free & open source

security cheatsheets
that actually stick

Hands-on reference sheets with interactive quizzes. No fluff — just the commands, concepts, and techniques you need.

5Cheatsheets
50+Quiz questions
100%Free
topics
🔺
Privilege Escalation

Linux Privesc

SUID, sudo misconfigs, capabilities, cron jobs, writable paths, kernel exploits — the full methodology.

32 concepts · 10 quiz Qs medium
🧩
Web Security

SSTI

Server-side template injection in Jinja2, Twig, Freemarker — detection, payloads, and RCE chains.

20 concepts · 10 quiz Qs medium
📄
Web Security

XXE Injection

XML external entity attacks — file read, SSRF, blind/OOB exfiltration, and WAF bypass techniques.

22 concepts · 10 quiz Qs medium
🔐
Auth & Identity

SAML Attacks

Signature wrapping, XML injection, authentication bypass, and common SSO misconfigurations.

18 concepts · 10 quiz Qs advanced
🔑
Auth & Identity

Sessions & Auth Tokens

JWT attacks, session fixation, cookie security, token storage mistakes — the full picture of broken auth.

25 concepts · 10 quiz Qs medium
CVE Deep-Dive

SAMLStorm

Critical authentication bypass in ruby-saml — how it works, what's exploitable, and how to patch.

deep-dive · quiz incoming advanced