Hacking Articles
23K subscribers
1.36K photos
165 files
971 links
House of Pentester
Download Telegram
Comprehensive Guide on FTK Imager

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Learn how to use FTK Imager for digital forensic investigations to acquire and analyze disk evidence safely. πŸ”πŸ’»

πŸ’‘ Key Takeaways:
πŸ’Ύ Creating Forensic Disk Images
🧠 Capturing Volatile Memory
πŸ“‚ Evidence & Image Analysis
πŸ”— Mounting Images as Drives
πŸ” AD Encryption & Decryption
πŸ“€ Exporting Evidence Files

πŸ“– Full Guide:
https://www.hackingarticles.in/comprehensive-guide-on-ftk-imager/
❀2
Memory Forensics Using Volatility Framework

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Discover how investigators analyze RAM memory dumps to uncover hidden processes, credentials, and malicious activity during forensic investigations. πŸ•΅οΈβ€β™‚οΈπŸ’»

πŸ’‘ Key Takeaways:
🧠 Memory Acquisition Basics
πŸ“¦ Supported Memory Dump Formats
πŸ” Image Profile Identification
βš™οΈ Volatility Plugins & Commands
🧾 Process & Network Artifact Analysis
πŸ” Credential & Registry Extraction

πŸ“– Full Guide:
https://www.hackingarticles.in/memory-forensics-using-volatility-framework/
❀1
🚨 STOP WASTING MONTHS ON RANDOM OSCP TUTORIALS 🚨

Most OSCP students don't fail because they lack tools.

They fail because they lack a METHODOLOGY. 🎯

What actually matters?

πŸ”Ž Enumeration
⚑️ Windows & Linux PrivEsc
🏰 Active Directory Attacks
🌐 Web Exploitation
🧠 Pivoting & Tunneling
πŸ”‘ Password Attacks
πŸ’£ Public Exploit Abuse
πŸ“‹ Professional Reporting

πŸ”₯ OSCP Training β€” ADMISSIONS OPEN

No endless theory.
No random tutorials.

βœ… Hands-on labs
βœ… Real-world attack scenarios
βœ… OSCP-focused methodology
βœ… Beginner β†’ Advanced guidance

⚠️ LIMITED SEATS AVAILABLE

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ info@ignitetechnologies.in

♻️ RT to help an OSCP aspirant.
❀1
Scheduled Tasks + SMB = Remote Command Execution. πŸ‘€

πŸ”₯ Impacket for Pentester: Atexec

Need remote command execution without creating a service? Atexec leverages Windows Task Scheduler to execute commands remotely, making it a valuable technique for lateral movement assessments in Active Directory environments. ⚠️

πŸ“š In This Guide

⏰ Understanding Atexec & Task Scheduler
βš™οΈ Installing & Configuring Impacket
πŸ”‘ Authentication with Passwords, NTLM Hashes & Kerberos
🌐 Remote Command Execution over SMB
πŸ“‹ Running Single Commands on Remote Hosts
πŸ–₯ Interactive Execution Workflows
🎯 Lateral Movement in Active Directory
πŸ”„ Comparing Atexec vs PsExec vs WMIExec
πŸ“Š Understanding Windows Scheduled Task Artifacts
🧠 Detection & DFIR Considerations
πŸ›‘ Hardening Remote Administration Paths
⚠️ Monitoring Scheduled Task Abuse

πŸ’‘ Unlike PsExec, Atexec executes commands through the Windows Task Scheduler service instead of creating a temporary service. Understanding how different Impacket execution methods work helps security teams assess, detect, and defend against unauthorized remote administration activity.

πŸ“– Read the Full Guide:
https://www.hackingarticles.in/impacket-for-pentester-atexec/

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles
❀3
Stop memorizing hundreds of pentesting commands. Let AI do it for you. πŸ‘€

πŸ”₯ Arsenal-NG: The Ultimate Pentest Cheat Sheet

From enumeration to exploitation, Arsenal-NG generates commands on demand, helping security professionals save time during assessments. ⚠️

πŸ“š In This Guide

πŸ€– Introduction to Arsenal-NG
βš™οΈ Installing Arsenal-NG
πŸ” Generating Reconnaissance Commands
🌐 Network Enumeration Made Easy
πŸ›  Web Application Testing Commands
🎯 Active Directory Assessment Workflows
πŸ”‘ Credential Attack Command Generation
πŸ“‘ Service Enumeration Techniques
🐧 Linux & Windows Pentesting Commands
πŸš€ Red Team & Post-Exploitation Use Cases
🧠 AI-Assisted Command Generation
πŸ“‹ Practical Pentesting Cheat Sheet Examples

πŸ’‘ Why remember every Nmap, NetExec, CrackMapExec, Impacket, BloodHound, or Metasploit command when you can generate them instantly? Arsenal-NG acts as a smart command assistant, helping pentesters quickly find the right syntax and workflow during authorized security assessments.

