Skip to content

H3llKa1ser/B00t2R00t

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

5,058 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ₯Ύ B00t2R00t

A comprehensive offensive security knowledge base β€” from initial foothold to full domain compromise.

B00t2R00t is a curated encyclopedia of penetration testing and red teaming techniques, methodologies, tools, and ready-to-use scripts. Spanning Active Directory, Cloud, Web, Network, Wireless, and Red Team operations, it's organized around the real attacker kill chain: Enumerate β†’ Exploit β†’ Escalate β†’ Persist.

⚠️ Disclaimer: This material is provided strictly for authorized security testing, research, and education. Only use these techniques on systems you own or have explicit written permission to test. The author assumes no liability for misuse. Unauthorized access to computer systems is illegal.

Focus Files Topics PRs


🧭 How to Use This Repo

  • New to a target type? Start in Methodology/ β€” it's the high-level playbook for what to do and in what order.
  • Need a specific technique? Jump straight to the relevant domain folder below.
  • Looking for a tool's syntax? Head to Tools/ β€” usage docs are separated from techniques on purpose.
  • On an engagement? Use the methodology as your checklist, then drill into the technique pages as needed.

πŸ“š Table of Contents

Section What's Inside
πŸ—ΊοΈ Methodology Step-by-step playbooks for each target type
🏰 Active Directory Enumeration, exploitation, Kerberos, ADCS, trusts, persistence
☁️ Cloud AWS, Azure, GCP, Kubernetes
🌐 Web Applications OWASP-style attacks, injection, auth bypasses, WAF evasion
πŸ”Œ Network Services Protocol-by-protocol attack references
πŸ“‘ Wireless WEP/WPA/WPS attacks, sniffing, MITM
🎭 Red Teaming Evasion, C2, payloads, phishing, exfiltration
⬆️ Privilege Escalation Linux, Windows, and Docker escapes
πŸ”€ Pivoting Tunneling, port forwarding, lateral movement
πŸ› CVEs Notable exploits and write-ups
πŸ€– AI Pentesting Prompt injection, jailbreaks, model attacks
πŸ› οΈ Tools Usage docs for the offensive toolkit
🧩 Miscellaneous File transfers, shells, wordlists, neat tricks

πŸ—ΊοΈ Methodology

The playbook layer β€” start here to understand the flow of an engagement before diving into specific techniques.


🏰 Active Directory Penetration Testing

The most extensive section β€” a complete AD attack lifecycle.

Phase Topics
Enumeration No Credentials Β· Valid Credentials Β· Username Only
Exploitation Kerberos Β· GPO Β· Known Vulns Β· ACL/ACE
ADCS Certificate Services attacks β€” ESC1–ESC10, theft, persistence, mindmaps
Kerberos Delegation Unconstrained / Constrained / RBCD
Lateral Movement PtH, PtT, Pass-the-Cert, WinRM, WMI, more
MITM & Relay NTLM Relay, Responder, coercion attacks
Privilege Escalation DACL attacks, dangerous groups, LAPS, more
Persistence Golden/Silver/Diamond tickets, DCShadow, Skeleton Key, more
Trust Relationships Cross-domain & cross-forest compromise
Domain Admin Access NTDS dumping, DPAPI backup keys
Mitigations Defensive guidance & Event IDs

☁️ Cloud Penetration Testing

Provider-by-provider attack references, each following enum β†’ exploit β†’ privesc β†’ persistence.

  • AWS β€” IAM, EC2, S3, Lambda, EKS, RDS, Secrets Manager, and more
  • Azure β€” Entra ID, managed identities, Key Vaults, app services, abuse paths
  • Google Cloud (GCP) β€” IAM fuzzing, metadata SSRF, privilege escalation
  • Kubernetes β€” cluster recon, node escapes, secrets
  • Cross-Platform β€” Cloudfox, Trufflehog, and multi-cloud tooling

🌐 Web Application Penetration Testing

Comprehensive coverage of web attacks:


πŸ”Œ Network Penetration Testing

A protocol-by-protocol attack library covering: SMB, LDAP, SSH, FTP, RDP, SNMP, SMTP, MSSQL, MySQL, PostgreSQL, MongoDB, Redis, NFS, RPC, IPMI, VNC, VoIP, Java RMI/JDWP, gRPC, WebDAV, and more β€” plus CI/CD tooling and database navigation.


πŸ“‘ Wireless Penetration Testing

Full wireless attack coverage: WEP cracking, WPA2-PSK, PMKID, WPS PIN/Pixie Dust, deauth & fake-auth, packet injection/sniffing, MITM, DNS spoofing, and traffic decryption.


🎭 Red Teaming

End-to-end adversary simulation tradecraft:


⬆️ Privilege Escalation

  • Linux β€” SUID, capabilities, cron, kernel exploits, sudo abuse, and dozens more
  • Windows β€” service misconfigs, potato exploits, DLL hijacking, token abuse, UAC bypass
  • Docker Escapes β€” privileged containers, exposed daemons, namespace abuse

πŸ”€ Pivoting

Tunneling and lateral movement: Chisel, Ligolo-ng, SSH tunneling, Proxychains, DNS/HTTP/ICMP tunneling, double pivots, and ready-to-go scripts.


πŸ› CVEs

Curated exploit write-ups: Zerologon, noPAC, PrintNightmare, ProxyShell, Certifried, PetitPotam, Log4j, and more.


πŸ€– Other Domains


πŸ› οΈ Tools

Usage references for the offensive toolkit, grouped by purpose:


🧩 Miscellaneous

Handy operational references: file transfer methods (Linux & Windows), reverse shells, shell stabilization, credential harvesting, wordlist creation, and a big bag of neat tricks.


🀝 Contributing

Contributions, corrections, and additions are welcome! Feel free to open an issue or submit a pull request.

πŸ“„ License

See LICENSE.md for details.


⭐ If you find this useful, consider starring the repo! ⭐

Built and maintained by H3llKa1ser

For educational and authorized testing purposes only.

About

A penetration testing Swiss Army Knife that's suitable for CTF challenges, bug bounty hunting and red team assessments.

Topics

Resources

Stars

Watchers

Forks

Releases

Packages

Used by

Contributors

Languages