Copy-ready payload references for penetration testing. Each cheat sheet contains categorized payloads with descriptions, filter bypasses, and platform-specific variants.
Cross-Site Scripting (XSS) payloads for testing reflected, stored, and DOM-based XSS vulnerabilities.
SQL Injection payloads for testing authentication bypass, UNION-based, error-based, and blind injection.
Reverse shell one-liners for Bash, Python, PHP, Perl, Ruby, Netcat, PowerShell, and more.
OS command injection payloads for testing command separators, blind injection, and filter bypasses.
Local File Inclusion and Path Traversal payloads for reading files, bypassing filters, and PHP wrappers.
Server-Side Request Forgery payloads for accessing internal services, cloud metadata, and bypassing filters.
Server-Side Template Injection payloads for Jinja2, Twig, FreeMarker, ERB, and more template engines.
XML External Entity injection payloads for file reading, SSRF, out-of-band exfiltration, and denial of service.
Cross-Site Request Forgery proof-of-concept payloads for auto-submitting forms, XHR, fetch, and JSON CSRF.
JWT attack payloads for algorithm confusion, none algorithm, key injection, and claim manipulation.
File upload bypass payloads for extension filtering, MIME type checks, content validation, and webshell deployment.
Open redirect payloads for URL parsing confusion, protocol tricks, and filter bypass techniques.
NoSQL injection payloads for MongoDB, CouchDB, and other NoSQL databases.
Insecure Direct Object Reference testing techniques for sequential IDs, UUIDs, encoded references, and parameter tampering.
JavaScript prototype pollution payloads for __proto__, constructor, and deep merge exploitation.
CRLF injection payloads for HTTP response splitting, header injection, and log poisoning.
WAF evasion techniques for XSS, SQLi, RCE, and LFI payloads using encoding, comments, and alternative syntax.
HTTP request smuggling payloads for CL.TE, TE.CL, TE.TE desync, and HTTP/2 downgrade attacks.
Insecure deserialization payloads for Java, PHP, Python, and .NET with gadget chains and tool commands.
CORS misconfiguration exploitation payloads for origin reflection, null origin, and wildcard subdomain attacks.
Race condition payloads for exploiting time-of-check to time-of-use (TOCTOU) bugs in web applications.
GraphQL injection and exploitation payloads for testing GraphQL APIs — introspection, batching, injection, and DoS.
Linux privilege escalation techniques: SUID, sudo misconfigs, cron jobs, capabilities, writable files, path hijacking, kernel exploits, and container escapes.
Windows privilege escalation techniques: unquoted service paths, weak permissions, DLL hijacking, token impersonation, AlwaysInstallElevated, UAC bypass, and credential access.
Post-exploitation commands for shell stabilization, persistence, file transfer, data exfiltration, network pivoting, and covering tracks on Linux and Windows.
Cloud attack payloads for AWS, GCP, Azure, and Kubernetes. SSRF-to-metadata exploitation, IAM credential theft, S3/Cloud Storage misconfigs, container escape, and Kubernetes service account abuse.
Active Directory enumeration, Kerberoasting, AS-REP roasting, Pass-the-Hash, DCSync, Golden Ticket, and lateral movement techniques.
OAuth 2.0 and OpenID Connect attack techniques including CSRF via missing state, open redirect in redirect_uri, token scope escalation, and PKCE bypass.
API security testing techniques covering BOLA/IDOR, mass assignment, broken function level auth, excessive data exposure, SSRF, and shadow APIs.
Kubernetes security testing — pod enumeration, secrets access, RBAC abuse, privileged container escape, kubelet API exploitation, and etcd attacks.
Mobile application security testing — Android/iOS static analysis, ADB dynamic analysis, traffic interception, SSL pinning bypass, and Frida instrumentation.
Cloud security testing for AWS, GCP, and Azure — credential enumeration, privilege escalation paths, lateral movement, and service-specific attack techniques.
Docker container escape techniques — privileged container abuse, Docker socket exploitation, cgroup release agent escape, and capability-based escapes.
Complete nmap command reference for host discovery, port scanning, service enumeration, OS detection, NSE scripts, and IDS evasion.
Complete sqlmap reference for SQL injection enumeration, data extraction, file read/write, and OS shell access across all major databases.
Complete ffuf reference for directory fuzzing, parameter discovery, vhost enumeration, and filter tuning.
Complete gobuster reference for directory brute-forcing, DNS subdomain discovery, vhost enumeration, and fuzzing.
Complete hashcat reference for hash modes, attack types, mask characters, rule-based attacks, and optimization flags.
Complete hydra reference for brute-forcing SSH, FTP, HTTP forms, SMB, RDP, and other protocols.
