• Home
    • Overview
    • 01 · Recon & Target Mapping
    • 02 · Web Attack Surface
    • 03 · Service & Protocol Exploitation
    • 04 · Foothold Consolidation
    • 05 · Privilege Escalation
    • 06 · Pivoting, Tunneling & Lateral Movement
    • 07 · Active Directory Attacks
    • 08 · Enterprise Kill Chain Capstone
    • Overview
    • EDR Evasion
    • C2 & Tradecraft
    • Active Directory
    • Exploit Dev
    • Reverse Engineering
      • Invisible Registry Keys, but Sort of
ssh — [email protected]
Pentesting Handbook Read the blog
AUTHORIZED USE ONLY — all techniques documented here assume a lawful, authorized engagement environment. nothing here is intended for unauthorized access.
Handbook Chapters browse all →
$ ls -la ~/pentest-handbook/
drwxr-xr-x01 Recon & Target Mapping/ Passive OSINT → active scanning → attack surface triage drwxr-xr-x02 Web Attack Surface/ Enumeration, common vulns, exploitation patterns drwxr-xr-x03 Service & Protocol Exploitation/ Non-HTTP services: SMB, FTP, SSH, databases, and more drwxr-xr-x04 Foothold Consolidation/ Stabilising shells, persistence, situational awareness drwxr-xr-x05 Privilege Escalation/ Linux and Windows privesc — enumeration to root/SYSTEM drwxr-xr-x06 Pivoting, Tunneling & Lateral Movement/ Moving through segmented networks drwxr-xr-x07 Active Directory Attacks/ AD enumeration, Kerberos abuse, domain compromise drwxr-xr-x08 Enterprise Kill Chain Capstone/ Full attack chain tying all prior chapters together
Latest Posts browse all →
$ ls -lt ~/blog/
2025-05-17· Invisible Registry Keys, but Sort of Null-byte persistence — invisible to regedit and reg.exe
fishbrain
Red teamer and pentester documenting the learning process.
GitHub LinkedIn