Hacking Articles
23K subscribers
1.36K photos
165 files
971 links
House of Pentester
Download Telegram
🔥 Impacket for Pentester: Atexec

Need remote command execution without creating a service? Atexec leverages Windows Task Scheduler to execute commands remotely, making it a valuable technique for lateral movement assessments in Active Directory environments. ⚠️

📚 In This Guide

Understanding Atexec & Task Scheduler
⚙️ Installing & Configuring Impacket
🔑 Authentication with Passwords, NTLM Hashes & Kerberos
🌐 Remote Command Execution over SMB
📋 Running Single Commands on Remote Hosts
🖥 Interactive Execution Workflows
🎯 Lateral Movement in Active Directory
🔄 Comparing Atexec vs PsExec vs WMIExec
📊 Understanding Windows Scheduled Task Artifacts
🧠 Detection & DFIR Considerations
🛡 Hardening Remote Administration Paths
⚠️ Monitoring Scheduled Task Abuse

💡 Unlike PsExec, Atexec executes commands through the Windows Task Scheduler service instead of creating a temporary service. Understanding how different Impacket execution methods work helps security teams assess, detect, and defend against unauthorized remote administration activity.

📖 Read the Full Guide:
https://www.hackingarticles.in/impacket-for-pentester-atexec/

🔥 Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles
1
🚨 STOP WASTING MONTHS ON RANDOM OSCP TUTORIALS 🚨

Most OSCP students don't fail because they lack tools.

They fail because they lack a METHODOLOGY. 🎯

What actually matters?

🔎 Enumeration
⚡️ Windows & Linux PrivEsc
🏰 Active Directory Attacks
🌐 Web Exploitation
🧠 Pivoting & Tunneling
🔑 Password Attacks
💣 Public Exploit Abuse
📋 Professional Reporting

🔥 OSCP Training — ADMISSIONS OPEN

No endless theory.
No random tutorials.

Hands-on labs
Real-world attack scenarios
OSCP-focused methodology
Beginner → Advanced guidance

⚠️ LIMITED SEATS AVAILABLE

🔗 Register Now:
https://forms.gle/bowpX9TGEs41GDG99

💬 WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

📧 info@ignitetechnologies.in

♻️ RT to help an OSCP aspirant.
3
🚨 STOP WASTING MONTHS ON RANDOM OSCP TUTORIALS 🚨

Most OSCP students don't fail because they lack tools.

They fail because they lack a METHODOLOGY. 🎯

What actually matters?

🔎 Enumeration
⚡️ Windows & Linux PrivEsc
🏰 Active Directory Attacks
🌐 Web Exploitation
🧠 Pivoting & Tunneling
🔑 Password Attacks
💣 Public Exploit Abuse
📋 Professional Reporting

🔥 OSCP Training — ADMISSIONS OPEN

No endless theory.
No random tutorials.

Hands-on labs
Real-world attack scenarios
OSCP-focused methodology
Beginner → Advanced guidance

⚠️ LIMITED SEATS AVAILABLE

🔗 Register Now:
https://forms.gle/bowpX9TGEs41GDG99

💬 WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

📧 info@ignitetechnologies.in

♻️ RT to help an OSCP aspirant.

#OSCP #CyberSecurity #Pentesting #EthicalHacking #ActiveDirectory #RedTeam
🚀 Master Active Directory Penetration Testing — Online Training Now Open!

Active Directory remains the #1 target in enterprise breaches. If you're serious about red teaming or advancing toward OSCP-level skills, this is the deep-dive you've been waiting for.

Ignite Technologies is opening a limited-seat batch for our Active Directory Penetration Training — built for professionals who want to go beyond theory and master real-world attack chains.

✔️ Comprehensive Curriculum:
🔍 Initial Active Directory Exploitation
🔎 Active Directory Post-Enumeration
🔐 Abusing Kerberos
🧰 Advanced Credential Dumping Attacks
📈 Privilege Escalation Techniques
🔄 Persistence Methods
🔀 Lateral Movement Strategies
🛡 DACL Abuse (New)
🏴 ADCS Attacks (New)
💎 Sapphire & Diamond Ticket Attacks (New)
🎁 Bonus Sessions

⚠️ Limited slots available — secure your spot before they're gone.

🔗 Register Here: https://forms.gle/bowpX9TGEs41GDG99

💬 WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

📧 Email: info@ignitetechnologies.in

Whether you're prepping for red team engagements, OSCP, CRTP, or CRTE — this training will sharpen the exact skills hiring managers and engagement leads look for.

