Hacking Articles
24.5K subscribers
1.47K photos
165 files
1.08K links
House of Pentester
Download Telegram
🐧 GNU/Linux Command Reference β€” Essential Cheatsheet πŸ”₯

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

A quick reference for the Linux commands you actually use every day. ⚑️

πŸ“‚ File Commands
ls β€’ cd β€’ rm β€’ cp β€’ mv β€’ cat β€’ less β€’ du

πŸ” Permissions
chmod β€’ chown β€’ sudo β€’ su

πŸ“¦ Archives & Encryption
tar β€’ gpg β€’ zip

✍️ Text Editing
nano + essential shortcuts

βš™οΈ Resource Management
ps β€’ top β€’ free β€’ df β€’ mount β€’ kill

⌨️ Terminal Shortcuts
Ctrl+C β€’ Ctrl+Z β€’ Ctrl+D β€’ Ctrl+R β€’ Tab

πŸ’‘ Perfect for:
Linux Admins β€’ DevOps β€’ Cybersecurity β€’ Pentesters β€’ Students

πŸ“Œ SAVE this cheatsheet.
πŸ” Repost it for your Linux community.
πŸ‘1
🐧 Useful CLI Tools for Linux Admins πŸ”₯

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Your Linux terminal toolkit β€” in ONE cheatsheet. ⚑️

🌐 Networking
ss β€’ ip β€’ tcpdump β€’ nmap β€’ dig β€’ ping β€’ traceroute β€’ netcat β€’ iftop β€’ ethtool

πŸ” Security
iptables β€’ ufw β€’ ssh β€’ openssl β€’ gpg β€’ fail2ban β€’ nmap β€’ rkhunter

πŸ“‹ Logging
journalctl β€’ logrotate β€’ lnav β€’ multitail β€’ awk β€’ sed

βš™οΈ System
top β€’ ps β€’ htop β€’ lsof β€’ lsusb β€’ rsync β€’ tmux β€’ lspci

πŸ’Ύ Storage
df β€’ du β€’ fdisk β€’ lsblk β€’ mount β€’ lvm β€’ iostat β€’ smartctl

πŸ“Œ Save this cheatsheet for your next Linux administration task.

πŸ” Repost for Linux admins, DevOps & cybersecurity professionals.
πŸ‘2
πŸš€ Git Cheatsheet for Developers & DevOps Engineers

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Stop searching for Git commands every time you get stuck. 😎

πŸ“Œ Quick Git Reference Covers:

πŸ”Ή Git Configuration
πŸ”Ή git init & git clone
πŸ”Ή Git Log & History
πŸ”Ή git add / commit / rm / mv
πŸ”Ή Branching & Switching
πŸ”Ή Merge & Rebase
πŸ”Ή Fetch / Pull / Push
πŸ”Ή Remote Repositories
πŸ”Ή Git Diff & Commit Inspection
πŸ”Ή Rewriting Git History
πŸ”Ή Reset / Revert / Clean
πŸ”Ή Undoing Changes

πŸ’» Perfect for:
Developers β€’ DevOps Engineers β€’ Cloud Engineers β€’ SREs β€’ Students

πŸ”– Bookmark this cheatsheet.
πŸ” Repost it for your developer network.

Official Git documentation also provides a quick reference for these core workflows.
πŸ”₯ OSCP isn’t just a certification. It’s a practical skill test.

Stop only learning. Start practicing. 🎯

πŸ’» Real CTFs
🧠 Practical Pentesting
⚑️ OSCP-focused Training
πŸ† Build confidence before the exam

πŸŽ“ Ready to level up your pentesting skills?

πŸ”— Course: https://www.ignitetechnologies.in/ctf-advanced.php
πŸ“ Register: https://forms.gle/bowpX9TGEs41GDG99
πŸ‘1
One tool. Multiple authentication methods. Remote Windows access. πŸ‘€

πŸ”₯ Impacket for Pentester: TSCTool

TSCTool gives pentesters a way to interact with Windows Terminal Services / Remote Desktop sessions remotely β€” a useful capability during authorized post-exploitation and lateral-movement assessments. ⚠️

πŸ“š In This Guide

πŸ–₯ Understand Windows Terminal Services
πŸ” Enumerate Remote Desktop Sessions
πŸ‘₯ Identify Active User Sessions
βš™οΈ Explore TSCTool Capabilities
πŸ”‘ Authenticate with Windows Credentials
🎫 Understand Kerberos-Based Authentication
🌐 Interact with Remote Sessions
🎯 Assess RDP Session Security
🧠 Analyze Session Management Risks
πŸ›‘ Monitor Terminal Services Activity
⚠️ Detection & Mitigation Strategies

πŸ’‘ RDP isn't just about connecting to a desktop.

Active sessions, session IDs, authentication mechanisms, and Terminal Services configuration can reveal valuable information during an authorized Windows security assessment.

πŸ“– Read the Full Guide:
https://www.hackingarticles.in/impacket-for-pentester-tstool/

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles
❀2
One Windows misconfiguration. One MSI file. SYSTEM access. πŸ‘€

πŸ”₯ AlwaysInstallElevated β€” Windows Privilege Escalation

What if a standard user could install an MSI package with administrative privileges?

That's exactly where AlwaysInstallElevated becomes dangerous. ⚠️

πŸ“š In This Guide

πŸ” Understand AlwaysInstallElevated
πŸ“‹ Enumerate HKCU & HKLM Registry Keys
βš™οΈ Identify the Misconfiguration
πŸ•΅οΈ Detect It with WinPEAS
πŸ“¦ Understand Malicious MSI Abuse
πŸš€ Explore Manual Privilege Escalation
πŸ’€ Understand SYSTEM-Level Execution
πŸ›  Exploit the Misconfiguration with Metasploit
🧠 Analyze the Attack Chain
πŸ›‘ Hardening Windows Installer Policies
⚠️ Detection & Mitigation Strategies

πŸ’‘ The scary part?

