24
🏷 city:London
🧠 vuln:CVE-2021-44228
πŸ” ssl:true

🧠 Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Shodan
❀1
Subdomain Enumeration Cheat Sheet

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Subdomain Enumeration is the process of discovering subdomains associated with a target domain during reconnaissance. It helps pentesters identify hidden services, development environments, APIs, and misconfigured systems that may expose vulnerabilities. ()

⚑️ Popular Subdomain Enumeration Tools

πŸ”Ž Subfinder
πŸ›° Amass
πŸ“‘ Assetfinder
🧠 Sublist3r
🌐 Findomain
πŸ“‚ DNSenum
πŸ“ DNSrecon
πŸ’£ Gobuster (DNS Mode)
⚑️ FFUF (DNS Fuzzing)
🧩 Knockpy

🧠 Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Subdomain%20Enumeration
❀3πŸ‘1
πŸ”₯ Ethical Hacking Proactive Training – Live & Practical πŸ”₯

Ready to build real-world cybersecurity skills with hands-on experience?

πŸš€ Ignite Technologies brings you a comprehensive Ethical Hacking Proactive Training Program designed with live sessions and core practical exposure β€” at an affordable price.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

🎯 Book Your Demo Session Today!

πŸ“˜ What You’ll Learn:

βœ… Introduction to Ethical Hacking
βœ… Old School Learning Methodology
βœ… Networking Fundamentals
βœ… Reconnaissance (Footprinting, Scanning & Enumeration)
βœ… System Hacking
βœ… Post Exploitation & Persistence
βœ… Web Server Penetration Testing
βœ… Website Hacking Techniques
βœ… Malware Threats & Analysis
βœ… Wireless Network Security
βœ… Cryptography & Steganography
βœ… Sniffing Attacks
βœ… Denial of Service (DoS)
βœ… Evading IDS, Firewalls & Honeypots
βœ… Social Engineering Techniques
βœ… Mobile Platform Security

πŸ’‘ Whether you're a beginner or looking to strengthen your penetration testing skills, this training is structured to provide practical knowledge aligned with real-world attack scenarios.

Limited seats available. Secure yours now.
πŸ‘1
Censys Search Engine for Pentesters

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Censys is a powerful internet scanning and reconnaissance platform used by security researchers and penetration testers to discover exposed assets, services, and vulnerabilities across the internet.

⚑️ Useful Censys Search Queries

🌐 services.port: 21
πŸ” services.port: 22
πŸ’» services.port: 3389
πŸ“‘ services.service_name: HTTP
πŸ”Ž services.tls.certificates.leaf_data.subject.common_name: example.com
🧠 services.software.product: Apache
πŸ“Š location.country: "India"
⚠️ services.port: 23
πŸ›° autonomous_system.name: "Amazon"

πŸ“š Mindmap: https://github.com/Ignitetechnologies/Mindmap/tree/main/Censys

These queries help pentesters perform internet-wide reconnaissance and asset discovery.
🚨 Cloud Security Framework Mindmap

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Cloud security frameworks help organizations secure cloud infrastructure, identities, applications, and data across different cloud platforms.

⚑️ Key Areas in Cloud Security Framework

☁️ Identity & Access Management (IAM)
πŸ” Data Security & Encryption
πŸ›‘ Network Security
πŸ“¦ Workload & Container Security
πŸ“Š Logging & Monitoring
πŸ”Ž Security Posture Management
βš™οΈ DevSecOps & CI/CD Security
🧠 Threat Detection & Incident Response
πŸ“‘ Governance, Risk & Compliance

🧠 Cloud Security Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Cloud%20Security%20Framework
❀1πŸ‘1
🚨 Container Security Mindmap

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Container security focuses on protecting containerized applications, images, registries, and runtime environments from vulnerabilities and misconfigurations. Containers share the host kernel, so weaknesses in images, runtime, or configuration can expose the host system or other containers. ()

⚑️ Key Areas in Container Security

🐳 Docker Security
☸️ Kubernetes Security
πŸ–Ό Container Image Security
πŸ“¦ Container Registry Security
πŸ›‘ Runtime Security
πŸ”‘ Secrets Management
πŸ“Š Monitoring & Logging
πŸ” Vulnerability Scanning
βš™οΈ DevSecOps Integration
🚨 Container Breakout Prevention

🧠 Container Security Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Container%20Security
❀1
OSEP Exam Practice Training (Online) – Registration Open! πŸš€

Ready to level up your offensive security skills and prepare for advanced red team operations?

