OffSec Notes
All Gitbook
OSEP
OSEP
  • Useful
  • Attack
    • Client Side Code Execution
      • Powershell rev.ps1
      • Window Script Host Jscript.js
      • In-Memory Reflective Load (.dll + .ps1)
      • HTML Smuggling: Auto Download
    • Evasions
      • C# Process Injection
      • C# DLL Injection
      • Process Hollowing
        • For In-Memory Reflective Load
      • VBA AV Bypass
        • Powershell Inside VBA
      • AMSI Bypass
        • FodHelper UAC Bypass
        • JScript
      • Application Whitelisting Bypass
        • PowerShell Language Mode
        • AppLocker Bypass with C#
        • AppLocker Bypass with JScript
    • MS SQL
      • Escalation
        • SQL
      • Linked SQL Servers
    • Kiosk Breakout
    • Active Directory
      • Bloodhound
      • Forest
      • Just Enough Administration (JEA)
      • Just-In-Time (JIT) Access
  • Post-Exploitation
    • Windows Credentials
      • Local Administrator Password Solution (LAPS)
      • Serivce Account Access Token
      • Mimikatz Abusing Kerberos
    • Linux
      • AV Bypass
      • Shared Library Hijacking
      • Shellcode
  • Network
    • Bypass Network Filters
      • Domain Fronting
      • DNS Tunneling
    • Windows Lateral Movement
      • Metasploit Tunneling
      • Chisel
    • Linux Lateral Movement
      • SSH
      • Ansible
      • Artifactory
      • Kerberos
    • Ligolo
  • Checklist / Flow
Powered by GitBook