HAK 2
Core Path 48% OFF
Core Path

HAK 2

OSCP + CPTS

Advanced practical path for learners preparing for OSCP/CPTS-style methodology, reporting, labs, and job readiness.

  • Structured practical learning path
  • Bangla explanations with hands-on guidance
  • Designed for ethical and legal skill building
Advanced6-8 MonthsBanglaHackForceBD
Module Outline

Course Syllabus

01 CPTS Syllabus Hack The Box CPTS Syllabus 28 chapters
01 Penetration Testing Process Penetration Testing Process module 140 topics Module 1
  • 1.1
    Introduction to the Penetration Tester Path 3 topics
    • 1.1.1
      HTB Academy Learning Philosophy
    • 1.1.2
      Ethical and Legal Considerations
    • 1.1.3
      Penetration Tester Path Syllabus
  • 1.2
    Academy Modules Layout 8 topics
    • 1.2.1
      Pre-Engagement 9 topics
      • 1.2.1.1
        Learning Process
      • 1.2.1.2
        Linux Fundamentals
      • 1.2.1.3
        Windows Fundamentals
      • 1.2.1.4
        Introduction to Networking
      • 1.2.1.5
        Introduction to Web Applications
      • 1.2.1.6
        Web Requests
      • 1.2.1.7
        JavaScript Deobfuscation
      • 1.2.1.8
        Introduction to Active Directory
      • 1.2.1.9
        Getting Started
    • 1.2.2
      Information Gathering 4 topics
      • 1.2.2.1
        Network Enumeration with Nmap
      • 1.2.2.2
        Footprinting
      • 1.2.2.3
        Information Gathering - Web Edition
      • 1.2.2.4
        OSINT: Corporate Recon
    • 1.2.3
      Vulnerability Assessment 4 topics
      • 1.2.3.1
        Vulnerability Assessment
      • 1.2.3.2
        File Transfers
      • 1.2.3.3
        Shells & Payloads
      • 1.2.3.4
        Using the Metasploit-Framework
    • 1.2.4
      Exploitation 15 topics
      • 1.2.4.1
        Password Attacks
      • 1.2.4.2
        Attacking Common Services
      • 1.2.4.3
        Pivoting, Tunneling & Port Forwarding
      • 1.2.4.4
        Active Directory Enumeration & Attacks
      • 1.2.4.5
        Web Exploitation
      • 1.2.4.6
        Using Web Proxies
      • 1.2.4.7
        Attacking Web Applications with Ffuf
      • 1.2.4.8
        Login Brute Forcing
      • 1.2.4.9
        SQL Injection Fundamentals
      • 1.2.4.10
        SQLMap Essentials
      • 1.2.4.11
        Cross-Site Scripting (XSS)
      • 1.2.4.12
        File Inclusion
      • 1.2.4.13
        Command Injections
      • 1.2.4.14
        Web Attacks
      • 1.2.4.15
        Attacking Common Applications
    • 1.2.5
      Post-Exploitation 2 topics
      • 1.2.5.1
        Linux Privilege Escalation
      • 1.2.5.2
        Windows Privilege Escalation
    • 1.2.6
      Lateral Movement
    • 1.2.7
      Proof-of-Concept 1 topic
      • 1.2.7.1
        Introduction to Python 3
    • 1.2.8
      Post-Engagement 2 topics
      • 1.2.8.1
        Documentation & Reporting
      • 1.2.8.2
        Attacking Enterprise Networks
  • 1.3
    Academy Exercises & Questions 3 topics
    • 1.3.1
      The Goal
    • 1.3.2
      Asking for Help
    • 1.3.3
      Words of Wisdom
  • 1.4
    Penetration Testing Overview 4 topics
    • 1.4.1
      Risk Management 1 topic
      • 1.4.1.1
        Vulnerability Assessments
    • 1.4.2
      Testing Methods 2 topics
      • 1.4.2.1
        External Penetration Test
      • 1.4.2.2
        Internal Penetration Test
    • 1.4.3
      Types of Penetration Testing
    • 1.4.4
      Types of Testing Environments
  • 1.5
    Laws and Regulations 6 topics
    • 1.5.1
      USA
    • 1.5.2
      Europe
    • 1.5.3
      UK
    • 1.5.4
      India
    • 1.5.5
      China
    • 1.5.6
      Precautionary Measures during Penetration Tests
  • 1.6
    Penetration Testing Process 2 topics
    • 1.6.1
      Penetration Testing Stages 8 topics
      • 1.6.1.1
        Pre-Engagement
      • 1.6.1.2
        Information Gathering
      • 1.6.1.3
        Vulnerability Assessment
      • 1.6.1.4
        Exploitation
      • 1.6.1.5
        Post-Exploitation
      • 1.6.1.6
        Lateral Movement
      • 1.6.1.7
        Proof-of-Concept
      • 1.6.1.8
        Post-Engagement
    • 1.6.2
      Importance
  • 1.7
    Pre-Engagement 5 topics
    • 1.7.1
      Scoping Questionnaire
    • 1.7.2
      Pre-Engagement Meeting 2 topics
      • 1.7.2.1
        Contract - Checklist
      • 1.7.2.2
        Rules of Engagement - Checklist
    • 1.7.3
      Kick-Off Meeting
    • 1.7.4
      Contractors Agreement 1 topic
      • 1.7.4.1
        Contractors Agreement - Checklist for Physical Assessments
    • 1.7.5
      Setting Up 1 topic
      • 1.7.5.1
        Questions
  • 1.8
    Information Gathering 5 topics
    • 1.8.1
      Open-Source Intelligence 1 topic
      • 1.8.1.1
        Private and Public SSH Keys
    • 1.8.2
      Infrastructure Enumeration
    • 1.8.3
      Service Enumeration
    • 1.8.4
      Host Enumeration
    • 1.8.5
      Pillaging
  • 1.9
    Vulnerability Assessment 3 topics
    • 1.9.1
      Vulnerability Research and Analysis
    • 1.9.2
      Assessment of Possible Attack Vectors
    • 1.9.3
      The Return 1 topic
      • 1.9.3.1
        Questions
  • 1.10
    Exploitation 2 topics
    • 1.10.1
      Prioritization of Possible Attacks 1 topic
      • 1.10.1.1
        Prioritization Example
    • 1.10.2
      Preparation for the Attack
  • 1.11
    Post-Exploitation 7 topics
    • 1.11.1
      Evasive Testing
    • 1.11.2
      Information Gathering
    • 1.11.3
      Pillaging
    • 1.11.4
      Persistence
    • 1.11.5
      Vulnerability Assessment
    • 1.11.6
      Privilege Escalation
    • 1.11.7
      Data Exfiltration 1 topic
      • 1.11.7.1
        Questions
  • 1.12
    Lateral Movement 6 topics
    • 1.12.1
      Pivoting
    • 1.12.2
      Evasive Testing
    • 1.12.3
      Information Gathering
    • 1.12.4
      Vulnerability Assessment
    • 1.12.5
      (Privilege) Exploitation
    • 1.12.6
      Post-Exploitation
  • 1.13
    Proof-of-Concept
  • 1.14
    Post-Engagement 8 topics
    • 1.14.1
      Cleanup
    • 1.14.2
      Documentation and Reporting
    • 1.14.3
      Report Review Meeting
    • 1.14.4
      Deliverable Acceptance
    • 1.14.5
      Post-Remediation Testing
    • 1.14.6
      Role of the Pentester in Remediation
    • 1.14.7
      Data Retention
    • 1.14.8
      Close Out 1 topic
      • 1.14.8.1
        Questions
  • 1.15
    Practice 1 topic
    • 1.15.1
      Practicing Steps 4 topics
      • 1.15.1.1
        Modules
      • 1.15.1.2
        Retired Machines
      • 1.15.1.3
        Active Machines
      • 1.15.1.4
        Pro Lab/Endgame
  • 1.16
    Wrapping Up
02 Getting Started Getting Started module 139 topics Module 2
  • 2.1
    Infosec Overview 3 topics
    • 2.1.1
      Risk Management Process
    • 2.1.2
      Red Team vs. Blue Team
    • 2.1.3
      Role of Penetration Testers
  • 2.2
    Getting Started with a Pentest Distro 3 topics
    • 2.2.1
      Choosing a Distro
    • 2.2.2
      Setting Up a Pentest Distro 2 topics
      • 2.2.2.1
        ISO
      • 2.2.2.2
        OVA
    • 2.2.3
      Practicing with Parrot
  • 2.3
    Staying Organized 4 topics
    • 2.3.1
      Folder Structure
    • 2.3.2
      Note Taking Tools
    • 2.3.3
      Other Tools and Tips
    • 2.3.4
      Moving On
  • 2.4
    Connecting Using VPN 3 topics
    • 2.4.1
      Why Use A VPN?
    • 2.4.2
      Connecting to HTB VPN
    • 2.4.3
      Help with VPN
  • 2.5
    Common Terms 3 topics
    • 2.5.1
      What is a Shell?
    • 2.5.2
      What is a Port?
    • 2.5.3
      What is a Web Server
  • 2.6
    Basic Tools 4 topics
    • 2.6.1
      Using SSH
    • 2.6.2
      Using Netcat
    • 2.6.3
      Using Tmux
    • 2.6.4
      Using Vim
  • 2.7
    Service Scanning 3 topics
    • 2.7.1
      Nmap 1 topic
      • 2.7.1.1
        Nmap Scripts
    • 2.7.2
      Attacking Network Services 5 topics
      • 2.7.2.1
        Banner Grabbing
      • 2.7.2.2
        FTP
      • 2.7.2.3
        SMB
      • 2.7.2.4
        Shares
      • 2.7.2.5
        SNMP
    • 2.7.3
      Conclusion
  • 2.8
    Web Enumeration 2 topics
    • 2.8.1
      Gobuster 3 topics
      • 2.8.1.1
        Directory/File Enumeration
      • 2.8.1.2
        DNS Subdomain Enumeration
      • 2.8.1.3
        Install SecLists
    • 2.8.2
      Web Enumeration Tips 5 topics
      • 2.8.2.1
        Banner Grabbing / Web Server Headers
      • 2.8.2.2
        Whatweb
      • 2.8.2.3
        Certificates
      • 2.8.2.4
        Robots.txt
      • 2.8.2.5
        Source Code
  • 2.9
    Public Exploits 2 topics
    • 2.9.1
      Finding Public Exploits
    • 2.9.2
      Metasploit Primer
  • 2.10
    Types of Shells 3 topics
    • 2.10.1
      Reverse Shell 3 topics
      • 2.10.1.1
        Netcat Listener
      • 2.10.1.2
        Connect Back IP
      • 2.10.1.3
        Reverse Shell Command
    • 2.10.2
      Bind Shell 3 topics
      • 2.10.2.1
        Bind Shell Command
      • 2.10.2.2
        Netcat Connection
      • 2.10.2.3
        Upgrading TTY
    • 2.10.3
      Web Shell 3 topics
      • 2.10.3.1
        Writing a Web Shell
      • 2.10.3.2
        Uploading a Web Shell
      • 2.10.3.3
        Accessing Web Shell
  • 2.11
    Privilege Escalation 8 topics
    • 2.11.1
      PrivEsc Checklists
    • 2.11.2
      Enumeration Scripts
    • 2.11.3
      Kernel Exploits
    • 2.11.4
      Vulnerable Software
    • 2.11.5
      User Privileges
    • 2.11.6
      Scheduled Tasks
    • 2.11.7
      Exposed Credentials
    • 2.11.8
      SSH Keys
  • 2.12
    Transferring Files 4 topics
    • 2.12.1
      Using wget
    • 2.12.2
      Using SCP
    • 2.12.3
      Using Base64
    • 2.12.4
      Validating File Transfers
  • 2.13
    Starting Out 2 topics
    • 2.13.1
      Resources 9 topics
      • 2.13.1.1
        Vulnerable Machines/Applications
      • 2.13.1.2
        YouTube Channels
      • 2.13.1.3
        Blogs
      • 2.13.1.4
        Tutorial Websites
      • 2.13.1.5
        HTB Starting Point
      • 2.13.1.6
        HTB Tracks
      • 2.13.1.7
        Beginner Friendly HTB Machines
      • 2.13.1.8
        Beginner Friendly HTB Challenges
      • 2.13.1.9
        Dante Prolab
    • 2.13.2
      Moving On
  • 2.14
    Navigating HTB 9 topics
    • 2.14.1
      Profile
    • 2.14.2
      Rankings
    • 2.14.3
      Tracks
    • 2.14.4
      Machines
    • 2.14.5
      Challenges
    • 2.14.6
      Fortress
    • 2.14.7
      Endgame
    • 2.14.8
      Pro Labs
    • 2.14.9
      Battlegrounds
  • 2.15
    Nibbles - Enumeration 1 topic
    • 2.15.1
      Nmap
  • 2.16
    Nibbles - Web Footprinting 1 topic
    • 2.16.1
      Directory Enumeration
  • 2.17
    Nibbles - Initial Foothold
  • 2.18
    Nibbles - Privilege Escalation
  • 2.19
    Nibbles - Alternate User Method - Metasploit 1 topic
    • 2.19.1
      Next Steps
  • 2.20
    Common Pitfalls 3 topics
    • 2.20.1
      VPN Issues 7 topics
      • 2.20.1.1
        Still Connected to VPN
      • 2.20.1.2
        Getting VPN Address
      • 2.20.1.3
        Checking Routing Table
      • 2.20.1.4
        Pinging Gateway
      • 2.20.1.5
        Working on Two Devices
      • 2.20.1.6
        Checking Region
      • 2.20.1.7
        VPN Troubleshooting
    • 2.20.2
      Burp Suite Proxy Issues 1 topic
      • 2.20.2.1
        Not Disabling Proxy
    • 2.20.3
      Changing SSH Key and Password
  • 2.21
    Getting Help 5 topics
    • 2.21.1
      Forum
    • 2.21.2
      Discord
    • 2.21.3
      Asking Questions Effectively
    • 2.21.4
      Answering Questions Effectively
    • 2.21.5
      Getting Technical Help
  • 2.22
    Next Steps 4 topics
    • 2.22.1
      Boxes & Challenges 3 topics
      • 2.22.1.1
        Root a Retired Easy Box
      • 2.22.1.2
        Complete a Retired Medium Box
      • 2.22.1.3
        Root Our First Live Box
    • 2.22.2
      Keep Learning
    • 2.22.3
      Giving Back 2 topics
      • 2.22.3.1
        Answer Questions
      • 2.22.3.2
        Share a Retired Box Walkthrough
    • 2.22.4
      Way Forward
  • 2.23
    Knowledge Check 1 topic
    • 2.23.1
      Tips
03 Network Enumeration with Nmap Network Enumeration with Nmap module 81 topics Module 3
  • 3.1
    Enumeration
  • 3.2
    Introduction to Nmap 4 topics
    • 3.2.1
      Use Cases
    • 3.2.2
      Nmap Architecture
    • 3.2.3
      Syntax
    • 3.2.4
      Scan Techniques
  • 3.3
    Host Discovery 4 topics
    • 3.3.1
      Scan Network Range
    • 3.3.2
      Scan IP List
    • 3.3.3
      Scan Multiple IPs
    • 3.3.4
      Scan Single IP 1 topic
      • 3.3.4.1
        Questions
  • 3.4
    Host and Port Scanning 3 topics
    • 3.4.1
      Discovering Open TCP Ports 6 topics
      • 3.4.1.1
        Scanning Top 10 TCP Ports
      • 3.4.1.2
        Nmap - Trace the Packets
      • 3.4.1.3
        Request
      • 3.4.1.4
        Response
      • 3.4.1.5
        Connect Scan
      • 3.4.1.6
        Connect Scan on TCP Port 443
    • 3.4.2
      Filtered Ports
    • 3.4.3
      Discovering Open UDP Ports 2 topics
      • 3.4.3.1
        UDP Port Scan
      • 3.4.3.2
        Version Scan
  • 3.5
    Saving the Results 2 topics
    • 3.5.1
      Different Formats 3 topics
      • 3.5.1.1
        Normal Output
      • 3.5.1.2
        Grepable Output
      • 3.5.1.3
        XML Output
    • 3.5.2
      Style sheets 1 topic
      • 3.5.2.1
        Nmap Report
  • 3.6
    Service Enumeration 2 topics
    • 3.6.1
      Service Version Detection
    • 3.6.2
      Banner Grabbing 3 topics
      • 3.6.2.1
        Tcpdump
      • 3.6.2.2
        Nc
      • 3.6.2.3
        Tcpdump - Intercepted Traffic
  • 3.7
    Nmap Scripting Engine 2 topics
    • 3.7.1
      Default Scripts 4 topics
      • 3.7.1.1
        Specific Scripts Category
      • 3.7.1.2
        Defined Scripts
      • 3.7.1.3
        Nmap - Specifying Scripts
      • 3.7.1.4
        Nmap - Aggressive Scan
    • 3.7.2
      Vulnerability Assessment 1 topic
      • 3.7.2.1
        Nmap - Vuln Category
  • 3.8
    Performance 4 topics
    • 3.8.1
      Timeouts 2 topics
      • 3.8.1.1
        Default Scan
      • 3.8.1.2
        Optimized RTT
    • 3.8.2
      Max Retries 2 topics
      • 3.8.2.1
        Default Scan
      • 3.8.2.2
        Reduced Retries
    • 3.8.3
      Rates 4 topics
      • 3.8.3.1
        Default Scan
      • 3.8.3.2
        Optimized Scan
      • 3.8.3.3
        Default Scan - Found Open Ports
      • 3.8.3.4
        Optimized Scan - Found Open Ports
    • 3.8.4
      Timing 4 topics
      • 3.8.4.1
        Default Scan
      • 3.8.4.2
        Insane Scan
      • 3.8.4.3
        Default Scan - Found Open Ports
      • 3.8.4.4
        Insane Scan - Found Open Ports
  • 3.9
    Firewall and IDS/IPS Evasion 6 topics
    • 3.9.1
      Firewalls
    • 3.9.2
      IDS/IPS 3 topics
      • 3.9.2.1
        Determine Firewalls and Their Rules
      • 3.9.2.2
        SYN-Scan
      • 3.9.2.3
        ACK-Scan
    • 3.9.3
      Detect IDS/IPS
    • 3.9.4
      Decoys 3 topics
      • 3.9.4.1
        Scan by Using Decoys
      • 3.9.4.2
        Testing Firewall Rule
      • 3.9.4.3
        Scan by Using Different Source IP
    • 3.9.5
      DNS Proxying 3 topics
      • 3.9.5.1
        SYN-Scan of a Filtered Port
      • 3.9.5.2
        SYN-Scan From DNS Port
      • 3.9.5.3
        Connect To The Filtered Port
    • 3.9.6
      Firewall and IDS/IPS Evasion Labs
  • 3.10
    Firewall and IDS/IPS Evasion - Easy Lab
  • 3.11
    Firewall and IDS/IPS Evasion - Medium Lab
  • 3.12
    Firewall and IDS/IPS Evasion - Hard Lab
04 Footprinting Footprinting module 208 topics Module 4
  • 4.1
    Enumeration Principles
  • 4.2
    Enumeration Methodology 7 topics
    • 4.2.1
      Layer No.1: Internet Presence
    • 4.2.2
      Layer No.2: Gateway
    • 4.2.3
      Layer No.3: Accessible Services
    • 4.2.4
      Layer No.4: Processes
    • 4.2.5
      Layer No.5: Privileges
    • 4.2.6
      Layer No.6: OS Setup
    • 4.2.7
      Enumeration Methodology in Practice
  • 4.3
    Domain Information 1 topic
    • 4.3.1
      Online Presence 4 topics
      • 4.3.1.1
        Certificate Transparency
      • 4.3.1.2
        Company Hosted Servers
      • 4.3.1.3
        Shodan - IP List
      • 4.3.1.4
        DNS Records
  • 4.4
    Cloud Resources 1 topic
    • 4.4.1
      Company Hosted Servers 7 topics
      • 4.4.1.1
        Google Search for AWS
      • 4.4.1.2
        Google Search for Azure
      • 4.4.1.3
        Target Website - Source Code
      • 4.4.1.4
        Domain.Glass Results
      • 4.4.1.5
        GrayHatWarfare Results
      • 4.4.1.6
        Private and Public SSH Keys Leaked
      • 4.4.1.7
        SSH Private Key
  • 4.5
    Staff 1 topic
    • 4.5.1
      LinkedIn - Job Post 3 topics
      • 4.5.1.1
        LinkedIn - Employee #1 About
      • 4.5.1.2
        Github
      • 4.5.1.3
        LinkedIn - Employee #2 Career
  • 4.6
    FTP 4 topics
    • 4.6.1
      TFTP
    • 4.6.2
      Default Configuration 3 topics
      • 4.6.2.1
        Install vsFTPd
      • 4.6.2.2
        vsFTPd Config File
      • 4.6.2.3
        FTPUSERS
    • 4.6.3
      Dangerous Settings 8 topics
      • 4.6.3.1
        Anonymous Login
      • 4.6.3.2
        vsFTPd Status
      • 4.6.3.3
        vsFTPd Detailed Output
      • 4.6.3.4
        Hiding IDs - YES
      • 4.6.3.5
        Recursive Listing
      • 4.6.3.6
        Download a File
      • 4.6.3.7
        Download All Available Files
      • 4.6.3.8
        Upload a File
    • 4.6.4
      Footprinting the Service 4 topics
      • 4.6.4.1
        Nmap FTP Scripts
      • 4.6.4.2
        Nmap
      • 4.6.4.3
        Nmap Script Trace
      • 4.6.4.4
        Service Interaction
  • 4.7
    SMB 4 topics
    • 4.7.1
      Samba
    • 4.7.2
      Default Configuration 1 topic
      • 4.7.2.1
        Default Configuration
    • 4.7.3
      Dangerous Settings 5 topics
      • 4.7.3.1
        Example Share
      • 4.7.3.2
        Restart Samba
      • 4.7.3.3
        SMBclient - Connecting to the Share
      • 4.7.3.4
        Download Files from SMB
      • 4.7.3.5
        Samba Status
    • 4.7.4
      Footprinting the Service 11 topics
      • 4.7.4.1
        Nmap
      • 4.7.4.2
        RPCclient
      • 4.7.4.3
        RPCclient - Enumeration
      • 4.7.4.4
        Rpcclient - User Enumeration
      • 4.7.4.5
        Rpcclient - Group Information
      • 4.7.4.6
        Brute Forcing User RIDs
      • 4.7.4.7
        Impacket - Samrdump.py
      • 4.7.4.8
        SMBmap
      • 4.7.4.9
        CrackMapExec
      • 4.7.4.10
        Enum4Linux-ng - Installation
      • 4.7.4.11
        Enum4Linux-ng - Enumeration
  • 4.8
    NFS 3 topics
    • 4.8.1
      Default Configuration 2 topics
      • 4.8.1.1
        Exports File
      • 4.8.1.2
        ExportFS
    • 4.8.2
      Dangerous Settings
    • 4.8.3
      Footprinting the Service 6 topics
      • 4.8.3.1
        Nmap
      • 4.8.3.2
        Show Available NFS Shares
      • 4.8.3.3
        Mounting NFS Share
      • 4.8.3.4
        List Contents with Usernames & Group Names
      • 4.8.3.5
        List Contents with UIDs & GUIDs
      • 4.8.3.6
        Unmounting
  • 4.9
    DNS 3 topics
    • 4.9.1
      Default Configuration 3 topics
      • 4.9.1.1
        Local DNS Configuration
      • 4.9.1.2
        Zone Files
      • 4.9.1.3
        Reverse Name Resolution Zone Files
    • 4.9.2
      Dangerous Settings
    • 4.9.3
      Footprinting the Service 6 topics
      • 4.9.3.1
        DIG - NS Query
      • 4.9.3.2
        DIG - Version Query
      • 4.9.3.3
        DIG - ANY Query
      • 4.9.3.4
        DIG - AXFR Zone Transfer
      • 4.9.3.5
        DIG - AXFR Zone Transfer - Internal
      • 4.9.3.6
        Subdomain Brute Forcing
  • 4.10
    SMTP 3 topics
    • 4.10.1
      Default Configuration 4 topics
      • 4.10.1.1
        Default Configuration
      • 4.10.1.2
        Telnet - HELO/EHLO
      • 4.10.1.3
        Telnet - VRFY
      • 4.10.1.4
        Send an Email
    • 4.10.2
      Dangerous Settings 1 topic
      • 4.10.2.1
        Open Relay Configuration
    • 4.10.3
      Footprinting the Service 2 topics
      • 4.10.3.1
        Nmap
      • 4.10.3.2
        Nmap - Open Relay
  • 4.11
    IMAP / POP3 3 topics
    • 4.11.1
      Default Configuration 2 topics
      • 4.11.1.1
        IMAP Commands
      • 4.11.1.2
        POP3 Commands
    • 4.11.2
      Dangerous Settings
    • 4.11.3
      Footprinting the Service 4 topics
      • 4.11.3.1
        Nmap
      • 4.11.3.2
        cURL
      • 4.11.3.3
        OpenSSL - TLS Encrypted Interaction POP3
      • 4.11.3.4
        OpenSSL - TLS Encrypted Interaction IMAP
  • 4.12
    SNMP 4 topics
    • 4.12.1
      MIB 5 topics
      • 4.12.1.1
        OID
      • 4.12.1.2
        SNMPv1
      • 4.12.1.3
        SNMPv2
      • 4.12.1.4
        SNMPv3
      • 4.12.1.5
        Community Strings
    • 4.12.2
      Default Configuration 1 topic
      • 4.12.2.1
        SNMP Daemon Config
    • 4.12.3
      Dangerous Settings
    • 4.12.4
      Footprinting the Service 3 topics
      • 4.12.4.1
        SNMPwalk
      • 4.12.4.2
        OneSixtyOne
      • 4.12.4.3
        Braa
  • 4.13
    MySQL 4 topics
    • 4.13.1
      MySQL Clients 2 topics
      • 4.13.1.1
        MySQL Databases
      • 4.13.1.2
        MySQL Commands
    • 4.13.2
      Default Configuration 1 topic
      • 4.13.2.1
        Default Configuration
    • 4.13.3
      Dangerous Settings
    • 4.13.4
      Footprinting the Service 2 topics
      • 4.13.4.1
        Scanning MySQL Server
      • 4.13.4.2
        Interaction with the MySQL Server
  • 4.14
    MSSQL 4 topics
    • 4.14.1
      MSSQL Clients 1 topic
      • 4.14.1.1
        MSSQL Databases
    • 4.14.2
      Default Configuration
    • 4.14.3
      Dangerous Settings
    • 4.14.4
      Footprinting the Service 3 topics
      • 4.14.4.1
        NMAP MSSQL Script Scan
      • 4.14.4.2
        MSSQL Ping in Metasploit
      • 4.14.4.3
        Connecting with Mssqlclient.py
  • 4.15
    Oracle TNS 1 topic
    • 4.15.1
      Default Configuration 12 topics
      • 4.15.1.1
        Tnsnames.ora
      • 4.15.1.2
        Listener.ora
      • 4.15.1.3
        Oracle-Tools-setup.sh
      • 4.15.1.4
        Testing ODAT
      • 4.15.1.5
        Nmap
      • 4.15.1.6
        Nmap - SID Bruteforcing
      • 4.15.1.7
        ODAT
      • 4.15.1.8
        SQLplus - Log In
      • 4.15.1.9
        Oracle RDBMS - Interaction
      • 4.15.1.10
        Oracle RDBMS - Database Enumeration
      • 4.15.1.11
        Oracle RDBMS - Extract Password Hashes
      • 4.15.1.12
        Oracle RDBMS - File Upload
  • 4.16
    IPMI 2 topics
    • 4.16.1
      Footprinting the Service 2 topics
      • 4.16.1.1
        Nmap
      • 4.16.1.2
        Metasploit Version Scan
    • 4.16.2
      Dangerous Settings 1 topic
      • 4.16.2.1
        Metasploit Dumping Hashes
  • 4.17
    Linux Remote Management Protocols 7 topics
    • 4.17.1
      SSH 1 topic
      • 4.17.1.1
        Public Key Authentication
    • 4.17.2
      Default Configuration 1 topic
      • 4.17.2.1
        Default Configuration
    • 4.17.3
      Dangerous Settings
    • 4.17.4
      Footprinting the Service 2 topics
      • 4.17.4.1
        SSH-Audit
      • 4.17.4.2
        Change Authentication Method
    • 4.17.5
      Rsync 3 topics
      • 4.17.5.1
        Scanning for Rsync
      • 4.17.5.2
        Probing for Accessible Shares
      • 4.17.5.3
        Enumerating an Open Share
    • 4.17.6
      R-Services 7 topics
      • 4.17.6.1
        /etc/hosts.equiv
      • 4.17.6.2
        Scanning for R-Services
      • 4.17.6.3
        Access Control & Trusted Relationships
      • 4.17.6.4
        Sample .rhosts File
      • 4.17.6.5
        Logging in Using Rlogin
      • 4.17.6.6
        Listing Authenticated Users Using Rwho
      • 4.17.6.7
        Listing Authenticated Users Using Rusers
    • 4.17.7
      Final Thoughts
  • 4.18
    Windows Remote Management Protocols 6 topics
    • 4.18.1
      RDP
    • 4.18.2
      Footprinting the Service 4 topics
      • 4.18.2.1
        Nmap
      • 4.18.2.2
        RDP Security Check - Installation
      • 4.18.2.3
        RDP Security Check
      • 4.18.2.4
        Initiate an RDP Session
    • 4.18.3
      WinRM
    • 4.18.4
      Footprinting the Service 1 topic
      • 4.18.4.1
        Nmap WinRM
    • 4.18.5
      WMI
    • 4.18.6
      Footprinting the Service 1 topic
      • 4.18.6.1
        WMIexec.py
  • 4.19
    Footprinting Lab - Easy
  • 4.20
    Footprinting Lab - Medium
  • 4.21
    Footprinting Lab - Hard
05 Information Gathering - Web Edition Information Gathering - Web Edition module 93 topics Module 5
  • 5.1
    Introduction 1 topic
    • 5.1.1
      Types of Reconnaissance 2 topics
      • 5.1.1.1
        Active Reconnaissance
      • 5.1.1.2
        Passive Reconnaissance
  • 5.2
    WHOIS 2 topics
    • 5.2.1
      History of WHOIS 4 topics
      • 5.2.1.1
        Formalisation and Standardization
      • 5.2.1.2
        The Rise of Distributed WHOIS and RIRs
      • 5.2.1.3
        ICANN and the Modernization of WHOIS
      • 5.2.1.4
        Privacy Concerns and the GDPR Era
    • 5.2.2
      Why WHOIS Matters for Web Recon
  • 5.3
    Utilising WHOIS 4 topics
    • 5.3.1
      Scenario 1: Phishing Investigation
    • 5.3.2
      Scenario 2: Malware Analysis
    • 5.3.3
      Scenario 3: Threat Intelligence Report
    • 5.3.4
      Using WHOIS
  • 5.4
    DNS 2 topics
    • 5.4.1
      How DNS Works 3 topics
      • 5.4.1.1
        The Hosts File
      • 5.4.1.2
        It's Like a Relay Race
      • 5.4.1.3
        Key DNS Concepts
    • 5.4.2
      Why DNS Matters for Web Recon
  • 5.5
    Digging DNS 3 topics
    • 5.5.1
      DNS Tools
    • 5.5.2
      The Domain Information Groper 1 topic
      • 5.5.2.1
        Common dig Commands
    • 5.5.3
      Groping DNS
  • 5.6
    Subdomains 2 topics
    • 5.6.1
      Why is this important for web reconnaissance?
