5.3 KiB
5.3 KiB
Hack Project — Directory Conventions
Red team / offensive security workspace. Last updated: 2026-07-26
Directory Map
Hack/
├── targets/ # Target data and scope definitions
│ ├── recon/ # Reconnaissance output per target (whois, DNS, OSINT)
│ └── scope/ # Scope of Work, Rules of Engagement, IP/domain lists
│
├── exploits/ # Exploit code and proof-of-concepts
│ ├── custom/ # Hand-written exploits (your own work)
│ └── public/ # Modified public exploits / EDB mirrors
│
├── payloads/ # Generated payloads and shellcode
│ ├── shellcode/ # Raw shellcode blobs (.bin, .hex)
│ └── generated/ # MSFvenom, sliver, donut outputs, staged payloads
│
├── tools/ # Custom tooling and automation
│ ├── scripts/ # One-off scripts and automation (Python, PS, Bash)
│ └── modules/ # Reusable modules / libraries shared across scripts
│
├── wordlists/ # Dictionaries for brute-forcing and fuzzing
│ ├── custom/ # Target-specific generated lists
│ └── curated/ # SecLists, rockyou, etc.
│
├── scans/ # Raw scan output (RESULTS)
│ ├── nmap/ # Nmap XML/gnmap output
│ ├── web/ # Web scans (ffuf, nikto, nuclei, gobuster)
│ └── host/ # Host-level scans (nessus, openvas, bloodhound)
│
├── loot/ # Captured data from successful ops (RESULTS — SENSITIVE)
│ ├── credentials/ # Plaintext creds, tokens, tickets
│ ├── hashes/ # NTLM, Kerberos, SHA, etc.
│ └── files/ # Exfiltrated or downloaded files
│
├── evidence/ # Artifacts for reporting (RESULTS)
│ ├── screenshots/ # Visual proof of exploitation
│ └── poc/ # Recorded PoC artifacts, command transcripts
│
├── reports/ # Deliverables (RESULTS)
│ ├── templates/ # Report templates (markdown, docx, pptx)
│ └── final/ # Finished reports for the engagement
│
├── notes/ # Working notes, attack trees, mind maps
├── logs/ # Activity logs, command history, tool output
├── config/ # Tool configs, environment files, proxy settings
├── temp/ # Scratch space — throwaway files (gitignored)
├── test/ # Test scripts and test cases for custom tooling
├── lib/ # Shared libraries and dependencies
└── Prompt/ # (Pre-existing) Prompt engineering files
Directory Categories
| Category | Directories | Description |
|---|---|---|
| Working | targets/, exploits/, payloads/, tools/, wordlists/, config/, lib/, notes/ |
Active workspace — files you create and edit during an engagement |
| Results | scans/, loot/, evidence/, reports/ |
Output and deliverables — generated data, captured artifacts, final reports |
| Temporary | temp/, logs/ |
Scratch and transient data — safe to wipe between operations |
| Test | test/ |
Test scripts and validation cases for custom tools and exploits |
| Sensitive | loot/, config/ |
Credentials, hashes, secrets — never commit to git |
Naming Conventions
Files
- Scan outputs:
<target>_<tool>_<date>.<ext>— e.g.10.10.10.5_nmap_20260726.xml - Recon data:
<target>_recon_<date>.<ext>— e.g.acme.com_recon_20260726.txt - Exploits:
<CVE-or-name>_<target>.<ext>— e.g.CVE-2024-3094_xz.py - Loot:
<target>_<type>_<date>.<ext>— e.g.DC01_hashes_20260726.txt - Reports:
<client>_<engagement>_<date>.<ext>— e.g.acme_pen-test_20260726.md - Logs:
<tool>_<date>.log— e.g.nmap_20260726.log
Dates
- All dates in filenames use
YYYYMMDDformat (no separators) - Timestamps in content use ISO 8601:
2026-07-26T14:30:00Z
Targets
- IP addresses: use as-is (
10.10.10.5) - Domains: use bare domain (
acme.com), not FQDN with subdomain unless scoped - Internal names: use hostname only (
DC01, notDC01.acme.local)
Workflow
- Scope → Drop RoE and target lists into
targets/scope/ - Recon → Run recon, output goes to
targets/recon/ - Scanning → Nmap/web/host scans output to respective
scans/subdirs - Exploitation → Write exploits in
exploits/custom/, generate payloads inpayloads/ - Collection → Captured creds/hashes/files go to
loot/subdirs - Evidence → Screenshots and PoC transcripts to
evidence/ - Reporting → Use templates from
reports/templates/, final output toreports/final/ - Cleanup → Wipe
temp/between engagements. Reviewlogs/before archiving.
Git Policy
- Tracked:
tools/,exploits/custom/,wordlists/custom/,lib/,test/,reports/templates/,config/(non-sensitive configs only) - Ignored:
temp/,loot/,logs/,scans/,evidence/,payloads/generated/,config/*.env,config/*secret* - Never committed: credentials, hashes, exfiltrated files, private keys, engagement-specific reports
See .gitignore for the full ignore list.