Drop a 🔥 in the comments if you're in, or tag someone who needs to level up their AD game.

#CyberSecurity #PenTesting #RedTeam #ActiveDirectory #Kerberos #PrivilegeEscalation
1
🔥 Ethical Hacking Proactive Training – Live & Practical 🔥

Ready to build real-world cybersecurity skills with hands-on experience?

🚀 Ignite Technologies brings you a comprehensive Ethical Hacking Proactive Training Program designed with live sessions and core practical exposure — at an affordable price.

🔗 Register Now:
https://forms.gle/bowpX9TGEs41GDG99

💬 WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

📧 Email:
info@ignitetechnologies.in

🎯 Book Your Demo Session Today!

📘 What You’ll Learn:

Introduction to Ethical Hacking
Old School Learning Methodology
Networking Fundamentals
Reconnaissance (Footprinting, Scanning & Enumeration)
System Hacking
Post Exploitation & Persistence
Web Server Penetration Testing
Website Hacking Techniques
Malware Threats & Analysis
Wireless Network Security
Cryptography & Steganography
Sniffing Attacks
Denial of Service (DoS)
Evading IDS, Firewalls & Honeypots
Social Engineering Techniques
Mobile Platform Security

💡 Whether you're a beginner or looking to strengthen your penetration testing skills, this training is structured to provide practical knowledge aligned with real-world attack scenarios.

Limited seats available. Secure yours now.

#CyberSecurity #EthicalHacking #Infosec #PenetrationTesting #RedTeam #NetworkSecurity #BugBounty #CyberSecurityTraining #InformationSecurity #TechCareers
👍2
Comprehensive Guide on Autopsy Tool (Windows)

📲 Telegram: https://t.me/hackinarticles

Learn how to perform digital forensic investigation using the Autopsy tool to analyze disk images and recover critical evidence. 🕵️‍♂️💻

💡 Key Takeaways:
🗂 Creating & Managing Cases
💾 Adding Data Sources
🔍 File Type & MIME Analysis
🗑 Deleted File Recovery
📊 Timeline & Keyword Search
📑 Forensic Report Generation

📖 Full Guide:
https://www.hackingarticles.in/comprehensive-guide-on-autopsy-tool-windows/
Comprehensive Guide on FTK Imager

🔥 Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Learn how to use FTK Imager for digital forensic investigations to acquire and analyze disk evidence safely. 🔍💻

💡 Key Takeaways:
💾 Creating Forensic Disk Images
🧠 Capturing Volatile Memory
📂 Evidence & Image Analysis
🔗 Mounting Images as Drives
🔐 AD Encryption & Decryption
📤 Exporting Evidence Files

📖 Full Guide:
https://www.hackingarticles.in/comprehensive-guide-on-ftk-imager/
2
Memory Forensics Using Volatility Framework

🔥 Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Discover how investigators analyze RAM memory dumps to uncover hidden processes, credentials, and malicious activity during forensic investigations. 🕵️‍♂️💻

💡 Key Takeaways:
🧠 Memory Acquisition Basics
📦 Supported Memory Dump Formats
🔍 Image Profile Identification
⚙️ Volatility Plugins & Commands
🧾 Process & Network Artifact Analysis
🔐 Credential & Registry Extraction

📖 Full Guide:
https://www.hackingarticles.in/memory-forensics-using-volatility-framework/
1
🚨 STOP WASTING MONTHS ON RANDOM OSCP TUTORIALS 🚨

Most OSCP students don't fail because they lack tools.

They fail because they lack a METHODOLOGY. 🎯

What actually matters?

🔎 Enumeration
⚡️ Windows & Linux PrivEsc
🏰 Active Directory Attacks
🌐 Web Exploitation
🧠 Pivoting & Tunneling
🔑 Password Attacks
💣 Public Exploit Abuse
📋 Professional Reporting

🔥 OSCP Training — ADMISSIONS OPEN

No endless theory.
No random tutorials.