    • 5.6.2
      Subdomain Enumeration 2 topics
      • 5.6.2.1
        Active Subdomain Enumeration
      • 5.6.2.2
        Passive Subdomain Enumeration
  • 5.7
    Subdomain Bruteforcing 1 topic
    • 5.7.1
      DNSEnum
  • 5.8
    DNS Zone Transfers 2 topics
    • 5.8.1
      What is a Zone Transfer
    • 5.8.2
      The Zone Transfer Vulnerability 2 topics
      • 5.8.2.1
        Remediation
      • 5.8.2.2
        Exploiting Zone Transfers
  • 5.9
    Virtual Hosts 2 topics
    • 5.9.1
      How Virtual Hosts Work: Understanding VHosts and Subdomains 2 topics
      • 5.9.1.1
        Server VHost Lookup
      • 5.9.1.2
        Types of Virtual Hosting
    • 5.9.2
      Virtual Host Discovery Tools 1 topic
      • 5.9.2.1
        gobuster
  • 5.10
    Certificate Transparency Logs 4 topics
    • 5.10.1
      What are Certificate Transparency Logs?
    • 5.10.2
      How Certificate Transparency Logs Work 1 topic
      • 5.10.2.1
        The Merkle Tree Structure
    • 5.10.3
      CT Logs and Web Recon
    • 5.10.4
      Searching CT Logs 1 topic
      • 5.10.4.1
        crt.sh lookup
  • 5.11
    Fingerprinting 2 topics
    • 5.11.1
      Fingerprinting Techniques
    • 5.11.2
      Fingerprinting inlanefreight.com 3 topics
      • 5.11.2.1
        Banner Grabbing
      • 5.11.2.2
        Wafw00f
      • 5.11.2.3
        Nikto
  • 5.12
    Crawling 2 topics
    • 5.12.1
      How Web Crawlers Work 2 topics
      • 5.12.1.1
        Breadth-First Crawling
      • 5.12.1.2
        Depth-First Crawling
    • 5.12.2
      Extracting Valuable Information 1 topic
      • 5.12.2.1
        The Importance of Context
  • 5.13
    robots.txt 2 topics
    • 5.13.1
      What is robots.txt? 3 topics
      • 5.13.1.1
        How robots.txt Works
      • 5.13.1.2
        Understanding robots.txt Structure
      • 5.13.1.3
        Why Respect robots.txt?
    • 5.13.2
      robots.txt in Web Reconnaissance 1 topic
      • 5.13.2.1
        Analyzing robots.txt
  • 5.14
    Well-Known URIs 1 topic
    • 5.14.1
      Web Recon and .well-known
  • 5.15
    Creepy Crawlies 2 topics
    • 5.15.1
      Popular Web Crawlers
    • 5.15.2
      Scrapy 3 topics
      • 5.15.2.1
        Installing Scrapy
      • 5.15.2.2
        ReconSpider
      • 5.15.2.3
        results.json
  • 5.16
    Search Engine Discovery 2 topics
    • 5.16.1
      Why Search Engine Discovery Matters
    • 5.16.2
      Search Operators 1 topic
      • 5.16.2.1
        Google Dorking
  • 5.17
    Web Archives 3 topics
    • 5.17.1
      What is the Wayback Machine? 1 topic
      • 5.17.1.1
        How Does the Wayback Machine Work?
    • 5.17.2
      Why the Wayback Machine Matters for Web Reconnaissance
    • 5.17.3
      Going Wayback on HTB
  • 5.18
    Automating Recon 2 topics
    • 5.18.1
      Why Automate Reconnaissance?
    • 5.18.2
      Reconnaissance Frameworks 1 topic
      • 5.18.2.1
        FinalRecon
  • 5.19
    Skills Assessment
06 Vulnerability Assessment Vulnerability Assessment module 109 topics Module 6
  • 6.1
    Security Assessments 5 topics
    • 6.1.1
      Vulnerability Assessment
    • 6.1.2
      Penetration Test
    • 6.1.3
      Vulnerability Assessments vs. Penetration Tests
    • 6.1.4
      Other Types of Security Assessments 4 topics
      • 6.1.4.1
        Security Audits
      • 6.1.4.2
        Bug Bounties
      • 6.1.4.3
        Red Team Assessment
      • 6.1.4.4
        Purple Team Assessment
    • 6.1.5
      Moving on
  • 6.2
    Vulnerability Assessment 4 topics
    • 6.2.1
      Methodology
    • 6.2.2
      Understanding Key Terms 4 topics
      • 6.2.2.1
        Vulnerability
      • 6.2.2.2
        Threat
      • 6.2.2.3
        Exploit
      • 6.2.2.4
        Risk
    • 6.2.3
      Asset Management 2 topics
      • 6.2.3.1
        Asset Inventory
      • 6.2.3.2
        Application and System Inventory
    • 6.2.4
      Onwards
  • 6.3
    Assessment Standards 2 topics
    • 6.3.1
      Compliance Standards 4 topics
      • 6.3.1.1
        Payment Card Industry Data Security Standard (PCI DSS)
      • 6.3.1.2
        Health Insurance Portability and Accountability Act (HIPAA)
      • 6.3.1.3
        Federal Information Security Management Act (FISMA)
      • 6.3.1.4
        ISO 27001
    • 6.3.2
      Penetration Testing Standards 4 topics
      • 6.3.2.1
        PTES
      • 6.3.2.2
        OSSTMM
      • 6.3.2.3
        NIST
      • 6.3.2.4
        OWASP
  • 6.4
    Common Vulnerability Scoring System (CVSS) 6 topics
    • 6.4.1
      Severity Scoring
    • 6.4.2
      Base Metric Group 2 topics
      • 6.4.2.1
        Exploitability Metrics
      • 6.4.2.2
        Impact Metrics
    • 6.4.3
      Temporal Metric Group 3 topics
      • 6.4.3.1
        Exploit Code Maturity
      • 6.4.3.2
        Remediation Level
      • 6.4.3.3
        Report Confidence
    • 6.4.4
      Environmental Metric Group 1 topic
      • 6.4.4.1
        Modified Base Metrics
    • 6.4.5
      Calculating CVSS Severity 1 topic
      • 6.4.5.1
        CVSS Calculation Example
    • 6.4.6
      Next Steps
  • 6.5
    Common Vulnerabilities and Exposures (CVE) 6 topics
    • 6.5.1
      Open Vulnerability Assessment Language (OVAL) 2 topics
      • 6.5.1.1
        OVAL Process
      • 6.5.1.2
        OVAL Definitions
    • 6.5.2
      Common Vulnerabilities and Exposures (CVE)
    • 6.5.3
      Stages of Obtaining a CVE 9 topics
      • 6.5.3.1
        Stage 1: Identify if CVE is Required and Relevant
      • 6.5.3.2
        Stage 2: Reach Out to Affected Product Vendor
      • 6.5.3.3
        Stage 3: Identify if Request Should Be For Vendor CNA or Third Party CNA
      • 6.5.3.4
        Stage 4: Requesting CVE ID Through CVE Web Form
      • 6.5.3.5
        Stage 5: Confirmation of CVE Form
      • 6.5.3.6
        Stage 6: Receival of CVE ID
      • 6.5.3.7
        Stage 7: Public Disclosure of CVE ID
      • 6.5.3.8
        Stage 8: Announcing the CVE
      • 6.5.3.9
        Stage 9: Providing Information to The CVE Team
    • 6.5.4
      Responsible Disclosure
    • 6.5.5
      Examples 2 topics
      • 6.5.5.1
        CVE-2020-5902
      • 6.5.5.2
        CVE-2021-34527
    • 6.5.6
      Getting Hands-on
  • 6.6
    Vulnerability Scanning Overview 2 topics
    • 6.6.1
      Nessus Overview
    • 6.6.2
      OpenVAS Overview
  • 6.7
    Getting Started with Nessus 5 topics
    • 6.7.1
      Downloading Nessus
    • 6.7.2
      Requesting Free License
    • 6.7.3
      Installing Package
    • 6.7.4
      Starting Nessus
    • 6.7.5
      Accessing Nessus
  • 6.8
    Nessus Scan 4 topics
    • 6.8.1
      New Scan
    • 6.8.2
      Discovery
    • 6.8.3
      Assessment
    • 6.8.4
      Advanced
  • 6.9
    Advanced Settings 4 topics
    • 6.9.1
      Scan Policies
    • 6.9.2
      Creating a Scan Policy
    • 6.9.3
      Nessus Plugins
    • 6.9.4
      Scanning with Credentials
  • 6.10
    Working with Nessus Scan Output 2 topics
    • 6.10.1
      Nessus Reports
    • 6.10.2
      Exporting Nessus Scans
  • 6.11
    Scanning Issues 2 topics
    • 6.11.1
      Mitigating Issues
    • 6.11.2
      Network Impact
  • 6.12
    Nessus Skills Assessment 1 topic
    • 6.12.1
      Requirements
  • 6.13
    Getting Started with OpenVAS 2 topics
    • 6.13.1
      Installing Package
    • 6.13.2
      Starting OpenVas
  • 6.14
    OpenVAS Scan 2 topics
    • 6.14.1
      Configuration
    • 6.14.2
      Setting Up a Scan
  • 6.15
    Exporting The Results 1 topic
    • 6.15.1
      Exporting Formats
  • 6.16
    OpenVAS Skills Assessment 1 topic
    • 6.16.1
      Requirements
  • 6.17
    Reporting 5 topics
    • 6.17.1
      Executive Summary
    • 6.17.2
      Overview of Assessment
    • 6.17.3
      Scope and Duration
    • 6.17.4
      Vulnerabilities and Recommendations
    • 6.17.5
      Closing
07 File Transfers File Transfers module 175 topics Module 7
  • 7.1
    File Transfers
  • 7.2
    Windows File Transfer Methods 24 topics
    • 7.2.1
      Introduction
    • 7.2.2
      Download Operations
    • 7.2.3
      PowerShell Base64 Encode & Decode 3 topics
      • 7.2.3.1
        Pwnbox Check SSH Key MD5 Hash
      • 7.2.3.2
        Pwnbox Encode SSH Key to Base64
      • 7.2.3.3
        Confirming the MD5 Hashes Match
    • 7.2.4
      PowerShell Web Downloads 5 topics
      • 7.2.4.1
        PowerShell DownloadFile Method
      • 7.2.4.2
        File Download
      • 7.2.4.3
        PowerShell DownloadString - Fileless Method
      • 7.2.4.4
        PowerShell Invoke-WebRequest
      • 7.2.4.5
        Common Errors with PowerShell
    • 7.2.5
      SMB Downloads 4 topics
      • 7.2.5.1
        Create the SMB Server
      • 7.2.5.2
        Copy a File from the SMB Server
      • 7.2.5.3
        Create the SMB Server with a Username and Password
      • 7.2.5.4
        Mount the SMB Server with Username and Password
    • 7.2.6
      FTP Downloads 4 topics
      • 7.2.6.1
        Installing the FTP Server Python3 Module - pyftpdlib
      • 7.2.6.2
        Setting up a Python3 FTP Server
      • 7.2.6.3
        Transfering Files from an FTP Server Using PowerShell
      • 7.2.6.4
        Create a Command File for the FTP Client and Download the Target File
    • 7.2.7
      Upload Operations
    • 7.2.8
      PowerShell Base64 Encode & Decode 2 topics
      • 7.2.8.1
        Encode File Using PowerShell
      • 7.2.8.2
        Decode Base64 String in Linux
    • 7.2.9
      PowerShell Web Uploads 3 topics
      • 7.2.9.1
        Installing a Configured WebServer with Upload
      • 7.2.9.2
        PowerShell Script to Upload a File to Python Upload Server
      • 7.2.9.3
        PowerShell Base64 Web Upload
    • 7.2.10
      SMB Uploads 5 topics
      • 7.2.10.1
        Configuring WebDav Server
      • 7.2.10.2
        Installing WebDav Python modules
      • 7.2.10.3
        Using the WebDav Python module
      • 7.2.10.4
        Connecting to the Webdav Share
      • 7.2.10.5
        Uploading Files using SMB
    • 7.2.11
      FTP Uploads 2 topics
      • 7.2.11.1
        PowerShell Upload File
      • 7.2.11.2
        Create a Command File for the FTP Client to Upload a File
    • 7.2.12
      Recap
    • 7.2.13
      Linux File Transfer Methods
    • 7.2.14
      Download Operations
    • 7.2.15
      Base64 Encoding / Decoding 4 topics
      • 7.2.15.1
        Pwnbox - Check File MD5 hash
      • 7.2.15.2
        Pwnbox - Encode SSH Key to Base64
      • 7.2.15.3
        Linux - Decode the File
      • 7.2.15.4
        Linux - Confirm the MD5 Hashes Match
    • 7.2.16
      Web Downloads with Wget and cURL 2 topics
      • 7.2.16.1
        Download a File Using wget
      • 7.2.16.2
        Download a File Using cURL
    • 7.2.17
      Fileless Attacks Using Linux 2 topics
      • 7.2.17.1
        Fileless Download with cURL
      • 7.2.17.2
        Fileless Download with wget
    • 7.2.18
      Download with Bash (/dev/tcp) 3 topics
      • 7.2.18.1
        Connect to the Target Webserver
      • 7.2.18.2
        HTTP GET Request
      • 7.2.18.3
        Print the Response
    • 7.2.19
      SSH Downloads 4 topics
      • 7.2.19.1
        Enabling the SSH Server
      • 7.2.19.2
        Starting the SSH Server
      • 7.2.19.3
        Checking for SSH Listening Port
      • 7.2.19.4
        Linux - Downloading Files Using SCP
    • 7.2.20
      Upload Operations
    • 7.2.21
      Web Upload 4 topics
      • 7.2.21.1
        Pwnbox - Start Web Server
      • 7.2.21.2
        Pwnbox - Create a Self-Signed Certificate
      • 7.2.21.3
        Pwnbox - Start Web Server
      • 7.2.21.4
        Linux - Upload Multiple Files
    • 7.2.22
      Alternative Web File Transfer Method 5 topics
      • 7.2.22.1
        Linux - Creating a Web Server with Python3
      • 7.2.22.2
        Linux - Creating a Web Server with Python2.7
      • 7.2.22.3
        Linux - Creating a Web Server with PHP
      • 7.2.22.4
        Linux - Creating a Web Server with Ruby
      • 7.2.22.5
        Download the File from the Target Machine onto the Pwnbox
    • 7.2.23
      SCP Upload 1 topic
      • 7.2.23.1
        File Upload using SCP
    • 7.2.24
      Onwards
  • 7.3
    Transferring Files with Code 7 topics
    • 7.3.1
      Python 2 topics
      • 7.3.1.1
        Python 2 - Download
      • 7.3.1.2
        Python 3 - Download
    • 7.3.2
      PHP 3 topics
      • 7.3.2.1
        PHP Download with File_get_contents()
      • 7.3.2.2
        PHP Download with Fopen()
      • 7.3.2.3
        PHP Download a File and Pipe it to Bash
    • 7.3.3
      Other Languages 2 topics
      • 7.3.3.1
        Ruby - Download a File
      • 7.3.3.2
        Perl - Download a File
    • 7.3.4
      JavaScript 1 topic
      • 7.3.4.1
        Download a File Using JavaScript and cscript.exe
    • 7.3.5
      VBScript 1 topic
      • 7.3.5.1
        Download a File Using VBScript and cscript.exe
    • 7.3.6
      Upload Operations using Python3 2 topics
      • 7.3.6.1
        Starting the Python uploadserver Module
      • 7.3.6.2
        Uploading a File Using a Python One-liner
    • 7.3.7
      Section Recap
  • 7.4
    Miscellaneous File Transfer Methods 5 topics
    • 7.4.1
      Netcat
    • 7.4.2
      File Transfer with Netcat and Ncat 11 topics
      • 7.4.2.1
        NetCat - Compromised Machine - Listening on Port 8000
      • 7.4.2.2
        Ncat - Compromised Machine - Listening on Port 8000
      • 7.4.2.3
        Netcat - Attack Host - Sending File to Compromised machine
      • 7.4.2.4
        Ncat - Attack Host - Sending File to Compromised machine
      • 7.4.2.5
        Attack Host - Sending File as Input to Netcat
      • 7.4.2.6
        Compromised Machine Connect to Netcat to Receive the File
      • 7.4.2.7
        Attack Host - Sending File as Input to Ncat
      • 7.4.2.8
        Compromised Machine Connect to Ncat to Receive the File
      • 7.4.2.9
        NetCat - Sending File as Input to Netcat
      • 7.4.2.10
        Ncat - Sending File as Input to Ncat
      • 7.4.2.11
        Compromised Machine Connecting to Netcat Using /dev/tcp to Receive the File
    • 7.4.3
      PowerShell Session File Transfer 4 topics
      • 7.4.3.1
        From DC01 - Confirm WinRM port TCP 5985 is Open on DATABASE01.
      • 7.4.3.2
        Create a PowerShell Remoting Session to DATABASE01
      • 7.4.3.3
        Copy samplefile.txt from our Localhost to the DATABASE01 Session
      • 7.4.3.4
        Copy DATABASE.txt from DATABASE01 Session to our Localhost
    • 7.4.4
      RDP 2 topics
      • 7.4.4.1
        Mounting a Linux Folder Using rdesktop
      • 7.4.4.2
        Mounting a Linux Folder Using xfreerdp
    • 7.4.5
      Practice Makes Perfect
  • 7.5
    Protected File Transfers 2 topics
    • 7.5.1
      File Encryption on Windows 3 topics
      • 7.5.1.1
        Invoke-AESEncryption.ps1
      • 7.5.1.2
        Import Module Invoke-AESEncryption.ps1
      • 7.5.1.3
        File Encryption Example
    • 7.5.2
      File Encryption on Linux 2 topics
      • 7.5.2.1
        Encrypting /etc/passwd with openssl
      • 7.5.2.2
        Decrypt passwd.enc with openssl
  • 7.6
    Catching Files over HTTP/S 3 topics
    • 7.6.1
      HTTP/S
    • 7.6.2
      Nginx - Enabling PUT 8 topics
      • 7.6.2.1
        Create a Directory to Handle Uploaded Files
      • 7.6.2.2
        Change the Owner to www-data
      • 7.6.2.3
        Create Nginx Configuration File
      • 7.6.2.4
        Symlink our Site to the sites-enabled Directory
      • 7.6.2.5
        Start Nginx
      • 7.6.2.6
        Verifying Errors
      • 7.6.2.7
        Remove NginxDefault Configuration
      • 7.6.2.8
        Upload File Using cURL
    • 7.6.3
      Using Built-in Tools
  • 7.7
    Living off The Land 3 topics
    • 7.7.1
      Using the LOLBAS and GTFOBins Project 7 topics
      • 7.7.1.1
        LOLBAS
      • 7.7.1.2
        Upload win.ini to our Pwnbox
      • 7.7.1.3
        File Received in our Netcat Session
      • 7.7.1.4
        GTFOBins
      • 7.7.1.5
        Create Certificate in our Pwnbox
      • 7.7.1.6
        Stand up the Server in our Pwnbox
      • 7.7.1.7
        Download File from the Compromised Machine
    • 7.7.2
      Other Common Living off the Land tools 5 topics
      • 7.7.2.1
        Bitsadmin Download function
      • 7.7.2.2
        File Download with Bitsadmin
      • 7.7.2.3
        Download
      • 7.7.2.4
        Certutil
      • 7.7.2.5
        Download a File with Certutil
    • 7.7.3
      Extra Practice
  • 7.8
    Detection 1 topic
    • 7.8.1
      Invoke-WebRequest - Client 9 topics
      • 7.8.1.1
        Invoke-WebRequest - Server
      • 7.8.1.2
        WinHttpRequest - Client
      • 7.8.1.3
        WinHttpRequest - Server
      • 7.8.1.4
        Msxml2 - Client
      • 7.8.1.5
        Msxml2 - Server
      • 7.8.1.6
        Certutil - Client
      • 7.8.1.7
        Certutil - Server
      • 7.8.1.8
        BITS - Client
      • 7.8.1.9
        BITS - Server
  • 7.9
    Evading Detection 3 topics
    • 7.9.1
      Changing User Agent 2 topics
      • 7.9.1.1
        Listing out User Agents
      • 7.9.1.2
        Request with Chrome User Agent
    • 7.9.2
      LOLBAS / GTFOBins 1 topic
      • 7.9.2.1
        Transferring File with GfxDownloadWrapper.exe
    • 7.9.3
      Closing Thoughts
08 Shells & Payloads Shells & Payloads module 192 topics Module 8
  • 8.1
    Shells Jack Us In, Payloads Deliver Us Shells 2 topics
    • 8.1.1
      Why Get a Shell?
    • 8.1.2
      Payloads Deliver us Shells
  • 8.2
    CAT5 Security's Engagement Preparation 1 topic
    • 8.2.1
      Shell basics 6 topics
      • 8.2.1.1
        Payload Basics
      • 8.2.1.2
        Getting a Shell on Windows
      • 8.2.1.3
        Getting a Shell on Linux
      • 8.2.1.4
        Landing a Web Shell
      • 8.2.1.5
        Spotting a Shell or Payload
      • 8.2.1.6
        Final Challenge
  • 8.3
    Anatomy of a Shell 2 topics
    • 8.3.1
      Command Language Interpreters
    • 8.3.2
      Hands-on with Terminal Emulators and Shells 4 topics
      • 8.3.2.1
        Terminal Example
      • 8.3.2.2
        Shell Validation From 'ps'
      • 8.3.2.3
        Shell Validation Using 'env'
      • 8.3.2.4
        PowerShell vs. Bash
  • 8.4
    Bind Shells 3 topics
    • 8.4.1
      What Is It? 1 topic
      • 8.4.1.1
        Bind Example
    • 8.4.2
      Practicing with GNU Netcat 5 topics
      • 8.4.2.1
        No. 1: Server - Target starting Netcat listener
      • 8.4.2.2
        No. 2: Client - Attack box connecting to target
      • 8.4.2.3
        No. 3: Server - Target receiving connection from client
      • 8.4.2.4
        No. 4: Client - Attack box sending message Hello Academy
      • 8.4.2.5
        No. 5: Server - Target receiving Hello Academy message
    • 8.4.3
      Establishing a Basic Bind Shell with Netcat 2 topics
      • 8.4.3.1
        No. 1: Server - Binding a Bash shell to the TCP session
      • 8.4.3.2
        No. 2: Client - Connecting to bind shell on target
  • 8.5
    Reverse Shells 2 topics
    • 8.5.1
      Reverse Shell Example
    • 8.5.2
      Hands-on With A Simple Reverse Shell in Windows 4 topics
      • 8.5.2.1
        Server ( attack box )
      • 8.5.2.2
        Client (target)
      • 8.5.2.3
        Disable AV
      • 8.5.2.4
        Server (attack box)
  • 8.6
    Introduction to Payloads 3 topics
    • 8.6.1
      One-Liners Examined 6 topics
      • 8.6.1.1
        Netcat/Bash Reverse Shell One-liner
      • 8.6.1.2
        Remove /tmp/f
      • 8.6.1.3
        Make A Named Pipe
      • 8.6.1.4
        Output Redirection
      • 8.6.1.5
        Set Shell Options
      • 8.6.1.6
        Open a Connection with Netcat
    • 8.6.2
      PowerShell One-liner Explained 11 topics
      • 8.6.2.1
        Powershell One-liner
      • 8.6.2.2
        Calling PowerShell
      • 8.6.2.3
        Binding A Socket
      • 8.6.2.4
        Setting The Command Stream
      • 8.6.2.5
        Empty Byte Stream
      • 8.6.2.6
        Stream Parameters
      • 8.6.2.7
        Set The Byte Encoding
      • 8.6.2.8
        Invoke-Expression
      • 8.6.2.9
        Show Working Directory
      • 8.6.2.10
        Sets Sendbyte
      • 8.6.2.11
        Terminate TCP Connection
    • 8.6.3
      Payloads Take Different Shapes and Forms
  • 8.7
    Automating Payloads & Delivery with Metasploit 1 topic
    • 8.7.1
      Practicing with Metasploit 8 topics
      • 8.7.1.1
        Starting MSF
      • 8.7.1.2
        NMAP Scan
      • 8.7.1.3
        Searching Within Metasploit
      • 8.7.1.4
        Option Selection
      • 8.7.1.5
        Examining an Exploit's Options
      • 8.7.1.6
        Setting Options
      • 8.7.1.7
        Exploits Away
      • 8.7.1.8
        Interactive Shell
  • 8.8
    Crafting Payloads with MSFvenom 6 topics
    • 8.8.1
      Practicing with MSFvenom 1 topic
      • 8.8.1.1
        List Payloads
    • 8.8.2
      Staged vs. Stageless Payloads
    • 8.8.3
      Building A Stageless Payload 7 topics
      • 8.8.3.1
        Build It
      • 8.8.3.2
        Call MSFvenom
      • 8.8.3.3
        Creating a Payload
      • 8.8.3.4
        Choosing the Payload based on Architecture
      • 8.8.3.5
        Address To Connect Back To
      • 8.8.3.6
        Format To Generate Payload In
      • 8.8.3.7
        Output
    • 8.8.4
      Executing a Stageless Payload 3 topics
      • 8.8.4.1
        Ubuntu Payload
      • 8.8.4.2
        NC Connection
      • 8.8.4.3
        Connection Established
    • 8.8.5
      Building a simple Stageless Payload for a Windows system 1 topic
      • 8.8.5.1
        Windows Payload
    • 8.8.6
      Executing a Simple Stageless Payload On a Windows System
  • 8.9
    Infiltrating Windows 8 topics
    • 8.9.1
      Windows Vulnerability Table
    • 8.9.2
      Prominent Windows Exploits
    • 8.9.3
      Enumerating Windows & Fingerprinting Methods 3 topics
      • 8.9.3.1
        Pinged Host
      • 8.9.3.2
        OS Detection Scan
      • 8.9.3.3
        Banner Grab to Enumerate Ports
    • 8.9.4
      Bats, DLLs, & MSI Files, Oh My! 1 topic
      • 8.9.4.1
        Payload Types to Consider
    • 8.9.5
      Tools, Tactics, and Procedures for Payload Generation, Transfer, and Execution 2 topics
      • 8.9.5.1
        Payload Generation
      • 8.9.5.2
        Payload Transfer and Execution:
    • 8.9.6
      Example Compromise Walkthrough 7 topics
      • 8.9.6.1
        Enumerate the Host
      • 8.9.6.2
        Determine an Exploit Path
      • 8.9.6.3
        Choose & Configure Our Exploit & Payload
      • 8.9.6.4
        Configure The Exploit & Payload
      • 8.9.6.5
        Validate Our Options
      • 8.9.6.6
        Execute Our Attack
      • 8.9.6.7
        Identify Our Shell
    • 8.9.7
      CMD-Prompt and Power[Shell]s for Fun and Profit.
