Cybersecurity Cheatsheets
- CTFs & Vulnerable Targets — Curated catalog of free + freemium platforms and downloadable targets.
- Certification Roadmap — Practical guide to certifications mapped to AYSEC tracks (2026).
- SQL Injection — Detection + exploitation payloads for MySQL, PostgreSQL, MSSQL, Oracle & SQLite
- Free Platforms Mapping — The 100% free / meaningful-free-tier platforms AYSEC recommends.
- Glossary — Quick definitions for terms used across the AYSEC tracks.
- Nmap — Host discovery, port scanning, service detection, NSE scripts & firewall evasion
- HackTheBox → AYSEC Mapping — HTB Academy modules + retired machines mapped to AYSEC tracks.
- Lab Setup Guide — A single comprehensive lab build supporting every AYSEC track.
- Reverse Shell — One-liners for bash, python, nc, php, PowerShell & msfvenom + TTY upgrade
- Per-Module Lab Manual — Reusable lab manual template + 8 worked examples.
- Tools Reference — Categorized list of every tool used in AYSEC, with module references.
- XSS (Cross-Site Scripting) — Payloads, context breakouts, DOM sinks & WAF/filter bypass
- 50 Original Hands-On Labs — Original AYSEC-house-style labs you can host locally.
- Linux Privilege Escalation — SUID, sudo, cron, capabilities, PATH & kernel — the full root checklist
- PortSwigger → AYSEC Mapping — The free PortSwigger Web Security Academy mapped to AppSec modules.
- Windows Privilege Escalation — Token abuse, service misconfigs, AlwaysInstallElevated & credential hunting
- Command Injection — Separators, blind/out-of-band techniques & filter bypass
- TryHackMe → AYSEC Mapping — Complete free + paid TryHackMe rooms and paths mapped to AYSEC.
- Password Cracking — Hashcat & John modes, hash identification, rules, masks & *2john tools
- Udemy & Paid Courses — Recommended paid courses by topic.
- Burp Suite — Proxy, Repeater, Intruder, Decoder & shortcuts for web app testing
- sqlmap — Automated SQL injection detection + exploitation flags and examples
- ffuf — Fast web fuzzing — directories, parameters, vhosts & response filters
- Gobuster — Directory, DNS subdomain & vhost brute-forcing
- WPScan — WordPress enumeration — users, plugins, themes & known vulns
- Nikto — Web server vulnerability & misconfiguration scanner
- Metasploit Framework — msfconsole workflow — search, use, set, exploit, sessions & meterpreter
- msfvenom — Generate reverse shells & payloads for every platform and format
- Hydra — Online password brute-forcing for SSH, FTP, HTTP, RDP & more
- Netcat — The TCP/IP swiss-army knife — listeners, shells, transfers & scans
- searchsploit — Search & use Exploit-DB offline from the terminal
- Impacket — AD attack scripts — secretsdump, psexec, GetUserSPNs, ntlmrelayx
- NetExec / CrackMapExec — Sweep SMB/WinRM/LDAP/MSSQL — creds, shares, dumps & modules
- BloodHound — Map Active Directory attack paths — SharpHound collection & Cypher
- Mimikatz — Dump credentials, pass-the-hash, golden tickets & DCSync
- Evil-WinRM — WinRM shell — login by password/hash, upload, download & load tools
- enum4linux & smbclient — SMB/Samba enumeration — shares, users, groups & null sessions
- Wireshark Display Filters — The display filters you actually use — ip, tcp, http, dns, tls & follow stream
- tcpdump — Capture & filter packets from the CLI — hosts, ports, flags & pcaps
- Volatility — Memory forensics — process, network, injection & credential plugins
- GDB + pwndbg — Debug & exploit binaries — breakpoints, memory exam, checksec & cyclic
- Ghidra — Reverse engineering — decompiler, XREFs, shortcuts & headless analysis
- Aircrack-ng — Wi-Fi auditing — monitor mode, handshake capture & WPA cracking