πͺ Nmap for Pentester: Port Status
π₯ Telegram: https://t.me/hackinarticles
When performing port scanning with Nmap, the results donβt only show open or closed ports. Instead, Nmap classifies ports into different states based on the responses received from the target system or firewall.
β‘οΈ Port states covered:
π’ Open
π΄ Closed
π‘ Filtered
π‘ Unfiltered
β Open | Filtered
β οΈ Closed | Filtered
π― Understanding these states helps pentesters interpret scan results correctly and identify potential attack surfaces during reconnaissance.
π Read the full guide:
https://www.hackingarticles.in/nmap-for-pentester-port-status/
π₯ Telegram: https://t.me/hackinarticles
When performing port scanning with Nmap, the results donβt only show open or closed ports. Instead, Nmap classifies ports into different states based on the responses received from the target system or firewall.
β‘οΈ Port states covered:
π’ Open
π΄ Closed
π‘ Filtered
π‘ Unfiltered
β Open | Filtered
β οΈ Closed | Filtered
π― Understanding these states helps pentesters interpret scan results correctly and identify potential attack surfaces during reconnaissance.
π Read the full guide:
https://www.hackingarticles.in/nmap-for-pentester-port-status/
π₯2
π‘ Nmap for Pentester: Host Discovery
π₯ Telegram: https://t.me/hackinarticles
Host Discovery is the first step in network reconnaissance. It helps pentesters identify which systems are alive in a network before performing deeper scans like port scanning or service enumeration.
β‘οΈ Techniques covered:
π‘ Ping Sweep (-sn)
π€ TCP SYN Ping (-PS)
π© TCP ACK Ping (-PA)
π¨ ICMP Echo Ping (-PE)
π¦ UDP Ping (-PU)
π IP Protocol Ping (-PO)
π§ ARP Ping (-PR)
π« No Ping Scan (-Pn)
π― These techniques help pentesters identify live hosts, bypass firewall restrictions, and improve target discovery during information gathering.
π Read the full guide:
https://www.hackingarticles.in/nmap-for-pentester-host-discovery/
π₯ Telegram: https://t.me/hackinarticles
Host Discovery is the first step in network reconnaissance. It helps pentesters identify which systems are alive in a network before performing deeper scans like port scanning or service enumeration.
β‘οΈ Techniques covered:
π‘ Ping Sweep (-sn)
π€ TCP SYN Ping (-PS)
π© TCP ACK Ping (-PA)
π¨ ICMP Echo Ping (-PE)
π¦ UDP Ping (-PU)
π IP Protocol Ping (-PO)
π§ ARP Ping (-PR)
π« No Ping Scan (-Pn)
π― These techniques help pentesters identify live hosts, bypass firewall restrictions, and improve target discovery during information gathering.
π Read the full guide:
https://www.hackingarticles.in/nmap-for-pentester-host-discovery/
β€4
π΅ Blue Teaming Active Directory: EvenMonitor
π₯ Telegram: https://t.me/hackinarticles
β΄οΈ Twitter: https://x.com/hackinarticles
Attackers target ADβ¦ defenders must monitor EVERYTHING β οΈ
β‘οΈ Defense Highlights
π Monitor AD events & suspicious logins
π Track user/group/permission changes
π¨ Detect privilege escalation & lateral movement
π§ Identify abnormal behavior patterns
π‘ Improve visibility across domain
π‘ Active Directory monitoring = continuous tracking of accounts, permissions & activities to detect threats early
β οΈ Without proper monitoring β attacks stay invisible until domain compromise
π Article: https://www.hackingarticles.in/blue-teaming-active-directory-evenmonitor/
π₯ Telegram: https://t.me/hackinarticles
β΄οΈ Twitter: https://x.com/hackinarticles
Attackers target ADβ¦ defenders must monitor EVERYTHING β οΈ
β‘οΈ Defense Highlights
π Monitor AD events & suspicious logins
π Track user/group/permission changes
π¨ Detect privilege escalation & lateral movement
π§ Identify abnormal behavior patterns
π‘ Improve visibility across domain
π‘ Active Directory monitoring = continuous tracking of accounts, permissions & activities to detect threats early
β οΈ Without proper monitoring β attacks stay invisible until domain compromise
π Article: https://www.hackingarticles.in/blue-teaming-active-directory-evenmonitor/
β€2
Active Directory Pentesting with BloodyAD π©Έ
π₯ Telegram: https://t.me/hackinarticles
β΄οΈ Twitter: https://x.com/hackinarticles
BloodyAD is a powerful Active Directory exploitation tool used to abuse AD permissions (DACLs) for privilege escalation, persistence, and domain compromise. It enables attackers to manipulate objects, reset passwords, and gain full control over the domain.