    • 8.9.8
      WSL and PowerShell For Linux
  • 8.10
    Infiltrating Unix/Linux 5 topics
    • 8.10.1
      Common Considerations
    • 8.10.2
      Gaining a Shell Through Attacking a Vulnerable Application 2 topics
      • 8.10.2.1
        Enumerate the Host
      • 8.10.2.2
        rConfig Management Tool
    • 8.10.3
      Discovering a Vulnerability in rConfig 2 topics
      • 8.10.3.1
        Search For an Exploit Module
      • 8.10.3.2
        Locate
    • 8.10.4
      Using the rConfig Exploit and Gaining a Shell 3 topics
      • 8.10.4.1
        Select an Exploit
      • 8.10.4.2
        Execute the Exploit
      • 8.10.4.3
        Interact With the Shell
    • 8.10.5
      Spawning a TTY Shell with Python 1 topic
      • 8.10.5.1
        Interactive Python
  • 8.11
    Spawning Interactive Shells 9 topics
    • 8.11.1
      /bin/sh -i 1 topic
      • 8.11.1.1
        Interactive
    • 8.11.2
      Perl 1 topic
      • 8.11.2.1
        Perl To Shell
    • 8.11.3
      Ruby 1 topic
      • 8.11.3.1
        Ruby To Shell
    • 8.11.4
      Lua 1 topic
      • 8.11.4.1
        Lua To Shell
    • 8.11.5
      AWK 1 topic
      • 8.11.5.1
        AWK To Shell
    • 8.11.6
      Find 1 topic
      • 8.11.6.1
        Using Find For A Shell
    • 8.11.7
      Using Exec To Launch A Shell
    • 8.11.8
      VIM 2 topics
      • 8.11.8.1
        Vim To Shell
      • 8.11.8.2
        Vim Escape
    • 8.11.9
      Execution Permissions Considerations 2 topics
      • 8.11.9.1
        Permissions
      • 8.11.9.2
        Sudo -l
  • 8.12
    Introduction to Web Shells 1 topic
    • 8.12.1
      What is a Web Shell?
  • 8.13
    Laudanum, One Webshell to Rule Them All 2 topics
    • 8.13.1
      Working with Laudanum
    • 8.13.2
      Laudanum Demonstration 5 topics
      • 8.13.2.1
        Move a Copy for Modification
      • 8.13.2.2
        Modify the Shell for Use
      • 8.13.2.3
        Take Advantage of the Upload Function
      • 8.13.2.4
        Navigate to Our Shell
      • 8.13.2.5
        Shell Success
  • 8.14
    Antak Webshell 5 topics
    • 8.14.1
      ASPX and a Quick Learning Tip
    • 8.14.2
      ASPX Explained
    • 8.14.3
      Antak Webshell
    • 8.14.4
      Working with Antak
    • 8.14.5
      Antak Demonstration 4 topics
      • 8.14.5.1
        Move a Copy for Modification
      • 8.14.5.2
        Modify the Shell for Use
      • 8.14.5.3
        Shell Success
      • 8.14.5.4
        Issuing Commands
  • 8.15
    PHP Web Shells 4 topics
    • 8.15.1
      PHP Login Page
    • 8.15.2
      Hands-on With a PHP-Based Web Shell. 2 topics
      • 8.15.2.1
        Vendors Tab
      • 8.15.2.2
        Proxy Settings
    • 8.15.3
      Bypassing the File Type Restriction 3 topics
      • 8.15.3.1
        Post Request
      • 8.15.3.2
        Vendor Added
      • 8.15.3.3
        Webshell Success
    • 8.15.4
      Considerations when Dealing with Web Shells
  • 8.16
    The Live Engagement 5 topics
    • 8.16.1
      Scenario:
    • 8.16.2
      Objectives:
    • 8.16.3
      Credentials and Other Needed Info:
    • 8.16.4
      Connectivity To The Foothold 2 topics
      • 8.16.4.1
        XFreeRDP Login
      • 8.16.4.2
        Target Hosts
    • 8.16.5
      Hints
  • 8.17
    Detection & Prevention 6 topics
    • 8.17.1
      Monitoring 2 topics
      • 8.17.1.1
        ATT&CK Framework
      • 8.17.1.2
        Notable MITRE ATT&CK Tactics and Techniques:
    • 8.17.2
      Events To Watch For:
    • 8.17.3
      Establish Network Visibility 2 topics
      • 8.17.3.1
        Suspicious Traffic.. In Clear Text
      • 8.17.3.2
        Following the Traffic
    • 8.17.4
      Protecting End Devices
    • 8.17.5
      Potential Mitigations:
    • 8.17.6
      Sum It All Up
09 Using the Metasploit Framework Using the Metasploit Framework module 173 topics Module 9
  • 9.1
    Preface 2 topics
    • 9.1.1
      Discipline
    • 9.1.2
      Conclusion
  • 9.2
    Introduction to Metasploit 3 topics
    • 9.2.1
      Metasploit Pro
    • 9.2.2
      Metasploit Framework Console
    • 9.2.3
      Understanding the Architecture 6 topics
      • 9.2.3.1
        Data, Documentation, Lib
      • 9.2.3.2
        Modules
      • 9.2.3.3
        Plugins
      • 9.2.3.4
        Scripts
      • 9.2.3.5
        Tools
      • 9.2.3.6
        Questions
  • 9.3
    Introduction to MSFconsole 2 topics
    • 9.3.1
      Preparation 2 topics
      • 9.3.1.1
        Launching MSFconsole
      • 9.3.1.2
        Installing MSF
    • 9.3.2
      MSF Engagement Structure
  • 9.4
    Modules 4 topics
    • 9.4.1
      Syntax 6 topics
      • 9.4.1.1
        Example
      • 9.4.1.2
        Index No.
      • 9.4.1.3
        Type
      • 9.4.1.4
        OS
      • 9.4.1.5
        Service
      • 9.4.1.6
        Name
    • 9.4.2
      Searching for Modules 3 topics
      • 9.4.2.1
        MSF - Search Function
      • 9.4.2.2
        MSF - Searching for EternalRomance
      • 9.4.2.3
        MSF - Specific Search
    • 9.4.3
      Module Selection 1 topic
      • 9.4.3.1
        MSF - Search for MS17_010
    • 9.4.4
      Using Modules 6 topics
      • 9.4.4.1
        MSF - Select Module
      • 9.4.4.2
        MSF - Module Information
      • 9.4.4.3
        MSF - Target Specification
      • 9.4.4.4
        MSF - Permanent Target Specification
      • 9.4.4.5
        MSF - Exploit Execution
      • 9.4.4.6
        MSF - Target Interaction
  • 9.5
    Targets 3 topics
    • 9.5.1
      MSF - Show Targets
    • 9.5.2
      Selecting a Target 1 topic
      • 9.5.2.1
        MSF - Target Selection
    • 9.5.3
      Target Types
  • 9.6
    Payloads 6 topics
    • 9.6.1
      Singles 2 topics
      • 9.6.1.1
        Stagers
      • 9.6.1.2
        Stages
    • 9.6.2
      Staged Payloads 2 topics
      • 9.6.2.1
        MSF - Staged Payloads
      • 9.6.2.2
        Meterpreter Payload
    • 9.6.3
      Searching for Payloads 2 topics
      • 9.6.3.1
        MSF - List Payloads
      • 9.6.3.2
        MSF - Searching for Specific Payload
    • 9.6.4
      Selecting Payloads 1 topic
      • 9.6.4.1
        MSF - Select Payload
    • 9.6.5
      Using Payloads 4 topics
      • 9.6.5.1
        MSF - Exploit and Payload Configuration
      • 9.6.5.2
        MSF - Meterpreter Commands
      • 9.6.5.3
        MSF - Meterpreter Navigation
      • 9.6.5.4
        MSF - Windows CMD
    • 9.6.6
      Payload Types
  • 9.7
    Encoders 1 topic
    • 9.7.1
      Selecting an Encoder 4 topics
      • 9.7.1.1
        Generating Payload - Without Encoding
      • 9.7.1.2
        Generating Payload - With Encoding
      • 9.7.1.3
        Shikata Ga Nai Encoding
      • 9.7.1.4
        MSF - VirusTotal
  • 9.8
    Databases 9 topics
    • 9.8.1
      Setting up the Database 6 topics
      • 9.8.1.1
        PostgreSQL Status
      • 9.8.1.2
        Start PostgreSQL
      • 9.8.1.3
        MSF - Initiate a Database
      • 9.8.1.4
        MSF - Connect to the Initiated Database
      • 9.8.1.5
        MSF - Reinitiate the Database
      • 9.8.1.6
        MSF - Database Options
    • 9.8.2
      Using the Database 1 topic
      • 9.8.2.1
        Workspaces
    • 9.8.3
      Importing Scan Results 2 topics
      • 9.8.3.1
        Stored Nmap Scan
      • 9.8.3.2
        Importing Scan Results
    • 9.8.4
      Using Nmap Inside MSFconsole 1 topic
      • 9.8.4.1
        MSF - Nmap
    • 9.8.5
      Data Backup 1 topic
      • 9.8.5.1
        MSF - DB Export
    • 9.8.6
      Hosts 1 topic
      • 9.8.6.1
        MSF - Stored Hosts
    • 9.8.7
      Services 1 topic
      • 9.8.7.1
        MSF - Stored Services of Hosts
    • 9.8.8
      Credentials 1 topic
      • 9.8.8.1
        MSF - Stored Credentials
    • 9.8.9
      Loot 1 topic
      • 9.8.9.1
        MSF - Stored Loot
  • 9.9
    Plugins 3 topics
    • 9.9.1
      Using Plugins 1 topic
      • 9.9.1.1
        MSF - Load Nessus
    • 9.9.2
      Installing new Plugins 3 topics
      • 9.9.2.1
        Downloading MSF Plugins
      • 9.9.2.2
        MSF - Copying Plugin to MSF
      • 9.9.2.3
        MSF - Load Plugin
    • 9.9.3
      Mixins
  • 9.10
    Sessions 2 topics
    • 9.10.1
      Using Sessions 2 topics
      • 9.10.1.1
        Listing Active Sessions
      • 9.10.1.2
        Interacting with a Session
    • 9.10.2
      Jobs 4 topics
      • 9.10.2.1
        Viewing the Jobs Command Help Menu
      • 9.10.2.2
        Viewing the Exploit Command Help Menu
      • 9.10.2.3
        Running an Exploit as a Background Job
      • 9.10.2.4
        Listing Running Jobs
  • 9.11
    Meterpreter 5 topics
    • 9.11.1
      Running Meterpreter 1 topic
      • 9.11.1.1
        MSF - Meterpreter Commands
    • 9.11.2
      Stealthy
    • 9.11.3
      Powerful
    • 9.11.4
      Extensible
    • 9.11.5
      Using Meterpreter 9 topics
      • 9.11.5.1
        MSF - Scanning Target
      • 9.11.5.2
        MSF - Searching for Exploit
      • 9.11.5.3
        MSF - Configuring Exploit & Payload
      • 9.11.5.4
        MSF - Meterpreter Migration
      • 9.11.5.5
        MSF - Interacting with the Target
      • 9.11.5.6
        MSF - Session Handling
      • 9.11.5.7
        MSF - Privilege Escalation
      • 9.11.5.8
        MSF - Dumping Hashes
      • 9.11.5.9
        MSF - Meterpreter LSA Secrets Dump
  • 9.12
    Writing and Importing Modules 3 topics
    • 9.12.1
      MSF - Search for Exploits 3 topics
      • 9.12.1.1
        MSF - Directory Structure
      • 9.12.1.2
        MSF - Loading Additional Modules at Runtime
      • 9.12.1.3
        MSF - Loading Additional Modules
    • 9.12.2
      Porting Over Scripts into Metasploit Modules 1 topic
      • 9.12.2.1
        Porting MSF Modules
    • 9.12.3
      Writing Our Module 4 topics
      • 9.12.3.1
        Proof-of-Concept - Requirements
      • 9.12.3.2
        Proof-of-Concept - Module Information
      • 9.12.3.3
        Proof-of-Concept - Functions
      • 9.12.3.4
        Proof-of-Concept
  • 9.13
    Introduction to MSFVenom 3 topics
    • 9.13.1
      Creating Our Payloads 4 topics
      • 9.13.1.1
        Scanning the Target
      • 9.13.1.2
        FTP Anonymous Access
      • 9.13.1.3
        Generating Payload
      • 9.13.1.4
        MSF - Setting Up Multi/Handler
    • 9.13.2
      Executing the Payload 1 topic
      • 9.13.2.1
        MSF - Meterpreter Shell
    • 9.13.3
      Local Exploit Suggester 2 topics
      • 9.13.3.1
        MSF - Searching for Local Exploit Suggester
      • 9.13.3.2
        MSF - Local Privilege Escalation
  • 9.14
    Firewall and IDS/IPS Evasion 8 topics
    • 9.14.1
      Endpoint Protection 1 topic
      • 9.14.1.1
        Perimeter Protection
    • 9.14.2
      Security Policies
    • 9.14.3
      Evasion Techniques
    • 9.14.4
      Archives 7 topics
      • 9.14.4.1
        Generating Payload
      • 9.14.4.2
        VirusTotal
      • 9.14.4.3
        Archiving the Payload
      • 9.14.4.4
        Removing the .RAR Extension
      • 9.14.4.5
        Archiving the Payload Again
      • 9.14.4.6
        Removing the .RAR Extension
      • 9.14.4.7
        VirusTotal
    • 9.14.5
      Packers
    • 9.14.6
      Exploit Coding
    • 9.14.7
      Recompiling Meterpreter from Source Code
    • 9.14.8
      A Note on Evasion
  • 9.15
    Metasploit-Framework Updates - August 2020 6 topics
    • 9.15.1
      Generation Features
    • 9.15.2
      Expanded Encryption
    • 9.15.3
      Cleaner Payload Artifacts
    • 9.15.4
      Plugins
    • 9.15.5
      Payloads
    • 9.15.6
      Closing Thoughts
10 Password Attacks Password Attacks module 292 topics Module 10
  • 10.1
    Theory of Protection 3 topics
    • 10.1.1
      Authentication
    • 10.1.2
      The Use of Passwords
    • 10.1.3
      Digging In
  • 10.2
    Credential Storage 2 topics
    • 10.2.1
      Linux 2 topics
      • 10.2.1.1
        Shadow File
      • 10.2.1.2
        Passwd File
    • 10.2.2
      Windows Authentication Process 5 topics
      • 10.2.2.1
        Windows Authentication Process Diagram
      • 10.2.2.2
        LSASS
      • 10.2.2.3
        SAM Database
      • 10.2.2.4
        Credential Manager
      • 10.2.2.5
        NTDS
  • 10.3
    John The Ripper 4 topics
    • 10.3.1
      Encryption Technologies
    • 10.3.2
      Attack Methods 3 topics
      • 10.3.2.1
        Dictionary Attacks
      • 10.3.2.2
        Brute Force Attacks
      • 10.3.2.3
        Rainbow Table Attacks
    • 10.3.3
      Cracking Modes 5 topics
      • 10.3.3.1
        Single Crack Mode
      • 10.3.3.2
        Cracking with John
      • 10.3.3.3
        Wordlist Mode
      • 10.3.3.4
        Incremental Mode
      • 10.3.3.5
        Incremental Mode in John
    • 10.3.4
      Cracking Files 1 topic
      • 10.3.4.1
        Cracking Files with John
  • 10.4
    Network Services 4 topics
    • 10.4.1
      WinRM 8 topics
      • 10.4.1.1
        CrackMapExec
      • 10.4.1.2
        Installing CrackMapExec
      • 10.4.1.3
        CrackMapExec Menu Options
      • 10.4.1.4
        CrackMapExec Protocol-Specific Help
      • 10.4.1.5
        CrackMapExec Usage
      • 10.4.1.6
        Evil-WinRM
      • 10.4.1.7
        Installing Evil-WinRM
      • 10.4.1.8
        Evil-WinRM Usage
    • 10.4.2
      SSH 4 topics
      • 10.4.2.1
        Symmetric Encryption
      • 10.4.2.2
        Asymmetrical Encryption
      • 10.4.2.3
        Hashing
      • 10.4.2.4
        Hydra - SSH
    • 10.4.3
      Remote Desktop Protocol (RDP) 2 topics
      • 10.4.3.1
        Hydra - RDP
      • 10.4.3.2
        xFreeRDP
    • 10.4.4
      SMB 5 topics
      • 10.4.4.1
        Hydra - SMB
      • 10.4.4.2
        Hydra - Error
      • 10.4.4.3
        Metasploit Framework
      • 10.4.4.4
        CrackMapExec
      • 10.4.4.5
        Smbclient
  • 10.5
    Password Mutations 1 topic
    • 10.5.1
      Password List 4 topics
      • 10.5.1.1
        Hashcat Rule File
      • 10.5.1.2
        Generating Rule-based Wordlist
      • 10.5.1.3
        Hashcat Existing Rules
      • 10.5.1.4
        Generating Wordlists Using CeWL
  • 10.6
    Password Reuse / Default Passwords 1 topic
    • 10.6.1
      Credential Stuffing 3 topics
      • 10.6.1.1
        Credential Stuffing - Hydra Syntax
      • 10.6.1.2
        Credential Stuffing - Hydra
      • 10.6.1.3
        Google Search - Default Credentials
  • 10.7
    Attacking SAM 4 topics
    • 10.7.1
      Copying SAM Registry Hives 4 topics
      • 10.7.1.1
        Using reg.exe save to Copy Registry Hives
      • 10.7.1.2
        Creating a Share with smbserver.py
      • 10.7.1.3
        Moving Hive Copies to Share
      • 10.7.1.4
        Confirming Hive Copies Transferred to Attack Host
    • 10.7.2
      Dumping Hashes with Impacket's secretsdump.py 2 topics
      • 10.7.2.1
        Locating secretsdump.py
      • 10.7.2.2
        Running secretsdump.py
    • 10.7.3
      Cracking Hashes with Hashcat 2 topics
      • 10.7.3.1
        Adding nthashes to a .txt File
      • 10.7.3.2
        Running Hashcat against NT Hashes
    • 10.7.4
      Remote Dumping & LSA Secrets Considerations 2 topics
      • 10.7.4.1
        Dumping LSA Secrets Remotely
      • 10.7.4.2
        Dumping SAM Remotely
  • 10.8
    Attacking LSASS 2 topics
    • 10.8.1
      Dumping LSASS Process Memory 5 topics
      • 10.8.1.1
        Task Manager Method
      • 10.8.1.2
        Rundll32.exe & Comsvcs.dll Method
      • 10.8.1.3
        Finding LSASS PID in cmd
      • 10.8.1.4
        Finding LSASS PID in PowerShell
      • 10.8.1.5
        Creating lsass.dmp using PowerShell
    • 10.8.2
      Using Pypykatz to Extract Credentials 6 topics
      • 10.8.2.1
        Running Pypykatz
      • 10.8.2.2
        MSV
      • 10.8.2.3
        WDIGEST
      • 10.8.2.4
        Kerberos
      • 10.8.2.5
        DPAPI
      • 10.8.2.6
        Cracking the NT Hash with Hashcat
  • 10.9
    Attacking Active Directory & NTDS.dit 4 topics
    • 10.9.1
      Dictionary Attacks against AD accounts using CrackMapExec 3 topics
      • 10.9.1.1
        Creating a Custom list of Usernames
      • 10.9.1.2
        Launching the Attack with CrackMapExec
      • 10.9.1.3
        Event Logs from the Attack
    • 10.9.2
      Capturing NTDS.dit 7 topics
      • 10.9.2.1
        Connecting to a DC with Evil-WinRM
      • 10.9.2.2
        Checking Local Group Membership
      • 10.9.2.3
        Checking User Account Privileges including Domain
      • 10.9.2.4
        Creating Shadow Copy of C:
      • 10.9.2.5
        Copying NTDS.dit from the VSS
      • 10.9.2.6
        Transferring NTDS.dit to Attack Host
      • 10.9.2.7
        A Faster Method: Using cme to Capture NTDS.dit
    • 10.9.3
      Cracking Hashes & Gaining Credentials 1 topic
      • 10.9.3.1
        Cracking a Single Hash with Hashcat
    • 10.9.4
      Pass-the-Hash Considerations 1 topic
      • 10.9.4.1
        Pass-the-Hash with Evil-WinRM Example
  • 10.10
    Credential Hunting in Windows 3 topics
    • 10.10.1
      Search Centric 1 topic
      • 10.10.1.1
        Key Terms to Search
    • 10.10.2
      Search Tools 3 topics
      • 10.10.2.1
        Running Lazagne All
      • 10.10.2.2
        Lazagne Output
      • 10.10.2.3
        Using findstr
    • 10.10.3
      Additional Considerations
  • 10.11
    Credential Hunting in Linux 3 topics
    • 10.11.1
      Files 9 topics
      • 10.11.1.1
        Configuration Files
      • 10.11.1.2
        Credentials in Configuration Files
      • 10.11.1.3
        Databases
      • 10.11.1.4
        Notes
      • 10.11.1.5
        Scripts
      • 10.11.1.6
        Cronjobs
      • 10.11.1.7
        SSH Keys
      • 10.11.1.8
        SSH Private Keys
      • 10.11.1.9
        SSH Public Keys
    • 10.11.2
      History 2 topics
      • 10.11.2.1
        Bash History
      • 10.11.2.2
        Logs
    • 10.11.3
      Memory and Cache 6 topics
      • 10.11.3.1
        Memory - Mimipenguin
      • 10.11.3.2
        Memory - LaZagne
      • 10.11.3.3
        Browsers
      • 10.11.3.4
        Firefox Stored Credentials
      • 10.11.3.5
        Decrypting Firefox Credentials
      • 10.11.3.6
        Browsers - LaZagne
  • 10.12
    Passwd, Shadow & Opasswd 4 topics
    • 10.12.1
      Passwd File 4 topics
      • 10.12.1.1
        Passwd Format
      • 10.12.1.2
        Editing /etc/passwd - Before
      • 10.12.1.3
        Editing /etc/passwd - After
      • 10.12.1.4
        Root without Password
    • 10.12.2
      Shadow File 3 topics
      • 10.12.2.1
        Shadow Format
      • 10.12.2.2
        Shadow File
      • 10.12.2.3
        Algorithm Types
    • 10.12.3
      Opasswd 1 topic
      • 10.12.3.1
        Reading /etc/security/opasswd
    • 10.12.4
      Cracking Linux Credentials 3 topics
      • 10.12.4.1
        Unshadow
      • 10.12.4.2
        Hashcat - Cracking Unshadowed Hashes
      • 10.12.4.3
        Hashcat - Cracking MD5 Hashes
  • 10.13
    Pass the Hash (PtH) 9 topics
    • 10.13.1
      Windows NTLM Introduction
    • 10.13.2
      Pass the Hash with Mimikatz (Windows) 1 topic
      • 10.13.2.1
        Pass the Hash from Windows Using Mimikatz:
    • 10.13.3
      Pass the Hash with PowerShell Invoke-TheHash (Windows) 3 topics
      • 10.13.3.1
        Invoke-TheHash with SMB
      • 10.13.3.2
        Netcat Listener
      • 10.13.3.3
        Invoke-TheHash with WMI
    • 10.13.4
      Pass the Hash with Impacket (Linux) 1 topic
      • 10.13.4.1
        Pass the Hash with Impacket PsExec
    • 10.13.5
      Pass the Hash with CrackMapExec (Linux) 2 topics
      • 10.13.5.1
        Pass the Hash with CrackMapExec
      • 10.13.5.2
        CrackMapExec - Command Execution
    • 10.13.6
      Pass the Hash with evil-winrm (Linux) 1 topic
      • 10.13.6.1
        Pass the Hash with evil-winrm
    • 10.13.7
      Pass the Hash with RDP (Linux) 2 topics
      • 10.13.7.1
        Enable Restricted Admin Mode to Allow PtH
      • 10.13.7.2
        Pass the Hash Using RDP
    • 10.13.8
      UAC Limits Pass the Hash for Local Accounts
    • 10.13.9
      Next Steps
  • 10.14
    Pass the Ticket (PtT) from Windows 10 topics
    • 10.14.1
      Kerberos Protocol Refresher
    • 10.14.2
      Pass the Ticket (PtT) Attack
    • 10.14.3
      Scenario
    • 10.14.4
      Harvesting Kerberos Tickets from Windows 2 topics
      • 10.14.4.1
        Mimikatz - Export Tickets
      • 10.14.4.2
        Rubeus - Export Tickets
    • 10.14.5
      Pass the Key or OverPass the Hash 3 topics
      • 10.14.5.1
        Mimikatz - Extract Kerberos Keys
      • 10.14.5.2
        Mimikatz - Pass the Key or OverPass the Hash
      • 10.14.5.3
        Rubeus - Pass the Key or OverPass the Hash
    • 10.14.6
      Pass the Ticket (PtT) 5 topics
      • 10.14.6.1
        Rubeus Pass the Ticket
      • 10.14.6.2
        Rubeus - Pass the Ticket
      • 10.14.6.3
        Convert .kirbi to Base64 Format
      • 10.14.6.4
        Pass the Ticket - Base64 Format
      • 10.14.6.5
        Mimikatz - Pass the Ticket
    • 10.14.7
      Pass The Ticket with PowerShell Remoting (Windows)
    • 10.14.8
      Mimikatz - PowerShell Remoting with Pass the Ticket 1 topic
      • 10.14.8.1
        Mimikatz - Pass the Ticket for Lateral Movement.
    • 10.14.9
      Rubeus - PowerShell Remoting with Pass the Ticket 2 topics
      • 10.14.9.1
        Create a Sacrificial Process with Rubeus
      • 10.14.9.2
        Rubeus - Pass the Ticket for Lateral Movement
    • 10.14.10
      Moving On
  • 10.15
    Pass the Ticket (PtT) from Linux 12 topics
    • 10.15.1
      Kerberos on Linux
    • 10.15.2
      Scenario 2 topics
      • 10.15.2.1
        Linux Auth from MS01 Image
      • 10.15.2.2
        Linux Auth via Port Forward
    • 10.15.3
      Identifying Linux and Active Directory Integration 2 topics
      • 10.15.3.1
        realm - Check If Linux Machine is Domain Joined
      • 10.15.3.2
        PS - Check if Linux Machine is Domain Joined
    • 10.15.4
      Finding Kerberos Tickets in Linux
    • 10.15.5
      Finding Keytab Files 2 topics
      • 10.15.5.1
        Using Find to Search for Files with Keytab in the Name
      • 10.15.5.2
        Identifying Keytab Files in Cronjobs
    • 10.15.6
      Finding ccache Files 2 topics
      • 10.15.6.1
        Reviewing Environment Variables for ccache Files.
