Files
hack/README.md
T

113 lines
5.3 KiB
Markdown

# Hack Project — Directory Conventions
> Red team / offensive security workspace. Last updated: 2026-07-26
---
## Directory Map
```
Hack/
├── targets/ # Target data and scope definitions
│ ├── recon/ # Reconnaissance output per target (whois, DNS, OSINT)
│ └── scope/ # Scope of Work, Rules of Engagement, IP/domain lists
│
├── exploits/ # Exploit code and proof-of-concepts
│ ├── custom/ # Hand-written exploits (your own work)
│ └── public/ # Modified public exploits / EDB mirrors
│
├── payloads/ # Generated payloads and shellcode
│ ├── shellcode/ # Raw shellcode blobs (.bin, .hex)
│ └── generated/ # MSFvenom, sliver, donut outputs, staged payloads
│
├── tools/ # Custom tooling and automation
│ ├── scripts/ # One-off scripts and automation (Python, PS, Bash)
│ └── modules/ # Reusable modules / libraries shared across scripts
│
├── wordlists/ # Dictionaries for brute-forcing and fuzzing
│ ├── custom/ # Target-specific generated lists
│ └── curated/ # SecLists, rockyou, etc.
│
├── scans/ # Raw scan output (RESULTS)
│ ├── nmap/ # Nmap XML/gnmap output
│ ├── web/ # Web scans (ffuf, nikto, nuclei, gobuster)
│ └── host/ # Host-level scans (nessus, openvas, bloodhound)
│
├── loot/ # Captured data from successful ops (RESULTS — SENSITIVE)
│ ├── credentials/ # Plaintext creds, tokens, tickets
│ ├── hashes/ # NTLM, Kerberos, SHA, etc.
│ └── files/ # Exfiltrated or downloaded files
│
├── evidence/ # Artifacts for reporting (RESULTS)
│ ├── screenshots/ # Visual proof of exploitation
│ └── poc/ # Recorded PoC artifacts, command transcripts
│
├── reports/ # Deliverables (RESULTS)
│ ├── templates/ # Report templates (markdown, docx, pptx)
│ └── final/ # Finished reports for the engagement
│
├── notes/ # Working notes, attack trees, mind maps
├── logs/ # Activity logs, command history, tool output
├── config/ # Tool configs, environment files, proxy settings
├── temp/ # Scratch space — throwaway files (gitignored)
├── test/ # Test scripts and test cases for custom tooling
├── lib/ # Shared libraries and dependencies
└── Prompt/ # (Pre-existing) Prompt engineering files
```
---
## Directory Categories
| Category | Directories | Description |
|---|---|---|
| **Working** | `targets/`, `exploits/`, `payloads/`, `tools/`, `wordlists/`, `config/`, `lib/`, `notes/` | Active workspace — files you create and edit during an engagement |
| **Results** | `scans/`, `loot/`, `evidence/`, `reports/` | Output and deliverables — generated data, captured artifacts, final reports |
| **Temporary** | `temp/`, `logs/` | Scratch and transient data — safe to wipe between operations |
| **Test** | `test/` | Test scripts and validation cases for custom tools and exploits |
| **Sensitive** | `loot/`, `config/` | Credentials, hashes, secrets — **never commit to git** |
---
## Naming Conventions
### Files
- **Scan outputs:** `<target>_<tool>_<date>.<ext>` — e.g. `10.10.10.5_nmap_20260726.xml`
- **Recon data:** `<target>_recon_<date>.<ext>` — e.g. `acme.com_recon_20260726.txt`
- **Exploits:** `<CVE-or-name>_<target>.<ext>` — e.g. `CVE-2024-3094_xz.py`
- **Loot:** `<target>_<type>_<date>.<ext>` — e.g. `DC01_hashes_20260726.txt`
- **Reports:** `<client>_<engagement>_<date>.<ext>` — e.g. `acme_pen-test_20260726.md`
- **Logs:** `<tool>_<date>.log` — e.g. `nmap_20260726.log`
### Dates
- All dates in filenames use `YYYYMMDD` format (no separators)
- Timestamps in content use ISO 8601: `2026-07-26T14:30:00Z`
### Targets
- IP addresses: use as-is (`10.10.10.5`)
- Domains: use bare domain (`acme.com`), not FQDN with subdomain unless scoped
- Internal names: use hostname only (`DC01`, not `DC01.acme.local`)
---
## Workflow
1. **Scope** → Drop RoE and target lists into `targets/scope/`
2. **Recon** → Run recon, output goes to `targets/recon/`
3. **Scanning** → Nmap/web/host scans output to respective `scans/` subdirs
4. **Exploitation** → Write exploits in `exploits/custom/`, generate payloads in `payloads/`
5. **Collection** → Captured creds/hashes/files go to `loot/` subdirs
6. **Evidence** → Screenshots and PoC transcripts to `evidence/`
7. **Reporting** → Use templates from `reports/templates/`, final output to `reports/final/`
8. **Cleanup** → Wipe `temp/` between engagements. Review `logs/` before archiving.
---
## Git Policy
- **Tracked:** `tools/`, `exploits/custom/`, `wordlists/custom/`, `lib/`, `test/`, `reports/templates/`, `config/` (non-sensitive configs only)
- **Ignored:** `temp/`, `loot/`, `logs/`, `scans/`, `evidence/`, `payloads/generated/`, `config/*.env`, `config/*secret*`
- **Never committed:** credentials, hashes, exfiltrated files, private keys, engagement-specific reports
See `.gitignore` for the full ignore list.