OSEP: Checklist
Stuck?
Try the following:
Re-use hashes/passwords on all possible machines -> Netexec (former CME)
Password re-use? Very common for offsec
Check local admin account on all possible machines
Check all possible other authentication services
If having any issues with permissions -> klist purge (tickets could be messy)
Keep track of:
All (new) pwned principals (machines/users/groups) -> fully check in Bloodhound
Can't catch shell / no response? Might be very strict ports, try most common:
80
443
8080
Last updated