      • 10.15.6.2
        Searching for ccache Files in /tmp
    • 10.15.7
      Abusing KeyTab Files 7 topics
      • 10.15.7.1
        Listing keytab File Information
      • 10.15.7.2
        Impersonating a User with a keytab
      • 10.15.7.3
        Connecting to SMB Share as Carlos
      • 10.15.7.4
        Keytab Extract
      • 10.15.7.5
        Extracting Keytab Hashes with KeyTabExtract
      • 10.15.7.6
        Log in as Carlos
      • 10.15.7.7
        Obtaining More Hashes
    • 10.15.8
      Abusing Keytab ccache 4 topics
      • 10.15.8.1
        Privilege Escalation to Root
      • 10.15.8.2
        Looking for ccache Files
      • 10.15.8.3
        Identifying Group Membership with the id Command
      • 10.15.8.4
        Importing the ccache File into our Current Session
    • 10.15.9
      Using Linux Attack Tools with Kerberos 14 topics
      • 10.15.9.1
        Host File Modified
      • 10.15.9.2
        Proxychains Configuration File
      • 10.15.9.3
        Download Chisel to our Attack Host
      • 10.15.9.4
        Connect to MS01 with xfreerdp
      • 10.15.9.5
        Execute chisel from MS01
      • 10.15.9.6
        Setting the KRB5CCNAME Environment Variable
      • 10.15.9.7
        Impacket
      • 10.15.9.8
        Using Impacket with proxychains and Kerberos Authentication
      • 10.15.9.9
        Evil-Winrm
      • 10.15.9.10
        Installing Kerberos Authentication Package
      • 10.15.9.11
        Default Kerberos Version 5 realm
      • 10.15.9.12
        Administrative Server for your Kerberos Realm
      • 10.15.9.13
        Kerberos Configuration File for INLANEFREIGHT.HTB
      • 10.15.9.14
        Using Evil-WinRM with Kerberos
    • 10.15.10
      Miscellaneous 2 topics
      • 10.15.10.1
        Impacket Ticket Converter
      • 10.15.10.2
        Importing Converted Ticket into Windows Session with Rubeus
    • 10.15.11
      Linikatz 1 topic
      • 10.15.11.1
        Linikatz Download and Execution
    • 10.15.12
      Onwards
  • 10.16
    Protected Files 3 topics
    • 10.16.1
      Hunting for Encoded Files 3 topics
      • 10.16.1.1
        Hunting for Files
      • 10.16.1.2
        Hunting for SSH Keys
      • 10.16.1.3
        Encrypted SSH Keys
    • 10.16.2
      Cracking with John 2 topics
      • 10.16.2.1
        John Hashing Scripts
      • 10.16.2.2
        Cracking SSH Keys
    • 10.16.3
      Cracking Documents 2 topics
      • 10.16.3.1
        Cracking Microsoft Office Documents
      • 10.16.3.2
        Cracking PDFs
  • 10.17
    Protected Archives 5 topics
    • 10.17.1
      Download All File Extensions
    • 10.17.2
      Cracking Archives
    • 10.17.3
      Cracking ZIP 4 topics
      • 10.17.3.1
        Using zip2john
      • 10.17.3.2
        Viewing the Contents of zip.hash
      • 10.17.3.3
        Cracking the Hash with John
      • 10.17.3.4
        Viewing the Cracked Hash
    • 10.17.4
      Cracking OpenSSL Encrypted Archives 4 topics
      • 10.17.4.1
        Listing the Files
      • 10.17.4.2
        Using file
      • 10.17.4.3
        Using a for-loop to Display Extracted Contents
      • 10.17.4.4
        Listing the Contents of the Cracked Archive
    • 10.17.5
      Cracking BitLocker Encrypted Drives 4 topics
      • 10.17.5.1
        Using bitlocker2john
      • 10.17.5.2
        Using hashcat to Crack backup.hash
      • 10.17.5.3
        Viewing the Cracked Hash
      • 10.17.5.4
        Windows - Mounting BitLocker VHD
  • 10.18
    Password Policies 5 topics
    • 10.18.1
      Password Policy
    • 10.18.2
      Password Policy Standards
    • 10.18.3
      Password Policy Recommendations
    • 10.18.4
      Enforcing Password Policy
    • 10.18.5
      Creating a Good password
  • 10.19
    Password Managers 6 topics
    • 10.19.1
      How Does a Password Manager Work?
    • 10.19.2
      Online Password Managers
    • 10.19.3
      Local Password Managers
    • 10.19.4
      Features
    • 10.19.5
      Alternatives
    • 10.19.6
      Passwordless
  • 10.20
    Password Attacks Lab - Easy
  • 10.21
    Password Attacks Lab - Medium
  • 10.22
    Password Attacks Lab - Hard
11 Attacking Common Services Attacking Common Services module 195 topics Module 11
  • 11.1
    Interacting with Common Services 5 topics
    • 11.1.1
      File Share Services
    • 11.1.2
      Server Message Block (SMB) 13 topics
      • 11.1.2.1
        Windows
      • 11.1.2.2
        Windows CMD - DIR
      • 11.1.2.3
        Windows CMD - Net Use
      • 11.1.2.4
        Windows CMD - DIR
      • 11.1.2.5
        Windows CMD - Findstr
      • 11.1.2.6
        Windows PowerShell
      • 11.1.2.7
        Windows PowerShell - PSCredential Object
      • 11.1.2.8
        Windows PowerShell - GCI
      • 11.1.2.9
        Windows PowerShell - Select-String
      • 11.1.2.10
        Linux
      • 11.1.2.11
        Linux - Mount
      • 11.1.2.12
        CredentialFile
      • 11.1.2.13
        Linux - Find
    • 11.1.3
      Other Services 5 topics
      • 11.1.3.1
        Email
      • 11.1.3.2
        Linux - Install Evolution
      • 11.1.3.3
        Video - Connecting to IMAP and SMTP using Evolution
      • 11.1.3.4
        Databases
      • 11.1.3.5
        MySQL example
    • 11.1.4
      Command Line Utilities 13 topics
      • 11.1.4.1
        MSSQL
      • 11.1.4.2
        Linux - SQSH
      • 11.1.4.3
        Windows - SQLCMD
      • 11.1.4.4
        MySQL
      • 11.1.4.5
        Linux - MySQL
      • 11.1.4.6
        Windows - MySQL
      • 11.1.4.7
        GUI Application
      • 11.1.4.8
        Install dbeaver
      • 11.1.4.9
        Run dbeaver
      • 11.1.4.10
        Video - Connecting to MSSQL DB using dbeaver
      • 11.1.4.11
        Video - Connecting to MySQL DB using dbeaver
      • 11.1.4.12
        Tools
      • 11.1.4.13
        Tools to Interact with Common Services
    • 11.1.5
      General Troubleshooting
  • 11.2
    The Concept of Attacks 5 topics
    • 11.2.1
      The Concept of Attacks
    • 11.2.2
      Source 1 topic
      • 11.2.2.1
        Log4j
    • 11.2.3
      Processes 1 topic
      • 11.2.3.1
        Log4j
    • 11.2.4
      Privileges 1 topic
      • 11.2.4.1
        Log4j
    • 11.2.5
      Destination 3 topics
      • 11.2.5.1
        Log4j
      • 11.2.5.2
        Initiation of the Attack
      • 11.2.5.3
        Trigger Remote Code Execution
  • 11.3
    Service Misconfigurations 3 topics
    • 11.3.1
      Authentication 2 topics
      • 11.3.1.1
        Anonymous Authentication
      • 11.3.1.2
        Misconfigured Access Rights
    • 11.3.2
      Unnecessary Defaults
    • 11.3.3
      Preventing Misconfiguration
  • 11.4
    Finding Sensitive Information 1 topic
    • 11.4.1
      Understanding of What We Have to Look for
  • 11.5
    Attacking FTP 3 topics
    • 11.5.1
      Enumeration 1 topic
      • 11.5.1.1
        Nmap
    • 11.5.2
      Misconfigurations 1 topic
      • 11.5.2.1
        Anonymous Authentication
    • 11.5.3
      Protocol Specifics Attacks 3 topics
      • 11.5.3.1
        Brute Forcing
      • 11.5.3.2
        Brute Forcing with Medusa
      • 11.5.3.3
        FTP Bounce Attack
  • 11.6
    Latest FTP Vulnerabilities 1 topic
    • 11.6.1
      The Concept of the Attack 5 topics
      • 11.6.1.1
        CoreFTP Exploitation
      • 11.6.1.2
        The Concept of Attacks
      • 11.6.1.3
        Directory Traversal
      • 11.6.1.4
        Arbitrary File Write
      • 11.6.1.5
        Target System
  • 11.7
    Attacking SMB 3 topics
    • 11.7.1
      Enumeration
    • 11.7.2
      Misconfigurations 3 topics
      • 11.7.2.1
        Anonymous Authentication
      • 11.7.2.2
        File Share
      • 11.7.2.3
        Remote Procedure Call (RPC)
    • 11.7.3
      Protocol Specifics Attacks 10 topics
      • 11.7.3.1
        Brute Forcing and Password Spray
      • 11.7.3.2
        SMB
      • 11.7.3.3
        Remote Code Execution (RCE)
      • 11.7.3.4
        Impacket PsExec
      • 11.7.3.5
        CrackMapExec
      • 11.7.3.6
        Enumerating Logged-on Users
      • 11.7.3.7
        Extract Hashes from SAM Database
      • 11.7.3.8
        Pass-the-Hash (PtH)
      • 11.7.3.9
        Forced Authentication Attacks
      • 11.7.3.10
        RPC
  • 11.8
    Latest SMB Vulnerabilities 1 topic
    • 11.8.1
      The Concept of the Attack 3 topics
      • 11.8.1.1
        The Concept of Attacks
      • 11.8.1.2
        Initiation of the Attack
      • 11.8.1.3
        Trigger Remote Code Execution
  • 11.9
    Attacking SQL Databases 9 topics
    • 11.9.1
      Enumeration 1 topic
      • 11.9.1.1
        Banner Grabbing
    • 11.9.2
      Authentication Mechanisms 2 topics
      • 11.9.2.1
        Misconfigurations
      • 11.9.2.2
        Privileges
    • 11.9.3
      Protocol Specific Attacks 9 topics
      • 11.9.3.1
        Read/Change the Database
      • 11.9.3.2
        MySQL - Connecting to the SQL Server
      • 11.9.3.3
        Sqlcmd - Connecting to the SQL Server
      • 11.9.3.4
        SQL Default Databases
      • 11.9.3.5
        SQL Syntax
      • 11.9.3.6
        Show Databases
      • 11.9.3.7
        Select a Database
      • 11.9.3.8
        Show Tables
      • 11.9.3.9
        Select all Data from Table "users"
    • 11.9.4
      Execute Commands 1 topic
      • 11.9.4.1
        XP_CMDSHELL
    • 11.9.5
      Write Local Files 4 topics
      • 11.9.5.1
        MySQL - Write Local File
      • 11.9.5.2
        MySQL - Secure File Privileges
      • 11.9.5.3
        MSSQL - Enable Ole Automation Procedures
      • 11.9.5.4
        MSSQL - Create a File
    • 11.9.6
      Read Local Files 2 topics
      • 11.9.6.1
        Read Local Files in MSSQL
      • 11.9.6.2
        MySQL - Read Local Files in MySQL
    • 11.9.7
      Capture MSSQL Service Hash 4 topics
      • 11.9.7.1
        XP_DIRTREE Hash Stealing
      • 11.9.7.2
        XP_SUBDIRS Hash Stealing
      • 11.9.7.3
        XP_SUBDIRS Hash Stealing with Responder
      • 11.9.7.4
        XP_SUBDIRS Hash Stealing with impacket
    • 11.9.8
      Impersonate Existing Users with MSSQL 3 topics
      • 11.9.8.1
        Identify Users that We Can Impersonate
      • 11.9.8.2
        Verifying our Current User and Role
      • 11.9.8.3
        Impersonating the SA User
    • 11.9.9
      Communicate with Other Databases with MSSQL 1 topic
      • 11.9.9.1
        Identify linked Servers in MSSQL
  • 11.10
    Latest SQL Vulnerabilities 1 topic
    • 11.10.1
      The Concept of the Attack 3 topics
      • 11.10.1.1
        The Concept of Attacks
      • 11.10.1.2
        Initiation of the Attack
      • 11.10.1.3
        Steal The Hash
  • 11.11
    Attacking RDP 3 topics
    • 11.11.1
      Misconfigurations 3 topics
      • 11.11.1.1
        Crowbar - RDP Password Spraying
      • 11.11.1.2
        Hydra - RDP Password Spraying
      • 11.11.1.3
        RDP Login
    • 11.11.2
      Protocol Specific Attacks 1 topic
      • 11.11.2.1
        RDP Session Hijacking
    • 11.11.3
      RDP Pass-the-Hash (PtH) 1 topic
      • 11.11.3.1
        Adding the DisableRestrictedAdmin Registry Key
  • 11.12
    Latest RDP Vulnerabilities 1 topic
    • 11.12.1
      The Concept of the Attack 3 topics
      • 11.12.1.1
        The Concept of Attacks
      • 11.12.1.2
        Initiation of the Attack
      • 11.12.1.3
        Trigger Remote Code Execution
  • 11.13
    Attacking DNS 4 topics
    • 11.13.1
      Enumeration
    • 11.13.2
      DNS Zone Transfer 1 topic
      • 11.13.2.1
        DIG - AXFR Zone Transfer
    • 11.13.3
      Domain Takeovers & Subdomain Enumeration 2 topics
      • 11.13.3.1
        Subdomain Enumeration
      • 11.13.3.2
        Subbrute
    • 11.13.4
      DNS Spoofing 1 topic
      • 11.13.4.1
        Local DNS Cache Poisoning
  • 11.14
    Latest DNS Vulnerabilities 2 topics
    • 11.14.1
      RedHuntLabs Study
    • 11.14.2
      The Concept of the Attack 3 topics
      • 11.14.2.1
        The Concept of Attacks
      • 11.14.2.2
        Initiation of Subdomain Takeover
      • 11.14.2.3
        Trigger the Forwarding
  • 11.15
    Attacking Email Services 5 topics
    • 11.15.1
      Enumeration 3 topics
      • 11.15.1.1
        Host - MX Records
      • 11.15.1.2
        DIG - MX Records
      • 11.15.1.3
        Host - A Records
    • 11.15.2
      Misconfigurations 5 topics
      • 11.15.2.1
        Authentication
      • 11.15.2.2
        VRFY Command
      • 11.15.2.3
        EXPN Command
      • 11.15.2.4
        RCPT TO Command
      • 11.15.2.5
        USER Command
    • 11.15.3
      Cloud Enumeration 1 topic
      • 11.15.3.1
        O365 Spray
    • 11.15.4
      Password Attacks 2 topics
      • 11.15.4.1
        Hydra - Password Attack
      • 11.15.4.2
        O365 Spray - Password Spraying
    • 11.15.5
      Protocol Specifics Attacks 1 topic
      • 11.15.5.1
        Open Relay
  • 11.16
    Latest Email Service Vulnerabilities 3 topics
    • 11.16.1
      Shodan Search 1 topic
      • 11.16.1.1
        Shodan Trend
    • 11.16.2
      The Concept of the Attack 3 topics
      • 11.16.2.1
        The Concept of Attacks
      • 11.16.2.2
        Initiation of the Attack
      • 11.16.2.3
        Trigger Remote Code Execution
    • 11.16.3
      Next Steps
  • 11.17
    Attacking Common Services - Easy
  • 11.18
    Attacking Common Services - Medium
  • 11.19
    Attacking Common Services - Hard
12 Pivoting, Tunneling, and Port Forwarding Pivoting, Tunneling, and Port Forwarding module 162 topics Module 12
  • 12.1
    Introduction to Pivoting, Tunneling, and Port Forwarding 1 topic
    • 12.1.1
      Lateral Movement, Pivoting, and Tunneling Compared 3 topics
      • 12.1.1.1
        Lateral Movement
      • 12.1.1.2
        Pivoting
      • 12.1.1.3
        Tunneling
  • 12.2
    The Networking Behind Pivoting 3 topics
    • 12.2.1
      IP Addressing & NICs 2 topics
      • 12.2.1.1
        Using ifconfig
      • 12.2.1.2
        Using ipconfig
    • 12.2.2
      Routing 1 topic
      • 12.2.2.1
        Routing Table on Pwnbox
    • 12.2.3
      Protocols, Services & Ports 1 topic
      • 12.2.3.1
        Questions
  • 12.3
    Dynamic Port Forwarding with SSH and SOCKS Tunneling 4 topics
    • 12.3.1
      Port Forwarding in Context
    • 12.3.2
      SSH Local Port Forwarding 5 topics
      • 12.3.2.1
        Scanning the Pivot Target
      • 12.3.2.2
        Executing the Local Port Forward
      • 12.3.2.3
        Confirming Port Forward with Netstat
      • 12.3.2.4
        Confirming Port Forward with Nmap
      • 12.3.2.5
        Forwarding Multiple Ports
    • 12.3.3
      Setting up to Pivot 5 topics
      • 12.3.3.1
        Looking for Opportunities to Pivot using ifconfig
      • 12.3.3.2
        Enabling Dynamic Port Forwarding with SSH
      • 12.3.3.3
        Checking /etc/proxychains.conf
      • 12.3.3.4
        Using Nmap with Proxychains
      • 12.3.3.5
        Enumerating the Windows Target through Proxychains
    • 12.3.4
      Using Metasploit with Proxychains 3 topics
      • 12.3.4.1
        Using rdp_scanner Module
      • 12.3.4.2
        Using xfreerdp with Proxychains
      • 12.3.4.3
        Successful RDP Pivot
  • 12.4
    Remote/Reverse Port Forwarding with SSH 1 topic
    • 12.4.1
      Creating a Windows Payload with msfvenom 7 topics
      • 12.4.1.1
        Configuring & Starting the multi/handler
      • 12.4.1.2
        Transferring Payload to Pivot Host
      • 12.4.1.3
        Starting Python3 Webserver on Pivot Host
      • 12.4.1.4
        Downloading Payload on the Windows Target
      • 12.4.1.5
        Using SSH -R
      • 12.4.1.6
        Viewing the Logs from the Pivot
      • 12.4.1.7
        Meterpreter Session Established
  • 12.5
    Meterpreter Tunneling & Port Forwarding 3 topics
    • 12.5.1
      Creating Payload for Ubuntu Pivot Host 13 topics
      • 12.5.1.1
        Configuring & Starting the multi/handler
      • 12.5.1.2
        Executing the Payload on the Pivot Host
      • 12.5.1.3
        Meterpreter Session Establishment
      • 12.5.1.4
        Ping Sweep
      • 12.5.1.5
        Ping Sweep For Loop on Linux Pivot Hosts
      • 12.5.1.6
        Ping Sweep For Loop Using CMD
      • 12.5.1.7
        Ping Sweep Using PowerShell
      • 12.5.1.8
        Configuring MSF's SOCKS Proxy
      • 12.5.1.9
        Confirming Proxy Server is Running
      • 12.5.1.10
        Adding a Line to proxychains.conf if Needed
      • 12.5.1.11
        Creating Routes with AutoRoute
      • 12.5.1.12
        Listing Active Routes with AutoRoute
      • 12.5.1.13
        Testing Proxy & Routing Functionality
    • 12.5.2
      Port Forwarding 4 topics
      • 12.5.2.1
        Portfwd options
      • 12.5.2.2
        Creating Local TCP Relay
      • 12.5.2.3
        Connecting to Windows Target through localhost
      • 12.5.2.4
        Netstat Output
    • 12.5.3
      Meterpreter Reverse Port Forwarding 4 topics
      • 12.5.3.1
        Reverse Port Forwarding Rules
      • 12.5.3.2
        Configuring & Starting multi/handler
      • 12.5.3.3
        Generating the Windows Payload
      • 12.5.3.4
        Establishing the Meterpreter session
  • 12.6
    Socat Redirection with a Reverse Shell 1 topic
    • 12.6.1
      Starting Socat Listener 4 topics
      • 12.6.1.1
        Creating the Windows Payload
      • 12.6.1.2
        Starting MSF Console
      • 12.6.1.3
        Configuring & Starting the multi/handler
      • 12.6.1.4
        Establishing the Meterpreter Session
  • 12.7
    Socat Redirection with a Bind Shell 1 topic
    • 12.7.1
      Creating the Windows Payload 3 topics
      • 12.7.1.1
        Starting Socat Bind Shell Listener
      • 12.7.1.2
        Configuring & Starting the Bind multi/handler
      • 12.7.1.3
        Establishing Meterpreter Session
  • 12.8
    SSH for Windows: plink.exe 1 topic
    • 12.8.1
      Getting To Know Plink 1 topic
      • 12.8.1.1
        Using Plink.exe
  • 12.9
    SSH Pivoting with Sshuttle 1 topic
    • 12.9.1
      Installing sshuttle 2 topics
      • 12.9.1.1
        Running sshuttle
      • 12.9.1.2
        Traffic Routing through iptables Routes
  • 12.10
    Web Server Pivoting with Rpivot 1 topic
    • 12.10.1
      Cloning rpivot 8 topics
      • 12.10.1.1
        Installing Python2.7
      • 12.10.1.2
        Alternative Installation of Python2.7
      • 12.10.1.3
        Running server.py from the Attack Host
      • 12.10.1.4
        Transfering rpivot to the Target
      • 12.10.1.5
        Running client.py from Pivot Target
      • 12.10.1.6
        Confirming Connection is Established
      • 12.10.1.7
        Browsing to the Target Webserver using Proxychains
      • 12.10.1.8
        Connecting to a Web Server using HTTP-Proxy & NTLM Auth
  • 12.11
    Port Forwarding with Windows Netsh 1 topic
    • 12.11.1
      Using Netsh.exe to Port Forward 2 topics
      • 12.11.1.1
        Verifying Port Forward
      • 12.11.1.2
        Connecting to the Internal Host through the Port Forward
  • 12.12
    DNS Tunneling with Dnscat2 1 topic
    • 12.12.1
      Setting Up & Using dnscat2 7 topics
      • 12.12.1.1
        Cloning dnscat2 and Setting Up the Server
      • 12.12.1.2
        Starting the dnscat2 server
      • 12.12.1.3
        Cloning dnscat2-powershell to the Attack Host
      • 12.12.1.4
        Importing dnscat2.ps1
      • 12.12.1.5
        Confirming Session Establishment
      • 12.12.1.6
        Listing dnscat2 Options
      • 12.12.1.7
        Interacting with the Established Session
  • 12.13
    SOCKS5 Tunneling with Chisel 2 topics
    • 12.13.1
      Setting Up & Using Chisel 7 topics
      • 12.13.1.1
        Cloning Chisel
      • 12.13.1.2
        Building the Chisel Binary
      • 12.13.1.3
        Transferring Chisel Binary to Pivot Host
      • 12.13.1.4
        Running the Chisel Server on the Pivot Host
      • 12.13.1.5
        Connecting to the Chisel Server
      • 12.13.1.6
        Editing & Confirming proxychains.conf
      • 12.13.1.7
        Pivoting to the DC
    • 12.13.2
      Chisel Reverse Pivot 3 topics
      • 12.13.2.1
        Starting the Chisel Server on our Attack Host
      • 12.13.2.2
        Connecting the Chisel Client to our Attack Host
      • 12.13.2.3
        Editing & Confirming proxychains.conf
  • 12.14
    ICMP Tunneling with SOCKS 2 topics
    • 12.14.1
      Setting Up & Using ptunnel-ng 10 topics
      • 12.14.1.1
        Cloning Ptunnel-ng
      • 12.14.1.2
        Building Ptunnel-ng with Autogen.sh
      • 12.14.1.3
        Alternative approach of building a static binary
      • 12.14.1.4
        Transferring Ptunnel-ng to the Pivot Host
      • 12.14.1.5
        Starting the ptunnel-ng Server on the Target Host
      • 12.14.1.6
        Connecting to ptunnel-ng Server from Attack Host
      • 12.14.1.7
        Tunneling an SSH connection through an ICMP Tunnel
      • 12.14.1.8
        Viewing Tunnel Traffic Statistics
      • 12.14.1.9
        Enabling Dynamic Port Forwarding over SSH
      • 12.14.1.10
        Proxychaining through the ICMP Tunnel
    • 12.14.2
      Network Traffic Analysis Considerations
  • 12.15
    RDP and SOCKS Tunneling with SocksOverRDP 1 topic
    • 12.15.1
      Loading SocksOverRDP.dll using regsvr32.exe 3 topics
      • 12.15.1.1
        Confirming the SOCKS Listener is Started
      • 12.15.1.2
        Configuring Proxifier
      • 12.15.1.3
        RDP Performance Considerations
  • 12.16
    Skills Assessment 3 topics
    • 12.16.1
      Scenario
    • 12.16.2
      Objectives
    • 12.16.3
      Connection Info
  • 12.17
    Detection & Prevention 4 topics
    • 12.17.1
      Setting a Baseline 1 topic
      • 12.17.1.1
        Things to Document and Track
    • 12.17.2
      People, Processes, and Technology 4 topics
      • 12.17.2.1
        People
      • 12.17.2.2
        BYOD and Other Concerns
      • 12.17.2.3
        Processes
      • 12.17.2.4
        Technology
    • 12.17.3
      From the Outside Moving In 2 topics
      • 12.17.3.1
        Perimeter First
      • 12.17.3.2
        Internal Considerations
    • 12.17.4
      MITRE Breakdown
  • 12.18
    Beyond this Module 4 topics
    • 12.18.1
      Real World
    • 12.18.2
      What's Next?
    • 12.18.3
      Pivoting & Tunneling Into Other Learning Opportunities 4 topics
      • 12.18.3.1
        Boxes To Pwn
      • 12.18.3.2
        ProLabs
      • 12.18.3.3
        Endgames
      • 12.18.3.4
        Writers/Educational Creators and Blogs To Follow
    • 12.18.4
      Closing Thoughts
13 Active Directory Enumeration & Attacks Active Directory Enumeration & Attacks module 564 topics Module 13
  • 13.1
    Introduction to Active Directory Enumeration & Attacks 6 topics
    • 13.1.1
      Active Directory Explained
    • 13.1.2
      Why Should We Care About AD?
    • 13.1.3
      Real-World Examples
    • 13.1.4
      This Is The Way
    • 13.1.5
      Practical Examples 3 topics
      • 13.1.5.1
        Connecting via FreeRDP
      • 13.1.5.2
        Connecting via SSH
      • 13.1.5.3
        Xfreerdp to the ATTACK01 Parrot Host
    • 13.1.6
      Toolkit
  • 13.2
    Tools of the Trade
  • 13.3
    Scenario 4 topics
    • 13.3.1
      Tasking Email
    • 13.3.2
      Assessment Scope 2 topics
      • 13.3.2.1
        In Scope For Assessment
      • 13.3.2.2
        Out Of Scope
    • 13.3.3
      Methods Used 3 topics
      • 13.3.3.1
        External Information Gathering (Passive Checks)
      • 13.3.3.2
        Internal Testing
      • 13.3.3.3
        Password Testing
    • 13.3.4
      The Stage Is Set
  • 13.4
    External Recon and Enumeration Principles 4 topics
    • 13.4.1
      What Are We Looking For?
