
Pentest-Cheat-Sheet
There are many cheat sheets out there, but this is mine.

There are many cheat sheets out there, but this is mine.

Extracts KeePass master passwords from memory dumps of unlocked databases, outputting potential characters by position, a passphrase, and a…

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Try to find the password of an encrypted Peercoin (or Bitcoin, Litecoin, etc...) wallet file.

AD Enum is a pentesting tool that allows to find misconfiguration through the the protocol LDAP and exploit some of those weaknesses with kerberos.

Find credentials in screenshots, save them to your secret manager, and irreversibly redact them from the image — local, offline, OCR-based.

SocialPwned is an OSINT tool that allows to get the emails, from a target, published in social networks such as Instagram, Linkedin and Twitter to…

Tor-based leaked credential search tool that queries the pwndb2 hidden service to find emails and passwords exposed in data breaches, with wildcard…

Browser-based password cracking toolkit with hash lookup, wordlist generation, rule-based attack simulation, and client-side hash cracking for…

Brute-force tool that recovers full executable paths from Windows prefetch hashes using bodyfiles, supporting XP, Vista, and 2008 hash functions for…

Hash database builder and reverse lookup tool — SHA256, RIPEMD160, Keccak256, BLAKE3 and more

tool to extract passwords from TeamViewer memory using Frida

Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall

PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping

KeePass 2.X dumper (CVE-2023-32784)

A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.

Original PoC for CVE-2023-30367

KeePass Master Password Extraction PoC for Linux