Practical offensive security
The Pentest Book.
A field guide to offensive workflows, organized by phase and built for quick lookup during an engagement.
Start readingPre-Foothold Operations
Pre foothold work turns an approved scope into a defensible attack surface map before any attempt to gain access. This module is an operational hub: it provides repeatable works...
7 notes & referencesReconnaissance
Reconnaissance is the first and foundational phase of any penetration test. The goal is to gather as much information as possible about the target without triggering alarms . Qu...
2 notes & referencesEnumeration
Enumeration is the most critical phase of any penetration test. This is where you actively probe discovered systems to map the attack surface: open ports, running services, OS v...
13 notes & referencesVulnerability Assessment
Vulnerability assessment is the systematic process of identifying, classifying, and prioritizing security weaknesses in target systems. After reconnaissance and enumeration have...
5 notes & referencesAutomated Exploitation and Validation
This module provides repeatable, operator controlled playbooks for turning reviewed findings into validation evidence. Automation is intentionally bounded: every workflow requir...
4 notes & referencesExploitation & Foothold
The exploitation phase is where identified vulnerabilities are weaponized to gain initial access to a target system. This phase is the most varied because exploitation technique...
37 notes & referencesPost-Exploitation Methodology
Post exploitation is the phase after gaining initial access to a target system. The goal is to stabilize access, gather situational awareness, hunt for credentials, and pivot de...
5 notes & referencesPrivilege Escalation
Privilege escalation is the process of elevating your access from a low privileged user to a higher privileged one ideally root on Linux or SYSTEM / Domain Admin on Windows. A f...
24 notes & referencesLateral Movement
Lateral movement is the phase where an attacker pivots from their initial foothold to other systems within the target environment. The goal is to expand access, locate sensitive...
9 notes & referencesPersistence
Persistence techniques should only be deployed when explicitly authorized in the engagement scope and rules of engagement. In most penetration tests, persistence is demonstrated...
2 notes & referencesData Exfiltration
Data exfiltration is the phase where sensitive information is extracted from the target environment to demonstrate business impact. In a penetration test, the goal is not to act...
0 notes & referencesReporting & Cleanup
The final phase of any penetration test is twofold: reporting your findings to the client in a clear, actionable format, and cleaning up every artifact, account, backdoor, and t...
0 notes & referencesWireless Pentesting
Wireless pentesting is a cross cutting domain that spans reconnaissance, exploitation, and lateral movement. WiFi protocols, enterprise network segmentation controls (VLANs, NAC...
15 notes & referencesPivoting & C2 Infrastructure
Pivoting transforms a single compromised host into a beachhead for the entire internal network. C2 infrastructure provides the persistent, resilient command and control layer th...
14 notes & referencesNetExec (nxc)
NetExec (binary: nxc or netexec) is the actively maintained successor to CrackMapExec (CME), which was deprecated in 2023. It is the single most versatile post exploitation and...
9 notes & referencesAppendices
4 notes and references.
4 notes & referencesCheat Sheets
7 notes and references.
7 notes & references