
hacktricks
Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

HackTheBox Pterodactyl walkthrough chaining CVE-2025-49132 path traversal, hash cracking, and CVE-2025-6018/6019 PAM and XFS race for root.

HackTheBox CCTV walkthrough chaining CVE-2024-51482 ZoneMinder SQL injection, bcrypt hash cracking, and CVE-2025-60787 motionEye RCE to obtain root.

JSON Web Token Hack Toolkit

HackTheBox Devvortex walkthrough covering subdomain fuzzing, Joomla API enumeration, template-based web shell, bcrypt hash cracking, and Apport-CLI…

Automated remote credential dumper for Windows environments, extracting DPAPI secrets, browser credentials, certificates, and configuration files…

bash CLI trainer — 30 levels from ls to privilege escalation

Single-file HTML cheat sheet for red teamers and pentesters with auto-injecting attacker/target variables, OS-aware reverse shell generator, and…

CredsHunter - Credential Hunting scripts for Windows and Linux OS

A small set of tools to convert packets from capture files to hash files for use with Hashcat or John the Ripper.

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

HTB OneTwoSeven full walkthrough: deterministic creds, chroot symlink escape, rewrite-rule bypass RCE, CVE-2024-1086 to root

Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)

Pentest completo sobre Metasploitable: recon con nmap, explotación con Metasploit (CVE-2007-2447), extracción y cracking de credenciales,…