contentintech

Security Tools Cheatsheet

Quick reference for security tools — nmap flags, Wireshark filters, and common command-line invocations for lab use.

NmapWiresharkBurpSIEM
NotesCheatsheet

Tools by Category

Use every tool below only against systems you own or are authorized to test (labs, CTFs, intentionally vulnerable targets).

ToolCategoryTypical Use
nmapRecon/scanHost discovery, port/service/version detection
masscanRecon/scanFast large-range open-port sweep
Burp SuiteWeb proxyIntercept, spider, repeat, fuzz HTTP
OWASP ZAPWeb proxyFree intercepting proxy + scanner
WiresharkPacket analysisGUI protocol dissection of captures
tcpdumpPacket analysisCLI capture on servers/headless hosts
Nessus / OpenVASVuln scannerFull network vulnerability assessment
nucleiVuln scannerTemplate-based, transparent checks
MetasploitExploitationValidate vulns in labs (Metasploitable)
hashcat / johnPassword auditAudit strength of your OWN hashes
ffuf / gobusterContent discoveryDirectory/file/vhost brute-force

Nmap Flags

FlagMeaning
-snPing/host discovery only, no port scan
-sSTCP SYN (stealth) scan
-sUUDP scan
-sVService/version detection
-sCRun default NSE scripts
-OOS detection
-p-All 65535 ports
-T4Timing template (faster)
-oAOutput all formats (base name)

Packet Filters

tcpdump Capture Filters

tcp port 80              # HTTP only
host 192.168.56.101      # to/from one host
src net 10.0.0.0/8       # from a subnet
tcp[tcpflags] & tcp-syn != 0   # SYN packets
-w out.pcap              # write to file
-nn                      # no name/port resolution

Wireshark Display Filters

ip.addr == 192.168.56.101
tcp.flags.syn == 1 && tcp.flags.ack == 0   # handshake start
tcp.analysis.retransmission
http.request.method == "POST"
tls.handshake.type == 1                    # ClientHello
dns.qry.name contains "example"

Web Proxies & Discovery

Burp / ZAP Quick Actions

ActionBurpZAP
Toggle interceptProxy > InterceptBreak toolbar
Crawl/spiderDashboard scanSpider / AJAX Spider
Replay requestRepeater (Ctrl+R)Manual Request Editor
Fuzz paramsIntruderFuzzer

ffuf / gobuster (Own Lab)

ffuf -w list.txt -u http://localhost:3000/FUZZ
ffuf -w list.txt -u http://TARGET/ -H "Host: FUZZ.lab"   # vhost
gobuster dir -u http://localhost:3000 -w list.txt -x php,txt
gobuster dns -d lab.local -w subs.txt

Password Auditing (Your Own Hashes)

# hashcat mode examples (-m): 0=MD5  100=SHA1  1400=SHA256  3200=bcrypt  1800=sha512crypt
hashcat -m 3200 my_hashes.txt rockyou.txt
hashcat -m 0 my_hashes.txt -a 3 ?l?l?l?l?d?d      # mask/brute
hashcat -m 3200 my_hashes.txt --show             # show cracked

# John the Ripper
john --wordlist=rockyou.txt my_hashes.txt
john --format=bcrypt my_hashes.txt
john --show my_hashes.txt

Blue-Team Tooling

ToolRoleNotes
Splunk / ELK / WazuhSIEMLog aggregation + correlation alerts
Suricata / SnortIDS/IPSSignature-based network detection/block
EDR agentsEndpointProcess/file/network behavior on hosts
osqueryEndpoint visibilitySQL queries over live OS state
Kali / ParrotDistroPreloaded toolkit; keep on isolated network

Section navigation