Join Ignite Technologies’ Exclusive β€œCapture The Flag” (CTF) Based OSEP Practice Program and train in a real-world, attack-driven environment designed for serious cybersecurity professionals.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š Training Modules Include:

πŸš€ Introduction
πŸ” Advanced Information Gathering
🎯 Initial Access & Client-Side Attacks
πŸ›‘ Bypassing Security Controls
πŸͺŸ Windows Privilege Escalation
🐧 Linux Privilege Escalation
🧭 Active Directory Enumeration
πŸ” Lateral Movement
🏰 Active Directory Attacks
🌐 Web Application Attacks
πŸ•³ Tunneling & Pivoting
🧬 Post-Exploitation & Persistence
πŸ₯· Defense Evasion & OPSEC
πŸ§ͺ Custom Malware & Tool Development
πŸ’₯ Advanced Exploitation
πŸ“ Reporting & Documentation

This program is ideal for professionals preparing for advanced offensive security certifications and those aiming to strengthen their red teaming capabilities.

Seats are limited. Secure yours today. πŸš€
API Penetration Testing Training (Online)

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Hurry up, get enrolled yourself with Ignite Technologies’ fully exclusive Training Program "API Penetration Testing Training."

βœ”οΈ Table of Content

πŸ“˜ Course Introduction
πŸ” How API works with Web application
βš–οΈ Types of APIs and their advantages/disadvantages
πŸ”Ž Analysing HTTP request and response headers
πŸ›‘ API Hacking methodologies
πŸ“„ Enumerate web pages and analyse functionalities
πŸ•΅οΈ API passive reconnaissance Strategies
πŸš€ API active reconnaissance (Kite runner)
πŸ”§ Introduction to POSTMAN
πŸ” Testing for Excessive data exposure
πŸ“‚ Directory indexing / brute force
πŸ”‘ Password mutation
🎯 Password spray attacks against web application
πŸ›‘ Introduction to JSON Web Token
πŸ•΅οΈ Hunting for JWT authentication vulnerabilities
πŸ’£ Exploiting JWT unverified signature
πŸ”“ Cracking JWT secret keys
🚫 Bypass JWT removing signature
🌍 Testing out-band SSRF vulnerabilities in an API
βš™οΈ Testing OS Command Injection
β˜•οΈ Exploiting Java deserialization vulnerabilities
πŸ—‚ Testing for improper assets management
πŸ“¦ Testing for Mass assignment vulnerabilities
🚧 Bypass filter, space, and blacklisted characters
πŸ” Bypass Captcha and MFA
πŸ“‹ Remediations and Reporting
❀2
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) – Enroll Now! πŸš€

Looking to strengthen your practical penetration testing skills and boost your confidence before the OSCP+ exam?

Join Ignite Technologies’ Exclusive Capture The Flag (CTF) Practice Program β€” designed to simulate real exam scenarios and real-world attack environments.

πŸ”— Register Here:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š What You’ll Cover:

🧠 Introduction to Exam Strategy & Methodology
🌐 Information Gathering & Enumeration
🧱 Vulnerability Scanning & Analysis
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks & Credential Exploitation
🧠 Tunneling & Pivoting Techniques
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits Effectively
πŸ“‹ Professional Report Writing

🎯 This training is ideal for:
β€’ OSCP+ aspirants
β€’ CTF players aiming to go professional
β€’ Pentesters wanting structured exam practice
β€’ Security professionals strengthening real-world attack skills

Limited seats available. Prepare smart. Hack ethically. πŸš€
❀1
Bug Bounty Tools Cheat Sheet

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Bug bounty hunters use a combination of reconnaissance, scanning, and exploitation tools to discover vulnerabilities in web applications and infrastructure.

⚑️ Popular Bug Bounty Tools

πŸ”Ž Subfinder
🌐 Amass
πŸ“‘ Assetfinder
⚑️ FFUF
🧠 Nuclei
πŸ•· Burp Suite
πŸ’‰ SQLMap
πŸ“‚ Dirsearch
πŸ” WPScan
πŸ“Š Dalfox

🧠 Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Tools
Defensive Security Tools Cheat Sheet

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Defensive security (Blue Team) tools are used to detect, monitor, analyze, and respond to cyber threats across networks, endpoints, and applications. These tools help security teams identify attacks early and strengthen an organization’s defense posture. ()

⚑️ Popular Defensive Security Tools

πŸ›‘ Wazuh
πŸ”Ž Zeek (Bro)
πŸ“‘ Suricata
🧠 Osquery
πŸ“Š Graylog
πŸ” YARA
πŸ“‚ Velociraptor
🚨 TheHive
πŸ“‘ Arkime
πŸ“œ Sigma

🧠 Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Tools/Defensive
πŸ‘1
Offensive Security Tools Cheat Sheet

