daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

htb-attack-flow-playbook.md (13360B)


      1 ---
      2 title: "HTB Attack Flow Playbook"
      3 description: "CPTS attack-flow reference for htb attack flow playbook in an authorised engagement."
      4 category: pentest-workflow
      5 subcategory: "CPTS Attack Flow"
      6 order: 18
      7 tags: ["methodology", "attack-flow", "kill-chain", "cpts-prep", "htb", "enumeration", "activedirectory", "adcs", "privilege-escalation", "pivoting", "cpts", "pentest-workflow"]
      8 tools: ["rustscan", "nmap", "ffuf", "netexec", "enum4linux-ng", "ldapsearch", "bloodhound-ce-python", "bloodyAD", "certipy", "impacket", "rubeus", "hashcat", "evil-winrm", "mimikatz", "ligolo-ng"]
      9 difficulty: intermediate
     10 updated: "2026-08-27"
     11 source: "vault:Pentest Attack Flow/HTB-Attack-Flow-Playbook.md"
     12 ---
     13 # HTB Attack Flow Playbook
     14 
     15 > [!abstract] About this guide
     16 > The complete workflow now lives in 17 focused notes: **passive recon → host discovery → web and service enumeration → foothold → AD and Kerberos → ACL and ADCS abuse → credentials → privilege escalation → lateral movement and pivoting → reporting**. This file remains the stable entry point so its aliases and inbound links continue to work.
     17 
     18 > [!dashboard] Open the workspace
     19 > [Open the HTB Pentest Attack Flow dashboard](/sheets/pentest-workflow/attack-flow-dashboard)
     20 >
     21 > The dashboard tracks all 17 notes without sharing the folder’s name, avoiding Make.md’s folder-note collision.
     22 
     23 > [!warning] Authorized targets only
     24 > Use this playbook only on systems and networks where you have explicit permission. Keep scope, evidence, timestamps, credentials, target changes, and rollback actions documented throughout the engagement.
     25 
     26 ## Engagement Setup
     27 
     28 > [!note] Set these once
     29 > The stage notes use these variables to keep commands readable. Replace every placeholder and confirm the active target before running anything.
     30 
     31 ```bash
     32 export IP="10.10.11.x"
     33 export TARGET="$IP"
     34 export DOMAIN="domain.htb"
     35 export DC="dc01.$DOMAIN"
     36 export LHOST="$(ip -br address show tun0 | awk '{print $3}' | cut -d/ -f1)"
     37 export U="user"
     38 export P="password"
     39 ```
     40 
     41 ```bash
     42 printf '%s\t%s %s %s\n' \
     43   "$IP" "$DOMAIN" "$DC" "${DC%%.*}" |
     44   sudo tee -a /etc/hosts
     45 ```
     46 
     47 > [!tip] Kerberos clock skew
     48 > If authentication returns `KRB_AP_ERR_SKEW`, compare your clock with the domain controller before changing tactics. See faketime-cheatsheet for the lab workflow.
