Skip to content

Releases: toyosee/cyberref-releases

CyberRef v0.4.0 - Depth & Defense

Choose a tag to compare

@toyosee toyosee released this 04 Oct 16:18
1e87618

CyberRef v0.4.0 - Depth & Defense

The biggest update yet. CyberRef now covers the full attack lifecycle AND
the defensive perspective. 25 command categories, 15 scenarios, and blue-team
content throughout.

What's New

🎯 7 New Scenarios (8 → 15)

  • XSS → Session Hijacking - client-side code execution leading to account takeover
  • XXE Injection - XML external entity file read and SSRF
  • SMB Relay Attack - NTLM relay via forced authentication
  • Kerberoasting - service account credential extraction from Kerberos
  • Linux Privilege Escalation - SUID, sudo, cron, and PATH hijacking
  • Reverse Shell Establishment - from RCE to interactive session
  • Log Analysis & Detection Engineering - the first blue-team scenario

Every attack scenario now includes purple team notes - how the attack
looks in logs, and what a defender would do about it.

📚 3 New Command Categories

  • Netcat & Shells - listen, connect, scan, transfer, bind/reverse shells
  • Reverse Shell One-Liners - bash, python, perl, php, ruby, powershell, socat
  • Tunneling & Pivoting - SSH forwards, chisel, socat, proxychains

~100 new commands. Total is now ~600.

🔵 Blue-Team Content

Scenarios can now include:

  • Log Sources - where the attack appears, with pattern matching
  • SIEM Queries - ready-to-run Splunk, Elastic, Wazuh queries
  • Purple Team Notes - connecting attack to detection in practice

🎛️ Filters

Filter scenarios by Kill Chain phase, CIA impact, or difficulty.

⌘ Command Palette

Press Ctrl+K anywhere to search commands, scenarios, or run quick actions.

⭐ Favorites & Recents

Star commands and scenarios; see your last 20 opens and copies in the sidebar.

Install

  1. Download cyberref.exe
  2. Double-click it
  3. Browser opens to http://localhost:8787

No install. No server. No internet required.

Note

Windows may warn on first run since the binary is unsigned - click
More info → Run anyway.


Built by ToyotechICT Solutions

Version 3

Choose a tag to compare

@toyosee toyosee released this 22 Sep 09:15
1e87618

CyberRef v0.3.0 — "Scenarios & Labs"

Biggest update yet. CyberRef is no longer just a command reference — it now
teaches how commands chain together into real attack workflows, with full
defense guidance for each. Eight guided scenarios covering the CIA triad,
MITRE ATT&CK, and the Cyber Kill Chain. Plus a new export feature that turns
any scenario into a runnable .sh script.


What's New

🎯 8 Guided Scenarios

Each scenario walks through the full attack lifecycle:

  • Overview — what the technique is, why it matters, which CIA leg it hits
  • Prerequisites — what you need before starting
  • Steps — ordered commands with rationale, expected output, and notes
  • Defense — hardening, detection, and response guidance
  • References — MITRE ATT&CK, OWASP, and vendor docs

Included scenarios:

Scenario Kill Chain Phase CIA Impact
Brute Force SSH Exploitation Confidentiality, Integrity
SQL Injection → Database Dump Exploitation Confidentiality, Integrity
Password Hash Cracking Actions on Objectives Confidentiality
FTP Anonymous Login Exploitation Confidentiality, Integrity
SYN Flood Denial of Service Actions on Objectives Availability
Password Spraying (AD) Exploitation Confidentiality, Integrity
Web Directory Brute Force Reconnaissance Confidentiality
Slowloris DoS (SlowHTTPTest) Actions on Objectives Availability

🔍 Unified Search

Search now covers both commands and scenarios in one box. Results are
split into two clear sections — scenario matches first, then command matches.

⬇ Export Scenario as .sh Script

Every scenario detail page has an Export as .sh script button. It downloads
a runnable bash script containing:

  • Header with scenario metadata (MITRE mapping, CIA impact, difficulty)
  • All steps as commented-out commands (with your current placeholder values substituted)
  • Expected output annotations
  • Defense checklist (hardening, detection, response)
  • Reference URLs

Commands are commented by default — safer to uncomment and run deliberately
than to execute blindly.

🛡️ Defense Notes on Every Scenario

Each scenario teaches both sides:

  • Hardening — how to prevent the attack
  • Detection — what to monitor in logs and SIEM
  • Response — what to do when detected

🎨 UI Improvements

  • Search results split into scenario/command sections with clear headers
  • Scenario cards with difficulty pills, kill chain badges, MITRE tags
  • CIA triad impact panel with color-coded severity pills
  • Step cards with numbered badges and expected-output highlighting
  • Dedicated defense panel styled in accent green

Install (Windows)

  1. Download cyberref.exe below
  2. Double-click it
  3. Browser opens to http://localhost:8787

Press Ctrl+C in the console to stop.


Example Workflow

  1. Open CyberRef, click 🎯 Scenarios & Labs
  2. Pick "Brute Force SSH"
  3. Read the scenario overview — see it targets the Confidentiality leg of CIA
  4. Fill in {TARGET} with your lab IP (it's remembered across sessions)
  5. Copy each step's command, paste into your terminal
  6. Scroll to Defense to see what would have caught this attack
  7. Click ⬇ Export as .sh script to get a runnable version for your notes

What's Included in the Box

  • 22 command categories — ~500 Linux / Kali commands with descriptions
  • 8 guided scenarios — full attack workflows with defense notes
  • Search across everything — one box, both content types
  • Placeholder substitution — {TARGET}, {USER}, {DOMAIN} remembered across sessions
  • Zero dependencies — one .exe, no install, no server, no internet

Coming Next

  • Windows / Active Directory command categories
  • MITRE ATT&CK filter chips (browse by tactic)
  • More scenarios: XSS, XXE, SMB relay, Kerberoasting, privilege escalation
  • CLI companion (cyberref search "kerb")
  • Favorites / pinning
  • Light theme toggle

Known Limitations

  • Scenarios are Linux / Kali-focused (Windows/AD coming in a future release)
  • Windows SmartScreen may warn on first run (unsigned binary)
    • Click More info → Run anyway
  • Export produces bash scripts only (PowerShell export planned)

Feedback

Issues and feature requests welcome:
https://github.com/toyotechict/cyberref-releases/issues

Note

Windows may warn on first run since the binary is unsigned — click
More info → Run anyway.


Built by ToyotechICT Solutions

CyberRef v0.2.0 Public

Choose a tag to compare

@toyosee toyosee released this 17 Sep 14:02
c8c445f

CyberRef v0.2.0 — First Release

Fast, offline command reference for cybersecurity practitioners.
Single binary, no install, no server. Download and run.

What's inside

  • 22 categories, ~500 Linux / Kali commands
  • Instant fuzzy search
  • Placeholder substitution ({TARGET}, {USER}, etc.) with persistent values
  • Fully offline, everything embedded in the .exe

Run it

  1. Download cyberref.exe below
  2. Double-click it
  3. Browser opens to http://localhost:8787

Press Ctrl+C in the console to stop.

Note

Windows may show a SmartScreen warning since the binary is unsigned.
Click "More info" → "Run anyway".

Built by ToyotechICT Solutions