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Offensive Security tools are used by pentesters and red teamers to identify vulnerabilities, exploit systems, and assess the security posture of networks, applications, and infrastructure. Many of these tools are included in penetration-testing platforms like Kali Linux and are widely used in real-world security assessments. ()

⚑️ Popular Offensive Security Tools

πŸ”Ž Nmap
🧠 Metasploit Framework
🌐 Burp Suite
πŸ’‰ SQLMap
πŸ” John the Ripper
⚑️ Hydra
πŸ“‘ Wireshark
🧩 OWASP ZAP
πŸ“‚ Nikto
πŸ›° Aircrack-ng

🧠 Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Tools/Offensive%20Security
❀2πŸ‘1
πŸš€ AI Penetration Testing Training (Live Online Program)

The future of cybersecurity is AI-driven β€” are you ready to test and secure it?

Ignite Technologies is launching an intensive AI Penetration Testing Training designed for security professionals, pentesters, red teamers, and researchers who want to understand how to attack and defend Large Language Models (LLMs) and AI systems.

πŸ”— Register Now: https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

⚠️ Limited seats available.

🧠 What You’ll Learn

πŸ”Ή LLM Architecture & Security Principles
πŸ”Ή Data Security in AI Systems
πŸ”Ή Model & Infrastructure Security
πŸ”Ή OWASP Top 10 for LLMs
πŸ”Ή LLM Installation & Secure Deployment
πŸ”Ή Model Context Protocol (MCP)
πŸ”Ή Publishing Models using Ollama
πŸ”Ή Retrieval-Augmented Generation (RAG) Security

πŸ”₯ Offensive AI Security Modules

βœ”οΈ Prompt Injection & Indirect Injection Attacks
βœ”οΈ Exploiting LLM APIs (Real-World Bug Scenarios)
βœ”οΈ Password & Sensitive Data Leakage via AI
βœ”οΈ Excessive Privilege Exploitation
βœ”οΈ LLM Misconfigurations
βœ”οΈ Data Extraction Attacks
βœ”οΈ Content Manipulation in LLM Outputs
βœ”οΈ AI-based Enumeration Techniques

πŸ›‘ Defensive & Automation Focus

βœ… Securing AI Systems
βœ… System Prompt Security Implications
βœ… Automated Penetration Testing with AI
βœ… Making AI Applications Secure & Public-Ready

If you're already into Pentesting, Red Teaming, Bug Bounty, OSCP prep, or Offensive Security, this program will give you a cutting-edge advantage in AI security.

Secure your seat before registrations close.
Tomcat Penetration Testing

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Apache Tomcat is a widely used Java-based web server and servlet container that runs Java web applications. Misconfigurations or exposed management interfaces can allow attackers to upload malicious files and gain remote access to the server.

πŸ“š Techniques Covered in This Guide

βš™οΈ Lab Setup
πŸ’» Installation
πŸ”§ Configuration
πŸ”Ž Enumeration with Nmap
πŸ’₯ Exploitation using Metasploit
🐚 Manual Exploitation (Reverse Shell)
🌐 Manual Exploitation (Web Shell)

πŸ“– Article:
https://www.hackingarticles.in/tomcat-penetration-testing/
πŸ‘1
Firefox for Pentester: Hacktool

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Hacktool is a browser extension for Firefox and Chrome that provides a penetration-testing cheat sheet containing ready-to-use payloads, commands, and encoding utilities useful during web application testing.

πŸ“š Features Covered in This Guide

🐚 Reverse Shell
🐘 PHP Reverse Shell
πŸ–₯ TTY Spawn Shell
🐧 Useful Linux Commands
⚑️ PowerShell Handy Commands
πŸ“‚ File Transfer Techniques
πŸ“ Local File Inclusion (LFI)
πŸ’‰ Cross-Site Scripting (XSS)
πŸ—„ SQL Injection Payloads
πŸ” Base64 Encoder / Decoder
πŸ”‘ Hash Generator
🌐 URL Encoder / Decoder
πŸ”’ Hexadecimal Encoder / Decoder
🧩 Template Injection (SSTI)
πŸ“‘ Exploit Feed RSS

πŸ“– Article:
https://www.hackingarticles.in/firefox-for-pentester-hacktool/
Active Directory Enumeration: PowerView

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

PowerView is a PowerShell-based reconnaissance tool used in Active Directory environments to enumerate users, groups, policies, sessions, and permissions. It helps penetration testers gather critical information for privilege escalation and lateral movement during post-exploitation. ()