πŸ“– Read the Full Guide:
https://www.hackingarticles.in/arsenal-ng-pentest-cheat-sheet/

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles
❀1
Still using only net user and ldapsearch for AD enumeration? You're missing the attack paths. πŸ‘€

πŸ”₯ Active Directory Enumeration with BloodHound Python

BloodHound Python transforms raw Active Directory data into a visual attack graph, helping security teams identify privilege escalation paths, dangerous permissions, and hidden relationships. ⚠️

πŸ“š In This Guide

🐍 Introduction to BloodHound Python
βš™οΈ Installing BloodHound & Dependencies
🌐 LDAP-Based Data Collection from Kali Linux
πŸ” Enumerating Users, Groups & Computers
πŸ‘₯ Mapping Active Directory Relationships
🩸 Collecting Data with BloodHound Python
πŸ“Š Importing Results into BloodHound CE
🎯 Finding Paths to Domain Admin
πŸ”‘ Identifying DCSync Privileges
πŸš€ Discovering Kerberoastable & AS-REP Roastable Accounts
πŸ›  Analyzing ACL Abuse Paths
🧠 Prioritizing High-Value Targets
πŸ›‘ Detection & Defensive Insights

πŸ’‘ Attackers don't compromise domains by guessing.

They follow relationships, permissions, delegated rights, and trust paths. BloodHound turns thousands of AD objects into a visual roadmap that helps uncover the shortest path to privilege escalation.

πŸ“– Read the Full Guide:
https://www.hackingarticles.in/active-directory-enumeration-with-bloodhound-python/

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles
❀2
πŸ’° Companies paid out over $300M in bug bounties last year β€” and the demand is only growing.

From Google to the Pentagon, ethical hackers are getting rewarded for finding what others miss. But here's the truth: most aspiring bounty hunters fail not because they lack curiosity β€” they lack a structured roadmap.

🎯 Ignite Technologies presents: Bug Bounty Training Program (Online)

A hands-on, exclusive program built for beginners and intermediates ready to break into bug bounty hunting and ethical hacking β€” the right way.

πŸ”₯ What you'll master:
βœ”οΈ Introduction to WAPT & OWASP Top 10
βœ”οΈ Pentest Lab Setup
βœ”οΈ Information Gathering & Reconnaissance
βœ”οΈ Netcat for Pentesters
βœ”οΈ Configuration Management Testing
βœ”οΈ Cryptography
βœ”οΈ Authentication Attacks
βœ”οΈ Session Management Exploitation
βœ”οΈ Local File Inclusion (LFI)
βœ”οΈ Remote File Inclusion (RFI)
βœ”οΈ Path Traversal
βœ”οΈ OS Command Injection
βœ”οΈ Open Redirect
βœ”οΈ Unrestricted File Upload
βœ”οΈ PHP Web Shells
βœ”οΈ HTML Injection
βœ”οΈ Cross-Site Scripting (XSS)
βœ”οΈ Client-Side Request Forgery (CSRF)
βœ”οΈ SQL Injection
βœ”οΈ XXE Injection
βœ”οΈ Bonus Section 🎁

πŸ’‘ Why this matters: Bug bounty isn't just about tools β€” it's about thinking like an attacker. This program walks you through the OWASP Top 10 and beyond, with real exploitation techniques you can apply on live programs (HackerOne, Bugcrowd, Intigriti).

πŸ“… Limited seats. Enroll today.

πŸ”— Register: https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

πŸ‘‰ Tag someone who's been talking about getting into bug bounty.
πŸ’¬ Drop a comment: What's the first vulnerability you ever found?
♻️ Repost to help an aspiring hacker in your network.
πŸ‘1
πŸ”₯ Ethical Hacking Proactive Training – Live & Practical πŸ”₯

Ready to build real-world cybersecurity skills with hands-on experience?

