htb-attack-flow-playbook.md (13360B)
1 --- 2 title: "HTB Attack Flow Playbook" 3 description: "CPTS attack-flow reference for htb attack flow playbook in an authorised engagement." 4 category: pentest-workflow 5 subcategory: "CPTS Attack Flow" 6 order: 18 7 tags: ["methodology", "attack-flow", "kill-chain", "cpts-prep", "htb", "enumeration", "activedirectory", "adcs", "privilege-escalation", "pivoting", "cpts", "pentest-workflow"] 8 tools: ["rustscan", "nmap", "ffuf", "netexec", "enum4linux-ng", "ldapsearch", "bloodhound-ce-python", "bloodyAD", "certipy", "impacket", "rubeus", "hashcat", "evil-winrm", "mimikatz", "ligolo-ng"] 9 difficulty: intermediate 10 updated: "2026-08-27" 11 source: "vault:Pentest Attack Flow/HTB-Attack-Flow-Playbook.md" 12 --- 13 # HTB Attack Flow Playbook 14 15 > [!abstract] About this guide 16 > The complete workflow now lives in 17 focused notes: **passive recon → host discovery → web and service enumeration → foothold → AD and Kerberos → ACL and ADCS abuse → credentials → privilege escalation → lateral movement and pivoting → reporting**. This file remains the stable entry point so its aliases and inbound links continue to work. 17 18 > [!dashboard] Open the workspace 19 > [Open the HTB Pentest Attack Flow dashboard](/sheets/pentest-workflow/attack-flow-dashboard) 20 > 21 > The dashboard tracks all 17 notes without sharing the folder’s name, avoiding Make.md’s folder-note collision. 22 23 > [!warning] Authorized targets only 24 > Use this playbook only on systems and networks where you have explicit permission. Keep scope, evidence, timestamps, credentials, target changes, and rollback actions documented throughout the engagement. 25 26 ## Engagement Setup 27 28 > [!note] Set these once 29 > The stage notes use these variables to keep commands readable. Replace every placeholder and confirm the active target before running anything. 30 31 ```bash 32 export IP="10.10.11.x" 33 export TARGET="$IP" 34 export DOMAIN="domain.htb" 35 export DC="dc01.$DOMAIN" 36 export LHOST="$(ip -br address show tun0 | awk '{print $3}' | cut -d/ -f1)" 37 export U="user" 38 export P="password" 39 ``` 40 41 ```bash 42 printf '%s\t%s %s %s\n' \ 43 "$IP" "$DOMAIN" "$DC" "${DC%%.*}" | 44 sudo tee -a /etc/hosts 45 ``` 46 47 > [!tip] Kerberos clock skew 48 > If authentication returns `KRB_AP_ERR_SKEW`, compare your clock with the domain controller before changing tactics. See faketime-cheatsheet for the lab workflow. 49 50 ## Kill Chain 51 52 <figure class="flow plate corners"> 53 <figcaption class="flow__cap"><span class="flow__kind">Engagement kill chain</span><span class="flow__dir">TD</span></figcaption> 54 <div class="flow__body"> 55 <svg class="flow-svg" viewBox="0 0 840 1410" role="img" aria-label="Passive recon and setup lead to recon, then an attack-surface decision fans out to web, services and AD enumeration; the foothold and AD paths run through credentials, privesc, lateral movement, Kerberos, ACL and ADCS abuse and converge on Domain Admin, then trusts and reporting"> 56 <path class="fedge" d="M400,78 L400,138" marker-end="url(#flow-arrow)" /> 57 <path class="fedge" d="M400,186 L400,246" marker-end="url(#flow-arrow)" /> 58 <path class="fedge" d="M400,294 L400,354" marker-end="url(#flow-arrow)" /> 59 <path class="fedge" d="M400,402 L150,462" marker-end="url(#flow-arrow)" /> 60 <path class="fedge" d="M400,402 