OPSECTLAS you are here: Essentials
Essentials

Red Team Lifecycle

reference

  1. Recon
  2. Enumerate
  3. Foothold
  4. PrivEsc
  5. Lateral
  6. Post-Ex
  1. 1
    RECONNAISSANCE
    • Passive: OSINT, WHOIS, Shodan, LinkedIn, DNS records, Google dorks
    • Active: DNS zone transfer, subdomain brute-force, email harvesting
    done whenYou have a target IP list, open ports picture, tech stack guesses
  2. 2
    SCANNING
    • Full TCP port scan, UDP top ports, service version detection, OS guessing
    done whenEvery open port is identified with service + version
  3. 3
    ENUMERATION
    • Deep-dive every service: banner grab, anonymous access, known misconfigs
    done whenYou have usernames, shares, software versions, web directories
  4. 4
    EXPLOITATION
    • Leverage findings: known CVEs, misconfigs, weak creds, injection points
    done whenYou have a shell (even low-priv) on the target
  5. 5
    PRIVILEGE ESCALATION
    • Linux: sudo, SUID, crons, capabilities, kernel. Windows: tokens, services, registry
    done whenYou are root / NT AUTHORITY\SYSTEM / Domain Admin
  6. 6
    LATERAL MOVEMENT
    • Pivot to other hosts: PTH, PTT, credential reuse, RDP, WinRM, SSH tunneling
    done whenYou've expanded your foothold across the network
  7. 7
    POST-EXPLOITATION
    • Dump creds, map network, maintain access, exfil proof files
    done whenProof files captured, hashes dumped, report artifacts collected
  8. 8
    REPORTING
    • Document: scope, findings, evidence, severity ratings, remediation steps
    done whenClient / examiner has a reproducible, evidence-backed report