Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
offensive-one-liners — 110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use reference; environmental + evasion detection in detection-defense-library. | Kitploit
Tools/GitLabGitLab/wattocyber/offensive-one-liners
Privilege EscalationReconnaissancePassword AttacksExploitationLateral MovementWeb Application ExploitationPost-ExploitationCTFPenetration Testing

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Red Teaming
Curated Resources
Container Escape
GitLabwattocyber/offensive-one-liners

offensive-one-liners

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use reference; environmental + evasion detection in detection-defense-library.

View RepositoryWebsite
12 days agoNot yet reviewed

offensive-one-liners

A notebook of 110 offensive security one-liners for authorized testing, CTFs, bug bounty, and lab research. Organized into one markdown notebook with 12 sections.

See offensive-one-liners.md for the full notebook.

Coverage

  1. Recon & Enumeration
  2. Active Directory & Kerberos (AS-REP roast, Kerberoast, DCSync, golden ticket)
  3. SMB & Lateral Movement (PTT, pass-the-hash, GPP passwords, EternalBlue)
  4. Web & API Exploitation (SQLi, NoSQLi, SSTI, request smuggling, GraphQL)
  5. SSRF, Cloud & Metadata (AWS/GCP/ECS metadata, k8s, internal vhost smuggling)
  6. Credential Attacks & Spraying
  7. Reverse Shells & Tunnels (TLS socat, chisel, ligolo-ng, frp)
  8. Privilege Escalation
  9. Persistence (incl. WMI event subscription, LD_PRELOAD)
  10. Container & Cloud Escape (docker socket, cgroup release_agent, nsenter)
  11. Pivoting & Proxy
  12. Misc Force Multipliers

Placeholders (TGT, LHOST, LPORT, DOMAIN, USER, PASS) are documented in the notebook.

Scope

These one-liners are for systems you own, explicitly authorized systems, CTF/benchmark targets, and lab environments. Nothing here grants authorization. Review target scope before running.

Download Tool