contentintech

Ethical Hacking Cheatsheet

Quick reference for authorized pentesting — the kill chain phases, lab-safe recon commands, and reporting structure.

PentestingReconCTFMethodology
NotesCheatsheet

Cyber Kill Chain Phases

PhaseAttacker goalDefense
ReconnaissanceCollect target info (OSINT)Reduce exposure, ASM
Scanning / EnumFind hosts, ports, versionsFirewall, IDS/IPS, segmentation
Gaining AccessExploit for a footholdPatch, input validation, least priv
Maintaining AccessPersistenceEDR, integrity monitoring
Covering TracksErase evidenceImmutable/central logging, SIEM

Recon & OSINT Tools (Lab / Authorized)

ToolUse
whois / digRegistration & DNS records
amass / subfinderSubdomain enumeration
crt.shCertificate transparency logs
theHarvesterEmails, hosts, names from public sources
Shodan / CensysInternet-exposed service search
whatwebWeb tech fingerprinting

nmap Flags

FlagMeaning
-snPing/host discovery only, no port scan
-sSTCP SYN scan (needs root)
-sVService/version detection
-sCRun default NSE scripts
-p- / -p 80,443All ports / specific ports
-AOS detect + version + scripts + traceroute
-T0..-T5Timing (T4 fast, T5 aggressive)
-oA baseOutput all formats (nmap/gnmap/xml)

Common Enumeration Commands

Web / SMB / DNS

# Web content / directories
gobuster dir -u http://target -w /usr/share/wordlists/dirb/common.txt
ffuf -u http://target/FUZZ -w wordlist.txt

# SMB enumeration
enum4linux-ng -A target
smbclient -L //target -N

# DNS
dig any target.local @dns-server
dnsrecon -d target.local

# Web tech + headers
whatweb http://target
curl -sI http://target

CVSS 3.1 Severity Bands

ScoreSeverity
0.0None
0.1 – 3.9Low
4.0 – 6.9Medium
7.0 – 8.9High
9.0 – 10.0Critical

Report Finding Template

Title:        <concise vulnerability name + location>
Severity:     <Critical/High/Med/Low> (CVSS x.x + vector)
Affected:     <URL / host / component>
Summary:      <what & why it matters, 1-2 lines>
Reproduction: 1. step  2. step  3. observed result
Impact:       <business consequence if exploited>
Remediation:  <concrete fix + defense in depth>
References:   <CWE / OWASP / CVE>

Legal / Authorization Checklist

  1. Signed authorization letter from an owner/authority.
  2. Written scope: in-scope and out-of-scope assets.
  3. Rules of engagement: techniques, test window, rate limits.
  4. Emergency contact and stop procedure agreed.
  5. Data-handling and confidentiality terms in place.
  6. For bounties: read and follow the program policy exactly.
  7. Never touch out-of-scope systems — ask first, in writing.

Legal Practice Platforms

PlatformBest for
TryHackMeGuided beginner-to-intermediate rooms
Hack The BoxRealistic boxes & pro labs
OWASP Juice ShopDeliberately vulnerable web app
VulnHubDownloadable vulnerable VMs
PortSwigger Web Security AcademyFree web vuln labs (XSS, SQLi, etc.)
picoCTFBeginner-friendly CTF challenges

Section navigation