KillChain Compendium: PenTest & Security Handbook
Go to file
whackx 2f245b34a1 some additions 2023-07-18 21:47:40 +02:00
Cryptography bump 2023-07-01 11:38:51 +02:00
Enumeration bump 2023-05-28 14:22:59 +02:00
Exfiltration restructured exfiltration 2022-11-13 01:37:38 +01:00
Exploits some additions 2023-07-18 21:47:40 +02:00
Forensics bump 2023-04-17 22:49:17 +02:00
Miscellaneous bump 2023-07-01 11:38:51 +02:00
Open Source Intelligence some additions 2023-07-18 21:47:40 +02:00
Persistence further restructuring 2022-11-12 23:18:06 +01:00
Post Exploitation some additions 2023-07-18 21:47:40 +02:00
Reverse Engineering bump 2023-05-28 14:22:59 +02:00
Reverse Shells bump 2023-04-17 22:49:17 +02:00
Steganography further restructuring 2022-11-12 23:18:06 +01:00
README.md added stuff 2023-03-28 21:30:56 +02:00
bismuth@10.10.209.128 some additions 2023-07-18 21:47:40 +02:00

README.md

Pentesting

Campaign

  • Checklist

  • vectr.io

  • Engagement --> Concept of Operations (CONOPS), Resource and Personnel Requirements, Timelines

  • Operations --> Operators, Known Information, Responsibilities

  • Mission --> Exact commands to run and execution time of the engagement

  • Remediation --> Report, Remediation consultation

Methodology

  • Steps
    • Reconnaissance
    • Enumeration/Scanning
    • Gaining Access
    • Privilege Escalation
    • Covering Tracks
    • Reporting

Reconnaissance

  • Duck / SearX / metacrawler / google
  • Wikipedia
  • Shodan.io
  • PeopleFinder.com
  • who.is
  • sublist3r
  • hunter.io
  • builtwith.com
  • wappalyzer

Enumeration

  • nmap
  • nikto
  • gobuster
  • dirbuster
  • metasploit
  • enum4linux / linpeas / winpeas / linenum

Exploitation

Post Exploitation

  • Pivoting

Privilege Escalation

  • Vertically or horizontally

Covering Tracks

Reporting

  • Includes
    • Vulnerabilities
    • Criticality
    • Description
    • Countermeasures
    • Finding summary

Frameworks