     49 
     50 ## Kill Chain
     51 
     52 <figure class="flow plate corners">
     53   <figcaption class="flow__cap"><span class="flow__kind">Engagement kill chain</span><span class="flow__dir">TD</span></figcaption>
     54   <div class="flow__body">
     55     <svg class="flow-svg" viewBox="0 0 840 1410" role="img" aria-label="Passive recon and setup lead to recon, then an attack-surface decision fans out to web, services and AD enumeration; the foothold and AD paths run through credentials, privesc, lateral movement, Kerberos, ACL and ADCS abuse and converge on Domain Admin, then trusts and reporting">
     56       <path class="fedge" d="M400,78 L400,138" marker-end="url(#flow-arrow)" />
     57       <path class="fedge" d="M400,186 L400,246" marker-end="url(#flow-arrow)" />
     58       <path class="fedge" d="M400,294 L400,354" marker-end="url(#flow-arrow)" />
     59       <path class="fedge" d="M400,402 L150,462" marker-end="url(#flow-arrow)" />
     60       <path class="fedge" d="M400,402 L400,462" marker-end="url(#flow-arrow)" />
     61       <path class="fedge" d="M400,402 L650,462" marker-end="url(#flow-arrow)" />
     62       <path class="fedge" d="M150,510 L255,570" marker-end="url(#flow-arrow)" />
     63       <path class="fedge" d="M400,510 L295,570" marker-end="url(#flow-arrow)" />
     64       <path class="fedge" d="M275,618 L275,678" marker-end="url(#flow-arrow)" />
     65       <path class="fedge" d="M650,510 L650,570" marker-end="url(#flow-arrow)" />
     66       <path class="fedge" d="M650,618 L650,678" marker-end="url(#flow-arrow)" />
     67       <path class="fedge" d="M650,726 L650,786" marker-end="url(#flow-arrow)" />
     68       <path class="fedge" d="M275,726 L275,786" marker-end="url(#flow-arrow)" />
     69       <path class="fedge" d="M275,834 L275,894" marker-end="url(#flow-arrow)" />
     70       <path class="fedge" d="M275,942 L275,1002" marker-end="url(#flow-arrow)" />
     71       <path class="fedge" d="M650,834 L650,1082 L380,1082 L380,1110" marker-end="url(#flow-arrow)" />
     72       <path class="fedge" d="M725,702 L790,702 L790,1092 L420,1092 L420,1110" marker-end="url(#flow-arrow)" />
     73       <path class="fedge" d="M575,594 L462,594 L462,702 L350,702" marker-end="url(#flow-arrow)" />
     74       <path class="fedge" d="M275,1050 L400,1110" marker-end="url(#flow-arrow)" />
     75       <path class="fedge" d="M400,1158 L400,1218" marker-end="url(#flow-arrow)" />
     76       <path class="fedge" d="M400,1266 L400,1326" marker-end="url(#flow-arrow)" />
     77       <g class="fnode is-entry"><rect class="fnode__box" x="325" y="30" width="150" height="48" /><text class="fnode__label" x="400" y="51" text-anchor="middle">0. PASSIVE RECON<tspan class="sub" x="400" dy="15">crt.sh · Shodan · dorks · git</tspan></text></g>
     78       <g class="fnode"><rect class="fnode__box" x="325" y="138" width="150" height="48" /><text class="fnode__label" x="400" y="159" text-anchor="middle">SETUP<tspan class="sub" x="400" dy="15">hosts · realm · clock</tspan></text></g>
     79       <g class="fnode"><rect class="fnode__box" x="325" y="246" width="150" height="48" /><text class="fnode__label" x="400" y="267" text-anchor="middle">1. RECON<tspan class="sub" x="400" dy="15">RustScan → Nmap</tspan></text></g>
     80       <g class="fnode is-decision"><rect class="fnode__box" x="325" y="354" width="150" height="48" /><text class="fnode__label" x="400" y="382" text-anchor="middle">Attack surface?</text></g>
     81       <g class="fnode"><rect class="fnode__box" x="75" y="462" width="150" height="48" /><text class="fnode__label" x="150" y="483" text-anchor="middle">2. WEB<tspan class="sub" x="150" dy="15">ffuf · Burp · app testing</tspan></text></g>
     82       <g class="fnode"><rect class="fnode__box" x="325" y="462" width="150" height="48" /><text class="fnode__label" x="400" y="483" text-anchor="middle">3. SERVICES<tspan class="sub" x="400" dy="15">NetExec · enum4linux-ng</tspan></text></g>
