General Framework
CPTS Notes
- Start Here
- General Framework
- Enumeration
- Enumeration with Nmap
- Reference
- Port References
- Linux Commands Cheatsheet
Overview
Disclaimer: This workflow took inspiration from many sources, mainly the CPTS course. This is my personal workflow, and intentionally exclude the formal process like pre-engagment & post-engagement in real pentesting. This was designed specifically for HTB-like boxes.
General steps to conquering boxes:
- Read the task carefully.
- Enumerate using
nmap. Read theEnumeration with Nmappage. - Identify running services.
- Enumerate the services further.
- Exploit vulnerable services.
- Get the inital foothold.
- Establish persistence.
- Post-exploitation. These are usually privilege escalation (privsec) or lateral movement.
- Get the flags.
While doing the steps, always draft a writeup (dirty is fine).
What to do with Services?
Once nmap tells you what is open, work each port. Every service has its own enumeration page; the table below is just the map from a port to where to start.
| Port | Service | First thing to try |
|---|---|---|
| 21 | FTP | Anonymous login, then list and pull files. |
| 22 | SSH | Note the version, keep it for later once you have creds. |
| 25 | SMTP | Enumerate users with VRFY / RCPT. |
| 53 | DNS | Zone transfer, hunt for extra hostnames. |
| 80 / 443 | HTTP / HTTPS | The biggest surface. Directory brute, vhosts, read the app. |
| 88 | Kerberos | Active Directory is present. |
| 111 | rpcbind | Lists RPC services, feed into showmount for NFS. |
| 139 / 445 | SMB | List shares, check for null sessions, pull files. |
| 161 (UDP) | SNMP | snmpwalk with public, it leaks a lot. |
| 389 / 636 | LDAP | AD objects, try an anonymous bind. |
| 1433 / 3306 / 5432 | MSSQL / MySQL / PostgreSQL | Weak creds, then read files or run commands. |
| 3389 | RDP | Keep for when you have creds. |
| 5985 / 5986 | WinRM | evil-winrm once you have creds. |
Full list of ports and services on the Port References page.
Rule of thumb: enumerate before you exploit. Most boxes fall to something you missed, not something you lacked.
After the Initial Foothold
A shell is the middle of the box, not the end. Settle in before you escalate.
- Stabilise the shell. Upgrade a raw reverse shell to a proper TTY so arrow keys, tab and
Ctrl-Cwork. - Know where you are.
whoami,id,hostname, and which network the box sits on. - Grab the user flag if it is readable now.
- Enumerate for privilege escalation. Who am I, what can I run, what is scheduled, what is misconfigured.
- Escalate. Get to
rootorSYSTEM. - Grab the root flag.
See the Linux and Windows privilege-escalation pages for the actual checks.
Active Directory Specifics
A domain-joined box is a different game. You are not after one host, you are after the domain.
- Treat every credential as a key to the whole domain, not just the box it came from.
- Enumerate the domain with the creds you have: users, groups, shares, and the trust between them.
- Look for the common paths: Kerberoasting, AS-REP roasting, and weak ACLs.
- Map the domain with BloodHound early. It shows the shortest path to Domain Admin.
AD gets its own series later. This page only says: notice when you are in one, and change your approach.