Personal OSCP study notes covering enumeration, exploitation, privilege escalation, lateral movement, and persistence across Windows and Linux environments.
| # | File | Topics |
|---|---|---|
| 00 | Quick Reference | AD & Windows PrivEsc checklists, recon scripts, multi-target setup, tool delivery, popular port cheat sheets, common issues |
| 01 | AD Enum & BloodHound | Native enumeration, PowerView, LDAP scripts, SPN enum, ACL recon, domain shares, GPP passwords, BloodHound/SharpHound, Cypher queries |
| 02 | AD Authentication Attacks | LSASS dumping, password spraying, AS-REP roasting, Kerberoasting, Silver Ticket, DCSync |
| 03 | AD Lateral Movement & Persistence | WMI, DCOM, WinRM, PsExec, Invoke-RunasCs, Pass-the-Hash, Overpass-the-Hash, Pass-the-Ticket, ACL abuse, Golden Ticket, NTDS.dit extraction |
| 04 | Windows Internals & PowerShell | SIDs, integrity levels, ACEs/DACLs, basic enumeration, file/ACL inspection, scheduled tasks, credential hunting, PowerShell mechanics, file transfer |
| 05 | Windows Privilege Escalation | Service binary hijacking, unquoted paths, DLL hijacking, insecure service permissions, scheduled task abuse, token impersonation (Potatoes), SeBackupPrivilege, SeRestorePrivilege, automation tools |
| 06 | Windows Connection & Sharing | xfreerdp, Evil-WinRM, RunasCs, impacket-psexec/wmiexec, SMB file sharing, Netcat, Kerberos ticket sessions |
| 07 | Linux Privilege Escalation | Enumeration (users, filesystem, network, processes, cron, Samba/Kerberos), SUID/capabilities, sudo abuse, /etc/passwd write, kernel exploits |
| 08 | Password Attacks | Hash identification, Hashcat offline cracking, Hydra online brute-force, credential extraction, KeePass, NTLM (local hash), Net-NTLMv2 (capture/crack/relay), Credential Guard bypass |
| 09 | Database Enum | MySQL, PostgreSQL, MSSQL, Redis, MongoDB, SQLite — connect, enumerate, file read/write, OS code execution, linked servers, NoSQL injection |
| 10 | Pivoting & Port Forwarding | Ligolo-ng (setup, remote forwarding, nested agents), Chisel (HTTP tunneling) |
| 11 | Shells | Netcat, Socat (plain/encrypted/stable), Msfvenom, shell stabilization, Windows reverse shells, PowerShell encoding, Powercat |