L400,462" marker-end="url(#flow-arrow)" /> 61 <path class="fedge" d="M400,402 L650,462" marker-end="url(#flow-arrow)" /> 62 <path class="fedge" d="M150,510 L255,570" marker-end="url(#flow-arrow)" /> 63 <path class="fedge" d="M400,510 L295,570" marker-end="url(#flow-arrow)" /> 64 <path class="fedge" d="M275,618 L275,678" marker-end="url(#flow-arrow)" /> 65 <path class="fedge" d="M650,510 L650,570" marker-end="url(#flow-arrow)" /> 66 <path class="fedge" d="M650,618 L650,678" marker-end="url(#flow-arrow)" /> 67 <path class="fedge" d="M650,726 L650,786" marker-end="url(#flow-arrow)" /> 68 <path class="fedge" d="M275,726 L275,786" marker-end="url(#flow-arrow)" /> 69 <path class="fedge" d="M275,834 L275,894" marker-end="url(#flow-arrow)" /> 70 <path class="fedge" d="M275,942 L275,1002" marker-end="url(#flow-arrow)" /> 71 <path class="fedge" d="M650,834 L650,1082 L380,1082 L380,1110" marker-end="url(#flow-arrow)" /> 72 <path class="fedge" d="M725,702 L790,702 L790,1092 L420,1092 L420,1110" marker-end="url(#flow-arrow)" /> 73 <path class="fedge" d="M575,594 L462,594 L462,702 L350,702" marker-end="url(#flow-arrow)" /> 74 <path class="fedge" d="M275,1050 L400,1110" marker-end="url(#flow-arrow)" /> 75 <path class="fedge" d="M400,1158 L400,1218" marker-end="url(#flow-arrow)" /> 76 <path class="fedge" d="M400,1266 L400,1326" marker-end="url(#flow-arrow)" /> 77 <g class="fnode is-entry"><rect class="fnode__box" x="325" y="30" width="150" height="48" /><text class="fnode__label" x="400" y="51" text-anchor="middle">0. PASSIVE RECON<tspan class="sub" x="400" dy="15">crt.sh · Shodan · dorks · git</tspan></text></g> 78 <g class="fnode"><rect class="fnode__box" x="325" y="138" width="150" height="48" /><text class="fnode__label" x="400" y="159" text-anchor="middle">SETUP<tspan class="sub" x="400" dy="15">hosts · realm · clock</tspan></text></g> 79 <g class="fnode"><rect class="fnode__box" x="325" y="246" width="150" height="48" /><text class="fnode__label" x="400" y="267" text-anchor="middle">1. RECON<tspan class="sub" x="400" dy="15">RustScan → Nmap</tspan></text></g> 80 <g class="fnode is-decision"><rect class="fnode__box" x="325" y="354" width="150" height="48" /><text class="fnode__label" x="400" y="382" text-anchor="middle">Attack surface?</text></g> 81 <g class="fnode"><rect class="fnode__box" x="75" y="462" width="150" height="48" /><text class="fnode__label" x="150" y="483" text-anchor="middle">2. WEB<tspan class="sub" x="150" dy="15">ffuf · Burp · app testing</tspan></text></g> 82 <g class="fnode"><rect class="fnode__box" x="325" y="462" width="150" height="48" /><text class="fnode__label" x="400" y="483" text-anchor="middle">3. SERVICES<tspan class="sub" x="400" dy="15">NetExec · enum4linux-ng</tspan></text></g> 83 <g class="fnode"><rect class="fnode__box" x="575" y="462" width="150" height="48" /><text class="fnode__label" x="650" y="483" text-anchor="middle">4. AD ENUM<tspan class="sub" x="650" dy="15">LDAP · BloodHound</tspan></text></g> 84 <g class="fnode"><rect class="fnode__box" x="200" y="570" width="150" height="48" /><text class="fnode__label" x="275" y="591" text-anchor="middle">FOOTHOLD TOOLKITS<tspan class="sub" x="275" dy="15">transfer · payload · shell</tspan></text></g> 85 <g class="fnode"><rect class="fnode__box" x="575" y="570" width="150" height="48" /><text