     83       <g class="fnode"><rect class="fnode__box" x="575" y="462" width="150" height="48" /><text class="fnode__label" x="650" y="483" text-anchor="middle">4. AD ENUM<tspan class="sub" x="650" dy="15">LDAP · BloodHound</tspan></text></g>
     84       <g class="fnode"><rect class="fnode__box" x="200" y="570" width="150" height="48" /><text class="fnode__label" x="275" y="591" text-anchor="middle">FOOTHOLD TOOLKITS<tspan class="sub" x="275" dy="15">transfer · payload · shell</tspan></text></g>
     85       <g class="fnode"><rect class="fnode__box" x="575" y="570" width="150" height="48" /><text class="fnode__label" x="650" y="591" text-anchor="middle">5. KERBEROS<tspan class="sub" x="650" dy="15">roast · AS-REP · tickets</tspan></text></g>
     86       <g class="fnode"><rect class="fnode__box" x="200" y="678" width="150" height="48" /><text class="fnode__label" x="275" y="706" text-anchor="middle">Foothold or credentials</text></g>
     87       <g class="fnode"><rect class="fnode__box" x="575" y="678" width="150" height="48" /><text class="fnode__label" x="650" y="699" text-anchor="middle">6. ACL ABUSE<tspan class="sub" x="650" dy="15">BloodHound edges</tspan></text></g>
     88       <g class="fnode"><rect class="fnode__box" x="200" y="786" width="150" height="48" /><text class="fnode__label" x="275" y="807" text-anchor="middle">8. CREDENTIALS<tspan class="sub" x="275" dy="15">hunt · spray · crack</tspan></text></g>
     89       <g class="fnode"><rect class="fnode__box" x="575" y="786" width="150" height="48" /><text class="fnode__label" x="650" y="807" text-anchor="middle">7. ADCS<tspan class="sub" x="650" dy="15">Certipy</tspan></text></g>
     90       <g class="fnode"><rect class="fnode__box" x="200" y="894" width="150" height="48" /><text class="fnode__label" x="275" y="915" text-anchor="middle">9. PRIVESC<tspan class="sub" x="275" dy="15">Linux / Windows</tspan></text></g>
     91       <g class="fnode"><rect class="fnode__box" x="200" y="1002" width="150" height="48" /><text class="fnode__label" x="275" y="1030" text-anchor="middle">10. LATERAL / PIVOT / LOOT</text></g>
     92       <g class="fnode is-goal"><rect class="fnode__box" x="325" y="1110" width="150" height="48" /><text class="fnode__label" x="400" y="1138" text-anchor="middle">Domain Admin</text></g>
     93       <g class="fnode"><rect class="fnode__box" x="325" y="1218" width="150" height="48" /><text class="fnode__label" x="400" y="1239" text-anchor="middle">TRUSTS<tspan class="sub" x="400" dy="15">domain · forest</tspan></text></g>
     94       <g class="fnode"><rect class="fnode__box" x="325" y="1326" width="150" height="48" /><text class="fnode__label" x="400" y="1347" text-anchor="middle">11. REPORT<tspan class="sub" x="400" dy="15">evidence · findings · retest</tspan></text></g>
     95       <g class="felabel"><rect class="felabel__box" x="250" y="424" width="50" height="16" /><text class="felabel__text" x="275" y="435" text-anchor="middle">80/443</text></g>
     96       <g class="felabel"><rect class="felabel__box" x="353" y="424" width="94" height="16" /><text class="felabel__text" x="400" y="435" text-anchor="middle">445/139 · 135</text></g>
     97       <g class="felabel"><rect class="felabel__box" x="500" y="424" width="50" height="16" /><text class="felabel__text" x="525" y="435" text-anchor="middle">389/88</text></g>
     98     </svg>
     99   </div>
    100 </figure>
    101 
    102 > [!tip] How to use the flow
    103 > Treat each stage as a question, not a mandatory sequence. New credentials, routes, hostnames, or privileges should send you back to the lowest-noise relevant enumeration stage. On an HTB box you may begin at Stage 01; a real engagement or CPTS-style assessment usually begins at Stage 00 and ends only after Stage 11.
