Hacking Articles
20.8K subscribers
1.12K photos
165 files
771 links
House of Pentester
Download Telegram
πŸšͺ Nmap for Pentester: Port Status

πŸ”₯ Telegram: https://t.me/hackinarticles

When performing port scanning with Nmap, the results don’t only show open or closed ports. Instead, Nmap classifies ports into different states based on the responses received from the target system or firewall.

⚑️ Port states covered:

🟒 Open
πŸ”΄ Closed
πŸ›‘ Filtered
πŸ“‘ Unfiltered
❓ Open | Filtered
⚠️ Closed | Filtered

🎯 Understanding these states helps pentesters interpret scan results correctly and identify potential attack surfaces during reconnaissance.

πŸ“– Read the full guide:
https://www.hackingarticles.in/nmap-for-pentester-port-status/
πŸ”₯2
πŸ“‘ Nmap for Pentester: Host Discovery

πŸ”₯ Telegram: https://t.me/hackinarticles

Host Discovery is the first step in network reconnaissance. It helps pentesters identify which systems are alive in a network before performing deeper scans like port scanning or service enumeration.

⚑️ Techniques covered:

πŸ“‘ Ping Sweep (-sn)
🀝 TCP SYN Ping (-PS)
πŸ“© TCP ACK Ping (-PA)
πŸ“¨ ICMP Echo Ping (-PE)
πŸ“¦ UDP Ping (-PU)
🌐 IP Protocol Ping (-PO)
πŸ–§ ARP Ping (-PR)
🚫 No Ping Scan (-Pn)

🎯 These techniques help pentesters identify live hosts, bypass firewall restrictions, and improve target discovery during information gathering.

πŸ“– Read the full guide:
https://www.hackingarticles.in/nmap-for-pentester-host-discovery/
❀4
πŸ”΅ Blue Teaming Active Directory: EvenMonitor

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Attackers target AD… defenders must monitor EVERYTHING ⚠️

⚑️ Defense Highlights
πŸ” Monitor AD events & suspicious logins
πŸ“Š Track user/group/permission changes
🚨 Detect privilege escalation & lateral movement
🧠 Identify abnormal behavior patterns
πŸ›‘ Improve visibility across domain

πŸ’‘ Active Directory monitoring = continuous tracking of accounts, permissions & activities to detect threats early

⚠️ Without proper monitoring β†’ attacks stay invisible until domain compromise

πŸ“– Article: https://www.hackingarticles.in/blue-teaming-active-directory-evenmonitor/
❀2
Active Directory Pentesting with BloodyAD 🩸

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

BloodyAD is a powerful Active Directory exploitation tool used to abuse AD permissions (DACLs) for privilege escalation, persistence, and domain compromise. It enables attackers to manipulate objects, reset passwords, and gain full control over the domain.

πŸ“š Techniques Covered in This Guide

βš™οΈ Lab Setup
πŸ”Ž Understanding AD ACL & DACL Abuse
🧠 BloodHound Path Analysis
πŸ” Authentication (Password / Hash / Kerberos)
πŸ‘₯ Add User to Privileged Groups
πŸ”‘ Reset Password & Takeover Accounts
⚑️ GenericAll / GenericWrite Abuse
πŸ›  WriteDACL & WriteOwner Exploitation
πŸ“‘ Resource-Based Constrained Delegation (RBCD)
🐚 Shadow Credentials Attack
🎯 Privilege Escalation to Domain Admin

πŸ“– Article:
https://www.hackingarticles.in/active-directory-penetration-testing-with-bloodyad/
❀2
Active Directory User Enumeration: Complete Guide 🧠

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

User Enumeration is the foundation of every Active Directory attack. It helps attackers map users, privileges, and misconfigurations to identify attack paths.

⚑️ Key Features of User Enumeration
πŸ” Enumerate all domain users (PowerView, pywerview)
🧩 Extract user attributes & group memberships
βš™οΈ Identify privileged & admin accounts
πŸ›‘ Discover SPN users (Kerberoasting targets)
πŸ“‘ Analyze login activity & password metadata

🎯 Enumeration Insights
πŸ’₯ Find Domain Admin & high-value targets
πŸ§ͺ Detect weak password practices
🧬 Identify Kerberoastable accounts
🌐 Discover delegation & ACL misconfigs
⚑️ Map attack paths for privilege escalation

πŸ“– Article: https://www.hackingarticles.in/active-directory-user-enumeration-a-comprehensive-guide/
❀5πŸ‘2
πŸ”΄ NetExec for OSCP & AD Pentesting: Complete Guide

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

NetExec is becoming the go-to tool for Active Directory enumeration, credential attacks & post-exploitation ⚑️

⚑️ What You’ll Learn
πŸ” SMB, LDAP & WinRM enumeration
πŸ”‘ Password spraying & credential validation
🎯 Kerberoasting & AS-REP Roasting
🩸 BloodHound data collection
πŸ“‚ LAPS & shares enumeration
πŸš€ Remote command execution & lateral movement
βš”οΈ AD exploitation techniques for OSCP labs

πŸ’‘ NetExec combines the power of CrackMapExec with modern modules, better performance & streamlined AD operations πŸ”₯

⚠️ One tool can uncover the entire attack surface of Active Directory

πŸ“– Article: https://www.hackingarticles.in/netexec-for-oscp-ad-pentesting/
πŸ‘2