- 1RECONNAISSANCE
- Passive: OSINT, WHOIS, Shodan, LinkedIn, DNS records, Google dorks
- Active: DNS zone transfer, subdomain brute-force, email harvesting
done whenYou have a target IP list, open ports picture, tech stack guesses - 2SCANNING
- Full TCP port scan, UDP top ports, service version detection, OS guessing
done whenEvery open port is identified with service + version - 3ENUMERATION
- Deep-dive every service: banner grab, anonymous access, known misconfigs
done whenYou have usernames, shares, software versions, web directories - 4EXPLOITATION
- Leverage findings: known CVEs, misconfigs, weak creds, injection points
done whenYou have a shell (even low-priv) on the target - 5PRIVILEGE ESCALATION
- Linux: sudo, SUID, crons, capabilities, kernel. Windows: tokens, services, registry
done whenYou are root / NT AUTHORITY\SYSTEM / Domain Admin - 6LATERAL MOVEMENT
- Pivot to other hosts: PTH, PTT, credential reuse, RDP, WinRM, SSH tunneling
done whenYou've expanded your foothold across the network - 7POST-EXPLOITATION
- Dump creds, map network, maintain access, exfil proof files
done whenProof files captured, hashes dumped, report artifacts collected - 8REPORTING
- Document: scope, findings, evidence, severity ratings, remediation steps
done whenClient / examiner has a reproducible, evidence-backed report