πŸš€ Ignite Technologies brings you a comprehensive Ethical Hacking Proactive Training Program designed with live sessions and core practical exposure β€” at an affordable price.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

🎯 Book Your Demo Session Today!

πŸ“˜ What You’ll Learn:

βœ… Introduction to Ethical Hacking
βœ… Old School Learning Methodology
βœ… Networking Fundamentals
βœ… Reconnaissance (Footprinting, Scanning & Enumeration)
βœ… System Hacking
βœ… Post Exploitation & Persistence
βœ… Web Server Penetration Testing
βœ… Website Hacking Techniques
βœ… Malware Threats & Analysis
βœ… Wireless Network Security
βœ… Cryptography & Steganography
βœ… Sniffing Attacks
βœ… Denial of Service (DoS)
βœ… Evading IDS, Firewalls & Honeypots
βœ… Social Engineering Techniques
βœ… Mobile Platform Security

πŸ’‘ Whether you're a beginner or looking to strengthen your penetration testing skills, this training is structured to provide practical knowledge aligned with real-world attack scenarios.

Limited seats available. Secure yours now.
Tcpdump Cheat Sheet for Pentesters

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Tcpdump is a powerful command-line packet analyzer used to capture and inspect network traffic. It is widely used for network troubleshooting, packet analysis, and security monitoring on Linux systems. ()

⚑️ Useful Tcpdump Commands

πŸ“‘ tcpdump -i eth0
πŸ”Ž tcpdump host 192.168.1.1
🌐 tcpdump port 80
πŸ“‚ tcpdump -w capture.pcap
πŸ“– tcpdump -r capture.pcap
🧠 tcpdump -i eth0 tcp
πŸ“Š tcpdump -n -vv
πŸ” tcpdump icmp
πŸ“ tcpdump src 192.168.1.5
πŸ“ tcpdump dst 192.168.1.5

🧠 Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Tcpdump
SSH Port Forwarding & Tunnelling

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

SSH tunnelling allows secure communication by forwarding traffic through an encrypted channel, enabling access to internal services and bypassing network restrictions.

⚑️ Key Highlights
πŸ” Encrypted communication over SSH
πŸ” Port forwarding (local, remote, dynamic)
🌐 Access internal services behind firewall
πŸš€ Secure data transfer over untrusted networks

⚑️ Types of Forwarding
πŸ“ Local Port Forwarding
🌍 Remote Port Forwarding
🧠 Dynamic Port Forwarding (SOCKS proxy)

πŸ’‘ SSH tunneling redirects traffic from one port to another through a secure channel, allowing systems to communicate safely even across restricted networks.

πŸ“– Article: https://www.hackingarticles.in/a-detailed-guide-on-ssh-port-forwarding-tunnelling/
Network Pivoting: Ligolo-MP Complete Guide

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Network pivoting allows attackers to move deeper into internal networks using a compromised machine as a bridge to access hidden systems and services.

⚑️ Key Highlights
πŸ”— Pivot into internal networks
🌐 Access hidden subnets & services
πŸ”„ Route traffic through compromised host
πŸš€ Perform lateral movement & internal recon

⚑️ Ligolo-MP Advantages
🧠 VPN-like tunneling (TUN interface)
πŸ” Encrypted communication (mTLS)
⚑️ Multiple concurrent tunnels
πŸ§‘β€πŸ€β€πŸ§‘ Multiplayer pivoting support
πŸ“‘ No need for SOCKS/port forwarding

πŸ’‘ Ligolo-MP creates a tunnel that makes your attacker machine behave as if it is inside the target network, enabling tools like Nmap to scan internal systems directly.

πŸ“– Article: https://www.hackingarticles.in/network-pivoting-using-ligolo-mp-complete-guide/
❀2
🚨 STOP WASTING MONTHS ON RANDOM OSCP TUTORIALS 🚨

Most OSCP students don't fail because they lack tools.

They fail because they lack a METHODOLOGY. 🎯

What actually matters?

πŸ”Ž Enumeration
⚑️ Windows & Linux PrivEsc
🏰 Active Directory Attacks
🌐 Web Exploitation
🧠 Pivoting & Tunneling
πŸ”‘ Password Attacks
πŸ’£ Public Exploit Abuse
πŸ“‹ Professional Reporting

πŸ”₯ OSCP Training β€” ADMISSIONS OPEN

No endless theory.
No random tutorials.

