- Description
- Internal and external network PT · host discovery to root.
- Best For
- Internal network engagements, lab environments with multiple hosts, OSCP-style multi-machine scenarios.
- Strength
- Full protocol coverage with exact enumeration commands, exploitation examples, and documentation steps.
in this domain 10 sections
- 01 Decision Tree: External Access Only → What First?
- 02 Host Discovery
- 03 Full Nmap Strategy
- 04 Service Enumeration Deep Dive
- 05 Vulnerability Research Workflow
- 06 Exploitation Examples
- 07 PrivEsc Summary (Pointers)
- 08 Proof Capture & Documentation
- 09 Pivoting & Tunneling
- 10 Network Poisoning & MITM