Handbook

Internal Pentesting Trainee Guide

Updated 29 Sept 2026Services✎ Suggest a change
On this page

What This Is

This is a guide for associates doing their first internal pentest. It's not a step by step walkthrough, think of it more as a reference you flick back to when you're stuck or need a command reminder. Attack flow and commands, minimal fluff.

Structure

Three sections, following how an internal engagement usually plays out:

1. Initial Access

Figuring out what's actually on the network before you touch anything. Live hosts, services, SMB signing, null sessions, general attack surface. Point is to know what you're dealing with. Then turning that enumeration into credentials or a shell. LLMNR/NBT-NS poisoning, NTLM relay etc. Getting your first foot in the door.

2. Low Privilege Foothold

Escalating a basic foothold to access sensitive data or escalate privileges.

3. Post-Domain Compromise

Once you've got Domain Admin (or equivalent), what next. NTDS extraction, lateral movement, ADCS abuse, and objective-based stuff like mailbox access or sensitive data hunting depending on scope.

How to Use It

  • Every technique follows the same layout: attack flow, tool reference, commands, expected output.
  • You won't always go in order. Some environments hand you a foothold before you've finished enumerating, some need heaps of enum before anything bites. Use whatever section fits what's in front of you.
  • If a command or flag here doesn't quite match what you're seeing, check -help or the tool's docs first. This guide gets you moving, it's not exhaustive.