My Hack The Box work. Scans, notes, and whatever exploit code I end up writing.
Each box gets its own folder. Anything I reuse across boxes sits at the repo root.
.
├── <lab-name>/ # one folder per HTB machine
│ ├── nmap/ # scans for that box
│ └── ... # exploits, notes, loot for that box
└── <shared tooling> # reused across boxes, lives at the root
Big third-party toolkits don't get committed. They live outside the repo, and I symlink them into the root and git-ignore the link.
Right now that's just SecLists:
ln -s ../SecLists SecListsIt points at the danielmiessler/SecLists clone.
Per-box Python work runs on uv. To rebuild a box's environment from its lockfile:
cd nexus-lab
uv sync