π Techniques Covered in This Guide
βοΈ Lab Setup
π Understanding AD ACL & DACL Abuse
π§ BloodHound Path Analysis
π Authentication (Password / Hash / Kerberos)
π₯ Add User to Privileged Groups
π Reset Password & Takeover Accounts
β‘οΈ GenericAll / GenericWrite Abuse
π WriteDACL & WriteOwner Exploitation
π‘ Resource-Based Constrained Delegation (RBCD)
π Shadow Credentials Attack
π― Privilege Escalation to Domain Admin
π Article:
https://www.hackingarticles.in/active-directory-penetration-testing-with-bloodyad/
π₯ Telegram: https://t.me/hackinarticles
β΄οΈ Twitter: https://x.com/hackinarticles
BloodyAD is a powerful Active Directory exploitation tool used to abuse AD permissions (DACLs) for privilege escalation, persistence, and domain compromise. It enables attackers to manipulate objects, reset passwords, and gain full control over the domain.
π Techniques Covered in This Guide
βοΈ Lab Setup
π Understanding AD ACL & DACL Abuse
π§ BloodHound Path Analysis
π Authentication (Password / Hash / Kerberos)
π₯ Add User to Privileged Groups
π Reset Password & Takeover Accounts
β‘οΈ GenericAll / GenericWrite Abuse
π WriteDACL & WriteOwner Exploitation
π‘ Resource-Based Constrained Delegation (RBCD)
π Shadow Credentials Attack
π― Privilege Escalation to Domain Admin
π Article:
https://www.hackingarticles.in/active-directory-penetration-testing-with-bloodyad/
β€2
Active Directory User Enumeration: Complete Guide π§
π₯ Telegram: https://t.me/hackinarticles
β΄οΈ Twitter: https://x.com/hackinarticles
User Enumeration is the foundation of every Active Directory attack. It helps attackers map users, privileges, and misconfigurations to identify attack paths.
β‘οΈ Key Features of User Enumeration
π Enumerate all domain users (PowerView, pywerview)
π§© Extract user attributes & group memberships
βοΈ Identify privileged & admin accounts
π‘ Discover SPN users (Kerberoasting targets)
π‘ Analyze login activity & password metadata
π― Enumeration Insights
π₯ Find Domain Admin & high-value targets
π§ͺ Detect weak password practices
𧬠Identify Kerberoastable accounts
π Discover delegation & ACL misconfigs
β‘οΈ Map attack paths for privilege escalation
π Article: https://www.hackingarticles.in/active-directory-user-enumeration-a-comprehensive-guide/
π₯ Telegram: https://t.me/hackinarticles
β΄οΈ Twitter: https://x.com/hackinarticles
User Enumeration is the foundation of every Active Directory attack. It helps attackers map users, privileges, and misconfigurations to identify attack paths.
β‘οΈ Key Features of User Enumeration
π Enumerate all domain users (PowerView, pywerview)
π§© Extract user attributes & group memberships
βοΈ Identify privileged & admin accounts
π‘ Discover SPN users (Kerberoasting targets)
π‘ Analyze login activity & password metadata
π― Enumeration Insights
π₯ Find Domain Admin & high-value targets
π§ͺ Detect weak password practices
𧬠Identify Kerberoastable accounts
π Discover delegation & ACL misconfigs
β‘οΈ Map attack paths for privilege escalation
π Article: https://www.hackingarticles.in/active-directory-user-enumeration-a-comprehensive-guide/
β€5π2
π΄ NetExec for OSCP & AD Pentesting: Complete Guide
π₯ Telegram: https://t.me/hackinarticles
β΄οΈ Twitter: https://x.com/hackinarticles
NetExec is becoming the go-to tool for Active Directory enumeration, credential attacks & post-exploitation β‘οΈ
β‘οΈ What Youβll Learn
π SMB, LDAP & WinRM enumeration
π Password spraying & credential validation
π― Kerberoasting & AS-REP Roasting
π©Έ BloodHound data collection
π LAPS & shares enumeration
π Remote command execution & lateral movement
βοΈ AD exploitation techniques for OSCP labs
π‘ NetExec combines the power of CrackMapExec with modern modules, better performance & streamlined AD operations π₯
β οΈ One tool can uncover the entire attack surface of Active Directory
π Article: https://www.hackingarticles.in/netexec-for-oscp-ad-pentesting/
π₯ Telegram: https://t.me/hackinarticles
β΄οΈ Twitter: https://x.com/hackinarticles
NetExec is becoming the go-to tool for Active Directory enumeration, credential attacks & post-exploitation β‘οΈ
β‘οΈ What Youβll Learn
π SMB, LDAP & WinRM enumeration
π Password spraying & credential validation
π― Kerberoasting & AS-REP Roasting
π©Έ BloodHound data collection
π LAPS & shares enumeration
π Remote command execution & lateral movement
βοΈ AD exploitation techniques for OSCP labs
π‘ NetExec combines the power of CrackMapExec with modern modules, better performance & streamlined AD operations π₯
β οΈ One tool can uncover the entire attack surface of Active Directory
π Article: https://www.hackingarticles.in/netexec-for-oscp-ad-pentesting/
π2
Windows Privilege Escalation: Bypass UAC
π₯ Telegram: https://t.me/hackinarticles
β΄οΈ Twitter: https://x.com/hackinarticles
User Account Control (UAC) is designed to prevent unauthorized administrative actions, but attackers often abuse trusted Windows components to bypass UAC and gain elevated privileges without triggering security prompts.