    104 
    105 ## Linked Table of Contents
    106 
    107 | # | Note | Use it when |
    108 |---:|---|---|
    109 | 00 | [Attack Flow Dashboard](/sheets/pentest-workflow/attack-flow-dashboard) | You want the workspace, progress view, or start page. |
    110 | 01 | [Stage 00 — Passive External Recon](/sheets/pentest-workflow/passive-external-recon) | You need external assets, identities, DNS, or leaked-source clues. |
    111 | 02 | [Stage 01 — Recon and Host Discovery](/sheets/pentest-workflow/recon-and-host-discovery) | You need live hosts, ports, services, names, and priorities. |
    112 | 03 | [Stage 02 — Web Enumeration and Exploitation](/sheets/pentest-workflow/web-enumeration-and-exploitation) | HTTP or HTTPS is part of the attack surface. |
    113 | 04 | [Foothold Toolkit — File Transfers](/sheets/pentest-workflow/foothold-file-transfers) | You need to move tools, payloads, or evidence. |
    114 | 05 | [Foothold Toolkit — Shells, Payloads, and Metasploit](/sheets/pentest-workflow/foothold-shells-payloads-metasploit) | You need to establish or stabilize a foothold. |
    115 | 06 | [Stage 03 — Service Enumeration](/sheets/pentest-workflow/service-enumeration) | SMB, RPC, LDAP, DNS, databases, or another exposed service needs depth. |
    116 | 07 | [Stage 04 — Active Directory Enumeration](/sheets/pentest-workflow/active-directory-enumeration) | You have domain context or credentials and need the privilege graph. |
    117 | 08 | [Stage 05 — Kerberos Attacks](/sheets/pentest-workflow/kerberos-attacks) | Kerberos configuration or tickets expose an attack path. |
    118 | 09 | [Stage 06 — ACL and Object Abuse](/sheets/pentest-workflow/acl-and-object-abuse) | BloodHound or LDAP shows delegated object rights. |
    119 | 10 | [Stage 07 — ADCS and Certificate Abuse](/sheets/pentest-workflow/adcs-and-certificate-abuse) | A certificate authority or enrollment service is present. |
    120 | 11 | [Stage 08 — Password Attacks and Credential Hunting](/sheets/pentest-workflow/password-attacks-and-credential-hunting) | You need to locate, validate, spray, or crack credential material. |
    121 | 12 | [Stage 09 — Privilege Escalation](/sheets/pentest-workflow/privilege-escalation) | A Linux or Windows foothold needs local escalation. |
    122 | 13 | [Stage 10 — Lateral Movement, Pivoting, and Loot](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) | You need remote execution, routes, tunnels, packet capture, or evidence collection. |
    123 | 14 | [Domain Trusts and Cross-Forest](/sheets/pentest-workflow/domain-trusts-and-cross-forest) | The attack graph crosses a domain or forest boundary. |
    124 | 15 | [Stage 11 — Documentation and Reporting](/sheets/pentest-workflow/documentation-and-reporting) | You need logs, evidence, findings, cleanup, or retest structure. |
    125 | 16 | [Appendix — Worked Chains](/sheets/pentest-workflow/worked-chains) | You want compact end-to-end examples. |
    126 | 17 | [Tool Index](/sheets/pentest-workflow/tool-index) | You know the tool and need its place in the workflow. |
    127 
    128 ## Companion Notes
    129 
    130 - [Attack-Flow-Guide](/sheets/pentest-workflow/attack-flow-guide) — phased decision trees.
    131 - [Most-Used-Commands](/sheets/pentest-workflow/most-used-commands) — compact raw syntax.
    132 - AD_Pentest_Tools_Cheat_Sheet — Active Directory tooling index.
    133 - Nmap Cheatsheet 2026 — scan design and Nmap reference.
    134 - Credential Hunting — focused credential-discovery workflow.
    135 - Attacking Enterprise Networks — the whole playbook run end to end against INLANEFREIGHT.
    136 
    137 ---
    138 
    139 > [!navigation] Begin
    140 > **Dashboard:** [HTB Pentest Attack Flow](/sheets/pentest-workflow/attack-flow-dashboard)
    141 >
    142 > **Next:** [Stage 00 — Passive External Recon](/sheets/pentest-workflow/passive-external-recon)