⚡ SheetCheater

Security cheatsheets for bug bounty hunters and pentesters. Copy-paste ready. No bullshit.

Subdomains & DNS

amass

Attack surface mapping and asset discovery. OWASP project.

APIs & JS

arjun

HTTP parameter discovery tool.

Subdomains & DNS

assetfinder

Fast subdomain discovery using passive sources. Simple and effective.

Other Injection

commix

Automated command injection exploitation tool.

XSS

dalfox

Fast XSS scanner and parameter analyzer. Go-based.

Fuzzing & Brute

dirsearch

Web path scanner with recursive brute forcing and smart features.

Subdomains & DNS

dnsrecon

DNS enumeration script with multiple techniques.

Subdomains & DNS

dnsx

Fast DNS toolkit for queries, resolution, and wildcard detection. ProjectDiscovery.

Infrastructure

Docker

Container runtime for packaging and running applications. Essential for pentest lab environments.

Fuzzing & Brute

feroxbuster

Fast recursive content discovery tool written in Rust.

Fuzzing & Brute

ffuf

Fast web fuzzer for content discovery, parameter fuzzing, and vhost enumeration. Use only on authorized targets.

Fuzzing & Brute

gobuster

Directory/file brute force and DNS/vhost enumeration tool.

Recon

Google Dorks

Advanced Google search operators for OSINT and reconnaissance. Always scope to authorized targets.

Credentials

Hashcat

GPU-accelerated password cracker for offline hash recovery. Use only on hashes you're authorized to test.

Web Recon

httpx

Fast HTTP prober for identifying live hosts, tech stack, and grabbing responses. ProjectDiscovery.

Credentials

Hydra

Fast network login cracker supporting 50+ protocols. Use only on authorized targets.

Vulnerability Scanning

interactsh

Out-of-band (OOB) interaction server for detecting blind vulnerabilities. ProjectDiscovery.

APIs & JS

jwt_tool

JWT (JSON Web Token) toolkit for testing and exploitation.

Web Recon

katana

Fast web crawler for collecting URLs and endpoints. ProjectDiscovery.

APIs & JS

linkfinder

JavaScript endpoint extractor.

Scanning

masscan

Internet-scale port scanner. Extremely fast.

Subdomains & DNS

massdns

High-performance DNS stub resolver for bulk lookups.

Windows

Meterpreter

Advanced Metasploit payload for post-exploitation. Use only on authorized targets.

Scanning

naabu

Fast port scanner with SYN/CONNECT scanning. ProjectDiscovery.

Active Directory

netexec

Network execution tool for pentesting (CrackMapExec successor).

Scanning

Nmap

Network scanner for host discovery, port scanning, service detection, and scripted enumeration. Use only on authorized targets.

Vulnerability Scanning

nuclei

Template-based vulnerability scanner. Fast, customizable, and community-driven. ProjectDiscovery.

Active Directory

responder

LLMNR/NBT-NS/mDNS poisoner for credential capture.

Scanning

rustscan

Fast port scanner that pipes to nmap for service detection.

APIs & JS

secretfinder

Find secrets (API keys, tokens) in JavaScript files.

Windows

smbclient

FTP-like client for SMB/CIFS shares. Use only on authorized targets.

Windows

smbmap

SMB share enumeration and access tool. Use only on authorized targets.

SQL Injection

sqlmap

Automatic SQL injection detection and exploitation tool.

Other Injection

ssrfmap

SSRF exploitation framework with modules.

Subdomains & DNS

subfinder

Fast subdomain discovery tool using passive sources. ProjectDiscovery.

Scanning

tshark

Terminal-based Wireshark for packet capture and analysis. Use only on authorized networks.

Web Recon

uncover

Search engine query tool for finding exposed assets. Shodan, Censys, Fofa, and more. ProjectDiscovery.

Web Recon

wafw00f

Web Application Firewall (WAF) detection tool.

Web Recon

whatweb

Web technology fingerprinting tool. Identifies CMS, frameworks, and server software.

XSS

xsstrike

Advanced XSS detection suite with fuzzing engine.