Complete Metasploit reference for msfconsole, Meterpreter, session management, privilege escalation, and post-exploitation.
Burp Suite shortcuts, Repeater techniques, Intruder attack types, scanner tips, Match & Replace rules, and essential BApp extensions.
Complete chisel reference for TCP/SOCKS tunneling, reverse port forwarding, multi-hop pivoting, and firewall evasion.
Complete mimikatz reference for credential dumping, Pass-the-Hash, Pass-the-Ticket, Golden/Silver Tickets, and DCSync attacks.
Real, public XPath/XQuery injection techniques for authorized pentests, bug bounties, and CTFs — auth bypass, blind boolean extraction, error-based leaks, and out-of-band exfil.
Real, public LDAP injection techniques for authorized pentests, bug bounties, and CTFs — auth bypass, enumeration, blind extraction, filter manipulation, and encoding.
Copy-ready HTTP header payloads and techniques for finding and exploiting web cache poisoning and cache deception during authorized testing.
Copy-ready WebSocket attack payloads and PoCs for authorized testing: CSWSH, origin-check bypass, message/auth injection, and wscat/Burp tooling.
Real-world business logic abuse techniques for authorized pentests, bug bounties, and CTFs: price/quantity tampering, workflow bypass, coupon abuse, privilege assumptions, and race conditions.
Copy-ready Google search operators and dorks for authorized recon, plus equivalents for GitHub code search, Shodan, and Censys.
Copy-ready commands for discovering subdomains via passive sources, active brute force, permutations, probing, and takeover checks during authorized testing.
Minimal web shells, system() one-liners, upload filter bypasses, and post-upload command execution for authorized penetration testing and CTF engagements.
Copy-ready techniques for bypassing Content Security Policy during authorized pentests, bug-bounty, and CTF/OSCP engagements.
Copy-ready commands for OSCP-style stack buffer overflow exploitation: fuzzing, EIP offset, bad chars, JMP ESP, shellcode, and DEP/ROP.
Copy-ready commands and techniques for exploiting weak cryptography in web apps and CTFs during authorized testing.
Capture-time BPF filters vs post-capture display filters, essential filters for HTTP/DNS/TLS/TCP, credential and file extraction, and headless tshark/tcpdump/ngrep one-liners for authorized packet analysis.
A field-tested toolkit of copy-ready commands for solving CTF steganography challenges, from first-pass triage through image and audio extraction to passphrase recovery.
Copy-ready Bash one-liners for host discovery, file transfer, reverse shells, local enumeration, and data exfiltration during authorized pentests.
Copy-ready password spraying and credential stuffing commands for authorized pentests, with lockout-aware timing and scope guidance throughout.
Public, copy-ready DNS recon, SPF/DKIM/DMARC interpretation, authorized swaks spoof testing, and header analysis for authorized email security assessments.
Battle-tested regular expressions for finding secrets, scraping endpoints from source, spotting ReDoS, and recon with grep/ripgrep.
Passive and active reconnaissance recipes — domains, subdomains, people/email, code, and cloud — for authorized engagements.
Test session management for fixation, weak identifiers, cookie-scope flaws, cookie injection, and broken logout/invalidation.
Wireless auditing workflow for networks you own or are authorized to test — monitor mode, handshake/PMKID capture, and cracking.
DFIR and CTF forensics workflow — file/disk triage, memory analysis with Volatility3, network artifacts, and Windows evidence.
Binary RE workflow for CTF and malware triage — static analysis, disassemblers/decompilers, dynamic debugging, and patching.
Account takeover techniques: password reset poisoning, reset-token leakage and prediction, OAuth/SSO flaws, email/2FA-change abuse, and CSRF chains that bind an attacker to a victim's account.
Android application pentesting reference — APK decompilation with apktool and jadx, Frida runtime hooking, SSL/TLS pinning bypass, exported component and intent abuse, deep link / App Links testing, and Keystore inspection.
Azure and Entra ID (Azure AD) attack techniques — access/refresh token theft, managed identity abuse via IMDS, role and privilege escalation, AzureHound collection, illicit OAuth consent grants, and lateral movement from cloud to on-prem.
Path confusion, delimiter tricks, and static-extension abuse for finding and exploiting Web Cache Deception (WCD) during authorized testing — plus a full discovery-to-exploitation workflow.
CI/CD pipeline attack techniques: poisoned pipeline execution (PPE), GitHub Actions expression injection, secret exfiltration, self-hosted runner abuse, OIDC trust misconfiguration, and supply-chain dependency confusion.
Copy-ready clickjacking techniques for authorized pentests and bug bounty: detecting framing, frame-buster bypass, X-Frame-Options/CSP frame-ancestors testing, PoC overlays, drag-and-drop data theft, and mobile tapjacking.