πŸ“š Enumeration Techniques Covered

πŸ‘€ Get-NetUser
πŸ”Ž Get-UserProperty
πŸ” Find-UserField
🎯 Invoke-UserHunter
🌐 Get-NetDomain
πŸ–₯ Get-NetLoggedon
πŸ“œ Get-DomainPolicy
πŸ“‚ Get-NetOU
πŸ‘₯ Get-NetGroup
🧩 Get-NetGroupMember
βš™οΈ Get-NetGPO
πŸ“ Find-GPOLocation
πŸ” Invoke-EnumerateLocalAdmin
πŸ’» Get-NetProcess
πŸ“‘ Invoke-ShareFinder
πŸ“ Invoke-FileFinder
πŸ›‘ Invoke-ACLScanner
πŸ”‘ Find-LocalAdminAccess
πŸ”— Get-NetSession

πŸ“– Article:
https://www.hackingarticles.in/active-directory-enumeration-powerview/
πŸ‘1
OSEP Exam Practice Training (Online) – Registration Open! πŸš€

Ready to level up your offensive security skills and prepare for advanced red team operations?

Join Ignite Technologies’ Exclusive β€œCapture The Flag” (CTF) Based OSEP Practice Program and train in a real-world, attack-driven environment designed for serious cybersecurity professionals.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š Training Modules Include:

πŸš€ Introduction
πŸ” Advanced Information Gathering
🎯 Initial Access & Client-Side Attacks
πŸ›‘ Bypassing Security Controls
πŸͺŸ Windows Privilege Escalation
🐧 Linux Privilege Escalation
🧭 Active Directory Enumeration
πŸ” Lateral Movement
🏰 Active Directory Attacks
🌐 Web Application Attacks
πŸ•³ Tunneling & Pivoting
🧬 Post-Exploitation & Persistence
πŸ₯· Defense Evasion & OPSEC
πŸ§ͺ Custom Malware & Tool Development
πŸ’₯ Advanced Exploitation
πŸ“ Reporting & Documentation

This program is ideal for professionals preparing for advanced offensive security certifications and those aiming to strengthen their red teaming capabilities.

Seats are limited. Secure yours today. πŸš€
❀4
πŸš€ AI Penetration Testing Training (Live Online Program)

The future of cybersecurity is AI-driven β€” are you ready to test and secure it?

Ignite Technologies is launching an intensive AI Penetration Testing Training designed for security professionals, pentesters, red teamers, and researchers who want to understand how to attack and defend Large Language Models (LLMs) and AI systems.

πŸ”— Register Now: https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

⚠️ Limited seats available.

🧠 What You’ll Learn

πŸ”Ή LLM Architecture & Security Principles
πŸ”Ή Data Security in AI Systems
πŸ”Ή Model & Infrastructure Security
πŸ”Ή OWASP Top 10 for LLMs
πŸ”Ή LLM Installation & Secure Deployment
πŸ”Ή Model Context Protocol (MCP)
πŸ”Ή Publishing Models using Ollama
πŸ”Ή Retrieval-Augmented Generation (RAG) Security

πŸ”₯ Offensive AI Security Modules

βœ”οΈ Prompt Injection & Indirect Injection Attacks
βœ”οΈ Exploiting LLM APIs (Real-World Bug Scenarios)
βœ”οΈ Password & Sensitive Data Leakage via AI
βœ”οΈ Excessive Privilege Exploitation
βœ”οΈ LLM Misconfigurations
βœ”οΈ Data Extraction Attacks
βœ”οΈ Content Manipulation in LLM Outputs
βœ”οΈ AI-based Enumeration Techniques

πŸ›‘ Defensive & Automation Focus

βœ… Securing AI Systems
βœ… System Prompt Security Implications
βœ… Automated Penetration Testing with AI
βœ… Making AI Applications Secure & Public-Ready

If you're already into Pentesting, Red Teaming, Bug Bounty, OSCP prep, or Offensive Security, this program will give you a cutting-edge advantage in AI security.

Secure your seat before registrations close.
❀1
NetExec (NXC) Mindmap for Pentesters

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

NetExec (NXC) is a powerful post-exploitation and lateral movement framework used in Active Directory and internal network penetration testing. This mindmap provides a structured overview of commands, techniques, and attack paths to efficiently use NetExec during assessments. ()

πŸ“š Topics Covered in the Mindmap

⚑️ NXC Overview
πŸ” Authentication Methods
🧠 Credential Attacks
πŸ’» SMB Enumeration
🌐 WinRM & Remote Execution
πŸ“‘ Lateral Movement Techniques
πŸ—‚ Share Enumeration
πŸ”Ž Domain & User Enumeration
πŸ›  Post-Exploitation Commands

🧠 Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/NXC
❀2