    • 13.4.2
      Where Are We Looking? 5 topics
      • 13.4.2.1
        Finding Address Spaces
      • 13.4.2.2
        DNS
      • 13.4.2.3
        Viewdns.info
      • 13.4.2.4
        Public Data
      • 13.4.2.5
        Sharepoint Admin Job Listing
    • 13.4.3
      Overarching Enumeration Principles
    • 13.4.4
      Example Enumeration Process 7 topics
      • 13.4.4.1
        Check for ASN/IP & Domain Data
      • 13.4.4.2
        Viewdns Results
      • 13.4.4.3
        Hunting For Files
      • 13.4.4.4
        Hunting E-mail Addresses
      • 13.4.4.5
        E-mail Dork Results
      • 13.4.4.6
        Username Harvesting
      • 13.4.4.7
        Credential Hunting
  • 13.5
    Initial Enumeration of the Domain 7 topics
    • 13.5.1
      Setting Up
    • 13.5.2
      Tasks 1 topic
      • 13.5.2.1
        Key Data Points
    • 13.5.3
      TTPs 9 topics
      • 13.5.3.1
        Identifying Hosts
      • 13.5.3.2
        Start Wireshark on ea-attack01
      • 13.5.3.3
        Wireshark Output
      • 13.5.3.4
        Tcpdump Output
      • 13.5.3.5
        Starting Responder
      • 13.5.3.6
        Responder Results
      • 13.5.3.7
        FPing Active Checks
      • 13.5.3.8
        Nmap Scanning
      • 13.5.3.9
        NMAP Result Highlights
    • 13.5.4
      Identifying Users 9 topics
      • 13.5.4.1
        Kerbrute - Internal AD Username Enumeration
      • 13.5.4.2
        Cloning Kerbrute GitHub Repo
      • 13.5.4.3
        Listing Compiling Options
      • 13.5.4.4
        Compiling for Multiple Platforms and Architectures
      • 13.5.4.5
        Listing the Compiled Binaries in dist
      • 13.5.4.6
        Testing the kerbrute_linux_amd64 Binary
      • 13.5.4.7
        Adding the Tool to our Path
      • 13.5.4.8
        Moving the Binary
      • 13.5.4.9
        Enumerating Users with Kerbrute
    • 13.5.5
      Identifying Potential Vulnerabilities
    • 13.5.6
      A Word Of Caution
    • 13.5.7
      Let's Find a User
  • 13.6
    LLMNR/NBT-NS Poisoning - from Linux 4 topics
    • 13.6.1
      LLMNR & NBT-NS Primer
    • 13.6.2
      Quick Example - LLMNR/NBT-NS Poisoning
    • 13.6.3
      TTPs 5 topics
      • 13.6.3.1
        Responder In Action
      • 13.6.3.2
        Responder Logs
      • 13.6.3.3
        Starting Responder with Default Settings
      • 13.6.3.4
        Capturing with Responder
      • 13.6.3.5
        Cracking an NTLMv2 Hash With Hashcat
    • 13.6.4
      Moving On
  • 13.7
    LLMNR/NBT-NS Poisoning - from Windows 6 topics
    • 13.7.1
      Inveigh - Overview
    • 13.7.2
      Using Inveigh
    • 13.7.3
      C# Inveigh (InveighZero)
    • 13.7.4
      Remediation
    • 13.7.5
      Detection
    • 13.7.6
      Moving On
  • 13.8
    Password Spraying Overview 2 topics
    • 13.8.1
      Story Time 2 topics
      • 13.8.1.1
        Scenario 1
      • 13.8.1.2
        Scenario 2
    • 13.8.2
      Password Spraying Considerations 1 topic
      • 13.8.2.1
        Password Spray Visualization
  • 13.9
    Enumerating & Retrieving Password Policies 7 topics
    • 13.9.1
      Enumerating the Password Policy - from Linux - Credentialed
    • 13.9.2
      Enumerating the Password Policy - from Linux - SMB NULL Sessions 5 topics
      • 13.9.2.1
        Using rpcclient
      • 13.9.2.2
        Obtaining the Password Policy using rpcclient
      • 13.9.2.3
        Using enum4linux
      • 13.9.2.4
        Using enum4linux-ng
      • 13.9.2.5
        Displaying the contents of ilfreight.json
    • 13.9.3
      Enumerating Null Session - from Windows 4 topics
      • 13.9.3.1
        Establish a null session from windows
      • 13.9.3.2
        Error: Account is Disabled
      • 13.9.3.3
        Error: Password is Incorrect
      • 13.9.3.4
        Error: Account is locked out (Password Policy)
    • 13.9.4
      Enumerating the Password Policy - from Linux - LDAP Anonymous Bind 1 topic
      • 13.9.4.1
        Using ldapsearch
    • 13.9.5
      Enumerating the Password Policy - from Windows 2 topics
      • 13.9.5.1
        Using net.exe
      • 13.9.5.2
        Using PowerView
    • 13.9.6
      Analyzing the Password Policy
    • 13.9.7
      Next Steps
  • 13.10
    Password Spraying - Making a Target User List 6 topics
    • 13.10.1
      Detailed User Enumeration
    • 13.10.2
      SMB NULL Session to Pull User List 3 topics
      • 13.10.2.1
        Using enum4linux
      • 13.10.2.2
        Using rpcclient
      • 13.10.2.3
        Using CrackMapExec --users Flag
    • 13.10.3
      Gathering Users with LDAP Anonymous 2 topics
      • 13.10.3.1
        Using ldapsearch
      • 13.10.3.2
        Using windapsearch
    • 13.10.4
      Enumerating Users with Kerbrute 1 topic
      • 13.10.4.1
        Kerbrute User Enumeration
    • 13.10.5
      Credentialed Enumeration to Build our User List 1 topic
      • 13.10.5.1
        Using CrackMapExec with Valid Credentials
    • 13.10.6
      Now for the Fun
  • 13.11
    Internal Password Spraying - from Linux 2 topics
    • 13.11.1
      Internal Password Spraying from a Linux Host 4 topics
      • 13.11.1.1
        Using a Bash one-liner for the Attack
      • 13.11.1.2
        Using Kerbrute for the Attack
      • 13.11.1.3
        Using CrackMapExec & Filtering Logon Failures
      • 13.11.1.4
        Validating the Credentials with CrackMapExec
    • 13.11.2
      Local Administrator Password Reuse 1 topic
      • 13.11.2.1
        Local Admin Spraying with CrackMapExec
  • 13.12
    Internal Password Spraying - from Windows 6 topics
    • 13.12.1
      Using DomainPasswordSpray.ps1
    • 13.12.2
      Mitigations
    • 13.12.3
      Other Considerations
    • 13.12.4
      Detection
    • 13.12.5
      External Password Spraying
    • 13.12.6
      Moving Deeper
  • 13.13
    Enumerating Security Controls 5 topics
    • 13.13.1
      Windows Defender 1 topic
      • 13.13.1.1
        Checking the Status of Defender with Get-MpComputerStatus
    • 13.13.2
      AppLocker 1 topic
      • 13.13.2.1
        Using Get-AppLockerPolicy cmdlet
    • 13.13.3
      PowerShell Constrained Language Mode 1 topic
      • 13.13.3.1
        Enumerating Language Mode
    • 13.13.4
      LAPS 3 topics
      • 13.13.4.1
        Using Find-LAPSDelegatedGroups
      • 13.13.4.2
        Using Find-AdmPwdExtendedRights
      • 13.13.4.3
        Using Get-LAPSComputers
    • 13.13.5
      Conclusion
  • 13.14
    Credentialed Enumeration - from Linux 6 topics
    • 13.14.1
      CrackMapExec 8 topics
      • 13.14.1.1
        CME Help Menu
      • 13.14.1.2
        CME Options (SMB)
      • 13.14.1.3
        CME - Domain User Enumeration
      • 13.14.1.4
        CME - Domain Group Enumeration
      • 13.14.1.5
        CME - Logged On Users
      • 13.14.1.6
        CME Share Searching
      • 13.14.1.7
        Share Enumeration - Domain Controller
      • 13.14.1.8
        Spider_plus
    • 13.14.2
      SMBMap 2 topics
      • 13.14.2.1
        SMBMap To Check Access
      • 13.14.2.2
        Recursive List Of All Directories
    • 13.14.3
      rpcclient 4 topics
      • 13.14.3.1
        SMB NULL Session with rpcclient
      • 13.14.3.2
        rpcclient Enumeration
      • 13.14.3.3
        RPCClient User Enumeration By RID
      • 13.14.3.4
        Enumdomusers
    • 13.14.4
      Impacket Toolkit 4 topics
      • 13.14.4.1
        Psexec.py
      • 13.14.4.2
        Using psexec.py
      • 13.14.4.3
        wmiexec.py
      • 13.14.4.4
        Using wmiexec.py
    • 13.14.5
      Windapsearch 3 topics
      • 13.14.5.1
        Windapsearch Help
      • 13.14.5.2
        Windapsearch - Domain Admins
      • 13.14.5.3
        Windapsearch - Privileged Users
    • 13.14.6
      Bloodhound.py 6 topics
      • 13.14.6.1
        BloodHound.py Options
      • 13.14.6.2
        Executing BloodHound.py
      • 13.14.6.3
        Viewing the Results
      • 13.14.6.4
        Upload the Zip File into the BloodHound GUI
      • 13.14.6.5
        Uploading the Zip File
      • 13.14.6.6
        Searching for Relationships
  • 13.15
    Credentialed Enumeration - from Windows 6 topics
    • 13.15.1
      TTPs
    • 13.15.2
      ActiveDirectory PowerShell Module 8 topics
      • 13.15.2.1
        Discover Modules
      • 13.15.2.2
        Load ActiveDirectory Module
      • 13.15.2.3
        Get Domain Info
      • 13.15.2.4
        Get-ADUser
      • 13.15.2.5
        Checking For Trust Relationships
      • 13.15.2.6
        Group Enumeration
      • 13.15.2.7
        Detailed Group Info
      • 13.15.2.8
        Group Membership
    • 13.15.3
      PowerView 5 topics
      • 13.15.3.1
        Domain User Information
      • 13.15.3.2
        Recursive Group Membership
      • 13.15.3.3
        Trust Enumeration
      • 13.15.3.4
        Testing for Local Admin Access
      • 13.15.3.5
        Finding Users With SPN Set
    • 13.15.4
      SharpView
    • 13.15.5
      Shares
    • 13.15.6
      Snaffler 6 topics
      • 13.15.6.1
        Snaffler Execution
      • 13.15.6.2
        Snaffler in Action
      • 13.15.6.3
        BloodHound
      • 13.15.6.4
        SharpHound in Action
      • 13.15.6.5
        Unsupported Operating Systems
      • 13.15.6.6
        Local Admins
  • 13.16
    Living Off the Land 8 topics
    • 13.16.1
      Scenario
    • 13.16.2
      Env Commands For Host & Network Recon 3 topics
      • 13.16.2.1
        Basic Enumeration Commands
      • 13.16.2.2
        Basic Enumeration
      • 13.16.2.3
        Systeminfo
    • 13.16.3
      Harnessing PowerShell 8 topics
      • 13.16.3.1
        Quick Checks Using PowerShell
      • 13.16.3.2
        Downgrade Powershell
      • 13.16.3.3
        Examining the Powershell Event Log
      • 13.16.3.4
        Starting V2 Logs
      • 13.16.3.5
        Checking Defenses
      • 13.16.3.6
        Firewall Checks
      • 13.16.3.7
        Windows Defender Check (from CMD.exe)
      • 13.16.3.8
        Get-MpComputerStatus
    • 13.16.4
      Am I Alone? 1 topic
      • 13.16.4.1
        Using qwinsta
    • 13.16.5
      Network Information 2 topics
      • 13.16.5.1
        Using arp -a
      • 13.16.5.2
        Viewing the Routing Table
    • 13.16.6
      Windows Management Instrumentation (WMI) 1 topic
      • 13.16.6.1
        Quick WMI checks
    • 13.16.7
      Net Commands 5 topics
      • 13.16.7.1
        Table of Useful Net Commands
      • 13.16.7.2
        Listing Domain Groups
      • 13.16.7.3
        Information about a Domain User
      • 13.16.7.4
        Net Commands Trick
      • 13.16.7.5
        Running Net1 Command
    • 13.16.8
      Dsquery 10 topics
      • 13.16.8.1
        Dsquery DLL
      • 13.16.8.2
        User Search
      • 13.16.8.3
        Computer Search
      • 13.16.8.4
        Wildcard Search
      • 13.16.8.5
        Users With Specific Attributes Set (PASSWD_NOTREQD)
      • 13.16.8.6
        Searching for Domain Controllers
      • 13.16.8.7
        LDAP Filtering Explained
      • 13.16.8.8
        UAC Values
      • 13.16.8.9
        OID match strings
      • 13.16.8.10
        Logical Operators
  • 13.17
    Kerberoasting - from Linux 6 topics
    • 13.17.1
      Kerberoasting Overview
    • 13.17.2
      Kerberoasting - Performing the Attack
    • 13.17.3
      Efficacy of the Attack
    • 13.17.4
      Performing the Attack
    • 13.17.5
      Kerberoasting with GetUserSPNs.py 8 topics
      • 13.17.5.1
        Installing Impacket using Pip
      • 13.17.5.2
        Listing GetUserSPNs.py Help Options
      • 13.17.5.3
        Listing SPN Accounts with GetUserSPNs.py
      • 13.17.5.4
        Requesting all TGS Tickets
      • 13.17.5.5
        Requesting a Single TGS ticket
      • 13.17.5.6
        Saving the TGS Ticket to an Output File
      • 13.17.5.7
        Cracking the Ticket Offline with Hashcat
      • 13.17.5.8
        Testing Authentication against a Domain Controller
    • 13.17.6
      More Roasting
  • 13.18
    Kerberoasting - from Windows 6 topics
    • 13.18.1
      Kerberoasting - Semi Manual method 3 topics
      • 13.18.1.1
        Enumerating SPNs with setspn.exe
      • 13.18.1.2
        Targeting a Single User
      • 13.18.1.3
        Retrieving All Tickets Using setspn.exe
    • 13.18.2
      Extracting Tickets from Memory with Mimikatz 6 topics
      • 13.18.2.1
        Preparing the Base64 Blob for Cracking
      • 13.18.2.2
        Placing the Output into a File as .kirbi
      • 13.18.2.3
        Extracting the Kerberos Ticket using kirbi2john.py
      • 13.18.2.4
        Modifiying crack_file for Hashcat
      • 13.18.2.5
        Viewing the Prepared Hash
      • 13.18.2.6
        Cracking the Hash with Hashcat
    • 13.18.3
      Automated / Tool Based Route 8 topics
      • 13.18.3.1
        Using PowerView to Extract TGS Tickets
      • 13.18.3.2
        Using PowerView to Target a Specific User
      • 13.18.3.3
        Exporting All Tickets to a CSV File
      • 13.18.3.4
        Viewing the Contents of the .CSV File
      • 13.18.3.5
        Using Rubeus
      • 13.18.3.6
        Viewing Rubeus's Capabilities
      • 13.18.3.7
        Using the /stats Flag
      • 13.18.3.8
        Using the /nowrap Flag
    • 13.18.4
      A Note on Encryption Types 6 topics
      • 13.18.4.1
        Cracking the Ticket with Hashcat & rockyou.txt
      • 13.18.4.2
        Checking Supported Encryption Types
      • 13.18.4.3
        Requesting a New Ticket
      • 13.18.4.4
        Running Hashcat & Checking the Status of the Cracking Job
      • 13.18.4.5
        Viewing the Length of Time it Took to Crack
      • 13.18.4.6
        Using the /tgtdeleg Flag
    • 13.18.5
      Mitigation & Detection
    • 13.18.6
      Continuing Onwards
  • 13.19
    Access Control List (ACL) Abuse Primer 4 topics
    • 13.19.1
      Access Control List (ACL) Overview 2 topics
      • 13.19.1.1
        Viewing forend's ACL
      • 13.19.1.2
        Viewing the SACLs through the Auditing Tab
    • 13.19.2
      Access Control Entries (ACEs) 1 topic
      • 13.19.2.1
        Viewing Permissions through Active Directory Users & Computers
    • 13.19.3
      Why are ACEs Important?
    • 13.19.4
      ACL Attacks in the Wild 1 topic
      • 13.19.4.1
        Questions
  • 13.20
    ACL Enumeration 2 topics
    • 13.20.1
      Enumerating ACLs with PowerView 10 topics
      • 13.20.1.1
        Using Find-InterestingDomainAcl
      • 13.20.1.2
        Using Get-DomainObjectACL
      • 13.20.1.3
        Performing a Reverse Search & Mapping to a GUID Value
      • 13.20.1.4
        Using the -ResolveGUIDs Flag
      • 13.20.1.5
        Creating a List of Domain Users
      • 13.20.1.6
        A Useful foreach Loop
      • 13.20.1.7
        Further Enumeration of Rights Using damundsen
      • 13.20.1.8
        Investigating the Help Desk Level 1 Group with Get-DomainGroup
      • 13.20.1.9
        Investigating the Information Technology Group
      • 13.20.1.10
        Looking for Interesting Access
    • 13.20.2
      Enumerating ACLs with BloodHound 4 topics
      • 13.20.2.1
        Viewing Node Info through BloodHound
      • 13.20.2.2
        Investigating ForceChangePassword Further
      • 13.20.2.3
        Viewing Potential Attack Paths through BloodHound
      • 13.20.2.4
        Viewing Pre-Build queries through BloodHound
  • 13.21
    ACL Abuse Tactics 3 topics
    • 13.21.1
      Abusing ACLs 8 topics
      • 13.21.1.1
        Creating a PSCredential Object
      • 13.21.1.2
        Creating a SecureString Object
      • 13.21.1.3
        Changing the User's Password
      • 13.21.1.4
        Creating a SecureString Object using damundsen
      • 13.21.1.5
        Adding damundsen to the Help Desk Level 1 Group
      • 13.21.1.6
        Confirming damundsen was Added to the Group
      • 13.21.1.7
        Creating a Fake SPN
      • 13.21.1.8
        Kerberoasting with Rubeus
    • 13.21.2
      Cleanup 3 topics
      • 13.21.2.1
        Removing the Fake SPN from adunn's Account
      • 13.21.2.2
        Removing damundsen from the Help Desk Level 1 Group
      • 13.21.2.3
        Confirming damundsen was Removed from the Group
    • 13.21.3
      Detection and Remediation 3 topics
      • 13.21.3.1
        Viewing Event ID 5136
      • 13.21.3.2
        Viewing Associated SDDL
      • 13.21.3.3
        Converting the SDDL String into a Readable Format
  • 13.22
    DCSync 3 topics
    • 13.22.1
      Scenario Setup
    • 13.22.2
      What is DCSync and How Does it Work? 11 topics
      • 13.22.2.1
        Viewing adunn's Replication Privileges through ADSI Edit
      • 13.22.2.2
        Using Get-DomainUser to View adunn's Group Membership
      • 13.22.2.3
        Using Get-ObjectAcl to Check adunn's Replication Rights
      • 13.22.2.4
        Extracting NTLM Hashes and Kerberos Keys Using secretsdump.py
      • 13.22.2.5
        Listing Hashes, Kerberos Keys, and Cleartext Passwords
      • 13.22.2.6
        Viewing an Account with Reversible Encryption Password Storage Set
      • 13.22.2.7
        Enumerating Further using Get-ADUser
      • 13.22.2.8
        Checking for Reversible Encryption Option using Get- DomainUser
      • 13.22.2.9
        Displaying the Decrypted Password
      • 13.22.2.10
        Using runas.exe
      • 13.22.2.11
        Performing the Attack with Mimikatz
    • 13.22.3
      Moving On
  • 13.23
    Privileged Access 5 topics
    • 13.23.1
      Scenario Setup
    • 13.23.2
      Remote Desktop 3 topics
      • 13.23.2.1
        Enumerating the Remote Desktop Users Group
      • 13.23.2.2
        Checking the Domain Users Group's Local Admin & Execution Rights using BloodHound
      • 13.23.2.3
        Checking Remote Access Rights using BloodHound
    • 13.23.3
      WinRM 7 topics
      • 13.23.3.1
        Enumerating the Remote Management Users Group
      • 13.23.3.2
        Using the Cypher Query in BloodHound
      • 13.23.3.3
        Adding the Cypher Query as a Custom Query in BloodHound
      • 13.23.3.4
        Establishing WinRM Session from Windows
      • 13.23.3.5
        Installing Evil-WinRM
      • 13.23.3.6
        Viewing Evil-WinRM's Help Menu
      • 13.23.3.7
        Connecting to a Target with Evil-WinRM and Valid Credentials
    • 13.23.4
      SQL Server Admin 7 topics
      • 13.23.4.1
        Using a Custom Cypher Query to Check for SQL Admin Rights in BloodHound
      • 13.23.4.2
        Enumerating MSSQL Instances with PowerUpSQL
      • 13.23.4.3
        Displaying mssqlclient.py Options
      • 13.23.4.4
        Running mssqlclient.py Against the Target
      • 13.23.4.5
        Viewing our Options with Access to the SQL Server
      • 13.23.4.6
        Choosing enable_xp_cmdshell
      • 13.23.4.7
        Enumerating our Rights on the System using xp_cmdshell
    • 13.23.5
      Moving On
  • 13.24
    Kerberos "Double Hop" Problem 5 topics
    • 13.24.1
      Background
    • 13.24.2
      Workarounds
    • 13.24.3
      Workaround #1: PSCredential Object
    • 13.24.4
      Workaround #2: Register PSSession Configuration
    • 13.24.5
      Wrap Up
  • 13.25
    Bleeding Edge Vulnerabilities 7 topics
    • 13.25.1
      Scenario Setup
    • 13.25.2
      NoPac (SamAccountName Spoofing) 6 topics
      • 13.25.2.1
        Ensuring Impacket is Installed
      • 13.25.2.2
        Cloning the NoPac Exploit Repo
      • 13.25.2.3
        Scanning for NoPac
      • 13.25.2.4
        Running NoPac & Getting a Shell
      • 13.25.2.5
        Confirming the Location of Saved Tickets
      • 13.25.2.6
        Using noPac to DCSync the Built-in Administrator Account
    • 13.25.3
      Windows Defender & SMBEXEC.py Considerations 1 topic
      • 13.25.3.1
        Windows Defender Quarantine Log
    • 13.25.4
      PrintNightmare 8 topics
      • 13.25.4.1
        Cloning the Exploit
      • 13.25.4.2
        Install cube0x0's Version of Impacket
      • 13.25.4.3
        Enumerating for MS-RPRN
      • 13.25.4.4
        Generating a DLL Payload
      • 13.25.4.5
        Creating a Share with smbserver.py
      • 13.25.4.6
        Configuring & Starting MSF multi/handler
      • 13.25.4.7
        Running the Exploit
      • 13.25.4.8
        Getting the SYSTEM Shell
    • 13.25.5
      PetitPotam (MS-EFSRPC) 13 topics
      • 13.25.5.1
        Starting ntlmrelayx.py
      • 13.25.5.2
        Running PetitPotam.py
      • 13.25.5.3
        Catching Base64 Encoded Certificate for DC01
      • 13.25.5.4
        Requesting a TGT Using gettgtpkinit.py
      • 13.25.5.5
        Setting the KRB5CCNAME Environment Variable
      • 13.25.5.6
        Using Domain Controller TGT to DCSync
      • 13.25.5.7
        Running klist
      • 13.25.5.8
        Confirming Admin Access to the Domain Controller
      • 13.25.5.9
        Submitting a TGS Request for Ourselves Using getnthash.py
      • 13.25.5.10
        Using Domain Controller NTLM Hash to DCSync
      • 13.25.5.11
        Requesting TGT and Performing PTT with DC01$ Machine Account
      • 13.25.5.12
        Confirming the Ticket is in Memory
      • 13.25.5.13
        Performing DCSync with Mimikatz
    • 13.25.6
      PetitPotam Mitigations
    • 13.25.7
      Recap
  • 13.26
    Miscellaneous Misconfigurations 14 topics
    • 13.26.1
      Scenario Setup
    • 13.26.2
      Exchange Related Group Membership 1 topic
      • 13.26.2.1
        Viewing Organization Management's Permissions
    • 13.26.3
      PrivExchange
    • 13.26.4
      Printer Bug 1 topic
      • 13.26.4.1
        Enumerating for MS-PRN Printer Bug
    • 13.26.5
      MS14-068
    • 13.26.6
      Sniffing LDAP Credentials
    • 13.26.7
      Enumerating DNS Records 4 topics
      • 13.26.7.1
        Using adidnsdump
      • 13.26.7.2
        Viewing the Contents of the records.csv File
      • 13.26.7.3
        Using the -r Option to Resolve Unknown Records
      • 13.26.7.4
        Finding Hidden Records in the records.csv File
    • 13.26.8
      Other Misconfigurations 2 topics
      • 13.26.8.1
        Password in Description Field
      • 13.26.8.2
        Finding Passwords in the Description Field using Get-Domain User
    • 13.26.9
      PASSWD_NOTREQD Field 1 topic
      • 13.26.9.1
        Checking for PASSWD_NOTREQD Setting using Get-DomainUser
    • 13.26.10
      Credentials in SMB Shares and SYSVOL Scripts 2 topics
      • 13.26.10.1
        Discovering an Interesting Script
      • 13.26.10.2
        Finding a Password in the Script
    • 13.26.11
      Group Policy Preferences (GPP) Passwords 4 topics
      • 13.26.11.1
        Viewing Groups.xml
      • 13.26.11.2
        Decrypting the Password with gpp-decrypt
      • 13.26.11.3
        Locating & Retrieving GPP Passwords with CrackMapExec
      • 13.26.11.4
        Using CrackMapExec's gpp_autologin Module
    • 13.26.12
      ASREPRoasting 6 topics
      • 13.26.12.1
        Viewing an Account with the Do not Require Kerberos Preauthentication Option
      • 13.26.12.2
        Enumerating for DONT_REQ_PREAUTH Value using Get- DomainUser
      • 13.26.12.3
        Retrieving AS-REP in Proper Format using Rubeus
      • 13.26.12.4
        Cracking the Hash Offline with Hashcat
      • 13.26.12.5
        Retrieving the AS-REP Using Kerbrute
      • 13.26.12.6
        Hunting for Users with Kerberoast Pre-auth Not Required
    • 13.26.13
      Group Policy Object (GPO) Abuse 4 topics
      • 13.26.13.1
        Enumerating GPO Names with PowerView
      • 13.26.13.2
        Enumerating GPO Names with a Built-In Cmdlet
      • 13.26.13.3
        Enumerating Domain User GPO Rights
      • 13.26.13.4
        Converting GPO GUID to Name
    • 13.26.14
      Onwards
  • 13.27
    Domain Trusts Primer 4 topics
    • 13.27.1
      Scenario
    • 13.27.2
      Domain Trusts Overview 1 topic
      • 13.27.2.1
        Trust Table Side By Side
    • 13.27.3
      Enumerating Trust Relationships 8 topics
      • 13.27.3.1
        Using Get-ADTrust
      • 13.27.3.2
        Checking for Existing Trusts using Get-DomainTrust
      • 13.27.3.3
        Using Get-DomainTrustMapping
      • 13.27.3.4
        Checking Users in the Child Domain using Get-DomainUser
      • 13.27.3.5
        Using netdom to query domain trust
      • 13.27.3.6
        Using netdom to query domain controllers
      • 13.27.3.7
        Using netdom to query workstations and servers
      • 13.27.3.8
        Visualizing Trust Relationships in BloodHound
    • 13.27.4
      Onwards
  • 13.28
    Attacking Domain Trusts - Child -> Parent Trusts - from Windows 4 topics
    • 13.28.1
      SID History Primer
    • 13.28.2
      ExtraSids Attack - Mimikatz 7 topics
      • 13.28.2.1
        Obtaining the KRBTGT Account's NT Hash using Mimikatz
      • 13.28.2.2
        Using Get-DomainSID
      • 13.28.2.3
        Obtaining Enterprise Admins Group's SID using Get- DomainGroup
      • 13.28.2.4
        Using ls to Confirm No Access
      • 13.28.2.5
        Creating a Golden Ticket with Mimikatz
      • 13.28.2.6
        Confirming a Kerberos Ticket is in Memory Using klist
      • 13.28.2.7
        Listing the Entire C: Drive of the Domain Controller
    • 13.28.3
      ExtraSids Attack - Rubeus 4 topics
      • 13.28.3.1
        Using ls to Confirm No Access Before Running Rubeus
      • 13.28.3.2
        Creating a Golden Ticket using Rubeus
      • 13.28.3.3
        Confirming the Ticket is in Memory Using klist
      • 13.28.3.4
        Performing a DCSync Attack
    • 13.28.4
      Next Steps
  • 13.29
    Attacking Domain Trusts - Child -> Parent Trusts - from Linux 2 topics
    • 13.29.1
      Performing DCSync with secretsdump.py 7 topics
      • 13.29.1.1
        Performing SID Brute Forcing using lookupsid.py
      • 13.29.1.2
        Looking for the Domain SID
      • 13.29.1.3
        Grabbing the Domain SID & Attaching to Enterprise Admin's RID
      • 13.29.1.4
        Constructing a Golden Ticket using ticketer.py
      • 13.29.1.5
        Setting the KRB5CCNAME Environment Variable
      • 13.29.1.6
        Getting a SYSTEM shell using Impacket's psexec.py
      • 13.29.1.7
        Performing the Attack with raiseChild.py
    • 13.29.2
      More Fun
  • 13.30
    Attacking Domain Trusts - Cross-Forest Trust Abuse - from Windows 4 topics
    • 13.30.1
      Cross-Forest Kerberoasting 3 topics
      • 13.30.1.1
        Enumerating Accounts for Associated SPNs Using Get- DomainUser
      • 13.30.1.2
        Enumerating the mssqlsvc Account
      • 13.30.1.3
        Performing a Kerberoasting Attacking with Rubeus Using /domain Flag
    • 13.30.2
      Admin Password Re-Use & Group Membership 2 topics
      • 13.30.2.1
        Using Get-DomainForeignGroupMember
      • 13.30.2.2
        Accessing DC03 Using Enter-PSSession
    • 13.30.3
      SID History Abuse - Cross Forest
    • 13.30.4
      Onwards
  • 13.31
    Attacking Domain Trusts - Cross-Forest Trust Abuse - from Linux 3 topics
    • 13.31.1
      Cross-Forest Kerberoasting 2 topics
      • 13.31.1.1
        Using GetUserSPNs.py
      • 13.31.1.2
        Using the -request Flag
    • 13.31.2
      Hunting Foreign Group Membership with Bloodhound- python 6 topics
      • 13.31.2.1
        Adding INLANEFREIGHT.LOCAL Information to /etc/resolv.conf
      • 13.31.2.2
        Running bloodhound-python Against INLANEFREIGHT.LOCAL
      • 13.31.2.3
        Compressing the File with zip -r
      • 13.31.2.4
        Adding FREIGHTLOGISTICS.LOCAL Information to /etc/resolv.conf
      • 13.31.2.5
        Running bloodhound-python Against FREIGHTLOGISTICS.LOCAL
      • 13.31.2.6
        Viewing Dangerous Rights through BloodHound
    • 13.31.3
      Closing Thoughts on Trusts
  • 13.32
    Hardening Active Directory 3 topics
    • 13.32.1
      Step One: Document and Audit 1 topic
      • 13.32.1.1
        Things To Document and Track
    • 13.32.2
      People, Processes, and Technology 5 topics
      • 13.32.2.1
        People
      • 13.32.2.2
        Protected Users Group
      • 13.32.2.3
        Viewing the Protected Users Group with Get-ADGroup
      • 13.32.2.4
        Processes
      • 13.32.2.5
        Technology
    • 13.32.3
      Protections By Section 1 topic
      • 13.32.3.1
        MITRE ATT&CK Breakdown
  • 13.33
    Additional AD Auditing Techniques 4 topics
    • 13.33.1
      Creating an AD Snapshot with Active Directory Explorer 3 topics
      • 13.33.1.1
        Logging in with AD Explorer
      • 13.33.1.2
        Browsing AD with AD Explorer
      • 13.33.1.3
        Creating a Snapshot of AD with AD Explorer
    • 13.33.2
      PingCastle 6 topics
      • 13.33.2.1
        Viewing the PingCastle Help Menu
      • 13.33.2.2
        Running PingCastle
      • 13.33.2.3
        PingCastle Interactive TUI
      • 13.33.2.4
        Scanner Options
      • 13.33.2.5
        Viewing The Report
      • 13.33.2.6
        Group Policy
    • 13.33.3
      Group3r 3 topics
      • 13.33.3.1
        Group3r Basic Usage
      • 13.33.3.2
        Reading Output
      • 13.33.3.3
        Group3r Finding
    • 13.33.4
      ADRecon 2 topics
      • 13.33.4.1
        Running ADRecon
      • 13.33.4.2
        Reporting
  • 13.34
    AD Enumeration & Attacks - Skills Assessment Part I 1 topic
    • 13.34.1
      Scenario
  • 13.35
    AD Enumeration & Attacks - Skills Assessment Part II 1 topic
    • 13.35.1
      Scenario
  • 13.36
    Beyond this Module 5 topics
    • 13.36.1
      Status Update
    • 13.36.2
      Real World
    • 13.36.3
      What's Next?
