Practical offensive security

The Pentest Book.

A field guide to offensive workflows, organized by phase and built for quick lookup during an engagement.

Start reading
01

Pre-Foothold Operations

Pre foothold work turns an approved scope into a defensible attack surface map before any attempt to gain access. This module is an operational hub: it provides repeatable works...

7 notes & references
02

Reconnaissance

Reconnaissance is the first and foundational phase of any penetration test. The goal is to gather as much information as possible about the target without triggering alarms . Qu...

2 notes & references
03

Enumeration

Enumeration is the most critical phase of any penetration test. This is where you actively probe discovered systems to map the attack surface: open ports, running services, OS v...

13 notes & references
04

Vulnerability Assessment

Vulnerability assessment is the systematic process of identifying, classifying, and prioritizing security weaknesses in target systems. After reconnaissance and enumeration have...

5 notes & references
05

Automated Exploitation and Validation

This module provides repeatable, operator controlled playbooks for turning reviewed findings into validation evidence. Automation is intentionally bounded: every workflow requir...

4 notes & references
06

Exploitation & Foothold

The exploitation phase is where identified vulnerabilities are weaponized to gain initial access to a target system. This phase is the most varied because exploitation technique...

37 notes & references
07

Post-Exploitation Methodology

Post exploitation is the phase after gaining initial access to a target system. The goal is to stabilize access, gather situational awareness, hunt for credentials, and pivot de...

5 notes & references
08

Privilege Escalation

Privilege escalation is the process of elevating your access from a low privileged user to a higher privileged one ideally root on Linux or SYSTEM / Domain Admin on Windows. A f...

24 notes & references
09

Lateral Movement

Lateral movement is the phase where an attacker pivots from their initial foothold to other systems within the target environment. The goal is to expand access, locate sensitive...

9 notes & references
10

Persistence

Persistence techniques should only be deployed when explicitly authorized in the engagement scope and rules of engagement. In most penetration tests, persistence is demonstrated...

2 notes & references
11

Data Exfiltration

Data exfiltration is the phase where sensitive information is extracted from the target environment to demonstrate business impact. In a penetration test, the goal is not to act...

0 notes & references
12

Reporting & Cleanup

The final phase of any penetration test is twofold: reporting your findings to the client in a clear, actionable format, and cleaning up every artifact, account, backdoor, and t...

0 notes & references
13

Wireless Pentesting

Wireless pentesting is a cross cutting domain that spans reconnaissance, exploitation, and lateral movement. WiFi protocols, enterprise network segmentation controls (VLANs, NAC...

15 notes & references
14

Pivoting & C2 Infrastructure

Pivoting transforms a single compromised host into a beachhead for the entire internal network. C2 infrastructure provides the persistent, resilient command and control layer th...

14 notes & references
15

NetExec (nxc)

NetExec (binary: nxc or netexec) is the actively maintained successor to CrackMapExec (CME), which was deprecated in 2023. It is the single most versatile post exploitation and...

9 notes & references
16

Appendices

4 notes and references.

4 notes & references
17

Cheat Sheets

7 notes and references.

7 notes & references