Port Scanning

Medium

nmap scanning techniques. SYN scans, service version detection, OS fingerprinting, and evasion techniques.

Full Guide

SMB Attacks

Critical

SMB exploitation, EternalBlue, SMB relay attacks, and lateral movement via smbexec and psexec.

Full Guide

DNS Attacks

High

DNS reconnaissance, zone transfers, DNS tunneling, and cache poisoning attacks.

Full Guide

LDAP Attacks

High

LDAP enumeration, bind vulnerabilities, injection attacks.

Full Guide

Linux Privesc

High

Linux privilege escalation. SUID binaries, sudo misconfigs, kernel exploits, and container escapes.

Full Guide

SSH Tunneling

Medium

SSH tunneling, port forwarding, dynamic proxy, VPN-like tunnels.

Full Guide

🕷️ Lateral Movement

Pass the Hash

High

Pass-the-Hash and Pass-the-Token attacks. Authenticate without knowing passwords.

Full Guide

Pass the Ticket

Critical

Kerberos ticket attacks. Golden Ticket, Silver Ticket, Skeleton Key, and Roasting attacks.

Full Guide

NTLM Relay

Critical

LLMNR/NBT-NS poisoning, SMB relay attacks, credential capture and relay.

Full Guide

Kerberoasting

High

Request TGS tickets for service accounts, crack offline to find weak passwords.

Full Guide

🛠️ Essential Tools

Nmap

Network exploration and security auditing. Port scanning, version detection, OS fingerprinting.

Netcat

Network Swiss Army knife. Reverse shells, file transfer, port scanning, banner grabbing.

Mimikatz

Credential extraction and lateral movement. Pass-the-Hash, sekurlsa, privilege::debug.

Responder

LLMNR/NBT-NS/mDNS poisoner. SMB relay, HTTP auth capture, credential stealing.

CrackMapExec

Swiss army knife for AD pentesting. Network attacking, credential dumping, red teaming.

BloodHound

AD attack path analysis. Graph database for finding privilege escalation paths.

Back to Home