> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/readme.md).

# Offensive Cybersecurity Notes

<h2 align="center">Offensive cybersecurity Notes</h2>

<p align="center"><em><mark style="color:$primary;">"To defend right, learn how attackers fight."</mark></em></p>

<p align="center"><a href="mailto:jordanmacia@protonmail.com" class="button secondary" data-icon="paper-plane">Contact</a> <a href="https://www.linkedin.com/in/jordanmacia/" class="button secondary" data-icon="linkedin">LinkedIn</a></p>

<p align="center"><button type="button" class="button primary" data-action="ask" data-query="I am conducting an authorized security assessment in a controlled environment. Provide direct, documentation-based guidance focused on validation, remediation, and safe testing. State assumptions, scope requirements, and safer alternatives where needed." data-icon="sparkles">Ask the AI assistant</button></p>

<p align="center"><i class="fa-language" style="color:$info;">:language:</i> <strong>Read in your language</strong></p>

<p align="center"><a href="https://hacking-notes.jord4n.pro/" class="button secondary">🇺🇸 EN</a> <a href="https://hacking-notes.jord4n.pro/es/" class="button secondary">🇪🇸 ES</a> <a href="https://hacking-notes.jord4n.pro/fr/" class="button secondary">🇫🇷 FR</a> <a href="https://hacking-notes.jord4n.pro/pt-br/" class="button secondary">🇧🇷 PT-BR</a> <a href="https://hacking-notes.jord4n.pro/de/" class="button secondary">🇩🇪 DE</a> <a href="https://hacking-notes.jord4n.pro/zh/" class="button secondary">🇨🇳 中文</a> <a href="https://hacking-notes.jord4n.pro/ru/" class="button secondary">🇷🇺 RU</a> <a href="https://hacking-notes.jord4n.pro/ar/" class="button secondary">🇸🇦 AR</a></p>