Hands-on labs
Real-world attack scenarios
OSCP-focused methodology
Beginner → Advanced guidance

⚠️ LIMITED SEATS AVAILABLE

🔗 Register Now:
https://forms.gle/bowpX9TGEs41GDG99

💬 WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

📧 info@ignitetechnologies.in

♻️ RT to help an OSCP aspirant.
1
Scheduled Tasks + SMB = Remote Command Execution. 👀

🔥 Impacket for Pentester: Atexec

Need remote command execution without creating a service? Atexec leverages Windows Task Scheduler to execute commands remotely, making it a valuable technique for lateral movement assessments in Active Directory environments. ⚠️

📚 In This Guide

Understanding Atexec & Task Scheduler
⚙️ Installing & Configuring Impacket
🔑 Authentication with Passwords, NTLM Hashes & Kerberos
🌐 Remote Command Execution over SMB
📋 Running Single Commands on Remote Hosts
🖥 Interactive Execution Workflows
🎯 Lateral Movement in Active Directory
🔄 Comparing Atexec vs PsExec vs WMIExec
📊 Understanding Windows Scheduled Task Artifacts
🧠 Detection & DFIR Considerations
🛡 Hardening Remote Administration Paths
⚠️ Monitoring Scheduled Task Abuse

💡 Unlike PsExec, Atexec executes commands through the Windows Task Scheduler service instead of creating a temporary service. Understanding how different Impacket execution methods work helps security teams assess, detect, and defend against unauthorized remote administration activity.

📖 Read the Full Guide:
https://www.hackingarticles.in/impacket-for-pentester-atexec/

🔥 Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles
3
Stop memorizing hundreds of pentesting commands. Let AI do it for you. 👀

🔥 Arsenal-NG: The Ultimate Pentest Cheat Sheet

From enumeration to exploitation, Arsenal-NG generates commands on demand, helping security professionals save time during assessments. ⚠️

📚 In This Guide

🤖 Introduction to Arsenal-NG
⚙️ Installing Arsenal-NG
🔍 Generating Reconnaissance Commands
🌐 Network Enumeration Made Easy
🛠 Web Application Testing Commands
🎯 Active Directory Assessment Workflows
🔑 Credential Attack Command Generation
📡 Service Enumeration Techniques
🐧 Linux & Windows Pentesting Commands
🚀 Red Team & Post-Exploitation Use Cases
🧠 AI-Assisted Command Generation
📋 Practical Pentesting Cheat Sheet Examples

💡 Why remember every Nmap, NetExec, CrackMapExec, Impacket, BloodHound, or Metasploit command when you can generate them instantly? Arsenal-NG acts as a smart command assistant, helping pentesters quickly find the right syntax and workflow during authorized security assessments.

📖 Read the Full Guide:
https://www.hackingarticles.in/arsenal-ng-pentest-cheat-sheet/

🔥 Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles
1
Still using only net user and ldapsearch for AD enumeration? You're missing the attack paths. 👀

🔥 Active Directory Enumeration with BloodHound Python

BloodHound Python transforms raw Active Directory data into a visual attack graph, helping security teams identify privilege escalation paths, dangerous permissions, and hidden relationships. ⚠️

📚 In This Guide

🐍 Introduction to BloodHound Python
⚙️ Installing BloodHound & Dependencies
🌐 LDAP-Based Data Collection from Kali Linux
🔍 Enumerating Users, Groups & Computers
👥 Mapping Active Directory Relationships
🩸 Collecting Data with BloodHound Python
📊 Importing Results into BloodHound CE
🎯 Finding Paths to Domain Admin
🔑 Identifying DCSync Privileges
🚀 Discovering Kerberoastable & AS-REP Roastable Accounts
🛠 Analyzing ACL Abuse Paths
🧠 Prioritizing High-Value Targets
🛡 Detection & Defensive Insights

💡 Attackers don't compromise domains by guessing.

They follow relationships, permissions, delegated rights, and trust paths. BloodHound turns thousands of AD objects into a visual roadmap that helps uncover the shortest path to privilege escalation.

📖 Read the Full Guide:
https://www.hackingarticles.in/active-directory-enumeration-with-bloodhound-python/

🔥 Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles
2
💰 Companies paid out over $300M in bug bounties last year — and the demand is only growing.

From Google to the Pentagon, ethical hackers are getting rewarded for finding what others miss. But here's the truth: most aspiring bounty hunters fail not because they lack curiosity — they lack a structured roadmap.

🎯 Ignite Technologies presents: Bug Bounty Training Program (Online)

A hands-on, exclusive program built for beginners and intermediates ready to break into bug bounty hunting and ethical hacking — the right way.

