Files
hack/README.md

5.3 KiB

Hack Project — Directory Conventions

Red team / offensive security workspace. Last updated: 2026-07-26


Directory Map

Hack/
├── targets/              # Target data and scope definitions
│   ├── recon/            # Reconnaissance output per target (whois, DNS, OSINT)
│   └── scope/            # Scope of Work, Rules of Engagement, IP/domain lists
│
├── exploits/             # Exploit code and proof-of-concepts
│   ├── custom/           # Hand-written exploits (your own work)
│   └── public/           # Modified public exploits / EDB mirrors
│
├── payloads/             # Generated payloads and shellcode
│   ├── shellcode/        # Raw shellcode blobs (.bin, .hex)
│   └── generated/        # MSFvenom, sliver, donut outputs, staged payloads
│
├── tools/                # Custom tooling and automation
│   ├── scripts/          # One-off scripts and automation (Python, PS, Bash)
│   └── modules/          # Reusable modules / libraries shared across scripts
│
├── wordlists/            # Dictionaries for brute-forcing and fuzzing
│   ├── custom/           # Target-specific generated lists
│   └── curated/          # SecLists, rockyou, etc.
│
├── scans/                # Raw scan output (RESULTS)
│   ├── nmap/             # Nmap XML/gnmap output
│   ├── web/              # Web scans (ffuf, nikto, nuclei, gobuster)
│   └── host/             # Host-level scans (nessus, openvas, bloodhound)
│
├── loot/                 # Captured data from successful ops (RESULTS — SENSITIVE)
│   ├── credentials/      # Plaintext creds, tokens, tickets
│   ├── hashes/           # NTLM, Kerberos, SHA, etc.
│   └── files/            # Exfiltrated or downloaded files
│
├── evidence/             # Artifacts for reporting (RESULTS)
│   ├── screenshots/      # Visual proof of exploitation
│   └── poc/              # Recorded PoC artifacts, command transcripts
│
├── reports/              # Deliverables (RESULTS)
│   ├── templates/        # Report templates (markdown, docx, pptx)
│   └── final/            # Finished reports for the engagement
│
├── notes/                # Working notes, attack trees, mind maps
├── logs/                 # Activity logs, command history, tool output
├── config/               # Tool configs, environment files, proxy settings
├── temp/                 # Scratch space — throwaway files (gitignored)
├── test/                 # Test scripts and test cases for custom tooling
├── lib/                  # Shared libraries and dependencies
└── Prompt/               # (Pre-existing) Prompt engineering files

Directory Categories

Category Directories Description
Working targets/, exploits/, payloads/, tools/, wordlists/, config/, lib/, notes/ Active workspace — files you create and edit during an engagement
Results scans/, loot/, evidence/, reports/ Output and deliverables — generated data, captured artifacts, final reports
Temporary temp/, logs/ Scratch and transient data — safe to wipe between operations
Test test/ Test scripts and validation cases for custom tools and exploits
Sensitive loot/, config/ Credentials, hashes, secrets — never commit to git

Naming Conventions

Files

  • Scan outputs: <target>_<tool>_<date>.<ext> — e.g. 10.10.10.5_nmap_20260726.xml
  • Recon data: <target>_recon_<date>.<ext> — e.g. acme.com_recon_20260726.txt
  • Exploits: <CVE-or-name>_<target>.<ext> — e.g. CVE-2024-3094_xz.py
  • Loot: <target>_<type>_<date>.<ext> — e.g. DC01_hashes_20260726.txt
  • Reports: <client>_<engagement>_<date>.<ext> — e.g. acme_pen-test_20260726.md
  • Logs: <tool>_<date>.log — e.g. nmap_20260726.log

Dates

  • All dates in filenames use YYYYMMDD format (no separators)
  • Timestamps in content use ISO 8601: 2026-07-26T14:30:00Z

Targets

  • IP addresses: use as-is (10.10.10.5)
  • Domains: use bare domain (acme.com), not FQDN with subdomain unless scoped
  • Internal names: use hostname only (DC01, not DC01.acme.local)

Workflow

  1. Scope → Drop RoE and target lists into targets/scope/
  2. Recon → Run recon, output goes to targets/recon/
  3. Scanning → Nmap/web/host scans output to respective scans/ subdirs
  4. Exploitation → Write exploits in exploits/custom/, generate payloads in payloads/
  5. Collection → Captured creds/hashes/files go to loot/ subdirs
  6. Evidence → Screenshots and PoC transcripts to evidence/
  7. Reporting → Use templates from reports/templates/, final output to reports/final/
  8. Cleanup → Wipe temp/ between engagements. Review logs/ before archiving.

Git Policy

  • Tracked: tools/, exploits/custom/, wordlists/custom/, lib/, test/, reports/templates/, config/ (non-sensitive configs only)
  • Ignored: temp/, loot/, logs/, scans/, evidence/, payloads/generated/, config/*.env, config/*secret*
  • Never committed: credentials, hashes, exfiltrated files, private keys, engagement-specific reports

See .gitignore for the full ignore list.