π What Youβll Learn in This Guide
πͺ Understanding User Account Control (UAC)
π Identifying Current Privilege Levels
βοΈ UAC Bypass Techniques & Attack Surface
π» Registry-Based UAC Bypass Methods
π Bypassing UAC with fodhelper.exe
π UAC Bypass Using ComputerDefaults.exe
π Gaining Elevated Shell Access
π Using Metasploit for UAC Bypass
π Verifying High-Integrity Sessions
π§ Understanding Auto-Elevating Windows Binaries
π‘ Detection & Monitoring Strategies
β οΈ UAC Hardening & Mitigation Techniques
π Article:
https://www.hackingarticles.in/windows-privilege-escalation-bypass-uac/
π₯ Telegram: https://t.me/hackinarticles
β΄οΈ Twitter: https://x.com/hackinarticles
User Account Control (UAC) is designed to prevent unauthorized administrative actions, but attackers often abuse trusted Windows components to bypass UAC and gain elevated privileges without triggering security prompts.
π What Youβll Learn in This Guide
πͺ Understanding User Account Control (UAC)
π Identifying Current Privilege Levels
βοΈ UAC Bypass Techniques & Attack Surface
π» Registry-Based UAC Bypass Methods
π Bypassing UAC with fodhelper.exe
π UAC Bypass Using ComputerDefaults.exe
π Gaining Elevated Shell Access
π Using Metasploit for UAC Bypass
π Verifying High-Integrity Sessions
π§ Understanding Auto-Elevating Windows Binaries
π‘ Detection & Monitoring Strategies
β οΈ UAC Hardening & Mitigation Techniques
π Article:
https://www.hackingarticles.in/windows-privilege-escalation-bypass-uac/
π3π₯3
Linux Privilege Escalation Using Misconfigured NFS
π₯ Telegram: https://t.me/hackinarticles
β΄οΈ Twitter: https://x.com/hackinarticles
Misconfigured NFS shares can become a direct path to root access on Linux systems β οΈ
π What You'll Learn in This Guide
π Understanding NFS & Network File Sharing
π Enumerating NFS Exports and Permissions
βοΈ Identifying Dangerous NFS Configurations
π¨ Exploiting no_root_squash Misconfigurations
π Mounting Remote NFS Shares
π Creating and Deploying SUID Binaries
π Gaining Root Access via NFS Abuse
π Privilege Escalation Walkthrough
π§ Enumeration & Post-Exploitation Techniques
π‘ Securing NFS Shares and Permissions
β οΈ Detection & Mitigation Best Practices
π‘ NFS misconfigurations, especially the no_root_squash option, can allow attackers to create privileged files on shared directories and escalate privileges to root on Linux systems.
π Article:
https://www.hackingarticles.in/linux-privilege-escalation-using-misconfigured-nfs/
π₯ Telegram: https://t.me/hackinarticles
β΄οΈ Twitter: https://x.com/hackinarticles
Misconfigured NFS shares can become a direct path to root access on Linux systems β οΈ
π What You'll Learn in This Guide
π Understanding NFS & Network File Sharing
π Enumerating NFS Exports and Permissions
βοΈ Identifying Dangerous NFS Configurations
π¨ Exploiting no_root_squash Misconfigurations
π Mounting Remote NFS Shares
π Creating and Deploying SUID Binaries
π Gaining Root Access via NFS Abuse
π Privilege Escalation Walkthrough
π§ Enumeration & Post-Exploitation Techniques
π‘ Securing NFS Shares and Permissions
β οΈ Detection & Mitigation Best Practices
π‘ NFS misconfigurations, especially the no_root_squash option, can allow attackers to create privileged files on shared directories and escalate privileges to root on Linux systems.
π Article:
https://www.hackingarticles.in/linux-privilege-escalation-using-misconfigured-nfs/