    • 13.36.4
      More AD Learning Opportunities 5 topics
      • 13.36.4.1
        Boxes To Pwn
      • 13.36.4.2
        ProLabs
      • 13.36.4.3
        Endgames
      • 13.36.4.4
        Great Videos to Check Out
      • 13.36.4.5
        Writers and Blogs To Follow
    • 13.36.5
      Closing Thoughts
14 Using Web Proxies Using Web Proxies module 71 topics Module 14
  • 14.1
    Intro to Web Proxies 4 topics
    • 14.1.1
      What Are Web Proxies?
    • 14.1.2
      Uses of Web Proxies
    • 14.1.3
      Burp Suite
    • 14.1.4
      OWASP Zed Attack Proxy (ZAP)
  • 14.2
    Setting Up 2 topics
    • 14.2.1
      Burp Suite
    • 14.2.2
      ZAP
  • 14.3
    Proxy Setup 3 topics
    • 14.3.1
      Pre-Configured Browser
    • 14.3.2
      Proxy Setup
    • 14.3.3
      Installing CA Certificate
  • 14.4
    Intercepting Web Requests 2 topics
    • 14.4.1
      Intercepting Requests 2 topics
      • 14.4.1.1
        Burp
      • 14.4.1.2
        ZAP
    • 14.4.2
      Manipulating Intercepted Requests
  • 14.5
    Intercepting Responses 2 topics
    • 14.5.1
      Burp
    • 14.5.2
      ZAP
  • 14.6
    Automatic Modification 2 topics
    • 14.6.1
      Automatic Request Modification 2 topics
      • 14.6.1.1
        Burp Match and Replace
      • 14.6.1.2
        ZAP Replacer
    • 14.6.2
      Automatic Response Modification
  • 14.7
    Repeating Requests 2 topics
    • 14.7.1
      Proxy History
    • 14.7.2
      Repeating Requests 2 topics
      • 14.7.2.1
        Burp
      • 14.7.2.2
        ZAP
  • 14.8
    Encoding/Decoding 3 topics
    • 14.8.1
      URL Encoding
    • 14.8.2
      Decoding
    • 14.8.3
      Encoding
  • 14.9
    Proxying Tools 3 topics
    • 14.9.1
      Proxychains
    • 14.9.2
      Nmap
    • 14.9.3
      Metasploit
  • 14.10
    Burp Intruder 5 topics
    • 14.10.1
      Target
    • 14.10.2
      Positions
    • 14.10.3
      Payloads 4 topics
      • 14.10.3.1
        Payload Sets
      • 14.10.3.2
        Payload Options
      • 14.10.3.3
        Payload Processing
      • 14.10.3.4
        Payload Encoding
    • 14.10.4
      Options
    • 14.10.5
      Attack
  • 14.11
    ZAP Fuzzer 6 topics
    • 14.11.1
      Fuzz
    • 14.11.2
      Locations
    • 14.11.3
      Payloads
    • 14.11.4
      Processors
    • 14.11.5
      Options
    • 14.11.6
      Start
  • 14.12
    Burp Scanner 5 topics
    • 14.12.1
      Target Scope
    • 14.12.2
      Crawler
    • 14.12.3
      Passive Scanner
    • 14.12.4
      Active Scanner
    • 14.12.5
      Reporting
  • 14.13
    ZAP Scanner 4 topics
    • 14.13.1
      Spider
    • 14.13.2
      Passive Scanner
    • 14.13.3
      Active Scanner
    • 14.13.4
      Reporting
  • 14.14
    Extensions 3 topics
    • 14.14.1
      BApp Store
    • 14.14.2
      ZAP Marketplace
    • 14.14.3
      Closing Thoughts
  • 14.15
    Skills Assessment - Using Web Proxies
15 Attacking Web Applications with Ffuf Attacking Web Applications with Ffuf module 28 topics Module 15
  • 15.1
    Introduction
  • 15.2
    Web Fuzzing 2 topics
    • 15.2.1
      Fuzzing
    • 15.2.2
      Wordlists
  • 15.3
    Directory Fuzzing 2 topics
    • 15.3.1
      Ffuf
    • 15.3.2
      Directory Fuzzing
  • 15.4
    Page Fuzzing 2 topics
    • 15.4.1
      Extension Fuzzing
    • 15.4.2
      Page Fuzzing
  • 15.5
    Recursive Fuzzing 2 topics
    • 15.5.1
      Recursive Flags
    • 15.5.2
      Recursive Scanning
  • 15.6
    DNS Records
  • 15.7
    Sub-domain Fuzzing 1 topic
    • 15.7.1
      Sub-domains
  • 15.8
    Vhost Fuzzing 2 topics
    • 15.8.1
      Vhosts vs. Sub-domains
    • 15.8.2
      Vhosts Fuzzing
  • 15.9
    Filtering Results 1 topic
    • 15.9.1
      Filtering
  • 15.10
    Parameter Fuzzing - GET 1 topic
    • 15.10.1
      GET Request Fuzzing
  • 15.11
    Parameter Fuzzing - POST
  • 15.12
    Value Fuzzing 2 topics
    • 15.12.1
      Custom Wordlist
    • 15.12.2
      Value Fuzzing
  • 15.13
    Skills Assessment - Web Fuzzing
16 Login Brute Forcing Login Brute Forcing module 62 topics Module 16
  • 16.1
    Introduction 4 topics
    • 16.1.1
      What is Brute Forcing?
    • 16.1.2
      How Brute Forcing Works
    • 16.1.3
      Types of Brute Forcing
    • 16.1.4
      The Role of Brute Forcing in Penetration Testing
  • 16.2
    Password Security Fundamentals 5 topics
    • 16.2.1
      The Importance of Strong Passwords
    • 16.2.2
      The Anatomy of a Strong Password
    • 16.2.3
      Common Password Weaknesses
    • 16.2.4
      Password Policies
    • 16.2.5
      The Perils of Default Credentials 1 topic
      • 16.2.5.1
        Brute-forcing and Password Security
  • 16.3
    Brute Force Attacks 1 topic
    • 16.3.1
      Cracking the PIN
  • 16.4
    Dictionary Attacks 4 topics
    • 16.4.1
      The Power of Words
    • 16.4.2
      Brute Force vs. Dictionary Attack
    • 16.4.3
      Building and Utilizing Wordlists
    • 16.4.4
      Throwing a dictionary at the problem
  • 16.5
    Hybrid Attacks 2 topics
    • 16.5.1
      Hybrid Attacks in Action 1 topic
      • 16.5.1.1
        The Power of Hybrid Attacks
    • 16.5.2
      Credential Stuffing: Leveraging Stolen Data for Unauthorized Access 1 topic
      • 16.5.2.1
        The Password Reuse Problem
  • 16.6
    Hydra 2 topics
    • 16.6.1
      Installation
    • 16.6.2
      Basic Usage 6 topics
      • 16.6.2.1
        Hydra Services
      • 16.6.2.2
        Brute-Forcing HTTP Authentication
      • 16.6.2.3
        Targeting Multiple SSH Servers
      • 16.6.2.4
        Testing FTP Credentials on a Non-Standard Port
      • 16.6.2.5
        Brute-Forcing a Web Login Form
      • 16.6.2.6
        Advanced RDP Brute-Forcing
  • 16.7
    Basic HTTP Authentication 1 topic
    • 16.7.1
      Exploiting Basic Auth with Hydra
  • 16.8
    Login Forms 4 topics
    • 16.8.1
      Understanding Login Forms
    • 16.8.2
      A Basic Login Form Example
    • 16.8.3
      http-post-form 4 topics
      • 16.8.3.1
        Understanding the Condition String
      • 16.8.3.2
        Manual Inspection
      • 16.8.3.3
        Browser Developer Tools
      • 16.8.3.4
        Proxy Interception
    • 16.8.4
      Constructing the params String for Hydra
  • 16.9
    Medusa 2 topics
    • 16.9.1
      Installation
    • 16.9.2
      Command Syntax and Parameter Table 4 topics
      • 16.9.2.1
        Medusa Modules
      • 16.9.2.2
        Targeting an SSH Server
      • 16.9.2.3
        Targeting Multiple Web Servers with Basic HTTP Authentication
      • 16.9.2.4
        Testing for Empty or Default Passwords
  • 16.10
    Web Services 2 topics
    • 16.10.1
      Kick-off
    • 16.10.2
      Gaining Access 3 topics
      • 16.10.2.1
        Expanding the Attack Surface
      • 16.10.2.2
        Targeting the FTP Server
      • 16.10.2.3
        Retrieving The Flag
  • 16.11
    Custom Wordlists 2 topics
    • 16.11.1
      Username Anarchy
    • 16.11.2
      CUPP
  • 16.12
    Skills Assessment Part 1
  • 16.13
    Skills Assessment Part 2
17 SQL Injection Fundamentals SQL Injection Fundamentals module 85 topics Module 17
  • 17.1
    Introduction 3 topics
    • 17.1.1
      SQL Injection (SQLi)
    • 17.1.2
      Use Cases and Impact
    • 17.1.3
      Prevention
  • 17.2
    Intro to Databases 2 topics
    • 17.2.1
      Database Management Systems
    • 17.2.2
      Architecture
  • 17.3
    Types of Databases 2 topics
    • 17.3.1
      Relational Databases
    • 17.3.2
      Non-relational Databases
  • 17.4
    Intro to MySQL 4 topics
    • 17.4.1
      Structured Query Language (SQL)
    • 17.4.2
      Command Line
    • 17.4.3
      Creating a database
    • 17.4.4
      Tables 1 topic
      • 17.4.4.1
        Table Properties
  • 17.5
    SQL Statements 5 topics
    • 17.5.1
      INSERT Statement
    • 17.5.2
      SELECT Statement
    • 17.5.3
      DROP Statement
    • 17.5.4
      ALTER Statement
    • 17.5.5
      UPDATE Statement
  • 17.6
    Query Results 4 topics
    • 17.6.1
      Sorting Results
    • 17.6.2
      LIMIT results
    • 17.6.3
      WHERE Clause
    • 17.6.4
      LIKE Clause
  • 17.7
    SQL Operators 6 topics
    • 17.7.1
      AND Operator
    • 17.7.2
      OR Operator
    • 17.7.3
      NOT Operator
    • 17.7.4
      Symbol Operators
    • 17.7.5
      Operators in queries
    • 17.7.6
      Multiple Operator Precedence
  • 17.8
    Intro to SQL Injections 5 topics
    • 17.8.1
      Use of SQL in Web Applications
    • 17.8.2
      What is an Injection?
    • 17.8.3
      SQL Injection
    • 17.8.4
      Syntax Errors
    • 17.8.5
      Types of SQL Injections
  • 17.9
    Subverting Query Logic 4 topics
    • 17.9.1
      Authentication Bypass
    • 17.9.2
      SQLi Discovery
    • 17.9.3
      OR Injection
    • 17.9.4
      Auth Bypass with OR operator
  • 17.10
    Using Comments 3 topics
    • 17.10.1
      Comments
    • 17.10.2
      Auth Bypass with comments
    • 17.10.3
      Another Example
  • 17.11
    Union Clause 3 topics
    • 17.11.1
      Union
    • 17.11.2
      Even Columns
    • 17.11.3
      Un-even Columns
  • 17.12
    Union Injection 2 topics
    • 17.12.1
      Detect number of columns 2 topics
      • 17.12.1.1
        Using ORDER BY
      • 17.12.1.2
        Using UNION
    • 17.12.2
      Location of Injection
  • 17.13
    Database Enumeration 6 topics
    • 17.13.1
      MySQL Fingerprinting
    • 17.13.2
      INFORMATION_SCHEMA Database
    • 17.13.3
      SCHEMATA
    • 17.13.4
      TABLES
    • 17.13.5
      COLUMNS
    • 17.13.6
      Data
  • 17.14
    Reading Files 3 topics
    • 17.14.1
      Privileges 2 topics
      • 17.14.1.1
        DB User
      • 17.14.1.2
        User Privileges
    • 17.14.2
      LOAD_FILE
    • 17.14.3
      Another Example
  • 17.15
    Writing Files 4 topics
    • 17.15.1
      Write File Privileges 1 topic
      • 17.15.1.1
        secure_file_priv
    • 17.15.2
      SELECT INTO OUTFILE
    • 17.15.3
      Writing Files through SQL Injection
    • 17.15.4
      Writing a Web Shell
  • 17.16
    Mitigating SQL Injection 6 topics
    • 17.16.1
      Input Sanitization
    • 17.16.2
      Input Validation
    • 17.16.3
      User Privileges
    • 17.16.4
      Web Application Firewall
    • 17.16.5
      Parameterized Queries
    • 17.16.6
      Conclusion
  • 17.17
    Skills Assessment - SQL Injection Fundamentals
18 SQLMap Essentials SQLMap Essentials module 79 topics Module 18
  • 18.1
    SQLMap Overview 10 topics
    • 18.1.1
      SQLMap Installation
    • 18.1.2
      Supported Databases
    • 18.1.3
      Supported SQL Injection Types
    • 18.1.4
      Boolean-based blind SQL Injection
    • 18.1.5
      Error-based SQL Injection
    • 18.1.6
      UNION query-based
    • 18.1.7
      Stacked queries
    • 18.1.8
      Time-based blind SQL Injection
    • 18.1.9
      Inline queries
    • 18.1.10
      Out-of-band SQL Injection 1 topic
      • 18.1.10.1
        Questions
  • 18.2
    Getting Started with SQLMap 1 topic
    • 18.2.1
      Basic Scenario
  • 18.3
    SQLMap Output Description 1 topic
    • 18.3.1
      Log Messages Description 14 topics
      • 18.3.1.1
        URL content is stable
      • 18.3.1.2
        Parameter appears to be dynamic
      • 18.3.1.3
        Parameter might be injectable
      • 18.3.1.4
        Parameter might be vulnerable to XSS attacks
      • 18.3.1.5
        Back-end DBMS is '...'
      • 18.3.1.6
        Level/risk values
      • 18.3.1.7
        Reflective values found
      • 18.3.1.8
        Parameter appears to be injectable
      • 18.3.1.9
        Time-based comparison statistical model
      • 18.3.1.10
        Extending UNION query injection technique tests
      • 18.3.1.11
        Technique appears to be usable
      • 18.3.1.12
        Parameter is vulnerable
      • 18.3.1.13
        Sqlmap identified injection points
      • 18.3.1.14
        Data logged to text files
  • 18.4
    Running SQLMap on an HTTP Request 5 topics
    • 18.4.1
      Curl Commands
    • 18.4.2
      GET/POST Requests
    • 18.4.3
      Full HTTP Requests
    • 18.4.4
      Custom SQLMap Requests
    • 18.4.5
      Custom HTTP Requests
  • 18.5
    Handling SQLMap Errors 4 topics
    • 18.5.1
      Display Errors
    • 18.5.2
      Store the Traffic
    • 18.5.3
      Verbose Output
    • 18.5.4
      Using Proxy
  • 18.6
    Attack Tuning 3 topics
    • 18.6.1
      Prefix/Suffix
    • 18.6.2
      Level/Risk
    • 18.6.3
      Advanced Tuning 6 topics
      • 18.6.3.1
        Status Codes
      • 18.6.3.2
        Titles
      • 18.6.3.3
        Strings
      • 18.6.3.4
        Text-only
      • 18.6.3.5
        Techniques
      • 18.6.3.6
        UNION SQLi Tuning
  • 18.7
    Database Enumeration 6 topics
    • 18.7.1
      SQLMap Data Exfiltration
    • 18.7.2
      Basic DB Data Enumeration
    • 18.7.3
      Table Enumeration
    • 18.7.4
      Table/Row Enumeration
    • 18.7.5
      Conditional Enumeration
    • 18.7.6
      Full DB Enumeration
  • 18.8
    Advanced Database Enumeration 4 topics
    • 18.8.1
      DB Schema Enumeration
    • 18.8.2
      Searching for Data
    • 18.8.3
      Password Enumeration and Cracking
    • 18.8.4
      DB Users Password Enumeration and Cracking
  • 18.9
    Bypassing Web Application Protections 8 topics
    • 18.9.1
      Anti-CSRF Token Bypass
    • 18.9.2
      Unique Value Bypass
    • 18.9.3
      Calculated Parameter Bypass
    • 18.9.4
      IP Address Concealing
    • 18.9.5
      WAF Bypass
    • 18.9.6
      User-agent Blacklisting Bypass
    • 18.9.7
      Tamper Scripts
    • 18.9.8
      Miscellaneous Bypasses
  • 18.10
    OS Exploitation 6 topics
    • 18.10.1
      File Read/Write
    • 18.10.2
      Checking for DBA Privileges
    • 18.10.3
      Reading Local Files
    • 18.10.4
      Writing Local Files
    • 18.10.5
      OS Command Execution
    • 18.10.6
      Skills Assessment
19 Cross-Site Scripting (XSS) Cross-Site Scripting (XSS) module 40 topics Module 19
  • 19.1
    Introduction 3 topics
    • 19.1.1
      What is XSS
    • 19.1.2
      XSS Attacks
    • 19.1.3
      Types of XSS
  • 19.2
    Stored XSS 1 topic
    • 19.2.1
      XSS Testing Payloads
  • 19.3
    Reflected XSS
  • 19.4
    DOM XSS 2 topics
    • 19.4.1
      Source & Sink
    • 19.4.2
      DOM Attacks
  • 19.5
    XSS Discovery 3 topics
    • 19.5.1
      Automated Discovery
    • 19.5.2
      Manual Discovery 1 topic
      • 19.5.2.1
        XSS Payloads
    • 19.5.3
      Code Review
  • 19.6
    Defacing 4 topics
    • 19.6.1
      Defacement Elements
    • 19.6.2
      Changing Background
    • 19.6.3
      Changing Page Title
    • 19.6.4
      Changing Page Text
  • 19.7
    Phishing 4 topics
    • 19.7.1
      XSS Discovery
    • 19.7.2
      Login Form Injection
    • 19.7.3
      Cleaning Up
    • 19.7.4
      Credential Stealing
  • 19.8
    Session Hijacking 3 topics
    • 19.8.1
      Blind XSS Detection
    • 19.8.2
      Loading a Remote Script
    • 19.8.3
      Session Hijacking
  • 19.9
    XSS Prevention 2 topics
    • 19.9.1
      Front-end 3 topics
      • 19.9.1.1
        Input Validation
      • 19.9.1.2
        Input Sanitization
      • 19.9.1.3
        Direct Input
    • 19.9.2
      Back-end 4 topics
      • 19.9.2.1
        Input Validation
      • 19.9.2.2
        Input Sanitization
      • 19.9.2.3
        Output HTML Encoding
      • 19.9.2.4
        Server Configuration
  • 19.10
    Skills Assessment
20 File Inclusion File Inclusion module 62 topics Module 20
  • 20.1
    Intro to File Inclusions 3 topics
    • 20.1.1
      Local File Inclusion (LFI)
    • 20.1.2
      Examples of Vulnerable Code 4 topics
      • 20.1.2.1
        PHP
      • 20.1.2.2
        NodeJS
      • 20.1.2.3
        Java
      • 20.1.2.4
        .NET
    • 20.1.3
      Read vs Execute
  • 20.2
    Local File Inclusion (LFI) 5 topics
    • 20.2.1
      Basic LFI
    • 20.2.2
      Path Traversal
    • 20.2.3
      Filename Prefix
    • 20.2.4
      Appended Extensions
    • 20.2.5
      Second-Order Attacks
  • 20.3
    Basic Bypasses 4 topics
    • 20.3.1
      Non-Recursive Path Traversal Filters
    • 20.3.2
      Encoding
    • 20.3.3
      Approved Paths
    • 20.3.4
      Appended Extension 2 topics
      • 20.3.4.1
        Path Truncation
      • 20.3.4.2
        Null Bytes
  • 20.4
    PHP Filters 4 topics
    • 20.4.1
      Input Filters
    • 20.4.2
      Fuzzing for PHP Files
    • 20.4.3
      Standard PHP Inclusion
    • 20.4.4
      Source Code Disclosure
  • 20.5
    PHP Wrappers 3 topics
    • 20.5.1
      Data 2 topics
      • 20.5.1.1
        Checking PHP Configurations
      • 20.5.1.2
        Remote Code Execution
    • 20.5.2
      Input
    • 20.5.3
      Expect
  • 20.6
    Remote File Inclusion (RFI) 6 topics
    • 20.6.1
      Local vs. Remote File Inclusion
    • 20.6.2
      Verify RFI
    • 20.6.3
      Remote Code Execution with RFI
    • 20.6.4
      HTTP
    • 20.6.5
      FTP
    • 20.6.6
      SMB
  • 20.7
    LFI and File Uploads 3 topics
    • 20.7.1
      Image upload 2 topics
      • 20.7.1.1
        Crafting Malicious Image
      • 20.7.1.2
        Uploaded File Path
    • 20.7.2
      Zip Upload
    • 20.7.3
      Phar Upload
  • 20.8
    Log Poisoning 2 topics
    • 20.8.1
      PHP Session Poisoning
    • 20.8.2
      Server Log Poisoning
  • 20.9
    Automated Scanning 4 topics
    • 20.9.1
      Fuzzing Parameters
    • 20.9.2
      LFI wordlists
    • 20.9.3
      Fuzzing Server Files 2 topics
      • 20.9.3.1
        Server Webroot
      • 20.9.3.2
        Server Logs/Configurations
    • 20.9.4
      LFI Tools
  • 20.10
    File Inclusion Prevention 4 topics
    • 20.10.1
      File Inclusion Prevention
    • 20.10.2
      Preventing Directory Traversal
    • 20.10.3
      Web Server Configuration
    • 20.10.4
      Web Application Firewall (WAF)
  • 20.11
    Skills Assessment - File Inclusion 1 topic
    • 20.11.1
      Scenario
21 File Upload Attacks File Upload Attacks module 43 topics Module 21
  • 21.1
    Intro to File Upload Attacks 1 topic
    • 21.1.1
      Types of File Upload Attacks
  • 21.2
    Absent Validation 3 topics
    • 21.2.1
      Arbitrary File Upload
    • 21.2.2
      Identifying Web Framework
    • 21.2.3
      Vulnerability Identification
  • 21.3
    Upload Exploitation 4 topics
    • 21.3.1
      Web Shells
    • 21.3.2
      Writing Custom Web Shell
    • 21.3.3
      Reverse Shell
    • 21.3.4
      Generating Custom Reverse Shell Scripts
  • 21.4
    Client-Side Validation 3 topics
    • 21.4.1
      Client-Side Validation
    • 21.4.2
      Back-end Request Modification
    • 21.4.3
      Disabling Front-end Validation
  • 21.5
    Blacklist Filters 3 topics
    • 21.5.1
      Blacklisting Extensions
    • 21.5.2
      Fuzzing Extensions
    • 21.5.3
      Non-Blacklisted Extensions
  • 21.6
    Whitelist Filters 4 topics
    • 21.6.1
      Whitelisting Extensions
    • 21.6.2
      Double Extensions
    • 21.6.3
      Reverse Double Extension
    • 21.6.4
      Character Injection
  • 21.7
    Type Filters 2 topics
    • 21.7.1
      Content-Type
    • 21.7.2
      MIME-Type
  • 21.8
    Limited File Uploads 3 topics
    • 21.8.1
      XSS
    • 21.8.2
      XXE
    • 21.8.3
      DoS
  • 21.9
    Other Upload Attacks 4 topics
    • 21.9.1
      Injections in File Name
    • 21.9.2
      Upload Directory Disclosure
    • 21.9.3
      Windows-specific Attacks
    • 21.9.4
      Advanced File Upload Attacks
  • 21.10
