root@0xpriv:~# history | grep -v boring
Snippets
One-liners worth keeping, with the flags that matter highlighted. Copy, change the target to something you are allowed to test, and run.
Cheat sheet
8 totalnmapabout the tool →
Service & version scan. The flag set that fingerprints what's actually listening.
nmap -sV -sC -T4 \ --top-ports 1000 \ target
ffufabout the tool →
Fuzz for hidden content. Only show the status codes worth a second look.
ffuf -w wordlist.txt \ -u https://lab-host/FUZZ \ -mc 200,301,302
subfinderabout the tool →
Passive subdomain list. No packets to the target — just what public sources already know.
subfinder -d example.com -silent
dig
Mail and policy records. Two lookups that describe how a domain handles email.
dig +short example.com MX dig +short example.com TXT
tcpdumpabout the tool →
Capture one port to a file. Write now, analyse later in Wireshark.
sudo tcpdump -i eth0 -nn port 443 \ -w capture.pcap
openssl
What TLS did we negotiate? Protocol version and cipher, straight from the handshake.
openssl s_client -connect host:443 -tls1_3 </dev/null \ | grep -E "Protocol|Cipher"
curl
Security headers at a glance. Is there a CSP and HSTS on the response?
curl -sI https://example.com \ | grep -iE "content-security|strict-transport"
journalctl
Successful SSH logins, last day. The lines that matter in a noisy auth log.
journalctl -u ssh --since "24 hours ago" \ | grep "Accepted"