Project · citation policy
Sources
Where the content comes from and how you can check it.
provenancePriority of sources
- The tool's own repository and manual pages — the only authoritative description of behaviour.
- Official release notes and changelogs for version-dependent statements.
- Distribution package metadata for install claims (which package provides which binary).
- Established reference works (RFCs, NIST publications, OWASP guidance) for concepts.
Explicitly not used
- Blog posts restating another blog post.
- Tutorial text that a tool's current --help contradicts.
- Vendor marketing pages as a source for capability claims beyond their own product description.
How sources appear
Every tool page has a References section with what each link lets you verify. Where a page quotes a specific flag, the flag's meaning is described in the tool's own documentation — no source should be needed to trust a summary, so summaries stay short and link out.
Wordlists, addresses and sample data
Examples use RFC 5737 documentation ranges (192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24) or private lab ranges, never live hosts. Example output is labelled as illustrative and must not be quoted as a guarantee.