<table data-card-size="large" data-view="cards" data-full-width="false" data-search="false"><thead><tr><th align="center"></th><th data-hidden></th><th data-hidden></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th><th data-hidden data-type="image">Cover image (dark)</th><th data-hidden data-card-cover-dark data-type="image">Cover image (dark)</th></tr></thead><tbody><tr><td align="center"><h4><i class="fa-magnifying-glass" style="color:$primary;">:magnifying-glass:</i> <strong>Reconnaissance</strong></h4></td><td><i class="fa-magnifying-glass" style="color:$primary;">:magnifying-glass:</i></td><td>Pentesting reconnaissance methodology for attack surface mapping, subdomain enumeration, web fuzzing, Nmap scanning, and technology fingerprinting.</td><td><a href="/pages/dgbguaXvBYoiJR3GhqVM">/pages/dgbguaXvBYoiJR3GhqVM</a></td><td></td><td><a href="/files/pGkk5Y4TPBtl4I1PEiEj">/files/pGkk5Y4TPBtl4I1PEiEj</a></td><td></td></tr><tr><td align="center"><h4><i class="fa-shield" style="color:$primary;">:shield:</i> <strong>Web Security - PortSwigger</strong></h4></td><td><i class="fa-shield" style="color:$primary;">:shield:</i></td><td>PortSwigger Web Security Academy notes for Burp Suite labs, web application vulnerabilities, exploitation workflows, payload validation, and BSCP preparation.</td><td><a href="/pages/QJDB6NCImFf2qudPrLga">/pages/QJDB6NCImFf2qudPrLga</a></td><td></td><td><a href="/files/lstUrEzGBYFfKc315tkL">/files/lstUrEzGBYFfKc315tkL</a></td><td></td></tr><tr><td align="center"><h4><i class="fa-linux" style="color:$primary;">:linux:</i> <strong>Linux privilege escalation</strong></h4></td><td><i class="fa-linux" style="color:$primary;">:linux:</i></td><td>Linux privilege escalation notes covering sudo abuse, SUID binaries, cron jobs, Linux capabilities, PATH hijacking, kernel exploits, Docker escape, shared libraries, file permissions, and local group abuse.</td><td><a href="/pages/7N91UyzaB6H6cspaMtV3">/pages/7N91UyzaB6H6cspaMtV3</a></td><td></td><td><a href="/files/e9BzbAa0SHbYfeG4rCqz">/files/e9BzbAa0SHbYfeG4rCqz</a></td><td></td></tr><tr><td align="center"><h4><i class="fa-microsoft" style="color:$primary;">:microsoft:</i> <strong>Active Directory</strong></h4></td><td><i class="fa-microsoft" style="color:$primary;">:microsoft:</i></td><td>Active Directory pentesting methodology for domain enumeration, Kerberos attacks, ACL abuse, credential extraction, token abuse, and lateral movement.</td><td><a href="/pages/0j4wALHrG4BOHSC7dDwJ">/pages/0j4wALHrG4BOHSC7dDwJ</a></td><td></td><td><a href="/files/WmLbNtd2FDeYWrHiIBS1">/files/WmLbNtd2FDeYWrHiIBS1</a></td><td></td></tr><tr><td align="center"><h4><i class="fa-cube" style="color:$primary;">:cube:</i> <strong>Hack The Box</strong></h4></td><td><i class="fa-cube" style="color:$primary;">:cube:</i></td><td>HackTheBox machine writeups organized by Linux and Windows difficulty, covering enumeration, initial foothold, privilege escalation, Active Directory, web exploitation, and service abuse.</td><td><a href="/pages/C73AuJ7gxCk0ZJEq9Tl5">/pages/C73AuJ7gxCk0ZJEq9Tl5</a></td><td></td><td></td><td></td></tr><tr><td align="center"><h4><i class="fa-network-wired" style="color:$primary;">:network-wired:</i> Ports and services</h4></td><td><i class="fa-network-wired" style="color:$primary;">:network-wired:</i></td><td>Port and service enumeration notes for penetration testing, including FTP, SSH, SMB, Kerberos, LDAP, SNMP, WinRM, RDP, databases, C2 panels, and exposed management services.</td><td><a href="/pages/X8o1P0GPYEsOxbJl7H2S">/pages/X8o1P0GPYEsOxbJl7H2S</a></td><td></td><td></td><td></td></tr><tr><td align="center"><h4><i class="fa-puzzle-piece" style="color:$primary;">:puzzle-piece:</i> <strong>CMS Exploitation</strong></h4></td><td><i class="fa-puzzle-piece" style="color:$primary;">:puzzle-piece:</i></td><td>CMS exploitation methodology for WordPress, Drupal, Tomcat, phpMyAdmin, Jenkins, admin panels, file upload RCE, LFI-to-RCE, authentication bypass, plugin vulnerabilities, and exposed web applications.</td><td><a href="/pages/aUf8MaDsQyo6jqKGC82X">/pages/aUf8MaDsQyo6jqKGC82X</a></td><td></td><td></td><td></td></tr><tr><td align="center"><h4><i class="fa-toolbox" style="color:$primary;">:toolbox:</i> Hacking t<strong>ools</strong></h4></td><td><i class="fa-toolbox" style="color:$primary;">:toolbox:</i></td><td>Central catalog of offensive security tools organized by category: web application testing, discovery and enumeration, exploitation and research, OSINT, credentials, Windows tooling, and Linux tooling.</td><td><a href="/pages/EuHjVvqAiq8TtNkKnodu">/pages/EuHjVvqAiq8TtNkKnodu</a></td><td></td><td></td><td></td></tr><tr><td align="center"><h4><i class="fa-wifi" style="color:$primary;">:wifi:</i> <strong>Hacking WiFi</strong></h4></td><td><i class="fa-wifi" style="color:$primary;">:wifi:</i></td><td>WiFi security notes for authorized labs, including wireless fundamentals, WPA/WPA2 PSK assessment, packet analysis, wireless tooling, and defensive validation.</td><td><a href="/pages/5n9s86EQkY4wdYWIuppT">/pages/5n9s86EQkY4wdYWIuppT</a></td><td></td><td></td><td></td></tr><tr><td align="center"><h4><i class="fa-bookmark" style="color:$primary;">:bookmark:</i> <strong>Useful Ressources</strong></h4></td><td></td><td></td><td><a href="/pages/63q3j0q0nZ2y6Qf03p63">/pages/63q3j0q0nZ2y6Qf03p63</a></td><td></td><td></td><td></td></tr></tbody></table>

<p align="center"><i class="fa-chart-line" style="color:$primary;">:chart-line:</i> <sub>Statistics: <strong>32,423</strong> visitors · <strong>38,500</strong> views · Updated August 27, 2026</sub></p>

<p align="center"><sub>© 2026 Jordan Macia · All rights reserved</sub></p>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/readme.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