🔥 What you'll master:
✔️ Introduction to WAPT & OWASP Top 10
✔️ Pentest Lab Setup
✔️ Information Gathering & Reconnaissance
✔️ Netcat for Pentesters
✔️ Configuration Management Testing
✔️ Cryptography
✔️ Authentication Attacks
✔️ Session Management Exploitation
✔️ Local File Inclusion (LFI)
✔️ Remote File Inclusion (RFI)
✔️ Path Traversal
✔️ OS Command Injection
✔️ Open Redirect
✔️ Unrestricted File Upload
✔️ PHP Web Shells
✔️ HTML Injection
✔️ Cross-Site Scripting (XSS)
✔️ Client-Side Request Forgery (CSRF)
✔️ SQL Injection
✔️ XXE Injection
✔️ Bonus Section 🎁

💡 Why this matters: Bug bounty isn't just about tools — it's about thinking like an attacker. This program walks you through the OWASP Top 10 and beyond, with real exploitation techniques you can apply on live programs (HackerOne, Bugcrowd, Intigriti).

📅 Limited seats. Enroll today.

🔗 Register: https://forms.gle/bowpX9TGEs41GDG99

💬 WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

📧 Email: info@ignitetechnologies.in

👉 Tag someone who's been talking about getting into bug bounty.
💬 Drop a comment: What's the first vulnerability you ever found?
♻️ Repost to help an aspiring hacker in your network.
👏1
🔥 Ethical Hacking Proactive Training – Live & Practical 🔥

Ready to build real-world cybersecurity skills with hands-on experience?

🚀 Ignite Technologies brings you a comprehensive Ethical Hacking Proactive Training Program designed with live sessions and core practical exposure — at an affordable price.

🔗 Register Now:
https://forms.gle/bowpX9TGEs41GDG99

💬 WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

📧 Email:
info@ignitetechnologies.in

🎯 Book Your Demo Session Today!

📘 What You’ll Learn:

Introduction to Ethical Hacking
Old School Learning Methodology
Networking Fundamentals
Reconnaissance (Footprinting, Scanning & Enumeration)
System Hacking
Post Exploitation & Persistence
Web Server Penetration Testing
Website Hacking Techniques
Malware Threats & Analysis
Wireless Network Security
Cryptography & Steganography
Sniffing Attacks
Denial of Service (DoS)
Evading IDS, Firewalls & Honeypots
Social Engineering Techniques
Mobile Platform Security

💡 Whether you're a beginner or looking to strengthen your penetration testing skills, this training is structured to provide practical knowledge aligned with real-world attack scenarios.

Limited seats available. Secure yours now.
Tcpdump Cheat Sheet for Pentesters

🔥 Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Tcpdump is a powerful command-line packet analyzer used to capture and inspect network traffic. It is widely used for network troubleshooting, packet analysis, and security monitoring on Linux systems. ()

⚡️ Useful Tcpdump Commands

📡 tcpdump -i eth0
🔎 tcpdump host 192.168.1.1
🌐 tcpdump port 80
📂 tcpdump -w capture.pcap
📖 tcpdump -r capture.pcap
🧠 tcpdump -i eth0 tcp
📊 tcpdump -n -vv
🔐 tcpdump icmp
📍 tcpdump src 192.168.1.5
📍 tcpdump dst 192.168.1.5

🧠 Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Tcpdump
SSH Port Forwarding & Tunnelling

🔥 Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

SSH tunnelling allows secure communication by forwarding traffic through an encrypted channel, enabling access to internal services and bypassing network restrictions.

⚡️ Key Highlights
🔐 Encrypted communication over SSH
🔁 Port forwarding (local, remote, dynamic)
🌐 Access internal services behind firewall
🚀 Secure data transfer over untrusted networks

⚡️ Types of Forwarding
📍 Local Port Forwarding
🌍 Remote Port Forwarding
🧠 Dynamic Port Forwarding (SOCKS proxy)

💡 SSH tunneling redirects traffic from one port to another through a secure channel, allowing systems to communicate safely even across restricted networks.

📖 Article: https://www.hackingarticles.in/a-detailed-guide-on-ssh-port-forwarding-tunnelling/
Network Pivoting: Ligolo-MP Complete Guide

🔥 Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Network pivoting allows attackers to move deeper into internal networks using a compromised machine as a bridge to access hidden systems and services.