βœ… Hands-on labs
βœ… Real-world attack scenarios
βœ… OSCP-focused methodology
βœ… Beginner β†’ Advanced guidance

⚠️ LIMITED SEATS AVAILABLE

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ info@ignitetechnologies.in

♻️ RT to help an OSCP aspirant.
πŸ’° Companies paid out over $300M in bug bounties last year β€” and the demand is only growing.

From Google to the Pentagon, ethical hackers are getting rewarded for finding what others miss. But here's the truth: most aspiring bounty hunters fail not because they lack curiosity β€” they lack a structured roadmap.

🎯 Ignite Technologies presents: Bug Bounty Training Program (Online)

A hands-on, exclusive program built for beginners and intermediates ready to break into bug bounty hunting and ethical hacking β€” the right way.

πŸ”₯ What you'll master:
βœ”οΈ Introduction to WAPT & OWASP Top 10
βœ”οΈ Pentest Lab Setup
βœ”οΈ Information Gathering & Reconnaissance
βœ”οΈ Netcat for Pentesters
βœ”οΈ Configuration Management Testing
βœ”οΈ Cryptography
βœ”οΈ Authentication Attacks
βœ”οΈ Session Management Exploitation
βœ”οΈ Local File Inclusion (LFI)
βœ”οΈ Remote File Inclusion (RFI)
βœ”οΈ Path Traversal
βœ”οΈ OS Command Injection
βœ”οΈ Open Redirect
βœ”οΈ Unrestricted File Upload
βœ”οΈ PHP Web Shells
βœ”οΈ HTML Injection
βœ”οΈ Cross-Site Scripting (XSS)
βœ”οΈ Client-Side Request Forgery (CSRF)
βœ”οΈ SQL Injection
βœ”οΈ XXE Injection
βœ”οΈ Bonus Section 🎁

πŸ’‘ Why this matters: Bug bounty isn't just about tools β€” it's about thinking like an attacker. This program walks you through the OWASP Top 10 and beyond, with real exploitation techniques you can apply on live programs (HackerOne, Bugcrowd, Intigriti).

πŸ“… Limited seats. Enroll today.

πŸ”— Register: https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

πŸ‘‰ Tag someone who's been talking about getting into bug bounty.
πŸ’¬ Drop a comment: What's the first vulnerability you ever found?
♻️ Repost to help an aspiring hacker in your network.
❀3
🚨 STOP WASTING MONTHS ON RANDOM OSCP TUTORIALS 🚨

Most OSCP students don't fail because they lack tools.

They fail because they lack a METHODOLOGY. 🎯

What actually matters?

πŸ”Ž Enumeration
⚑️ Windows & Linux PrivEsc
🏰 Active Directory Attacks
🌐 Web Exploitation
🧠 Pivoting & Tunneling
πŸ”‘ Password Attacks
πŸ’£ Public Exploit Abuse
πŸ“‹ Professional Reporting

πŸ”₯ OSCP Training β€” ADMISSIONS OPEN

No endless theory.
No random tutorials.

βœ… Hands-on labs
βœ… Real-world attack scenarios
βœ… OSCP-focused methodology
βœ… Beginner β†’ Advanced guidance

⚠️ LIMITED SEATS AVAILABLE

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ info@ignitetechnologies.in

♻️ RT to help an OSCP aspirant.

#OSCP #CyberSecurity #Pentesting #EthicalHacking #ActiveDirectory #RedTeam
❀1
πŸš€ AI Penetration Testing Training β€” Live Online Program

The cybersecurity landscape is changing rapidly.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

Organizations are deploying AI applications, chatbots, RAG systems, AI agents, and LLM-powered platforms at scale.

Unfortunately, many of these systems are being deployed without proper security testing.

