Pentesting commands — cheat sheet
Quick-reference commands for recon, enumeration, exploitation, and post-exploit work on Linux and Windows targets.
Quick-reference commands for recon, enumeration, exploitation, and post-exploit work on Linux and Windows targets.

Henry → targeted Kerberoast on Alfred → AddSelf to INFRASTRUCTURE → ReadGMSAPassword on ansible_dev$ → Sam → John → WinRM pivot → reanimate tombstoned cert_admin via John’s GenericAll on OU=ADCS → ESC15 (CVE-2024-49019) on the WebServer template → Administrator.

Olivia → BloodHound ACL chain (ForceChangePassword) → Benjamin → FTP .psafe3 → hashcat → password spray to Emily → targetedKerberoast on Ethan → DCSync Administrator.
Centralised logging and detection engineering in my Windows homelab using Splunk Enterprise and Universal Forwarders.
Overview of my Active Directory homelab: domain setup, users, security exercises, and next steps for monitoring and detection.

Exploiting MS17-010 (EternalBlue) on a Windows 7 SP1 target. Recon, SMB enumeration, exploitation, and proof of SYSTEM access.