You don't always need a kernel exploit or a zero-day.

A dangerous Windows Installer policy can allow a low-privileged user to execute an MSI with elevated privileges and reach NT AUTHORITY\SYSTEM. πŸ‘€

πŸ“– Read the Full Guide:
https://www.hackingarticles.in/windows-privilege-escalation-alwaysinstallelevated/

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles
❀2
One tool. Multiple authentication methods. Remote Windows access. πŸ‘€

πŸ”₯ Impacket for Pentester: TSTool

TSCTool gives pentesters a way to interact with Windows Terminal Services / Remote Desktop sessions remotely β€” a useful capability during authorized post-exploitation and lateral-movement assessments. ⚠️

πŸ“š In This Guide

πŸ–₯ Understand Windows Terminal Services
πŸ” Enumerate Remote Desktop Sessions
πŸ‘₯ Identify Active User Sessions
βš™οΈ Explore TSCTool Capabilities
πŸ”‘ Authenticate with Windows Credentials
🎫 Understand Kerberos-Based Authentication
🌐 Interact with Remote Sessions
🎯 Assess RDP Session Security
🧠 Analyze Session Management Risks
πŸ›‘ Monitor Terminal Services Activity
⚠️ Detection & Mitigation Strategies

πŸ’‘ RDP isn't just about connecting to a desktop.

Active sessions, session IDs, authentication mechanisms, and Terminal Services configuration can reveal valuable information during an authorized Windows security assessment.

πŸ“– Read the Full Guide:
https://www.hackingarticles.in/impacket-for-pentester-tstool/

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles
❀2
BloodHound MCP: Automating Active Directory Analysis with AI

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Analyzing complex Active Directory environments can be time-consuming. BloodHound MCP combines AI with BloodHound data to accelerate attack path discovery and AD security assessments ⚠️

πŸ“š What You'll Learn in This Guide

🩸 Introduction to BloodHound MCP
πŸ€– AI-Powered Active Directory Analysis
βš™οΈ Setting Up BloodHound MCP
πŸ“Š Importing & Processing BloodHound Data
πŸ” Identifying Attack Paths with AI
🎯 Privilege Escalation Path Discovery
πŸ‘₯ Analyzing Users, Groups & Permissions
🌐 Mapping Trust Relationships
πŸš€ Automating AD Security Assessments
πŸ“‹ Natural Language Queries for BloodHound
🧠 Red Teaming & Defensive Use Cases
πŸ›‘ Hardening Active Directory Environments

πŸ’‘ BloodHound MCP enhances traditional BloodHound analysis by leveraging AI to interpret graph data, identify privilege escalation paths, answer natural language questions, and streamline Active Directory security assessments for both red and blue teams.

πŸ“– Article:
https://www.hackingarticles.in/bloodhound-mcp-automating-active-directory-analysis-with-ai/
πŸ‘2
Automated Penetration Testing with Claude AI

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

AI is rapidly changing the cybersecurity landscape, helping penetration testers automate reconnaissance, analysis, and exploitation workflows more efficiently than ever ⚠️

πŸ“š What You'll Learn in This Guide

πŸ€– Introduction to Claude AI for Pentesting
βš™οΈ Setting Up AI-Assisted Security Workflows
πŸ” Automated Reconnaissance & Enumeration
πŸ“‹ Analyzing Scan Results with AI
🎯 Vulnerability Identification & Prioritization
πŸš€ Automating Penetration Testing Tasks
πŸ›  Integrating Claude with Security Tools
πŸ“‚ Streamlining Report Generation
🧠 AI-Powered Decision Making for Red Teams
πŸ”„ Enhancing Productivity During Assessments
πŸ›‘ Ethical Considerations & Responsible Usage
⚠️ Limitations of AI in Offensive Security

πŸ’‘ Claude AI can assist security professionals by automating repetitive tasks, interpreting security findings, generating commands, and accelerating penetration testing workflows. Human validation remains essential to ensure accuracy and responsible use.

πŸ“– Article:
https://www.hackingarticles.in/automating-penetration-testing-with-claude-ai/
❀1
AI-Powered Penetration Testing with Metasploit

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Artificial Intelligence is transforming the way security professionals perform penetration testing, making reconnaissance, analysis, and exploitation workflows more efficient than ever ⚠️

πŸ“š What You'll Learn in This Guide

πŸ€– Introduction to AI-Powered Pentesting
πŸ” AI-Assisted Reconnaissance & Enumeration
βš™οΈ Integrating AI with Metasploit Framework
🧠 Using LLMs to Analyze Scan Results
🎯 Automated Vulnerability Identification
πŸš€ AI-Driven Exploitation Workflows
πŸ“‹ Generating Security Reports with AI
πŸ”„ Streamlining Post-Exploitation Tasks
πŸ›  MCP & AI Integration Concepts
πŸ“‚ Enhancing Red Team Operations
πŸ›‘ Ethical Considerations & Safe Testing
⚠️ Limitations of AI in Penetration Testing

πŸ’‘ AI can help penetration testers interpret results, automate repetitive tasks, prioritize vulnerabilities, and accelerate security assessments. When combined with Metasploit, it enables more efficient workflows while still requiring human oversight and validation.

πŸ“– Article:
https://www.hackingarticles.in/ai-powered-penetration-testing-with-metasploit/
1❀4