Knowledge Base
Battle-tested attack playbooks and methodologies — the offensive techniques that carry an engagement from the first packet to full domain dominance.
01 / RECON
Reconnaissance
Network footprinting, port scanning, OSINT, and web surface enumeration to map the target infrastructure.
23 Topics
Reconnaissance
Network footprinting, port scanning, OSINT, and web surface enumeration to map the target infrastructure.
Information Gathering - Web
02 / WEB
Web Attacks
File upload vulnerabilities, injection flaws, and deep dives into web application exploitation techniques.
34 Topics
Web Attacks
File upload vulnerabilities, injection flaws, and deep dives into web application exploitation techniques.
File Upload Attacks
SQL Injection
Attacking with Ffuf
03 / APPS
Attacking Common Applications
Targeting enterprise web apps, CMS platforms, WordPress, custom portals, and administrative suites.
2 Topics
Attacking Common Applications
Targeting enterprise web apps, CMS platforms, WordPress, custom portals, and administrative suites.
Enterprise Applications
04 / CREDENTIALS
Credential Attacks
Password cracking, credential hunting, Pass-the-Hash, Pass-the-Ticket, and dumping hashes from SAM/NTDS.
27 Topics
Credential Attacks
Password cracking, credential hunting, Pass-the-Hash, Pass-the-Ticket, and dumping hashes from SAM/NTDS.
Password Cracking
Windows Credential Extraction
Lateral Movement & Relay
05 / ACTIVE DIRECTORY
Active Directory
The complete AD pentesting playbook: LLMNR poisoning, Kerberoasting, ADCS escalation, and Golden Tickets.
31 Topics
Active Directory
The complete AD pentesting playbook: LLMNR poisoning, Kerberoasting, ADCS escalation, and Golden Tickets.
Initial Access & Enumeration
Domain Exploitation & ADCS
06 / FRAMEWORKS
Exploitation Frameworks
Mastering Metasploit, managing payloads with MSFVenom, handling sessions, and writing custom modules.
13 Topics
Exploitation Frameworks
Mastering Metasploit, managing payloads with MSFVenom, handling sessions, and writing custom modules.
07 / PIVOTING
Pivoting, Tunneling & Port Forwarding
SSH tunneling, SOCKS proxies, Socat relays, Chisel, DNS/ICMP tunneling, double pivots, and detection evasion.
11 Topics
Pivoting, Tunneling & Port Forwarding
SSH tunneling, SOCKS proxies, Socat relays, Chisel, DNS/ICMP tunneling, double pivots, and detection evasion.
Core Techniques
Tool Deep Dives
08 / WIN PRIVESC
Windows Privilege Escalation & Access Control
Windows access control architecture, tokens, SIDs, integrity levels, privilege mechanics, service hardening, and credential security.
14 Modules
Windows Privilege Escalation & Access Control
Windows access control architecture, tokens, SIDs, integrity levels, privilege mechanics, service hardening, and credential security.