What This Is
This is a guide for associates doing their first internal pentest. It's not a step by step walkthrough, think of it more as a reference you flick back to when you're stuck or need a command reminder. Attack flow and commands, minimal fluff.
Structure
Three sections, following how an internal engagement usually plays out:
1. Initial Access
Figuring out what's actually on the network before you touch anything. Live hosts, services, SMB signing, null sessions, general attack surface. Point is to know what you're dealing with. Then turning that enumeration into credentials or a shell. LLMNR/NBT-NS poisoning, NTLM relay etc. Getting your first foot in the door.
2. Low Privilege Foothold
Escalating a basic foothold to access sensitive data or escalate privileges.
3. Post-Domain Compromise
Once you've got Domain Admin (or equivalent), what next. NTDS extraction, lateral movement, ADCS abuse, and objective-based stuff like mailbox access or sensitive data hunting depending on scope.
How to Use It
- Every technique follows the same layout: attack flow, tool reference, commands, expected output.
- You won't always go in order. Some environments hand you a foothold before you've finished enumerating, some need heaps of enum before anything bites. Use whatever section fits what's in front of you.
- If a command or flag here doesn't quite match what you're seeing, check
-helpor the tool's docs first. This guide gets you moving, it's not exhaustive.