// Home // Blog // Cheatsheets // Contact

Pentest Cheatsheets

Hands-on reference guides for authorized penetration testing. Full commands, tool coverage, MITRE ATT&CK mapping, and OPSEC notes for each environment. Built for real engagements.

Azure AD Active Directory Red Team Cloud Web
Available Now
☁️
Azure AD / Entra ID
Apr 2026 · 12 sections · Maintained

Complete Azure AD penetration testing guide — tenant recon, password spraying, device code phishing, token attacks (PRT / FOCI), privilege escalation via RBAC and app permissions, hybrid AD pivots, persistence, and exfiltration via Graph API.

Recon Initial Access Token Attacks PrivEsc Persistence Exfiltration
AADInternals ROADtools AzureHound GraphSpy Evilginx2
View cheatsheet →
Coming Soon
🏛️
Active Directory
On-premises AD attacks

Kerberoasting, AS-REP roasting, BloodHound analysis, DACL abuse, DCSync, Pass-the-Hash, Pass-the-Ticket, ACL attacks, and domain persistence techniques.

Coming Soon
🌐
Web Application
OWASP-aligned testing guide

SQL injection, XSS, SSRF, XXE, IDOR, authentication bypass, API security testing, JWT attacks, OAuth abuse, and business logic flaws with full payloads.

Coming Soon
🐧
Linux Privilege Escalation
Local PrivEsc reference

SUID/GUID, sudo misconfigs, cron jobs, capabilities, NFS, weak file permissions, kernel exploits, container escapes, and service exploitation.

Coming Soon
🪟
Windows Privilege Escalation
Local PrivEsc reference

AlwaysInstallElevated, unquoted service paths, DLL hijacking, token impersonation, SeImpersonatePrivilege, registry abuse, and UAC bypass techniques.

Coming Soon