Before the tool-specific notes, here is how the whole thing fits together. When I feel lost on a box, it is almost always because I lost track of which phase I am in and what would move me to the next one. This page is the map. The other notes are the detail for each stop on it.

The loop that runs the whole engagement

Hacking a box is not a straight line, it is a loop you run at every level of access:

  1. Enumerate what you can see from where you are.
  2. Find a weakness in that attack surface.
  3. Exploit it to gain something (a shell, a credential, a new host you can reach).
  4. Consolidate: bank the new access, then start the loop over from the new vantage point.

You run this loop from outside the network, then again as a low-priv user, then again as root or SYSTEM, then again from each new host you reach. Same four steps, new surface each time. Once this clicks, no box feels random anymore.

The phases, and how they connect

Phase You have You want The note
Recon / Enumeration An IP or scope A map of the attack surface enumeration/
Foothold A weakness Any code execution or valid creds foothold/
Shell stabilize A janky shell A real interactive shell foothold/
Local enumeration A user shell A privesc path privesc-linux/, privesc-windows/
Privilege escalation A path root / SYSTEM privesc-linux/, privesc-windows/
Post-exploitation Full control of a host Creds, secrets, next targets active-directory/, password-attacks/
Lateral movement Creds and a route The next host pivoting/, active-directory/
Reporting A pile of notes A clean writeup reporting/

The arrows between phases are the important part. Every phase produces the input for the next. A version number from enumeration becomes a foothold. A password from post-exploitation becomes lateral movement. If you ever feel stuck, you are usually missing the output of the phase before.

The mindset rules

These matter more than any single command.

  • Enumerate, do not guess. If you are throwing random exploits, you skipped a step. Go back and look harder.
  • Every new fact restarts the loop. A username, a hostname, a version, a password. Each one sends you back to re-enumerate with it in hand.
  • Read everything, fully. The answer is usually in output you skimmed. Config files, HTML comments, script contents, error messages.
  • Reuse everything. Passwords get reused across users and services constantly. Spray every credential you find against every login you find.
  • Take notes as you go. A running log of commands and interesting output is what lets you retrace your path. It is also the raw material for the report.
  • When stuck, drop a level. Re-run the enumeration for the phase you are in. You missed something.

A decision flow for “what do I do next”

When you do not know your next move, walk this:

  1. Do I have a shell yet?
    • No: am I still finding new attack surface (ports, vhosts, params, files)? If yes, keep enumerating. If I have truly exhausted it, go deep on the most likely weakness and build the exploit.
    • Yes: go to step 2.
  2. Am I root / SYSTEM on this host?
    • No: run local enumeration (the privesc notes). Look for the one thing that is misconfigured.
    • Yes: go to step 3.
  3. Have I looted this host fully (creds, keys, configs, history, other users’ files)?
    • No: loot it. Everything here is fuel for the next host.
    • Yes: go to step 4.
  4. Are there other hosts or networks I can now reach?
    • Yes: pivot, and run the whole loop against the new host.
    • No, and all flags are captured: write the report.

Keep this flow in your head and you will always have a next action.

How the notes fit together

  • Start every box in enumeration/methodology.md.
  • The moment you get execution, jump to foothold/ to stabilize the shell.
  • Then privesc-linux/ or privesc-windows/ depending on the OS.
  • On a domain, active-directory/ becomes the center of gravity.
  • pivoting/ is for when one host is a stepping stone to a network.
  • reporting/ is not optional. Write one for every box. It is the difference between a hobbyist and a pentester.

Where to go deeper

  • 0xdf’s blog. Full box writeups that show the loop above running end to end. Read one, then try to predict each next move before you scroll.
  • IppSec’s videos. Watch the decision-making in real time, especially how he backs up and re-enumerates when a path dead-ends.
  • HackTricks. The reference you keep open for the detail of any specific service or technique.
  • The HTB Academy Penetration Tester path. The structured version of everything above.