Attack-path walkthroughs
End-to-end red-team engagement paths, one stage at a time. Every step is mapped to MITRE ATT&CK (v19.2) and paired with the detection it generates and the control that stops it, with links to the cheat sheets, tools and quizzes that cover the detail.
External web app to an internal foothold
A classic external penetration test: from internet-facing recon, through a web-application flaw, to a web shell and a pivot into the internal network.
8 stagesPhishing to Domain Admin
The canonical Active Directory attack path: a phishing foothold on a workstation, escalated through credential theft and Kerberos abuse to full domain dominance.
5 stagesLinux: low-priv shell to root and pivot
You have a low-privilege shell on a Linux host. This path walks enumeration, a privilege-escalation primitive (SUID/sudo/capabilities), credential looting and an onward pivot.
6 stagesCloud: a leaked key to account takeover
A single leaked access key becomes full control of a cloud tenant: enumerate, escalate IAM privileges, persist, and reach the data โ mapped to the MITRE ATT&CK cloud matrix.
5 stagesKubernetes: exposed workload to cluster-admin
From an exploitable pod, through a container escape and a service-account token, to control of the whole cluster โ mapped to the MITRE ATT&CK Containers matrix.
4 stagesAD CS (ESC1) to Domain Admin
A misconfigured Active Directory Certificate Services template lets a low-privileged user enrol a certificate as any account โ a fast, quiet path to Domain Admin.
4 stagesSSRF to cloud account takeover
A server-side request forgery in a cloud-hosted web app reaches the instance metadata service, steals the attached role's credentials, and pivots into the cloud account.
5 stagesPassword spraying to a cloud mailbox
A low-and-slow password spray against a cloud identity provider lands a valid login, defeats weak MFA, and reaches email and cloud roles โ an identity-first attack path.
4 stagesWi-Fi (WPA2) to the internal network
Capturing a WPA2 handshake, cracking the pre-shared key offline, and joining the wireless network turns radio range into an internal foothold.
4 stagesSQL injection to remote code execution
A SQL injection flaw exposes the database, then the database's own features โ command execution or file write โ are leveraged into a shell on the server.
4 stagesOAuth consent phishing to a cloud mailbox
An illicit-consent (OAuth) phish tricks a user into authorising a malicious application, which then reads mail and data through the API โ no password and no MFA prompt needed.