Practical content discovery reference: ffuf and feroxbuster patterns, wordlist selection, recursion, extension fuzzing, backup/temp file hunting, and virtual host enumeration for finding hidden directories, files, and endpoints.
Audit and attack HTTP cookies: HttpOnly/Secure/SameSite flags, domain/path scoping, __Host-/__Secure- prefixes, session fixation, cookie injection & tossing, and jar overflow eviction.
Dependency confusion and software supply chain attacks — internal package squatting, scoped package abuse, install-script RCE, detection across npm/PyPI/Maven, and registry-level defenses.
Copy-ready dig, host, nslookup, and dnsrecon commands for querying DNS records, attempting zone transfers, brute-forcing subdomains, and reverse-resolving netblocks during authorized testing.
DOM clobbering payloads that overwrite JavaScript variables via id/name attributes — gadget chains, sanitizer bypass, and defenses for HTML-injection where scripts are blocked.
Expression Language injection payloads for Java EL, Struts OGNL, and Spring SpEL — detection, RCE, sandbox escape, and WAF bypass.
Google Cloud Platform attack techniques: metadata server SSRF, service account token theft and impersonation, IAM privilege escalation paths, Cloud Storage enumeration, and gcloud/curl post-exploitation. For authorized GCP penetration testing.
Find and exploit exposed .git directories with git-dumper, mine commit history for secrets, and hunt leaked credentials with GitHub dorking, gitleaks, and TruffleHog.
gRPC penetration testing reference: server reflection enumeration, grpcurl, protobuf message tampering, TLS/metadata auth testing, and fuzzing protobuf-encoded RPC endpoints.
CRLF and HTTP response-splitting injection: breaking out of header values to forge headers, set-cookie session fixation, host-header poisoning, and cache-poisoning vectors during authorized testing.
iOS application penetration testing — Frida and Objection instrumentation, SSL pinning bypass, Keychain and data-store dumping, jailbreak detection bypass, and IPA static analysis.
Kerberos attack techniques for Active Directory pentests — Kerberoasting, AS-REP roasting, Golden and Silver Tickets, delegation abuse (unconstrained, constrained, RBCD), and overpass-the-hash.
Log4Shell (CVE-2021-44228) and JNDI injection payloads: detection strings, lookup nesting for WAF bypass, LDAP/RMI/DNS callback setups, marshalsec + exploit servers, and affected version reference.
Techniques for bypassing multi-factor authentication: response manipulation, OTP brute-force, race conditions, backup-code abuse, remember-device flaws, and broken enrollment/recovery flows.
Find hidden HTTP parameters and mass-assignment fields with Arjun, Param Miner, x8, ffuf, and wordlist tactics — reflection, status, size, and word-count diffing to surface what the app forgot to document.
Network pivoting and tunneling reference: SSH local/remote/dynamic port forwarding, chisel, ligolo-ng, socat relays, proxychains, and SOCKS to reach segmented internal networks.
window.postMessage attack payloads and PoCs for authorized testing: missing origin checks, DOM XSS sinks in message handlers, listener discovery, and cross-window exploitation.
Techniques to bypass rate limiting and brute-force protections: IP-spoofing headers, casing and path mutation, parameter pollution, race-window concurrency, and account-lockout evasion for authorized pentests.
AWS S3 bucket enumeration and misconfiguration testing: name discovery and brute force, anonymous/authenticated listing, ACL and bucket-policy checks, public object access, write/upload abuse, and subdomain takeover of dangling S3 endpoints.
SAML authentication attack techniques covering XML signature wrapping (XSW), comment-injection canonicalization bugs, signature stripping, assertion tampering, IdP confusion, and recipient/audience validation flaws.
Hunt hardcoded credentials in source code and git history: detection regexes, gitleaks/trufflehog/noseyparker commands, Shannon entropy, cloud-key signatures, and the files where secrets actually leak.
SMB enumeration commands for null sessions, share hunting, and user/group discovery using smbclient, enum4linux-ng, rpcclient, nmap, and crackmapexec/netexec.
SNMP enumeration reference covering snmpwalk, community-string brute forcing, key MIB OIDs, snmp-check, and abusing writable communities to read and modify device configuration.
Server-Side Includes (SSI) injection payloads for command execution, file reading, environment disclosure, and detection across Apache, Nginx, and IIS.
Techniques to defeat SSRF allowlists and blocklists: IP encodings, DNS rebinding, open-redirect chaining, alternate URL schemes, and reaching cloud metadata behind broken filters.
Real, public XSLT injection techniques for authorized pentests, bug bounties, and CTFs — processor fingerprinting, file read, SSRF, and RCE via Java/PHP/.NET extension functions.