class="fnode__label" x="650" y="591" text-anchor="middle">5. KERBEROS<tspan class="sub" x="650" dy="15">roast · AS-REP · tickets</tspan></text></g> 86 <g class="fnode"><rect class="fnode__box" x="200" y="678" width="150" height="48" /><text class="fnode__label" x="275" y="706" text-anchor="middle">Foothold or credentials</text></g> 87 <g class="fnode"><rect class="fnode__box" x="575" y="678" width="150" height="48" /><text class="fnode__label" x="650" y="699" text-anchor="middle">6. ACL ABUSE<tspan class="sub" x="650" dy="15">BloodHound edges</tspan></text></g> 88 <g class="fnode"><rect class="fnode__box" x="200" y="786" width="150" height="48" /><text class="fnode__label" x="275" y="807" text-anchor="middle">8. CREDENTIALS<tspan class="sub" x="275" dy="15">hunt · spray · crack</tspan></text></g> 89 <g class="fnode"><rect class="fnode__box" x="575" y="786" width="150" height="48" /><text class="fnode__label" x="650" y="807" text-anchor="middle">7. ADCS<tspan class="sub" x="650" dy="15">Certipy</tspan></text></g> 90 <g class="fnode"><rect class="fnode__box" x="200" y="894" width="150" height="48" /><text class="fnode__label" x="275" y="915" text-anchor="middle">9. PRIVESC<tspan class="sub" x="275" dy="15">Linux / Windows</tspan></text></g> 91 <g class="fnode"><rect class="fnode__box" x="200" y="1002" width="150" height="48" /><text class="fnode__label" x="275" y="1030" text-anchor="middle">10. LATERAL / PIVOT / LOOT</text></g> 92 <g class="fnode is-goal"><rect class="fnode__box" x="325" y="1110" width="150" height="48" /><text class="fnode__label" x="400" y="1138" text-anchor="middle">Domain Admin</text></g> 93 <g class="fnode"><rect class="fnode__box" x="325" y="1218" width="150" height="48" /><text class="fnode__label" x="400" y="1239" text-anchor="middle">TRUSTS<tspan class="sub" x="400" dy="15">domain · forest</tspan></text></g> 94 <g class="fnode"><rect class="fnode__box" x="325" y="1326" width="150" height="48" /><text class="fnode__label" x="400" y="1347" text-anchor="middle">11. REPORT<tspan class="sub" x="400" dy="15">evidence · findings · retest</tspan></text></g> 95 <g class="felabel"><rect class="felabel__box" x="250" y="424" width="50" height="16" /><text class="felabel__text" x="275" y="435" text-anchor="middle">80/443</text></g> 96 <g class="felabel"><rect class="felabel__box" x="353" y="424" width="94" height="16" /><text class="felabel__text" x="400" y="435" text-anchor="middle">445/139 · 135</text></g> 97 <g class="felabel"><rect class="felabel__box" x="500" y="424" width="50" height="16" /><text class="felabel__text" x="525" y="435" text-anchor="middle">389/88</text></g> 98 </svg> 99 </div> 100 </figure> 101 102 > [!tip] How to use the flow 103 > Treat each stage as a question, not a mandatory sequence. New credentials, routes, hostnames, or privileges should send you back to the lowest-noise relevant enumeration stage. On an HTB box you may begin at Stage 01; a real engagement or CPTS-style assessment usually begins at Stage 00 and ends only after Stage 11. 