    Preventing File Upload Vulnerabilities 4 topics
    • 21.10.1
      Extension Validation
    • 21.10.2
      Content Validation
    • 21.10.3
      Upload Disclosure
    • 21.10.4
      Further Security
  • 21.11
    Skills Assessment - File Upload Attacks 1 topic
    • 21.11.1
      Extra Exercise
22 Command Injections Command Injections module 51 topics Module 22
  • 22.1
    Intro to Command Injections 2 topics
    • 22.1.1
      What are Injections
    • 22.1.2
      OS Command Injections 2 topics
      • 22.1.2.1
        PHP Example
      • 22.1.2.2
        NodeJS Example
  • 22.2
    Detection 2 topics
    • 22.2.1
      Command Injection Detection
    • 22.2.2
      Command Injection Methods
  • 22.3
    Injecting Commands 2 topics
    • 22.3.1
      Injecting Our Command
    • 22.3.2
      Bypassing Front-End Validation 1 topic
      • 22.3.2.1
        Burp POST Request
  • 22.4
    Other Injection Operators 2 topics
    • 22.4.1
      AND Operator
    • 22.4.2
      OR Operator
  • 22.5
    Identifying Filters 3 topics
    • 22.5.1
      Filter/WAF Detection
    • 22.5.2
      Blacklisted Characters
    • 22.5.3
      Identifying Blacklisted Character
  • 22.6
    Bypassing Space Filters 2 topics
    • 22.6.1
      Bypass Blacklisted Operators
    • 22.6.2
      Bypass Blacklisted Spaces 3 topics
      • 22.6.2.1
        Using Tabs
      • 22.6.2.2
        Using $IFS
      • 22.6.2.3
        Using Brace Expansion
  • 22.7
    Bypassing Other Blacklisted Characters 3 topics
    • 22.7.1
      Linux
    • 22.7.2
      Windows
    • 22.7.3
      Character Shifting
  • 22.8
    Bypassing Blacklisted Commands 4 topics
    • 22.8.1
      Commands Blacklist
    • 22.8.2
      Linux & Windows 1 topic
      • 22.8.2.1
        Burp POST Request
    • 22.8.3
      Linux Only
    • 22.8.4
      Windows Only
  • 22.9
    Advanced Command Obfuscation 3 topics
    • 22.9.1
      Case Manipulation 1 topic
      • 22.9.1.1
        Burp POST Request
    • 22.9.2
      Reversed Commands 1 topic
      • 22.9.2.1
        Burp POST Request
    • 22.9.3
      Encoded Commands 1 topic
      • 22.9.3.1
        Burp POST Request
  • 22.10
    Evasion Tools 2 topics
    • 22.10.1
      Linux (Bashfuscator)
    • 22.10.2
      Windows (DOSfuscation)
  • 22.11
    Command Injection Prevention 4 topics
    • 22.11.1
      System Commands
    • 22.11.2
      Input Validation
    • 22.11.3
      Input Sanitization
    • 22.11.4
      Server Configuration
  • 22.12
    Skills Assessment
23 Web Attacks Web Attacks module 63 topics Module 23
  • 23.1
    Introduction to Web Attacks 1 topic
    • 23.1.1
      Web Attacks 3 topics
      • 23.1.1.1
        HTTP Verb Tampering
      • 23.1.1.2
        Insecure Direct Object References (IDOR)
      • 23.1.1.3
        XML External Entity (XXE) Injection
  • 23.2
    Intro to HTTP Verb Tampering 3 topics
    • 23.2.1
      HTTP Verb Tampering
    • 23.2.2
      Insecure Configurations
    • 23.2.3
      Insecure Coding
  • 23.3
    Bypassing Basic Authentication 2 topics
    • 23.3.1
      Identify
    • 23.3.2
      Exploit
  • 23.4
    Bypassing Security Filters 2 topics
    • 23.4.1
      Identify
    • 23.4.2
      Exploit
  • 23.5
    Verb Tampering Prevention 2 topics
    • 23.5.1
      Insecure Configuration
    • 23.5.2
      Insecure Coding
  • 23.6
    Intro to IDOR 2 topics
    • 23.6.1
      What Makes an IDOR Vulnerability
    • 23.6.2
      Impact of IDOR Vulnerabilities
  • 23.7
    Identifying IDORs 4 topics
    • 23.7.1
      URL Parameters & APIs
    • 23.7.2
      AJAX Calls
    • 23.7.3
      Understand Hashing/Encoding
    • 23.7.4
      Compare User Roles
  • 23.8
    Mass IDOR Enumeration 2 topics
    • 23.8.1
      Insecure Parameters
    • 23.8.2
      Mass Enumeration
  • 23.9
    Bypassing Encoded References 2 topics
    • 23.9.1
      Function Disclosure
    • 23.9.2
      Mass Enumeration
  • 23.10
    IDOR in Insecure APIs 2 topics
    • 23.10.1
      Identifying Insecure APIs
    • 23.10.2
      Exploiting Insecure APIs
  • 23.11
    Chaining IDOR Vulnerabilities 3 topics
    • 23.11.1
      Information Disclosure
    • 23.11.2
      Modifying Other Users' Details
    • 23.11.3
      Chaining Two IDOR Vulnerabilities
  • 23.12
    IDOR Prevention 2 topics
    • 23.12.1
      Object-Level Access Control
    • 23.12.2
      Object Referencing
  • 23.13
    Intro to XXE 3 topics
    • 23.13.1
      XML
    • 23.13.2
      XML DTD
    • 23.13.3
      XML Entities
  • 23.14
    Local File Disclosure 5 topics
    • 23.14.1
      Identifying
    • 23.14.2
      Reading Sensitive Files
    • 23.14.3
      Reading Source Code
    • 23.14.4
      Remote Code Execution with XXE
    • 23.14.5
      Other XXE Attacks
  • 23.15
    Advanced File Disclosure 2 topics
    • 23.15.1
      Advanced Exfiltration with CDATA
    • 23.15.2
      Error Based XXE
  • 23.16
    Blind Data Exfiltration 2 topics
    • 23.16.1
      Out-of-band Data Exfiltration
    • 23.16.2
      Automated OOB Exfiltration
  • 23.17
    XXE Prevention 2 topics
    • 23.17.1
      Avoiding Outdated Components
    • 23.17.2
      Using Safe XML Configurations
  • 23.18
    Web Attacks - Skills Assessment 1 topic
    • 23.18.1
      Scenario
24 Attacking Common Applications Attacking Common Applications module 150 topics Module 24
  • 24.1
    Introduction to Attacking Common Applications 4 topics
    • 24.1.1
      Application Data
    • 24.1.2
      A Quick Story
    • 24.1.3
      Common Applications
    • 24.1.4
      Module Targets
  • 24.2
    Application Discovery & Enumeration 7 topics
    • 24.2.1
      Nmap - Web Discovery
    • 24.2.2
      Getting Organized
    • 24.2.3
      Initial Enumeration
    • 24.2.4
      Using EyeWitness
    • 24.2.5
      Using Aquatone
    • 24.2.6
      Interpreting the Results
    • 24.2.7
      Moving On
  • 24.3
    WordPress - Discovery & Enumeration 5 topics
    • 24.3.1
      Discovery/Footprinting
    • 24.3.2
      Enumeration
    • 24.3.3
      Enumerating Users
    • 24.3.4
      WPScan
    • 24.3.5
      Moving On
  • 24.4
    Attacking WordPress 4 topics
    • 24.4.1
      Login Bruteforce
    • 24.4.2
      Code Execution
    • 24.4.3
      Leveraging Known Vulnerabilities 2 topics
      • 24.4.3.1
        Vulnerable Plugins - mail-masta
      • 24.4.3.2
        Vulnerable Plugins - wpDiscuz
    • 24.4.4
      Moving On
  • 24.5
    Joomla - Discovery & Enumeration 2 topics
    • 24.5.1
      Discovery/Footprinting
    • 24.5.2
      Enumeration
  • 24.6
    Attacking Joomla 3 topics
    • 24.6.1
      Abusing Built-In Functionality
    • 24.6.2
      Leveraging Known Vulnerabilities
    • 24.6.3
      Moving On
  • 24.7
    Drupal - Discovery & Enumeration 2 topics
    • 24.7.1
      Discovery/Footprinting
    • 24.7.2
      Enumeration
  • 24.8
    Attacking Drupal 7 topics
    • 24.8.1
      Leveraging the PHP Filter Module
    • 24.8.2
      Uploading a Backdoored Module
    • 24.8.3
      Leveraging Known Vulnerabilities
    • 24.8.4
      Drupalgeddon
    • 24.8.5
      Drupalgeddon2
    • 24.8.6
      Drupalgeddon3
    • 24.8.7
      Onwards
  • 24.9
    Tomcat - Discovery & Enumeration 2 topics
    • 24.9.1
      Discovery/Footprinting
    • 24.9.2
      Enumeration
  • 24.10
    Attacking Tomcat 5 topics
    • 24.10.1
      Tomcat Manager - Login Brute Force
    • 24.10.2
      Tomcat Manager - WAR File Upload
    • 24.10.3
      A Quick Note on Web shells
    • 24.10.4
      CVE-2020-1938 : Ghostcat
    • 24.10.5
      Moving On
  • 24.11
    Jenkins - Discovery & Enumeration 2 topics
    • 24.11.1
      Discovery/Footprinting
    • 24.11.2
      Enumeration
  • 24.12
    Attacking Jenkins 3 topics
    • 24.12.1
      Script Console
    • 24.12.2
      Miscellaneous Vulnerabilities
    • 24.12.3
      Shifting Gears
  • 24.13
    Splunk - Discovery & Enumeration 2 topics
    • 24.13.1
      Discovery/Footprinting
    • 24.13.2
      Enumeration
  • 24.14
    Attacking Splunk 1 topic
    • 24.14.1
      Abusing Built-In Functionality
  • 24.15
    PRTG Network Monitor 3 topics
    • 24.15.1
      Discovery/Footprinting/Enumeration
    • 24.15.2
      Leveraging Known Vulnerabilities
    • 24.15.3
      Onwards
  • 24.16
    osTicket 4 topics
    • 24.16.1
      Footprinting/Discovery/Enumeration 3 topics
      • 24.16.1.1
        User Input
      • 24.16.1.2
        Processing
      • 24.16.1.3
        Solution
    • 24.16.2
      Attacking osTicket
    • 24.16.3
      osTicket - Sensitive Data Exposure
    • 24.16.4
      Closing Thoughts
  • 24.17
    Gitlab - Discovery & Enumeration 3 topics
    • 24.17.1
      Footprinting & Discovery
    • 24.17.2
      Enumeration
    • 24.17.3
      Onwards
  • 24.18
    Attacking GitLab 2 topics
    • 24.18.1
      Username Enumeration
    • 24.18.2
      Authenticated Remote Code Execution
  • 24.19
    Attacking Tomcat CGI 2 topics
    • 24.19.1
      Enumeration 4 topics
      • 24.19.1.1
        Nmap - Open Ports
      • 24.19.1.2
        Finding a CGI script
      • 24.19.1.3
        Fuzzing Extentions - .CMD
      • 24.19.1.4
        Fuzzing Extentions - .BAT
    • 24.19.2
      Exploitation
  • 24.20
    Attacking Common Gateway Interface (CGI) Applications - Shellshock 5 topics
    • 24.20.1
      CGI Attacks
    • 24.20.2
      Shellshock via CGI
    • 24.20.3
      Hands-on Example 3 topics
      • 24.20.3.1
        Enumeration - Gobuster
      • 24.20.3.2
        Confirming the Vulnerability
      • 24.20.3.3
        Exploitation to Reverse Shell Access
    • 24.20.4
      Mitigation
    • 24.20.5
      Closing Thoughts
  • 24.21
    Attacking Thick Client Applications 2 topics
    • 24.21.1
      Penetration Testing Steps 4 topics
      • 24.21.1.1
        Information Gathering
      • 24.21.1.2
        Client Side attacks
      • 24.21.1.3
        Network Side Attacks
      • 24.21.1.4
        Server Side Attacks
    • 24.21.2
      Retrieving hardcoded Credentials from Thick-Client Applications
  • 24.22
    Exploiting Web Vulnerabilities in Thick-Client Applications 3 topics
    • 24.22.1
      Foothold
    • 24.22.2
      Path Traversal
    • 24.22.3
      SQL Injection
  • 24.23
    ColdFusion - Discovery & Enumeration 1 topic
    • 24.23.1
      Enumeration 1 topic
      • 24.23.1.1
        NMap ports and service scan results
  • 24.24
    Attacking ColdFusion 3 topics
    • 24.24.1
      Searchsploit
    • 24.24.2
      Directory Traversal 1 topic
      • 24.24.2.1
        Coldfusion - Exploitation
    • 24.24.3
      Unauthenticated RCE 4 topics
      • 24.24.3.1
        Searchsploit
      • 24.24.3.2
        Exploit Modification
      • 24.24.3.3
        Exploitation
      • 24.24.3.4
        Reverse Shell
  • 24.25
    IIS Tilde Enumeration 1 topic
    • 24.25.1
      Enumeration 4 topics
      • 24.25.1.1
        Nmap - Open ports
      • 24.25.1.2
        Tilde Enumeration using IIS ShortName Scanner
      • 24.25.1.3
        Generate Wordlist
      • 24.25.1.4
        Gobuster Enumeration
  • 24.26
    LDAP 3 topics
    • 24.26.1
      ldapsearch
    • 24.26.2
      LDAP Injection
    • 24.26.3
      Enumeration 2 topics
      • 24.26.3.1
        nmap
      • 24.26.3.2
        Injection
  • 24.27
    Web Mass Assignment Vulnerabilities 2 topics
    • 24.27.1
      Exploiting Mass Assignment Vulnerability
    • 24.27.2
      Prevention
  • 24.28
    Attacking Applications Connecting to Services 2 topics
    • 24.28.1
      ELF Executable Examination
    • 24.28.2
      DLL File Examination
  • 24.29
    Other Notable Applications 1 topic
    • 24.29.1
      Honorable Mentions
  • 24.30
    Application Hardening 3 topics
    • 24.30.1
      General Hardening Tips
    • 24.30.2
      Application-Specific Hardening Tips
    • 24.30.3
      Conclusion
  • 24.31
    Attacking Common Applications - Skills Assessment I
  • 24.32
    Attacking Common Applications - Skills Assessment II
  • 24.33
    Attacking Common Applications - Skills Assessment III
25 Linux Privilege Escalation Linux Privilege Escalation module 162 topics Module 25
  • 25.1
    Introduction to Linux Privilege Escalation 2 topics
    • 25.1.1
      Enumeration 11 topics
      • 25.1.1.1
        List Current Processes
      • 25.1.1.2
        Home Directory Contents
      • 25.1.1.3
        User's Home Directory Contents
      • 25.1.1.4
        SSH Directory Contents
      • 25.1.1.5
        Bash History
      • 25.1.1.6
        Sudo - List User's Privileges
      • 25.1.1.7
        Passwd
      • 25.1.1.8
        Cron Jobs
      • 25.1.1.9
        File Systems & Additional Drives
      • 25.1.1.10
        Find Writable Directories
      • 25.1.1.11
        Find Writable Files
    • 25.1.2
      Moving on
  • 25.2
    Environment Enumeration 2 topics
    • 25.2.1
      Gaining Situational Awareness 7 topics
      • 25.2.1.1
        Existing Users
      • 25.2.1.2
        Existing Groups
      • 25.2.1.3
        Mounted File Systems
      • 25.2.1.4
        Unmounted File Systems
      • 25.2.1.5
        All Hidden Files
      • 25.2.1.6
        All Hidden Directories
      • 25.2.1.7
        Temporary Files
    • 25.2.2
      Moving On
  • 25.3
    Linux Services & Internals Enumeration 2 topics
    • 25.3.1
      Internals 8 topics
      • 25.3.1.1
        Network Interfaces
      • 25.3.1.2
        Hosts
      • 25.3.1.3
        User's Last Login
      • 25.3.1.4
        Logged In Users
      • 25.3.1.5
        Command History
      • 25.3.1.6
        Finding History Files
      • 25.3.1.7
        Cron
      • 25.3.1.8
        Proc
    • 25.3.2
      Services 8 topics
      • 25.3.2.1
        Installed Packages
      • 25.3.2.2
        Sudo Version
      • 25.3.2.3
        Binaries
      • 25.3.2.4
        GTFObins
      • 25.3.2.5
        Trace System Calls
      • 25.3.2.6
        Configuration Files
      • 25.3.2.7
        Scripts
      • 25.3.2.8
        Running Services by User
  • 25.4
    Credential Hunting 1 topic
    • 25.4.1
      SSH Keys
  • 25.5
    Path Abuse
  • 25.6
    Wildcard Abuse
  • 25.7
    Escaping Restricted Shells 2 topics
    • 25.7.1
      RBASH 2 topics
      • 25.7.1.1
        RKSH
      • 25.7.1.2
        RZSH
    • 25.7.2
      Escaping 5 topics
      • 25.7.2.1
        Command injection
      • 25.7.2.2
        Command Substitution
      • 25.7.2.3
        Command Chaining
      • 25.7.2.4
        Environment Variables
      • 25.7.2.5
        Shell Functions
  • 25.8
    Special Permissions 1 topic
    • 25.8.1
      GTFOBins
  • 25.9
    Sudo Rights Abuse
  • 25.10
    Privileged Groups 4 topics
    • 25.10.1
      LXC / LXD
    • 25.10.2
      Docker
    • 25.10.3
      Disk
    • 25.10.4
      ADM
  • 25.11
    Capabilities 3 topics
    • 25.11.1
      Set Capability
    • 25.11.2
      Enumerating Capabilities 1 topic
      • 25.11.2.1
        Enumerating Capabilities
    • 25.11.3
      Exploitation 1 topic
      • 25.11.3.1
        Exploiting Capabilities
  • 25.12
    Vulnerable Services 1 topic
    • 25.12.1
      Screen Version Identification 2 topics
      • 25.12.1.1
        Privilege Escalation - Screen_Exploit.sh
      • 25.12.1.2
        Screen_Exploit_POC.sh
  • 25.13
    Cron Job Abuse
  • 25.14
    Containers 1 topic
    • 25.14.1
      Linux Containers 1 topic
      • 25.14.1.1
        Linux Daemon
  • 25.15
    Docker 3 topics
    • 25.15.1
      Docker Architecture 5 topics
      • 25.15.1.1
        Docker Daemon
      • 25.15.1.2
        Managing Docker Containers
      • 25.15.1.3
        Network and Storage
      • 25.15.1.4
        Docker Clients
      • 25.15.1.5
        Docker Desktop
    • 25.15.2
      Docker Images and Containers
    • 25.15.3
      Docker Privilege Escalation 4 topics
      • 25.15.3.1
        Docker Shared Directories
      • 25.15.3.2
        Docker Sockets
      • 25.15.3.3
        Docker Group
      • 25.15.3.4
        Docker Socket
  • 25.16
    Kubernetes 3 topics
    • 25.16.1
      K8s Concept 4 topics
      • 25.16.1.1
        Nodes
      • 25.16.1.2
        Control Plane
      • 25.16.1.3
        Minions
      • 25.16.1.4
        K8's Security Measures
    • 25.16.2
      Kubernetes API 6 topics
      • 25.16.2.1
        Authentication
      • 25.16.2.2
        K8's API Server Interaction
      • 25.16.2.3
        Kubelet API - Extracting Pods
      • 25.16.2.4
        Kubeletctl - Extracting Pods
      • 25.16.2.5
        Kubelet API - Available Commands
      • 25.16.2.6
        Kubelet API - Executing Commands
    • 25.16.3
      Privilege Escalation 6 topics
      • 25.16.3.1
        Kubelet API - Extracting Tokens
      • 25.16.3.2
        Kubelet API - Extracting Certificates
      • 25.16.3.3
        List Privileges
      • 25.16.3.4
        Pod YAML
      • 25.16.3.5
        Creating a new Pod
      • 25.16.3.6
        Extracting Root's SSH Key
  • 25.17
    Logrotate
  • 25.18
    Miscellaneous Techniques 3 topics
    • 25.18.1
      Passive Traffic Capture
    • 25.18.2
      Weak NFS Privileges
    • 25.18.3
      Hijacking Tmux Sessions
  • 25.19
    Kernel Exploits 1 topic
    • 25.19.1
      Kernel Exploit Example
  • 25.20
    Shared Libraries 1 topic
    • 25.20.1
      LD_PRELOAD Privilege Escalation
  • 25.21
    Shared Object Hijacking
  • 25.22
    Python Library Hijacking 4 topics
    • 25.22.1
      Importing Modules
    • 25.22.2
      Wrong Write Permissions 6 topics
      • 25.22.2.1
        Python Script
      • 25.22.2.2
        Python Script - Contents
      • 25.22.2.3
        Module Permissions
      • 25.22.2.4
        Module Contents
      • 25.22.2.5
        Module Contents - Hijacking
      • 25.22.2.6
        Privilege Escalation
    • 25.22.3
      Library Path 5 topics
      • 25.22.3.1
        PYTHONPATH Listing
      • 25.22.3.2
        Psutil Default Installation Location
      • 25.22.3.3
        Misconfigured Directory Permissions
      • 25.22.3.4
        Hijacked Module Contents - psutil.py
      • 25.22.3.5
        Privilege Escalation via Hijacking Python Library Path
    • 25.22.4
      PYTHONPATH Environment Variable 2 topics
      • 25.22.4.1
        Checking sudo permissions
      • 25.22.4.2
        Privilege Escalation using PYTHONPATH Environment Variable
  • 25.23
    Sudo 1 topic
    • 25.23.1
      Sudo Policy Bypass
  • 25.24
    Polkit
  • 25.25
    Dirty Pipe 1 topic
    • 25.25.1
      Download Dirty Pipe Exploit 4 topics
      • 25.25.1.1
        Verify Kernel Version
      • 25.25.1.2
        Exploitation
      • 25.25.1.3
        Find SUID Binaries
      • 25.25.1.4
        Exploitation
  • 25.26
    Netfilter 1 topic
    • 25.26.1
      CVE-2021-22555 4 topics
      • 25.26.1.1
        CVE-2022-25636
      • 25.26.1.2
        CVE-2023-32233
      • 25.26.1.3
        Proof-Of-Concept
      • 25.26.1.4
        Exploitation
  • 25.27
    Linux Hardening 5 topics
    • 25.27.1
      Updates and Patching
    • 25.27.2
      Configuration Management
    • 25.27.3
      User Management
    • 25.27.4
      Audit
    • 25.27.5
      Conclusion
  • 25.28
    Linux Local Privilege Escalation - Skills Assessment
26 Windows Privilege Escalation Windows Privilege Escalation module 402 topics Module 26
  • 26.1
    Introduction to Windows Privilege Escalation 6 topics
    • 26.1.1
      Scenario 1 - Overcoming Network Restrictions
    • 26.1.2
      Scenario 2 - Pillaging Open Shares
    • 26.1.3
      Scenario 3 - Hunting Credentials and Abusing Account Privileges
    • 26.1.4
      Why does Privilege Escalation Happen?
