# Hack Project — Directory Conventions > Red team / offensive security workspace. Last updated: 2026-07-26 --- ## Directory Map ``` Hack/ ├── targets/ # Target data and scope definitions │ ├── recon/ # Reconnaissance output per target (whois, DNS, OSINT) │ └── scope/ # Scope of Work, Rules of Engagement, IP/domain lists │ ├── exploits/ # Exploit code and proof-of-concepts │ ├── custom/ # Hand-written exploits (your own work) │ └── public/ # Modified public exploits / EDB mirrors │ ├── payloads/ # Generated payloads and shellcode │ ├── shellcode/ # Raw shellcode blobs (.bin, .hex) │ └── generated/ # MSFvenom, sliver, donut outputs, staged payloads │ ├── tools/ # Custom tooling and automation │ ├── scripts/ # One-off scripts and automation (Python, PS, Bash) │ └── modules/ # Reusable modules / libraries shared across scripts │ ├── wordlists/ # Dictionaries for brute-forcing and fuzzing │ ├── custom/ # Target-specific generated lists │ └── curated/ # SecLists, rockyou, etc. │ ├── scans/ # Raw scan output (RESULTS) │ ├── nmap/ # Nmap XML/gnmap output │ ├── web/ # Web scans (ffuf, nikto, nuclei, gobuster) │ └── host/ # Host-level scans (nessus, openvas, bloodhound) │ ├── loot/ # Captured data from successful ops (RESULTS — SENSITIVE) │ ├── credentials/ # Plaintext creds, tokens, tickets │ ├── hashes/ # NTLM, Kerberos, SHA, etc. │ └── files/ # Exfiltrated or downloaded files │ ├── evidence/ # Artifacts for reporting (RESULTS) │ ├── screenshots/ # Visual proof of exploitation │ └── poc/ # Recorded PoC artifacts, command transcripts │ ├── reports/ # Deliverables (RESULTS) │ ├── templates/ # Report templates (markdown, docx, pptx) │ └── final/ # Finished reports for the engagement │ ├── notes/ # Working notes, attack trees, mind maps ├── logs/ # Activity logs, command history, tool output ├── config/ # Tool configs, environment files, proxy settings ├── temp/ # Scratch space — throwaway files (gitignored) ├── test/ # Test scripts and test cases for custom tooling ├── lib/ # Shared libraries and dependencies └── Prompt/ # (Pre-existing) Prompt engineering files ``` --- ## Directory Categories | Category | Directories | Description | |---|---|---| | **Working** | `targets/`, `exploits/`, `payloads/`, `tools/`, `wordlists/`, `config/`, `lib/`, `notes/` | Active workspace — files you create and edit during an engagement | | **Results** | `scans/`, `loot/`, `evidence/`, `reports/` | Output and deliverables — generated data, captured artifacts, final reports | | **Temporary** | `temp/`, `logs/` | Scratch and transient data — safe to wipe between operations | | **Test** | `test/` | Test scripts and validation cases for custom tools and exploits | | **Sensitive** | `loot/`, `config/` | Credentials, hashes, secrets — **never commit to git** | --- ## Naming Conventions ### Files - **Scan outputs:** `__.` — e.g. `10.10.10.5_nmap_20260726.xml` - **Recon data:** `_recon_.` — e.g. `acme.com_recon_20260726.txt` - **Exploits:** `_.` — e.g. `CVE-2024-3094_xz.py` - **Loot:** `__.` — e.g. `DC01_hashes_20260726.txt` - **Reports:** `__.` — e.g. `acme_pen-test_20260726.md` - **Logs:** `_.log` — e.g. `nmap_20260726.log` ### Dates - All dates in filenames use `YYYYMMDD` format (no separators) - Timestamps in content use ISO 8601: `2026-07-26T14:30:00Z` ### Targets - IP addresses: use as-is (`10.10.10.5`) - Domains: use bare domain (`acme.com`), not FQDN with subdomain unless scoped - Internal names: use hostname only (`DC01`, not `DC01.acme.local`) --- ## Workflow 1. **Scope** → Drop RoE and target lists into `targets/scope/` 2. **Recon** → Run recon, output goes to `targets/recon/` 3. **Scanning** → Nmap/web/host scans output to respective `scans/` subdirs 4. **Exploitation** → Write exploits in `exploits/custom/`, generate payloads in `payloads/` 5. **Collection** → Captured creds/hashes/files go to `loot/` subdirs 6. **Evidence** → Screenshots and PoC transcripts to `evidence/` 7. **Reporting** → Use templates from `reports/templates/`, final output to `reports/final/` 8. **Cleanup** → Wipe `temp/` between engagements. Review `logs/` before archiving. --- ## Git Policy - **Tracked:** `tools/`, `exploits/custom/`, `wordlists/custom/`, `lib/`, `test/`, `reports/templates/`, `config/` (non-sensitive configs only) - **Ignored:** `temp/`, `loot/`, `logs/`, `scans/`, `evidence/`, `payloads/generated/`, `config/*.env`, `config/*secret*` - **Never committed:** credentials, hashes, exfiltrated files, private keys, engagement-specific reports See `.gitignore` for the full ignore list.