commit 5b8ba9d7477d1bcc155873493cff96d361b277d0 parent 49733de3ed0c6c2fcd0b73ccaec2083dc593ad51 Author: DAEMON <zer0sec.xp@icloud.com> Date: Mon, 31 Aug 2026 21:10:08 +0100 sheets: wire Attacking Enterprise Networks into pentest-workflow nav (order + backlinks) Give the sheet order: 32 so it sits deterministically at the end of the General CPTS Cheatsheets section (it was the only pentest-workflow sheet without an order). Link the AEN capstone mention in worked-chains to the dedicated sheet, and add it to the playbook's Companion Notes so the orphaned sheet is reachable from both. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012y66o4t9QiC9h1KBAy7yAj Diffstat:
3 files changed, 3 insertions(+), 1 deletion(-)
diff --git a/src/content/sheets/pentest-workflow/attacking-enterprise-networks.md b/src/content/sheets/pentest-workflow/attacking-enterprise-networks.md @@ -3,6 +3,7 @@ title: "Attacking Enterprise Networks — Lateral Movement to Domain" description: "Worked HTB Attacking Enterprise Networks chain through INLANEFREIGHT: BloodHound, ForceChangePassword, share hunting, Kerberoasting, WinRM, MS01 privesc, pillage — plus ACL abuse, tunneling, and MySQL/MSSQL exploitation." category: pentest-workflow subcategory: "General CPTS Cheatsheets" +order: 32 tags: ["htb", "attacking-enterprise-networks", "active-directory", "lateral-movement", "kerberoasting", "bloodhound", "mssql", "mysql", "pivoting", "pentest-workflow"] tools: ["SharpHound", "BloodHound", "PowerView", "NetExec", "Impacket", "Snaffler", "smbclient", "xfreerdp", "evil-winrm", "Kerbrute", "Hashcat", "mimikatz", "Inveigh", "proxychains"] difficulty: advanced diff --git a/src/content/sheets/pentest-workflow/htb-attack-flow-playbook.md b/src/content/sheets/pentest-workflow/htb-attack-flow-playbook.md @@ -113,6 +113,7 @@ flowchart TD - AD_Pentest_Tools_Cheat_Sheet — Active Directory tooling index. - Nmap Cheatsheet 2026 — scan design and Nmap reference. - Credential Hunting — focused credential-discovery workflow. +- [Attacking Enterprise Networks](/sheets/pentest-workflow/attacking-enterprise-networks) — the whole playbook run end to end against INLANEFREIGHT. --- diff --git a/src/content/sheets/pentest-workflow/worked-chains.md b/src/content/sheets/pentest-workflow/worked-chains.md @@ -275,7 +275,7 @@ Note: HTB-Forest. Notes: HTB-Fluffy · Fluffy Attack Plan. ### The web-to-AD pattern (many CPTS/AEN boxes) -`[S0/S2]` external recon + web enum finds an app → `[S2]` an app-specific exploit (upload/LFI/known-CVE/thick-client creds) → foothold shell on a domain-joined host → `[S9]` local privesc if needed → `[S4]` you're now inside AD: BloodHound + LDAP cookbook as the machine/user → follow the AD shape above. The **Attacking Enterprise Networks** capstone is exactly this, end to end. Chain A above is this pattern written out step by step. +`[S0/S2]` external recon + web enum finds an app → `[S2]` an app-specific exploit (upload/LFI/known-CVE/thick-client creds) → foothold shell on a domain-joined host → `[S9]` local privesc if needed → `[S4]` you're now inside AD: BloodHound + LDAP cookbook as the machine/user → follow the AD shape above. The [**Attacking Enterprise Networks**](/sheets/pentest-workflow/attacking-enterprise-networks) capstone is exactly this, end to end — see that sheet for the full INLANEFREIGHT chain written out command by command. Chain A above is this pattern written out step by step. > [!note] More box notes to mine for patterns > Garfield (Season 10), the Pro-Lab chains (Dante, Zephyr), and the AD Track. Same shape scaled up: multiple hosts, pivots between segments ([Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot)), and trusts ([Cross-Forest](/sheets/pentest-workflow/domain-trusts-and-cross-forest)) once you're DA in the first domain.