104 105 ## Linked Table of Contents 106 107 | # | Note | Use it when | 108 |---:|---|---| 109 | 00 | [Attack Flow Dashboard](/sheets/pentest-workflow/attack-flow-dashboard) | You want the workspace, progress view, or start page. | 110 | 01 | [Stage 00 — Passive External Recon](/sheets/pentest-workflow/passive-external-recon) | You need external assets, identities, DNS, or leaked-source clues. | 111 | 02 | [Stage 01 — Recon and Host Discovery](/sheets/pentest-workflow/recon-and-host-discovery) | You need live hosts, ports, services, names, and priorities. | 112 | 03 | [Stage 02 — Web Enumeration and Exploitation](/sheets/pentest-workflow/web-enumeration-and-exploitation) | HTTP or HTTPS is part of the attack surface. | 113 | 04 | [Foothold Toolkit — File Transfers](/sheets/pentest-workflow/foothold-file-transfers) | You need to move tools, payloads, or evidence. | 114 | 05 | [Foothold Toolkit — Shells, Payloads, and Metasploit](/sheets/pentest-workflow/foothold-shells-payloads-metasploit) | You need to establish or stabilize a foothold. | 115 | 06 | [Stage 03 — Service Enumeration](/sheets/pentest-workflow/service-enumeration) | SMB, RPC, LDAP, DNS, databases, or another exposed service needs depth. | 116 | 07 | [Stage 04 — Active Directory Enumeration](/sheets/pentest-workflow/active-directory-enumeration) | You have domain context or credentials and need the privilege graph. | 117 | 08 | [Stage 05 — Kerberos Attacks](/sheets/pentest-workflow/kerberos-attacks) | Kerberos configuration or tickets expose an attack path. | 118 | 09 | [Stage 06 — ACL and Object Abuse](/sheets/pentest-workflow/acl-and-object-abuse) | BloodHound or LDAP shows delegated object rights. | 119 | 10 | [Stage 07 — ADCS and Certificate Abuse](/sheets/pentest-workflow/adcs-and-certificate-abuse) | A certificate authority or enrollment service is present. | 120 | 11 | [Stage 08 — Password Attacks and Credential Hunting](/sheets/pentest-workflow/password-attacks-and-credential-hunting) | You need to locate, validate, spray, or crack credential material. | 121 | 12 | [Stage 09 — Privilege Escalation](/sheets/pentest-workflow/privilege-escalation) | A Linux or Windows foothold needs local escalation. | 122 | 13 | [Stage 10 — Lateral Movement, Pivoting, and Loot](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) | You need remote execution, routes, tunnels, packet capture, or evidence collection. | 123 | 14 | [Domain Trusts and Cross-Forest](/sheets/pentest-workflow/domain-trusts-and-cross-forest) | The attack graph crosses a domain or forest boundary. | 124 | 15 | [Stage 11 — Documentation and Reporting](/sheets/pentest-workflow/documentation-and-reporting) | You need logs, evidence, findings, cleanup, or retest structure. | 125 | 16 | [Appendix — Worked Chains](/sheets/pentest-workflow/worked-chains) | You want compact end-to-end examples. | 126 | 17 | [Tool Index](/sheets/pentest-workflow/tool-index) | You know the tool and need its place in the workflow. | 127 128 ## Companion Notes 129 130 - [Attack-Flow-Guide](/sheets/pentest-workflow/attack-flow-guide) — phased decision trees. 131 - [Most-Used-Commands](/sheets/pentest-workflow/most-used-commands) — compact raw syntax. 132 - AD_Pentest_Tools_Cheat_Sheet — Active Directory tooling index. 133 - Nmap Cheatsheet 2026 — scan design and Nmap reference. 134 - Credential Hunting — focused credential-discovery workflow. 135 - Attacking Enterprise Networks — the whole playbook run end to end against INLANEFREIGHT. 136 137 --- 138 139 > [!navigation] Begin 140 > **Dashboard:** [HTB Pentest Attack Flow](/sheets/pentest-workflow/attack-flow-dashboard) 141 > 142 > **Next:** [Stage 00 — Passive External Recon](/sheets/pentest-workflow/passive-external-recon)