    • 26.1.5
      Moving On
    • 26.1.6
      Practical Examples 1 topic
      • 26.1.6.1
        Connecting via FreeRDP
  • 26.2
    Useful Tools
  • 26.3
    Situational Awareness 3 topics
    • 26.3.1
      Network Information 3 topics
      • 26.3.1.1
        Interface(s), IP Address(es), DNS Information
      • 26.3.1.2
        ARP Table
      • 26.3.1.3
        Routing Table
    • 26.3.2
      Enumerating Protections 3 topics
      • 26.3.2.1
        Check Windows Defender Status
      • 26.3.2.2
        List AppLocker Rules
      • 26.3.2.3
        Test AppLocker Policy
    • 26.3.3
      Next Steps
  • 26.4
    Initial Enumeration 4 topics
    • 26.4.1
      Key Data Points
    • 26.4.2
      System Information 7 topics
      • 26.4.2.1
        Tasklist
      • 26.4.2.2
        Display All Environment Variables
      • 26.4.2.3
        View Detailed Configuration Information
      • 26.4.2.4
        Patches and Updates
      • 26.4.2.5
        Installed Programs
      • 26.4.2.6
        Display Running Processes
      • 26.4.2.7
        Netstat
    • 26.4.3
      User & Group Information 8 topics
      • 26.4.3.1
        Logged-In Users
      • 26.4.3.2
        Current User
      • 26.4.3.3
        Current User Privileges
      • 26.4.3.4
        Current User Group Information
      • 26.4.3.5
        Get All Users
      • 26.4.3.6
        Get All Groups
      • 26.4.3.7
        Details About a Group
      • 26.4.3.8
        Get Password Policy & Other Account Information
    • 26.4.4
      Moving On
  • 26.5
    Communication with Processes 4 topics
    • 26.5.1
      Access Tokens
    • 26.5.2
      Enumerating Network Services 2 topics
      • 26.5.2.1
        Display Active Network Connections
      • 26.5.2.2
        More Examples
    • 26.5.3
      Named Pipes 4 topics
      • 26.5.3.1
        More on Named Pipes
      • 26.5.3.2
        Listing Named Pipes with Pipelist
      • 26.5.3.3
        Listing Named Pipes with PowerShell
      • 26.5.3.4
        Reviewing LSASS Named Pipe Permissions
    • 26.5.4
      Named Pipes Attack Example 1 topic
      • 26.5.4.1
        Checking WindscribeService Named Pipe Permissions
  • 26.6
    Windows Privileges Overview 5 topics
    • 26.6.1
      Windows Authorization Process
    • 26.6.2
      Rights and Privileges in Windows
    • 26.6.3
      User Rights Assignment 3 topics
      • 26.6.3.1
        Local Admin User Rights - Elevated
      • 26.6.3.2
        Standard User Rights
      • 26.6.3.3
        Backup Operators Rights
    • 26.6.4
      Detection
    • 26.6.5
      Moving On
  • 26.7
    SeImpersonate and SeAssignPrimaryToken 2 topics
    • 26.7.1
      SeImpersonate Example - JuicyPotato 6 topics
      • 26.7.1.1
        Connecting with MSSQLClient.py
      • 26.7.1.2
        Enabling xp_cmdshell
      • 26.7.1.3
        Confirming Access
      • 26.7.1.4
        Checking Account Privileges
      • 26.7.1.5
        Escalating Privileges Using JuicyPotato
      • 26.7.1.6
        Catching SYSTEM Shell
    • 26.7.2
      PrintSpoofer and RoguePotato 2 topics
      • 26.7.2.1
        Escalating Privileges using PrintSpoofer
      • 26.7.2.2
        Catching Reverse Shell as SYSTEM
  • 26.8
    SeDebugPrivilege 1 topic
    • 26.8.1
      Remote Code Execution as SYSTEM
  • 26.9
    SeTakeOwnershipPrivilege 2 topics
    • 26.9.1
      Leveraging the Privilege 8 topics
      • 26.9.1.1
        Reviewing Current User Privileges
      • 26.9.1.2
        Enabling SeTakeOwnershipPrivilege
      • 26.9.1.3
        Choosing a Target File
      • 26.9.1.4
        Checking File Ownership
      • 26.9.1.5
        Taking Ownership of the File
      • 26.9.1.6
        Confirming Ownership Changed
      • 26.9.1.7
        Modifying the File ACL
      • 26.9.1.8
        Reading the File
    • 26.9.2
      When to Use? 1 topic
      • 26.9.2.1
        Files of Interest
  • 26.10
    Windows Built-in Groups 2 topics
    • 26.10.1
      Backup Operators 9 topics
      • 26.10.1.1
        Importing Libraries
      • 26.10.1.2
        Verifying SeBackupPrivilege is Enabled
      • 26.10.1.3
        Enabling SeBackupPrivilege
      • 26.10.1.4
        Copying a Protected File
      • 26.10.1.5
        Attacking a Domain Controller - Copying NTDS.dit
      • 26.10.1.6
        Copying NTDS.dit Locally
      • 26.10.1.7
        Backing up SAM and SYSTEM Registry Hives
      • 26.10.1.8
        Extracting Credentials from NTDS.dit
      • 26.10.1.9
        Extracting Hashes Using SecretsDump
    • 26.10.2
      Robocopy 1 topic
      • 26.10.2.1
        Copying Files with Robocopy
  • 26.11
    Event Log Readers 1 topic
    • 26.11.1
      Confirming Group Membership 3 topics
      • 26.11.1.1
        Searching Security Logs Using wevtutil
      • 26.11.1.2
        Passing Credentials to wevtutil
      • 26.11.1.3
        Searching Security Logs Using Get-WinEvent
  • 26.12
    DnsAdmins 4 topics
    • 26.12.1
      Leveraging DnsAdmins Access 11 topics
      • 26.12.1.1
        Generating Malicious DLL
      • 26.12.1.2
        Starting Local HTTP Server
      • 26.12.1.3
        Downloading File to Target
      • 26.12.1.4
        Loading DLL as Non-Privileged User
      • 26.12.1.5
        Loading DLL as Member of DnsAdmins
      • 26.12.1.6
        Loading Custom DLL
      • 26.12.1.7
        Finding User's SID
      • 26.12.1.8
        Checking Permissions on DNS Service
      • 26.12.1.9
        Stopping the DNS Service
      • 26.12.1.10
        Starting the DNS Service
      • 26.12.1.11
        Confirming Group Membership
    • 26.12.2
      Cleaning Up 4 topics
      • 26.12.2.1
        Confirming Registry Key Added
      • 26.12.2.2
        Deleting Registry Key
      • 26.12.2.3
        Starting the DNS Service Again
      • 26.12.2.4
        Checking DNS Service Status
    • 26.12.3
      Using Mimilib.dll
    • 26.12.4
      Creating a WPAD Record 2 topics
      • 26.12.4.1
        Disabling the Global Query Block List
      • 26.12.4.2
        Adding a WPAD Record
  • 26.13
    Hyper-V Administrators 1 topic
    • 26.13.1
      Target File 2 topics
      • 26.13.1.1
        Taking Ownership of the File
      • 26.13.1.2
        Starting the Mozilla Maintenance Service
  • 26.14
    Print Operators 4 topics
    • 26.14.1
      Confirming Privileges 7 topics
      • 26.14.1.1
        Checking Privileges Again
      • 26.14.1.2
        Compile with cl.exe
      • 26.14.1.3
        Add Reference to Driver
      • 26.14.1.4
        Verify Driver is not Loaded
      • 26.14.1.5
        Verify Privilege is Enabled
      • 26.14.1.6
        Verify Capcom Driver is Listed
      • 26.14.1.7
        Use ExploitCapcom Tool to Escalate Privileges
    • 26.14.2
      Alternate Exploitation - No GUI
    • 26.14.3
      Automating the Steps 1 topic
      • 26.14.3.1
        Automating with EopLoadDriver
    • 26.14.4
      Clean-up 1 topic
      • 26.14.4.1
        Removing Registry Key
  • 26.15
    Server Operators 1 topic
    • 26.15.1
      Querying the AppReadiness Service 7 topics
      • 26.15.1.1
        Checking Service Permissions with PsService
      • 26.15.1.2
        Checking Local Admin Group Membership
      • 26.15.1.3
        Modifying the Service Binary Path
      • 26.15.1.4
        Starting the Service
      • 26.15.1.5
        Confirming Local Admin Group Membership
      • 26.15.1.6
        Confirming Local Admin Access on Domain Controller
      • 26.15.1.7
        Retrieving NTLM Password Hashes from the Domain Controller
  • 26.16
    User Account Control 1 topic
    • 26.16.1
      Checking Current User 13 topics
      • 26.16.1.1
        Confirming Admin Group Membership
      • 26.16.1.2
        Reviewing User Privileges
      • 26.16.1.3
        Confirming UAC is Enabled
      • 26.16.1.4
        Checking UAC Level
      • 26.16.1.5
        Checking Windows Version
      • 26.16.1.6
        Reviewing Path Variable
      • 26.16.1.7
        Generating Malicious srrstr.dll DLL
      • 26.16.1.8
        Starting Python HTTP Server on Attack Host
      • 26.16.1.9
        Downloading DLL Target
      • 26.16.1.10
        Starting nc Listener on Attack Host
      • 26.16.1.11
        Testing Connection
      • 26.16.1.12
        Executing SystemPropertiesAdvanced.exe on Target Host
      • 26.16.1.13
        Receiving Connection Back
  • 26.17
    Weak Permissions 6 topics
    • 26.17.1
      Permissive File System ACLs 3 topics
      • 26.17.1.1
        Running SharpUp
      • 26.17.1.2
        Checking Permissions with icacls
      • 26.17.1.3
        Replacing Service Binary
    • 26.17.2
      Weak Service Permissions 7 topics
      • 26.17.2.1
        Reviewing SharpUp Again
      • 26.17.2.2
        Checking Permissions with AccessChk
      • 26.17.2.3
        Check Local Admin Group
      • 26.17.2.4
        Changing the Service Binary Path
      • 26.17.2.5
        Stopping Service
      • 26.17.2.6
        Starting the Service
      • 26.17.2.7
        Confirming Local Admin Group Addition
    • 26.17.3
      Weak Service Permissions - Cleanup 3 topics
      • 26.17.3.1
        Reverting the Binary Path
      • 26.17.3.2
        Starting the Service Again
      • 26.17.3.3
        Verifying Service is Running
    • 26.17.4
      Unquoted Service Path 3 topics
      • 26.17.4.1
        Service Binary Path
      • 26.17.4.2
        Querying Service
      • 26.17.4.3
        Searching for Unquoted Service Paths
    • 26.17.5
      Permissive Registry ACLs 2 topics
      • 26.17.5.1
        Checking for Weak Service ACLs in Registry
      • 26.17.5.2
        Changing ImagePath with PowerShell
    • 26.17.6
      Modifiable Registry Autorun Binary 1 topic
      • 26.17.6.1
        Check Startup Programs
  • 26.18
    Kernel Exploits 3 topics
    • 26.18.1
      Notable Vulnerabilities 5 topics
      • 26.18.1.1
        Checking Permissions on the SAM File
      • 26.18.1.2
        Performing Attack and Parsing Password Hashes
      • 26.18.1.3
        Checking for Spooler Service
      • 26.18.1.4
        Adding Local Admin with PrintNightmare PowerShell PoC
      • 26.18.1.5
        Confirming New Admin User
    • 26.18.2
      Enumerating Missing Patches 2 topics
      • 26.18.2.1
        Examining Installed Updates
      • 26.18.2.2
        Viewing Installed Updates with WMI
    • 26.18.3
      CVE-2020-0668 Example 13 topics
      • 26.18.3.1
        Checking Current User Privileges
      • 26.18.3.2
        After Building Solution
      • 26.18.3.3
        Checking Permissions on Binary
      • 26.18.3.4
        Generating Malicious Binary
      • 26.18.3.5
        Hosting the Malicious Binary
      • 26.18.3.6
        Downloading the Malicious Binary
      • 26.18.3.7
        Running the Exploit
      • 26.18.3.8
        Checking Permissions of New File
      • 26.18.3.9
        Replacing File with Malicious Binary
      • 26.18.3.10
        Metasploit Resource Script
      • 26.18.3.11
        Launching Metasploit with Resource Script
      • 26.18.3.12
        Starting the Service
      • 26.18.3.13
        Receiving a Meterpreter Session
  • 26.19
    Vulnerable Services 3 topics
    • 26.19.1
      Enumerating Installed Programs 3 topics
      • 26.19.1.1
        Enumerating Local Ports
      • 26.19.1.2
        Enumerating Process ID
      • 26.19.1.3
        Enumerating Running Service
    • 26.19.2
      Druva inSync Windows Client Local Privilege Escalation Example 4 topics
      • 26.19.2.1
        Druva inSync PowerShell PoC
      • 26.19.2.2
        Modifying PowerShell PoC
      • 26.19.2.3
        Starting a Python Web Server
      • 26.19.2.4
        Catching a SYSTEM Shell
    • 26.19.3
      Moving On
  • 26.20
    DLL Injection 4 topics
    • 26.20.1
      LoadLibrary
    • 26.20.2
      Manual Mapping
    • 26.20.3
      Reflective DLL Injection
    • 26.20.4
      DLL Hijacking 2 topics
      • 26.20.4.1
        Proxying
      • 26.20.4.2
        Invalid Libraries
  • 26.21
    Credential Hunting 5 topics
    • 26.21.1
      Application Configuration Files 1 topic
      • 26.21.1.1
        Searching for Files
    • 26.21.2
      Dictionary Files 1 topic
      • 26.21.2.1
        Chrome Dictionary Files
    • 26.21.3
      Unattended Installation Files 1 topic
      • 26.21.3.1
        Unattend.xml
    • 26.21.4
      PowerShell History File 3 topics
      • 26.21.4.1
        Command to
      • 26.21.4.2
        Confirming PowerShell History Save Path
      • 26.21.4.3
        Reading PowerShell History File
    • 26.21.5
      PowerShell Credentials 1 topic
      • 26.21.5.1
        Decrypting PowerShell Credentials
  • 26.22
    Other Files 3 topics
    • 26.22.1
      Manually Searching the File System for Credentials 7 topics
      • 26.22.1.1
        Search File Contents for String - Example 1
      • 26.22.1.2
        Search File Contents for String - Example 2
      • 26.22.1.3
        Search File Contents for String - Example 3
      • 26.22.1.4
        Search File Contents with PowerShell
      • 26.22.1.5
        Search for File Extensions - Example 1
      • 26.22.1.6
        Search for File Extensions - Example 2
      • 26.22.1.7
        Search for File Extensions Using PowerShell
    • 26.22.2
      Sticky Notes Passwords 3 topics
      • 26.22.2.1
        Looking for StickyNotes DB Files
      • 26.22.2.2
        Viewing Sticky Notes Data Using PowerShell
      • 26.22.2.3
        Strings to View DB File Contents
    • 26.22.3
      Other Files of Interest 1 topic
      • 26.22.3.1
        Other Interesting Files
  • 26.23
    Further Credential Theft 8 topics
    • 26.23.1
      Cmdkey Saved Credentials 2 topics
      • 26.23.1.1
        Listing Saved Credentials
      • 26.23.1.2
        Run Commands as Another User
    • 26.23.2
      Browser Credentials 1 topic
      • 26.23.2.1
        Retrieving Saved Credentials from Chrome
    • 26.23.3
      Password Managers 2 topics
      • 26.23.3.1
        Extracting KeePass Hash
      • 26.23.3.2
        Cracking Hash Offline
    • 26.23.4
      Email
    • 26.23.5
      More Fun with Credentials 2 topics
      • 26.23.5.1
        Viewing LaZagne Help Menu
      • 26.23.5.2
        Running All LaZagne Modules
    • 26.23.6
      Even More Fun with Credentials 1 topic
      • 26.23.6.1
        Running SessionGopher as Current User
    • 26.23.7
      Clear-Text Password Storage in the Registry 4 topics
      • 26.23.7.1
        Windows AutoLogon
      • 26.23.7.2
        Enumerating Autologon with reg.exe
      • 26.23.7.3
        Putty
      • 26.23.7.4
        Enumerating Sessions and Finding Credentials:
    • 26.23.8
      Wifi Passwords 2 topics
      • 26.23.8.1
        Viewing Saved Wireless Networks
      • 26.23.8.2
        Retrieving Saved Wireless Passwords
  • 26.24
    Citrix Breakout 8 topics
    • 26.24.1
      Bypassing Path Restrictions
    • 26.24.2
      Accessing SMB share from restricted environment
    • 26.24.3
      Alternate Explorer
    • 26.24.4
      Alternate Registry Editors
    • 26.24.5
      Modify existing shortcut file
    • 26.24.6
      Script Execution
    • 26.24.7
      Escalating Privileges
    • 26.24.8
      Bypassing UAC 1 topic
      • 26.24.8.1
        Additional resources worth checking:
  • 26.25
    Interacting with Users 5 topics
    • 26.25.1
      Traffic Capture
    • 26.25.2
      Process Command Lines 2 topics
      • 26.25.2.1
        Monitoring for Process Command Lines
      • 26.25.2.2
        Running Monitor Script on Target Host
    • 26.25.3
      Vulnerable Services
    • 26.25.4
      SCF on a File Share 3 topics
      • 26.25.4.1
        Malicious SCF File
      • 26.25.4.2
        Starting Responder
      • 26.25.4.3
        Cracking NTLMv2 Hash with Hashcat
    • 26.25.5
      Capturing Hashes with a Malicious .lnk File 1 topic
      • 26.25.5.1
        Generating a Malicious .lnk File
  • 26.26
    Pillaging 7 topics
    • 26.26.1
      Data Sources
    • 26.26.2
      Scenario
    • 26.26.3
      Installed Applications 10 topics
      • 26.26.3.1
        Identifying Common Applications
      • 26.26.3.2
        Get Installed Programs via PowerShell & Registry Keys
      • 26.26.3.3
        mRemoteNG
      • 26.26.3.4
        Discover mRemoteNG Configuration Files
      • 26.26.3.5
        mRemoteNG Configuration File - confCons.xml
      • 26.26.3.6
        Decrypt the Password with mremoteng_decrypt
      • 26.26.3.7
        mRemoteNG Configuration File - confCons.xml
      • 26.26.3.8
        Attempt to Decrypt the Password with a Custom Password
      • 26.26.3.9
        Decrypt the Password with mremoteng_decrypt and a Custom Password
      • 26.26.3.10
        For Loop to Crack the Master Password with mremoteng_decrypt
    • 26.26.4
      Abusing Cookies to Get Access to IM Clients 5 topics
      • 26.26.4.1
        Copy Firefox Cookies Database
      • 26.26.4.2
        Extract Slack Cookie from Firefox Cookies Database
      • 26.26.4.3
        PowerShell Script - Invoke-SharpChromium
      • 26.26.4.4
        Copy Cookies to SharpChromium Expected Location
      • 26.26.4.5
        Invoke-SharpChromium Cookies Extraction
    • 26.26.5
      Clipboard 2 topics
      • 26.26.5.1
        Monitor the Clipboard with PowerShell
      • 26.26.5.2
        Capture Credentials from the Clipboard with Invoke- ClipboardLogger
    • 26.26.6
      Roles and Services 6 topics
      • 26.26.6.1
        Attacking Backup Servers
      • 26.26.6.2
        restic - Initialize Backup Directory
      • 26.26.6.3
        restic - Back up a Directory
      • 26.26.6.4
        restic - Back up a Directory with VSS
      • 26.26.6.5
        restic - Check Backups Saved in a Repository
      • 26.26.6.6
        restic - Restore a Backup with ID
    • 26.26.7
      Conclusion
  • 26.27
    Miscellaneous Techniques 6 topics
    • 26.27.1
      Living Off The Land Binaries and Scripts (LOLBAS) 3 topics
      • 26.27.1.1
        Transferring File with Certutil
      • 26.27.1.2
        Encoding File with Certutil
      • 26.27.1.3
        Decoding File with Certutil
    • 26.27.2
      Always Install Elevated 4 topics
      • 26.27.2.1
        Enumerating Always Install Elevated Settings
      • 26.27.2.2
        Generating MSI Package
      • 26.27.2.3
        Executing MSI Package
      • 26.27.2.4
        Catching Shell
    • 26.27.3
      CVE-2019-1388
    • 26.27.4
      Scheduled Tasks 3 topics
      • 26.27.4.1
        Enumerating Scheduled Tasks
      • 26.27.4.2
        Enumerating Scheduled Tasks with PowerShell
      • 26.27.4.3
        Checking Permissions on C:\Scripts Directory
    • 26.27.5
      User/Computer Description Field 2 topics
      • 26.27.5.1
        Checking Local User Description Field
      • 26.27.5.2
        Enumerating Computer Description Field with Get-WmiObject Cmdlet
    • 26.27.6
      Mount VHDX/VMDK 3 topics
      • 26.27.6.1
        Mount VMDK on Linux
      • 26.27.6.2
        Mount VHD/VHDX on Linux
      • 26.27.6.3
        Retrieving Hashes using Secretsdump.py
  • 26.28
    Legacy Operating Systems 2 topics
    • 26.28.1
      End of Life Systems (EOL) 2 topics
      • 26.28.1.1
        Windows Desktop - EOL Dates by Version
      • 26.28.1.2
        Windows Server - EOL Dates by Version
    • 26.28.2
      Impact
  • 26.29
    Windows Server 3 topics
    • 26.29.1
      Server 2008 vs. Newer Versions
    • 26.29.2
      Server 2008 Case Study 9 topics
      • 26.29.2.1
        Querying Current Patch Level
      • 26.29.2.2
        Running Sherlock
      • 26.29.2.3
        Obtaining a Meterpreter Shell
      • 26.29.2.4
        Rundll Command on Target Host
      • 26.29.2.5
        Receiving Reverse Shell
      • 26.29.2.6
        Searching for Local Privilege Escalation Exploit
      • 26.29.2.7
        Migrating to a 64-bit Process
      • 26.29.2.8
        Setting Privilege Escalation Module Options
      • 26.29.2.9
        Receiving Elevated Reverse Shell
    • 26.29.3
      Attacking Server 2008
  • 26.30
    Windows Desktop Versions 3 topics
    • 26.30.1
      Windows 7 vs. Newer Versions
    • 26.30.2
      Windows 7 Case Study 6 topics
      • 26.30.2.1
        Install Python Dependencies (local VM only)
      • 26.30.2.2
        Gathering Systeminfo Command Output
      • 26.30.2.3
        Updating the Local Microsoft Vulnerability Database
      • 26.30.2.4
        Running Windows Exploit Suggester
      • 26.30.2.5
        Exploiting MS16-032 with PowerShell PoC
      • 26.30.2.6
        Spawning a SYSTEM Console
    • 26.30.3
      Attacking Windows 7
  • 26.31
    Windows Hardening 10 topics
    • 26.31.1
      Secure Clean OS Installation
    • 26.31.2
      Updates and Patching
    • 26.31.3
      Configuration Management
    • 26.31.4
      User Management
    • 26.31.5
      Audit
    • 26.31.6
      Logging
    • 26.31.7
      Sysmon
    • 26.31.8
      Network and Host Logs.
    • 26.31.9
      Key Hardening Measures
    • 26.31.10
      Conclusion
  • 26.32
    Windows Privilege Escalation Skills Assessment - Part I
  • 26.33
    Windows Privilege Escalation Skills Assessment - Part II
27 Documentation & Reporting Documentation & Reporting module 120 topics Module 27
  • 27.1
    Introduction to Documentation and Reporting
  • 27.2
    Documentation & Reporting in Practice
  • 27.3
    About this Module
  • 27.4
    Notetaking & Organization 9 topics
    • 27.4.1
      Notetaking Sample Structure
    • 27.4.2
      Notetaking Tools 1 topic
      • 27.4.2.1
        Obsidian
    • 27.4.3
      Logging 2 topics
      • 27.4.3.1
        Exploitation Attempts
      • 27.4.3.2
        Tmux.conf
    • 27.4.4
      Artifacts Left Behind 1 topic
      • 27.4.4.1
        Account Creation/System Modifications
    • 27.4.5
      Evidence 2 topics
      • 27.4.5.1
        What to Capture
      • 27.4.5.2
        Storage
    • 27.4.6
      Formatting and Redaction 4 topics
      • 27.4.6.1
        Screenshots
      • 27.4.6.2
        Blurring Password Data
      • 27.4.6.3
        Blanking Out Password with Solid Shape
      • 27.4.6.4
        Terminal
    • 27.4.7
      What Not to Archive
    • 27.4.8
      Module Exercises
    • 27.4.9
      Onwards
  • 27.5
    Types of Reports 11 topics
    • 27.5.1
      Differences Across Assessment Types 3 topics
      • 27.5.1.1
        Vulnerability Assessment
      • 27.5.1.2
        Internal vs External
      • 27.5.1.3
        Report Contents
    • 27.5.2
      Penetration Testing 1 topic
      • 27.5.2.1
        Internal vs External
    • 27.5.3
      Inter-Disciplinary Assessments 3 topics
      • 27.5.3.1
        Purple Team Style Assessments
      • 27.5.3.2
        Cloud Focused Penetration Testing
      • 27.5.3.3
        Comprehensive IoT Testing
    • 27.5.4
      Web Application Penetration Testing
    • 27.5.5
      Hardware Penetration Testing
    • 27.5.6
      Draft Report
    • 27.5.7
      Final Report 1 topic
      • 27.5.7.1
        Post-Remediation Report
    • 27.5.8
      Attestation Report
    • 27.5.9
      Other Deliverables 2 topics
      • 27.5.9.1
        Slide Deck
      • 27.5.9.2
        Spreadsheet of Findings
    • 27.5.10
      Vulnerability Notifications 2 topics
      • 27.5.10.1
        When to Draft One
      • 27.5.10.2
        Contents
    • 27.5.11
      Piecing it Together 1 topic
      • 27.5.11.1
        Questions
  • 27.6
    Components of a Report 11 topics
    • 27.6.1
      Prioritizing Our Efforts
    • 27.6.2
      Writing an Attack Chain
    • 27.6.3
      Sample Attack Chain - INLANEFREIGHT.LOCAL Internal Penetration Test 14 topics
      • 27.6.3.1
        Detailed reproduction steps for this attack chain are as follows:
      • 27.6.3.2
        Responder
      • 27.6.3.3
        Hashcat
      • 27.6.3.4
        GetUserSPNs
      • 27.6.3.5
        Bloodhound
      • 27.6.3.6
        GetUserSPNs
      • 27.6.3.7
        Hashcat
      • 27.6.3.8
        CrackMapExec
      • 27.6.3.9
        Logged In Users
      • 27.6.3.10
        Rubeus
      • 27.6.3.11
        Cached Kerberos Tickets
      • 27.6.3.12
        Mimikatz
      • 27.6.3.13
        CrackMapExec
      • 27.6.3.14
        Dumping NTDS with SecretsDump
    • 27.6.4
      Writing a Strong Executive Summary 4 topics
      • 27.6.4.1
        Key Concepts
      • 27.6.4.2
        Do
      • 27.6.4.3
        Do Not
      • 27.6.4.4
        Vocabulary Changes
    • 27.6.5
      Example Executive Summary 1 topic
      • 27.6.5.1
        Anatomy of the Executive Summary
    • 27.6.6
      Summary of Recommendations
    • 27.6.7
      Findings
    • 27.6.8
      Appendices
    • 27.6.9
      Static Appendices 4 topics
      • 27.6.9.1
        Scope
      • 27.6.9.2
        Methodology
      • 27.6.9.3
        Severity Ratings
      • 27.6.9.4
        Biographies
    • 27.6.10
      Dynamic Appendices 6 topics
      • 27.6.10.1
        Exploitation Attempts and Payloads
      • 27.6.10.2
        Compromised Credentials
      • 27.6.10.3
        Configuration Changes
      • 27.6.10.4
        Additional Affected Scope
      • 27.6.10.5
        Information Gathering
      • 27.6.10.6
        Domain Password Analysis
    • 27.6.11
      Report Type Differences 1 topic
      • 27.6.11.1
        Questions
  • 27.7
    How to Write Up a Finding 7 topics
    • 27.7.1
      Breakdown of a Finding
    • 27.7.2
      Showing Finding Reproduction Steps Adequately
    • 27.7.3
      Effective Remediation Recommendations 4 topics
      • 27.7.3.1
        Example 1
      • 27.7.3.2
        Rationale
      • 27.7.3.3
        Example 2
      • 27.7.3.4
        Rationale
    • 27.7.4
      Selecting Quality References
    • 27.7.5
      Example Findings 3 topics
      • 27.7.5.1
        Weak Kerberos Authentication (“Kerberoasting”)
      • 27.7.5.2
        Tomcat Manager Weak/Default Credentials
      • 27.7.5.3
        Poorly Written Finding
    • 27.7.6
      Hands-On Practice
    • 27.7.7
      Nearly There
  • 27.8
    Reporting Tips and Tricks 9 topics
    • 27.8.1
      Templates
    • 27.8.2
      MS Word Tips & Tricks
    • 27.8.3
      Automation
    • 27.8.4
      Reporting Tools/Findings Database
    • 27.8.5
      Misc Tips/Tricks
    • 27.8.6
      Client Communication
    • 27.8.7
      Presenting Your Report - The Final Product 1 topic
      • 27.8.7.1
        QA Process
    • 27.8.8
      Report Review Meeting
    • 27.8.9
      Wrap Up
  • 27.9
    Documentation & Reporting Practice Lab
  • 27.10
    Beyond this Module - Documentation & Reporting 2 topics
    • 27.10.1
      Practicing
    • 27.10.2
      Next Steps
28 Attacking Enterprise Networks Attacking Enterprise Networks module 80 topics Module 28
  • 28.1
    Intro to Attacking Enterprise Networks
  • 28.2
    Scenario & Kickoff 2 topics
    • 28.2.1
      Project Kickoff
    • 28.2.2
      Start of Testing
  • 28.3
    External Information Gathering 1 topic
    • 28.3.1
      Enumeration Results
  • 28.4
    Service Enumeration & Exploitation 4 topics
    • 28.4.1
      Listening Services
    • 28.4.2
      FTP
    • 28.4.3
      SSH 1 topic
      • 28.4.3.1
        Email Services
    • 28.4.4
      Moving On
  • 28.5
    Web Enumeration & Exploitation 14 topics
    • 28.5.1
      Web Application Enumeration
    • 28.5.2
      blog.inlanefreight.local
    • 28.5.3
      careers.inlanefreight.local
    • 28.5.4
      dev.inlanefreight.local
    • 28.5.5
      ir.inlanefreight.local
    • 28.5.6
      status.inlanefreight.local
    • 28.5.7
      support.inlanefreight.local
    • 28.5.8
      tracking.inlanefreight.local
    • 28.5.9
      Dealing with The Unexpected
    • 28.5.10
      vpn.inlanefreight.local
    • 28.5.11
      gitlab.inlanefreight.local
    • 28.5.12
      shopdev2.inlanefreight.local
    • 28.5.13
      monitoring.inlanefreight.local
    • 28.5.14
      Next Steps
  • 28.6
    Initial Access 1 topic
    • 28.6.1
      Getting a Reverse Shell
  • 28.7
    Post-Exploitation Persistence 3 topics
    • 28.7.1
      Sinking Our Hooks In
    • 28.7.2
      Local Privilege Escalation
    • 28.7.3
      Establishing Persistence
  • 28.8
    Internal Information Gathering 9 topics
    • 28.8.1
      Setting Up Pivoting - SSH
    • 28.8.2
      Setting Up Pivoting - Metasploit
    • 28.8.3
      Host Discovery - 172.16.8.0/23 Subnet - Metasploit
    • 28.8.4
      Host Discovery - 172.16.8.0/23 Subnet - SSH Tunnel
    • 28.8.5
      Host Enumeration
    • 28.8.6
      Active Directory Quick Hits - SMB NULL SESSION
    • 28.8.7
      172.16.8.50 - Tomcat
    • 28.8.8
      Enumerating 172.16.8.20 - DotNetNuke (DNN)
    • 28.8.9
      Moving On
  • 28.9
    Exploitation & Privilege Escalation 4 topics
    • 28.9.1
      Attacking DNN
    • 28.9.2
      Privilege Escalation
    • 28.9.3
      Alternate Method - Reverse Port Forwarding
    • 28.9.4
      Off to a Good Start
  • 28.10
    Lateral Movement
  • 28.11
    Share Hunting 6 topics
    • 28.11.1
      Kerberoasting
    • 28.11.2
      Password Spraying
    • 28.11.3
      Misc Techniques
    • 28.11.4
      Next Steps
    • 28.11.5
      Post-Exploitation/Pillaging
    • 28.11.6
      Closing In
  • 28.12
    Active Directory Compromise 1 topic
    • 28.12.1
      Next Steps
  • 28.13
    Post-Exploitation 7 topics
    • 28.13.1
      Domain Password Analysis - Cracking NTDS
    • 28.13.2
      Active Directory Security Audit
    • 28.13.3
      Hunting for Sensitive Data/Hosts
    • 28.13.4
      The Double Pivot - MGMT01
    • 28.13.5
      Data Exfiltration Simulation
    • 28.13.6
      Attacking Domain Trusts
    • 28.13.7
      Closing Thoughts
  • 28.14
    Engagement Closeout 6 topics
    • 28.14.1
      Attack Path Recap
    • 28.14.2
      Structuring our Findings
    • 28.14.3
      Post-Engagement Cleanup
    • 28.14.4
      Client Communication
    • 28.14.5
      Internal Project Closeout
    • 28.14.6
      Next Steps
  • 28.15
    Beyond This Module 3 topics
    • 28.15.1
      Practice on the Main Platform 3 topics
      • 28.15.1.1
        Starting Point
      • 28.15.1.2
        Tracks
      • 28.15.1.3
        Pro Labs
    • 28.15.2
      Give Back
    • 28.15.3
      Start Looking for Work

Student Feedback

What Students Say About This Course

No reviews yet.

Message HackForceBD
WhatsAppOpen TelegramOpen Facebook MessengerOpen