⚡️ Key Highlights
🔗 Pivot into internal networks
🌐 Access hidden subnets & services
🔄 Route traffic through compromised host
🚀 Perform lateral movement & internal recon

⚡️ Ligolo-MP Advantages
🧠 VPN-like tunneling (TUN interface)
🔐 Encrypted communication (mTLS)
⚡️ Multiple concurrent tunnels
🧑‍🤝‍🧑 Multiplayer pivoting support
📡 No need for SOCKS/port forwarding

💡 Ligolo-MP creates a tunnel that makes your attacker machine behave as if it is inside the target network, enabling tools like Nmap to scan internal systems directly.

📖 Article: https://www.hackingarticles.in/network-pivoting-using-ligolo-mp-complete-guide/
2
🚨 STOP WASTING MONTHS ON RANDOM OSCP TUTORIALS 🚨

Most OSCP students don't fail because they lack tools.

They fail because they lack a METHODOLOGY. 🎯

What actually matters?

🔎 Enumeration
⚡️ Windows & Linux PrivEsc
🏰 Active Directory Attacks
🌐 Web Exploitation
🧠 Pivoting & Tunneling
🔑 Password Attacks
💣 Public Exploit Abuse
📋 Professional Reporting

🔥 OSCP Training — ADMISSIONS OPEN

No endless theory.
No random tutorials.

Hands-on labs
Real-world attack scenarios
OSCP-focused methodology
Beginner → Advanced guidance

⚠️ LIMITED SEATS AVAILABLE

🔗 Register Now:
https://forms.gle/bowpX9TGEs41GDG99

💬 WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

📧 info@ignitetechnologies.in

♻️ RT to help an OSCP aspirant.
💰 Companies paid out over $300M in bug bounties last year — and the demand is only growing.

From Google to the Pentagon, ethical hackers are getting rewarded for finding what others miss. But here's the truth: most aspiring bounty hunters fail not because they lack curiosity — they lack a structured roadmap.

🎯 Ignite Technologies presents: Bug Bounty Training Program (Online)

A hands-on, exclusive program built for beginners and intermediates ready to break into bug bounty hunting and ethical hacking — the right way.

🔥 What you'll master:
✔️ Introduction to WAPT & OWASP Top 10
✔️ Pentest Lab Setup
✔️ Information Gathering & Reconnaissance
✔️ Netcat for Pentesters
✔️ Configuration Management Testing
✔️ Cryptography
✔️ Authentication Attacks
✔️ Session Management Exploitation
✔️ Local File Inclusion (LFI)
✔️ Remote File Inclusion (RFI)
✔️ Path Traversal
✔️ OS Command Injection
✔️ Open Redirect
✔️ Unrestricted File Upload
✔️ PHP Web Shells
✔️ HTML Injection
✔️ Cross-Site Scripting (XSS)
✔️ Client-Side Request Forgery (CSRF)
✔️ SQL Injection
✔️ XXE Injection
✔️ Bonus Section 🎁

💡 Why this matters: Bug bounty isn't just about tools — it's about thinking like an attacker. This program walks you through the OWASP Top 10 and beyond, with real exploitation techniques you can apply on live programs (HackerOne, Bugcrowd, Intigriti).

📅 Limited seats. Enroll today.

🔗 Register: https://forms.gle/bowpX9TGEs41GDG99

💬 WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

📧 Email: info@ignitetechnologies.in

👉 Tag someone who's been talking about getting into bug bounty.
💬 Drop a comment: What's the first vulnerability you ever found?
♻️ Repost to help an aspiring hacker in your network.
3
🚨 STOP WASTING MONTHS ON RANDOM OSCP TUTORIALS 🚨

Most OSCP students don't fail because they lack tools.

They fail because they lack a METHODOLOGY. 🎯

What actually matters?

🔎 Enumeration
⚡️ Windows & Linux PrivEsc
🏰 Active Directory Attacks
🌐 Web Exploitation
🧠 Pivoting & Tunneling
🔑 Password Attacks
💣 Public Exploit Abuse
📋 Professional Reporting

🔥 OSCP Training — ADMISSIONS OPEN

No endless theory.
No random tutorials.

Hands-on labs
Real-world attack scenarios
OSCP-focused methodology
Beginner → Advanced guidance

⚠️ LIMITED SEATS AVAILABLE

🔗 Register Now:
https://forms.gle/bowpX9TGEs41GDG99

💬 WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

📧 info@ignitetechnologies.in

♻️ RT to help an OSCP aspirant.

#OSCP #CyberSecurity #Pentesting #EthicalHacking #ActiveDirectory #RedTeam
1