Collection of tips and procedures when pentesting a target or in a red team engagement. Collected through various sources as well as from my own experience, updated with every interesting finding I encounter. This is not a complete engagement plan/walkthough, rather than simple notes.

PTES Cheat Sheet (Penetration Testing Execution Standard)

Reconnaissance

Portscanning

Dorking

OSINT

Asset discovery

Exploitation

Web Application

API testing

SMTP

Active Directory

Password cracking

Red Team

https://attack.mitre.org/

https://www.atomicredteam.io/atomic-red-team

https://github.com/victoni/RedTeam-Tools

https://github.com/vari-sh/RedTeamGrimoire/

Planning

C2

Initial Access

Pivoting

Privilege Escalation

Credential Access

AD Recon

Defense Evasion

Persistence

Lateral Movement

Organizational post-engagement actions

Malware Development

Misc

Wordlists

“Living-Off” Resources

Android Application Pentesting

Useful links

Pentest Book - This book contains a bunch of info, scripts and knowledge used during my pentests, by six2dez

PayloadAllTheThings - A list of useful payloads and bypass' for Web Application Security and Pentest/CTF

Mobile Application Cheatsheet - The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics