📓 Jorkle's Notes

      • Breached Credentials Cheatsheet
      • directory-traversal
      • DNS Enumeration Cheatsheet
      • Internal Network Initial Access Cheatsheet
      • Linux Privilege Escalation Cheatsheet
      • People OSINT Cheatsheet
      • PowerView Cheatsheet
      • Search Engine OSINT Cheatsheet
      • SMB Enumeration Cheatsheet
      • ASREP Roasting
      • CONCEPT - What is DSRM?
      • Kerberos Authentication
      • kerberos-delegation
      • SCCM Knowledge for Pentesting Interviews
      • SCCM/MECM Basics
      • What is a Golden Ticket Attack?
              • WiFi (DoS) Deauthentication Attack
        • Foundations
        • IntelTechniques Search Tools
        • Am I Inside of a Docker Container?
        • ASREP Roasting
        • ASREQ-Roasting
        • Coercion to ADCS ESC8 Compromise
        • constrained-delegation
        • DCSYNC with SafetyKatz
        • Diamond Ticket
        • Discover Birthdays
        • Discover SMB Shares remotely
        • Discover Systems Recently Accessed By Compromised Machine
        • Download File With LOLBAS
        • Dump and Crack Kerberos Keys
        • Dump and Crack Kerberos Keys
        • Dump Domain Cached Credentials
        • Dump Google Chrome Passwords
        • Dump LSA Secrets
        • Dump LSASS Logon Passwords
        • Dump NTDS.dit
        • Dump PXE Passwords from Windows (No PXE Password Protection)
        • Dump SAM Database
        • Dump SAM Database from VM Virtual Hard Disk (VHD/VMDK)
        • Dump Windows Credential Manager
        • Enumerate Domain Shares
        • Enumerate OS Name and Version on Linux
        • Enumerate SCCM (MECM) using LDAP
        • Enumerate SMB Version
        • Enumerate Users and Groups via SMB
        • Enumerate Users using Kerberos
        • Enumerate Users With Kerberos PREAUTH Not Enabled
        • Enumerate Windows Firewall Configuration
        • Fetch Powershell History
        • Find Annual Company Reports
        • Find Company Information using CrunchBase
        • Find Interesting Files on Linux
        • Gather Company Email Addresses
        • Golden Ticket
        • Host Discovery
        • How to use PSRemoting with Enter-PSSession
        • Identify Domain Controllers
        • Identify if SCCM (MECM) is Present
        • Internal Port Scanning
        • kerberoasting
        • Kerberos Unconstrained Delegation
        • Load Powershell Scripts and Modules
        • Logon Script Persistence
        • mitm6-poisoning
        • Null/Anon & Guest SMB Auth
        • Obfuscate Powershell Scripts and Modules
        • Organization OSINT via SEC.GOV Edgar Filings
        • Over Pass The Hash
        • Persistence using DSRM Password
        • run-and-run-once-persistence
        • SCCM Computer Account SMB Relay Coercion to MSSQL Server Admi
        • Scheduled Task (Elevated) Persistence
        • Scheduled Task (Non Elevated) Persistence
        • Silver Ticket
        • Skeleton Key
        • SMB Relaying
        • Time Roasting
        • Windows Service Elevated Persistence
    Home

    ❯

    Techniques

    Techniques

    Dec 15, 20251 min read

    Map of Content

    Scanning & Enumeration

    Port Scanning

    Internal Port Scanning

    Host Discovery

    • Host Discovery

    Docker

    • Am I Inside of a Docker Container

    Windows/Active Directory

    • Fetch PowerShell Command History
    • Enumerate Windows Firewall Configuration
    • Guest SMB Authentication
    • Enumerate SMB Shares
    • Enumerate SMB Version
    • Enumerate Users Using Kerberos
    • Enumerate Users and Groups Using SMB
    • Enumerate Users Without Kerberos Preauth
    • Discover Recently Accessed Systems

    Persistence

    Windows / Active Directory

    Non-Elevated Persistence (Persistence Method Functions Without Elevated Privileges)
    • Scheduled Task
    • Run and Run Once
    • Logon Script
    Elevated Persistence (Persistence Method Requires Elevated Privileges)
    • Golden Ticket Attack
    • Silver Ticket
    • Diamond Ticket Attack
    • Skeleton Key
    • DSRM Password
    • Scheduled Task
    • Windows Service
    • AdminSDHolder
    • CustomSSP

    Initial Access / Gaining Access / Lateral Movement

    Windows / Active Directory

    • ASREP Roasting
    • Kerberoasting
    • MiTM6 Poisoning
    • Anon SMB Auth

    Looting / Post Exploitation

    Windows / Active Directory

    • DCSync Attack
    • Dump Windows Credential Manager
    • Dump SAM Database
    • Dump NTDS.dit
    • Dump LSASS Logon Passwords
    • Dump LSA Secrets
    • Dump Chrome Passwords
    • Dump Cached Domain Credentials
    • Dump And Crack Kerberos Keys With
    • Download Files LOLBAS

    Recon / OSINT

    Organizational Recon/OSINT

    • Gather Company Email Addresses
    • Find Company Information Using Crunchbase
    • Find Annual Company Reports

    People Recon/OSINT

    • Discover Birthdays

    Graph View

    • Map of Content
    • Scanning & Enumeration
    • Persistence
    • Initial Access / Gaining Access / Lateral Movement
    • Looting / Post Exploitation
    • Recon / OSINT
    • Organizational Recon/OSINT
    • People Recon/OSINT

    Backlinks

    • Jorkle Notes - Home
    • Blog
    • Contact
    • Gitrub
    • Linkedin