Releases: toyosee/cyberref-releases
Release list
CyberRef v0.4.0 - Depth & Defense
CyberRef v0.4.0 - Depth & Defense
The biggest update yet. CyberRef now covers the full attack lifecycle AND
the defensive perspective. 25 command categories, 15 scenarios, and blue-team
content throughout.
What's New
🎯 7 New Scenarios (8 → 15)
- XSS → Session Hijacking - client-side code execution leading to account takeover
- XXE Injection - XML external entity file read and SSRF
- SMB Relay Attack - NTLM relay via forced authentication
- Kerberoasting - service account credential extraction from Kerberos
- Linux Privilege Escalation - SUID, sudo, cron, and PATH hijacking
- Reverse Shell Establishment - from RCE to interactive session
- Log Analysis & Detection Engineering - the first blue-team scenario
Every attack scenario now includes purple team notes - how the attack
looks in logs, and what a defender would do about it.
📚 3 New Command Categories
- Netcat & Shells - listen, connect, scan, transfer, bind/reverse shells
- Reverse Shell One-Liners - bash, python, perl, php, ruby, powershell, socat
- Tunneling & Pivoting - SSH forwards, chisel, socat, proxychains
~100 new commands. Total is now ~600.
🔵 Blue-Team Content
Scenarios can now include:
- Log Sources - where the attack appears, with pattern matching
- SIEM Queries - ready-to-run Splunk, Elastic, Wazuh queries
- Purple Team Notes - connecting attack to detection in practice
🎛️ Filters
Filter scenarios by Kill Chain phase, CIA impact, or difficulty.
⌘ Command Palette
Press Ctrl+K anywhere to search commands, scenarios, or run quick actions.
⭐ Favorites & Recents
Star commands and scenarios; see your last 20 opens and copies in the sidebar.
Install
- Download
cyberref.exe - Double-click it
- Browser opens to
http://localhost:8787
No install. No server. No internet required.
Note
Windows may warn on first run since the binary is unsigned - click
More info → Run anyway.
Built by ToyotechICT Solutions
Version 3
CyberRef v0.3.0 — "Scenarios & Labs"
Biggest update yet. CyberRef is no longer just a command reference — it now
teaches how commands chain together into real attack workflows, with full
defense guidance for each. Eight guided scenarios covering the CIA triad,
MITRE ATT&CK, and the Cyber Kill Chain. Plus a new export feature that turns
any scenario into a runnable .sh script.
What's New
🎯 8 Guided Scenarios
Each scenario walks through the full attack lifecycle:
- Overview — what the technique is, why it matters, which CIA leg it hits
- Prerequisites — what you need before starting
- Steps — ordered commands with rationale, expected output, and notes
- Defense — hardening, detection, and response guidance
- References — MITRE ATT&CK, OWASP, and vendor docs
Included scenarios:
| Scenario | Kill Chain Phase | CIA Impact |
|---|---|---|
| Brute Force SSH | Exploitation | Confidentiality, Integrity |
| SQL Injection → Database Dump | Exploitation | Confidentiality, Integrity |
| Password Hash Cracking | Actions on Objectives | Confidentiality |
| FTP Anonymous Login | Exploitation | Confidentiality, Integrity |
| SYN Flood Denial of Service | Actions on Objectives | Availability |
| Password Spraying (AD) | Exploitation | Confidentiality, Integrity |
| Web Directory Brute Force | Reconnaissance | Confidentiality |
| Slowloris DoS (SlowHTTPTest) | Actions on Objectives | Availability |
🔍 Unified Search
Search now covers both commands and scenarios in one box. Results are
split into two clear sections — scenario matches first, then command matches.
⬇ Export Scenario as .sh Script
Every scenario detail page has an Export as .sh script button. It downloads
a runnable bash script containing:
- Header with scenario metadata (MITRE mapping, CIA impact, difficulty)
- All steps as commented-out commands (with your current placeholder values substituted)
- Expected output annotations
- Defense checklist (hardening, detection, response)
- Reference URLs
Commands are commented by default — safer to uncomment and run deliberately
than to execute blindly.
🛡️ Defense Notes on Every Scenario
Each scenario teaches both sides:
- Hardening — how to prevent the attack
- Detection — what to monitor in logs and SIEM
- Response — what to do when detected
🎨 UI Improvements
- Search results split into scenario/command sections with clear headers
- Scenario cards with difficulty pills, kill chain badges, MITRE tags
- CIA triad impact panel with color-coded severity pills
- Step cards with numbered badges and expected-output highlighting
- Dedicated defense panel styled in accent green
Install (Windows)
- Download
cyberref.exebelow - Double-click it
- Browser opens to
http://localhost:8787
Press Ctrl+C in the console to stop.
Example Workflow
- Open CyberRef, click 🎯 Scenarios & Labs
- Pick "Brute Force SSH"
- Read the scenario overview — see it targets the Confidentiality leg of CIA
- Fill in
{TARGET}with your lab IP (it's remembered across sessions) - Copy each step's command, paste into your terminal
- Scroll to Defense to see what would have caught this attack
- Click ⬇ Export as .sh script to get a runnable version for your notes
What's Included in the Box
- 22 command categories — ~500 Linux / Kali commands with descriptions
- 8 guided scenarios — full attack workflows with defense notes
- Search across everything — one box, both content types
- Placeholder substitution —
{TARGET},{USER},{DOMAIN}remembered across sessions - Zero dependencies — one
.exe, no install, no server, no internet
Coming Next
- Windows / Active Directory command categories
- MITRE ATT&CK filter chips (browse by tactic)
- More scenarios: XSS, XXE, SMB relay, Kerberoasting, privilege escalation
- CLI companion (
cyberref search "kerb") - Favorites / pinning
- Light theme toggle
Known Limitations
- Scenarios are Linux / Kali-focused (Windows/AD coming in a future release)
- Windows SmartScreen may warn on first run (unsigned binary)
- Click More info → Run anyway
- Export produces bash scripts only (PowerShell export planned)
Feedback
Issues and feature requests welcome:
https://github.com/toyotechict/cyberref-releases/issues
Note
Windows may warn on first run since the binary is unsigned — click
More info → Run anyway.
Built by ToyotechICT Solutions
CyberRef v0.2.0 Public
CyberRef v0.2.0 — First Release
Fast, offline command reference for cybersecurity practitioners.
Single binary, no install, no server. Download and run.
What's inside
- 22 categories, ~500 Linux / Kali commands
- Instant fuzzy search
- Placeholder substitution ({TARGET}, {USER}, etc.) with persistent values
- Fully offline, everything embedded in the .exe
Run it
- Download cyberref.exe below
- Double-click it
- Browser opens to http://localhost:8787
Press Ctrl+C in the console to stop.
Note
Windows may show a SmartScreen warning since the binary is unsigned.
Click "More info" → "Run anyway".
Built by ToyotechICT Solutions