惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
Last Week in AI
Last Week in AI
腾讯CDC
The Cloudflare Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
MyScale Blog
MyScale Blog
博客园 - Franky
MongoDB | Blog
MongoDB | Blog
I
InfoQ
雷峰网
雷峰网
人人都是产品经理
人人都是产品经理
Blog — PlanetScale
Blog — PlanetScale
Y
Y Combinator Blog
H
Help Net Security
T
Tailwind CSS Blog
美团技术团队
aimingoo的专栏
aimingoo的专栏
博客园 - 三生石上(FineUI控件)
云风的 BLOG
云风的 BLOG
Google DeepMind News
Google DeepMind News
P
Proofpoint News Feed

Black Hills Information Security, Inc.

Bad Habits: An ANTISOC Operation Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other How to Identify and Exploit New Vulnerabilities Swapper – A Pure Regex Match/Replace Burp Extension A Practical Guide to BloodHound Data Collection Network Engineering Basics Signed, Trusted, and Abused: Proxy Execution via WebView2 Getting Started In Pentesting – Advice From The BHIS Pentest Lead Cloud Security: Tips and Resources for Securing the Cloud Lessons From A Chatbot Incident How to Lead Effective Tabletops Understanding GRC: How to Navigate Risks and Compliance Standards The “P” in PAM is for Persistence: Linux Persistence Technique Malware Analysis: How to Analyze and Understand Malware OSINT: How to Find, Use, and Control Open-Source Intelligence What to Do with Your First Home Lab When the SOC Goes to Deadwood: A Night to Remember Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions Common Cyber Threats Finding the Right Penetration Testing Company Deceptive-Auditing: An Active Directory Honeypots Tool The Curious Case of the Comburglar How to Set Smart Goals (That Actually Work For You) Inside the BHIS SOC: A Conversation with Hayden Covington Abusing Delegation with Impacket (Part 3): Resource-Based Constrained Delegation Why You Got Hacked – 2025 Super Edition Abusing Delegation with Impacket (Part 2): Constrained Delegation Abusing Delegation with Impacket (Part 1): Unconstrained Delegation GoSpoof – Turning Attacks into Intel Model Context Protocol (MCP)
Offensive Tooling Cheatsheets: An Infosec Survival Guide ...
BHIS · 2025-08-06 · via Black Hills Information Security, Inc.

, , , , ,

Skip to the cheatsheets!

How and Why This Was Made

The Infosec Survival Guide continues to be an experiment. The first edition resulted in more of an explanation of our services and how they were helpful. The second edition—now known as the “Yellow Book”—was our attempt to create something with more direct value for readers. That direction continued with the “Green Book,” which covered a range of varying topics to help infosec professionals get started, learn more, and find reliable jumping-off points into new areas. It wasn’t meant to be exhaustive, but to offer foundational knowledge and point toward helpful resources.

As always, the goal of the Guide is rooted in a collaboration between BHIS and YOU, our amazing, active community. The cheatsheets you’ll find throughout this resource were written largely by volunteers who generously offered their time and knowledge to help us provide free, useful resources to others in the field.

When we started the “Offensive Tooling Cheatsheet Edition,” the plan was to produce another fully published, printed book. It was a new kind of experiment for the Content & Community team. Up to that point, we hadn’t spent much time in the cheatsheet space; we were far more comfortable with articles and long-form written content. Cheatsheets were a different beast entirely. They brought new challenges. Where grammatical edits and sentence restructuring all fell into our ballpark, lines of code and the functions of digital tools were a bit beyond us. We were constantly asking: “Is this good?” “Is this accurate?” “Did this code block transfer correctly?” “Is that floating period a typo?” (It wasn’t .)

It’s worth noting: we’re the ‘creativity’ department. While some on the team have a working knowledge of the more technical aspects, many of us aren’t so hands-on in cybersecurity. So for this edition, we leaned on our internal Security Analysts more than ever. Every cheatsheet went through careful technical peer review to ensure we were publishing accurate, high-quality content. While we usually focus on grammar, tone, and structure, this time we were also double- and triple-checking syntax, command formatting, and how things held up in design.

As the project evolved, we realized this version wasn’t destined to be a printed book. We needed the flexibility to keep updating as tools and technologies shift (as we all know they rapidly do). A digital format made more sense, giving folks the ability to freely access, print, and use each cheatsheet as needed.

So this edition became something different: An Infosec Survival Guide Resource released as blog posts, with fully designed, printer-friendly PDF cheatsheets.

The Cheatsheets

Here, you’ll find a fully designed, printer-friendly compiled PDF of all the cheatsheets:

If you prefer an online blog-version, or want individual cheatsheet PDFs, access them here:

Thank you for sticking with us. Thank you for choosing to help others. Thank you for allowing us to build cool stuff like this. We couldn’t do this without you.



Explore the Infosec Survival Guide and more… for FREE!

Get instant access to all issues of the Infosec Survival Guide, as well as content like our self-published infosec zine, PROMPT#, and exclusive Darknet Diaries comics—all available at no cost.

You can check out all current and upcoming issues here: https://www.blackhillsinfosec.com/prompt-zine/