โ† Home

Attack-path walkthroughs

End-to-end red-team engagement paths, one stage at a time. Every step is mapped to MITRE ATT&CK (v19.2) and paired with the detection it generates and the control that stops it, with links to the cheat sheets, tools and quizzes that cover the detail.

Knowledge, not weapons. These walkthroughs are conceptual and defensive-aware โ€” they explain and map attack paths for authorized testing and learning, and are not copy-paste playbooks.
5 stages

External web app to an internal foothold

A classic external penetration test: from internet-facing recon, through a web-application flaw, to a web shell and a pivot into the internal network.

External โ†’ internal network Beginner WebExternalPivoting
8 stages

Phishing to Domain Admin

The canonical Active Directory attack path: a phishing foothold on a workstation, escalated through credential theft and Kerberos abuse to full domain dominance.

On-prem Active Directory Intermediate Active DirectoryWindowsPhishing
5 stages

Linux: low-priv shell to root and pivot

You have a low-privilege shell on a Linux host. This path walks enumeration, a privilege-escalation primitive (SUID/sudo/capabilities), credential looting and an onward pivot.

Linux server Intermediate LinuxPrivilege EscalationPost-exploitation
6 stages

Cloud: a leaked key to account takeover

A single leaked access key becomes full control of a cloud tenant: enumerate, escalate IAM privileges, persist, and reach the data โ€” mapped to the MITRE ATT&CK cloud matrix.

Public cloud (IaaS / identity) Intermediate CloudIAMIdentity
5 stages

Kubernetes: exposed workload to cluster-admin

From an exploitable pod, through a container escape and a service-account token, to control of the whole cluster โ€” mapped to the MITRE ATT&CK Containers matrix.

Kubernetes cluster Advanced KubernetesContainersCloud-native
4 stages

AD CS (ESC1) to Domain Admin

A misconfigured Active Directory Certificate Services template lets a low-privileged user enrol a certificate as any account โ€” a fast, quiet path to Domain Admin.

On-prem Active Directory + AD CS Advanced Active DirectoryAD CSCertificates
4 stages

SSRF to cloud account takeover

A server-side request forgery in a cloud-hosted web app reaches the instance metadata service, steals the attached role's credentials, and pivots into the cloud account.

Cloud-hosted web application Intermediate WebCloudSSRF
5 stages

Password spraying to a cloud mailbox

A low-and-slow password spray against a cloud identity provider lands a valid login, defeats weak MFA, and reaches email and cloud roles โ€” an identity-first attack path.

Cloud identity / M365-style tenant Intermediate IdentityCloudMFA
4 stages

Wi-Fi (WPA2) to the internal network

Capturing a WPA2 handshake, cracking the pre-shared key offline, and joining the wireless network turns radio range into an internal foothold.

Corporate WPA2-PSK wireless Intermediate WirelessCredential AccessNetwork
4 stages

SQL injection to remote code execution

A SQL injection flaw exposes the database, then the database's own features โ€” command execution or file write โ€” are leveraged into a shell on the server.

Web application with a SQL back end Intermediate WebSQL injectionExecution
4 stages

OAuth consent phishing to a cloud mailbox

An illicit-consent (OAuth) phish tricks a user into authorising a malicious application, which then reads mail and data through the API โ€” no password and no MFA prompt needed.

Cloud identity / M365-style tenant Intermediate IdentityCloudPhishing