This AI Penetration Testing curriculum covers the critical areas security professionals need to understand, including:

🧠 LLM Architecture & Security Principles
πŸ” Data Security in AI Systems
πŸ›‘ Model Security
🌐 Infrastructure Security
πŸ“‹ OWASP Top 10 for LLMs
βš™οΈ Secure LLM Installation & Deployment
πŸ”„ Model Context Protocol (MCP)
πŸš€ Publishing Models with Ollama
πŸ“š Retrieval-Augmented Generation (RAG)
🌍 Making AI Applications Public
πŸ” AI-Powered Enumeration Techniques
πŸ’₯ Prompt Injection Attacks
⚑️ LLM API Exploitation
πŸ”“ Password Leakage via AI Models
🎭 Indirect Prompt Injection
⚠️ LLM Misconfigurations
πŸ”‘ Excessive Privilege Abuse in LLM APIs
πŸ“ Content Manipulation Attacks
πŸ“€ Data Extraction Attacks
πŸ›‘ Securing AI Systems
πŸ“– System Prompt Security
πŸ€– Automated Penetration Testing with AI

The program focuses on both offensive and defensive AI security concepts, covering model, data, infrastructure, deployment, and API attack surfaces.
Topics include RAG security, prompt injection, LLM API exploitation, password leakage risks, indirect prompt injection, excessive privilege abuse, data extraction attacks, and automated AI-powered security assessments.
πŸ”₯ Join our cybersecurity community:

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

AI Security is no longer a niche skill.

It is quickly becoming a core competency for pentesters, red teamers, security researchers, and defenders. πŸš€

#AISecurity #LLMSecurity #CyberSecurity #Pentesting #RedTeam #GenAI #OWASP #AI #OffensiveSecurity #InfoSec
❀2
πŸ’° Companies paid out over $300M in bug bounties last year β€” and the demand is only growing.

From Google to the Pentagon, ethical hackers are getting rewarded for finding what others miss. But here's the truth: most aspiring bounty hunters fail not because they lack curiosity β€” they lack a structured roadmap.

🎯 Ignite Technologies presents: Bug Bounty Training Program (Online)

A hands-on, exclusive program built for beginners and intermediates ready to break into bug bounty hunting and ethical hacking β€” the right way.

πŸ”₯ What you'll master:
βœ”οΈ Introduction to WAPT & OWASP Top 10
βœ”οΈ Pentest Lab Setup
βœ”οΈ Information Gathering & Reconnaissance
βœ”οΈ Netcat for Pentesters
βœ”οΈ Configuration Management Testing
βœ”οΈ Cryptography
βœ”οΈ Authentication Attacks
βœ”οΈ Session Management Exploitation
βœ”οΈ Local File Inclusion (LFI)
βœ”οΈ Remote File Inclusion (RFI)
βœ”οΈ Path Traversal
βœ”οΈ OS Command Injection
βœ”οΈ Open Redirect
βœ”οΈ Unrestricted File Upload
βœ”οΈ PHP Web Shells
βœ”οΈ HTML Injection
βœ”οΈ Cross-Site Scripting (XSS)
βœ”οΈ Client-Side Request Forgery (CSRF)
βœ”οΈ SQL Injection
βœ”οΈ XXE Injection
βœ”οΈ Bonus Section 🎁

πŸ’‘ Why this matters: Bug bounty isn't just about tools β€” it's about thinking like an attacker. This program walks you through the OWASP Top 10 and beyond, with real exploitation techniques you can apply on live programs (HackerOne, Bugcrowd, Intigriti).

πŸ“… Limited seats. Enroll today.

πŸ”— Register: https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

πŸ‘‰ Tag someone who's been talking about getting into bug bounty.
πŸ’¬ Drop a comment: What's the first vulnerability you ever found?
♻️ Repost to help an aspiring hacker in your network.
❀2
SSQL for Pentesters: Metasploit

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Learn how to pentest Microsoft SQL Server using Metasploit, from server discovery and credential attacks to command execution and privilege escalation.

🧠 Topics covered:
β€’ MSSQL Server Discovery & Enumeration
β€’ Password Brute‑Force Attacks
β€’ Database & Schema Dumping
β€’ Command Execution via xp_cmdshell
β€’ Privilege Escalation to sysadmin

πŸ“– Read the full guide:
https://www.hackingarticles.in/mssql-for-pentester-metasploit/
MSSQL for Pentesters: Command Execution with xp_cmdshell

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Learn how attackers abuse xp_cmdshell in Microsoft SQL Server to execute operating system commands directly from the database engine, enabling powerful post‑exploitation and remote command execution techniques.

🧠 Topics covered:
β€’ Enabling xp_cmdshell in MSSQL
β€’ OS command execution from SQL Server
β€’ Reverse shell via PowerShell / Netcat
β€’ Exploitation using Metasploit, CrackMapExec & PowerUpSQL

πŸ“– Read the full guide:
https://www.hackingarticles.in/mssql-for-pentester-command-execution-with-xp_cmdshell/
❀1