root@0xpriv:~# history | grep -v boring

Snippets

One-liners worth keeping, with the flags that matter highlighted. Copy, change the target to something you are allowed to test, and run.

Cheat sheet

1 matching
curl
Security headers at a glance. Is there a CSP and HSTS on the response?
curl -sI https://example.com \
  | grep -iE "content-security|strict-transport"