A living offensive-security reference: 450+ cross-linked technique pages, payload arsenals, tool references, and cheatsheets. Built in Obsidian and indexed for semantic search, so hunt skills consult it before attacking.
Pages cross-link with Obsidian [[wikilinks]] and a graph map-of-content, clickable inside
Obsidian. On GitHub, browse via the directory links below.
| Domain | Pages | Domain | Pages |
|---|---|---|---|
| Active Directory | 102 | Cloud | 51 |
| Web | 67 | Exploit Dev | 18 |
| Network | 17 | Red Team | 15 |
| macOS | 10 | Methodology | 10 |
| OSINT | 7 | Cracking | 6 |
| Linux | 6 | Mobile / IoT | 5 |
| Forensics | 2 | Blockchain | 1 |
- Payloads - per-vulnerability-class payload sets (SQLi, XSS, SSRF, SSTI, XXE, IDOR, deserialization, and more)
- Tools - per-tool references (nmap, ffuf, nuclei, httpx, sqlmap, BloodHound, netexec, ...)
- Cheatsheets - quick-reference command sheets and default-credential tables
HackTricks methodology ingest (synthesized and attributed, sources: hacktricks-*):
- New macOS area (TCC, Gatekeeper, code-signing, sandbox escape, SIP, dylib injection, keychain, persistence, MDM)
- Deeper Exploit Dev (format-string, ROP, ARM64, malware-analysis, heap)
- Linux privesc plus new D-Bus and container/Kubernetes escape pages
- Android / iOS enrichment, and new Blockchain / Web3 and physical-attacks pages
2026 CVE research (from public forks; single-source, verify against vendor advisories):
- Linux kernel rootkits (LKM / ftrace-hooking) - modern 6.x LKM stealth and detection
- Drupal JSON:API PostgreSQL SQLi (CVE-2026-9082) in SQL Injection
- 2026 kernel LPEs (futex requeue-PI, netfilter IDLETIMER, IPv6 RPL SRH, pidfd FD-theft) in Kernel Exploitation
- WS2025 local NTLM reflection to SYSTEM (CVE-2026-24294) in Internal NTLM Relay
- Chrome / Firefox renderer RCE plus all the above in the CVE Arsenal
MIT, see ../LICENSE.