') + ')', 'gi');
if (regex.test(text)) {
found = true;
var frag = document.createDocumentFragment();
var parts = text.split(regex);
parts.forEach(function(part, i) {
if (i % 2 === 0) {
frag.appendChild(document.createTextNode(part));
} else {
var span = document.createElement('span');
span.className = 'userscript-highlight';
span.textContent = part;
frag.appendChild(span);
}
});
node.parentNode.replaceChild(frag, node);
}
});
} else if (node.nodeType === 1 && node.childNodes) { // element
var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];
if (!skipTags.includes(node.tagName)) {
Array.from(node.childNodes).forEach(highlight);
}
}
}
highlight(document.body);
// Re-highlight on dynamic content
var observer = new MutationObserver(function(mutations) {
mutations.forEach(function(m) {
m.addedNodes.forEach(function(node) {
if (node.nodeType === 1 || node.nodeType === 3) highlight(node);
});
});
});
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); }
})();
(function(){
try {
var __m = "*";
var __re = new RegExp('^' + ".*" + ', 'i');
if (__m === '*' || __re.test(location.href)) {
// Strip utm_, fbclid, gclid, etc. from all links on page
(function() {
var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',
'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',
'ref', 'ref_src', 'source', 'medium', 'campaign'];
function cleanUrl(url) {
try {
var u = new URL(url, window.location.origin);
var changed = false;
trackingParams.forEach(function(p) {
if (u.searchParams.has(p)) {
u.searchParams.delete(p);
changed = true;
}
});
return changed ? u.toString() : url;
} catch (e) {
return url;
}
}
function cleanLinks() {
document.querySelectorAll('a[href]').forEach(function(a) {
var clean = cleanUrl(a.href);
if (clean !== a.href) a.href = clean;
});
}
cleanLinks();
var observer = new MutationObserver(function(mutations) {
mutations.forEach(function(m) {
m.addedNodes.forEach(function(node) {
if (node.nodeType === 1) {
if (node.tagName === 'A') cleanLinks();
node.querySelectorAll('a[href]').forEach(function(a) {
var clean = cleanUrl(a.href);
if (clean !== a.href) a.href = clean;
});
}
});
});
});
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); }
})();
(function(){
try {
var __m = "youtube.com";
var __re = new RegExp('^' + "youtube\\.com" + ', 'i');
if (__m === '*' || __re.test(location.href)) {
// Auto-enable theater mode on YouTube
(function() {
function tryTheater() {
var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]');
if (btn && !btn.classList.contains('activated')) {
btn.click();
}
}
// Try immediately
tryTheater();
// Try after navigation (SPA)
var lastUrl = location.href;
setInterval(function() {
if (location.href !== lastUrl) {
lastUrl = location.href;
setTimeout(tryTheater, 500);
}
}, 1000);
// Also try on player load
var observer = new MutationObserver(tryTheater);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); }
})();
(function(){
try {
var __m = "*";
var __re = new RegExp('^' + ".*" + ', 'i');
if (__m === '*' || __re.test(location.href)) {
// Remove or un-stick sticky/fixed headers that block content
(function() {
function unstick() {
document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) {
if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {
el.style.position = 'static';
el.style.top = 'auto';
el.style.zIndex = 'auto';
}
});
}
unstick();
var observer = new MutationObserver(unstick);
observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });
})();
}
} catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); }
})();
})();
GitHub - Constan4/Cybersecurity: Apuntes y herramientas de ciberseguridad en español: reconocimiento, CVE/CVSS, explotación, post-explotación, hardening Windows y CTF. Python + PowerShell. · GitHub
You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Repositorio de ciberseguridad ofensiva y defensiva en español.
Apuntes de estudio, scripts originales y herramientas para el ciclo completo de auditoría.
¿Qué es este repositorio?
Un compendio de conocimiento práctico organizado en el orden lógico del ciclo de auditoría:
desde el reconocimiento inicial hasta el hardening del sistema. Cada módulo incluye
apuntes conceptuales detallados y herramientas Python/PowerShell listas para usar.
Categorías, enfoque por tipo, plataformas, plantilla
⚙️ Requisitos
# Python 3.8+
python3 --version
# Kali Linux (recomendado para módulos ofensivos)# Los scripts de Python usan solo la librería estándar salvo excepción# Para módulos de explotación
msfvenom --version
msfconsole --version
# PowerShell 5+ (para hardening_audit.ps1)$PSVersionTable.PSVersion
🚀 Inicio rápido
# 1. Clonar el repositorio
git clone https://github.com/Constan4/Cybersecurity.git
cd Cybersecurity
# 2. Empezar por los apuntes de reconocimiento
cat 01-Reconocimiento/apuntes/nmap-guia-completa.md
# 3. Probar el primer script en tu red local (con autorización)
python3 01-Reconocimiento/scripts/network_recon.py -t 192.168.1.0/24 --solo-ping
📖 Marcos de referencia
Este repositorio sigue la metodología PTES (Penetration Testing Execution Standard)
y mapea las técnicas con el framework MITRE ATT&CK. Los controles defensivos
se alinean con el CIS Controls v8 y los benchmarks del NIST.
⚠️ Aviso Legal
Todo el contenido de este repositorio es exclusivamente para fines educativos.
Las técnicas, herramientas y scripts documentados aquí deben utilizarse únicamente en:
Entornos de laboratorio propios y controlados
Sistemas con autorización expresa y escrita del propietario
Programas de Bug Bounty dentro del scope definido
Auditorías con contrato firmado
El acceso no autorizado a sistemas informáticos es un delito penal en la mayoría
de jurisdicciones. El autor no se responsabiliza del uso indebido de este material.
Constan4 — Estudiante de Ciberseguridad github.com/Constan4/Cybersecurity
About
Apuntes y herramientas de ciberseguridad en español: reconocimiento, CVE/CVSS, explotación, post-explotación, hardening Windows y CTF. Python + PowerShell.