Click Study Flashcards above to open the flashcard hub — hundreds of PenTest+ cards you can flip, match, type, or quiz yourself on. Every card is drawn from the five official PT0-003 domains, so you study exactly what the exam tests.[2]
Pair them with our free practice test and study guide. Want extra insurance for exam day? Capital Prep’s PenTest+ premium study materials come with a PenTest+ exam pass guarantee: your money back if you don’t pass, plus up to $439 toward your retake fee — and Career Employer students get a special discount.
CompTIA PenTest+ is one of the 14 CompTIA certifications — explore our CompTIA flashcards to compare and prep across the whole family.
PenTest+ Flashcard Study Modes
Flip mode lets you move through one card at a time and check yourself. Match is a timed game that pairs terms with their definitions. Type shows you the definition and asks you to write the term back, so a card like msfvenom has to come from memory. Quiz turns the same cards into multiple choice.

Why Flashcards Work for PenTest+
Attacks & Exploits is the largest section at 96 cards and carries 35% of the exam, so it sets the tone for the whole deck. The cards drill attack tooling, technique names, and the vocabulary that surrounds them, including Nmap, Hashcat, and msfvenom, along with foundational terms like Exploit, Payload, Phishing, BeEF, and Netcat.
Reconnaissance & Enumeration holds 51 cards against a 21% weight. These fronts cover passive and active information gathering, the data sources testers lean on, and the utilities that collect it. Expect terms such as OSINT, WHOIS, and Shodan, plus discovery and capture tools like Amass, Censys, Maltego, Masscan, and tcpdump.
Vulnerability Discovery & Analysis is 41 cards for 17% of the exam. The terms here run from classification systems to scanners and testing methods, so you get CVE and CWE next to Nessus, Nikto, WPScan, and Wapiti, with technique cards like Fuzzing and sqlmap rounding out the set.
Post-exploitation & Lateral Movement brings 54 cards for a 14% weight. The cards drill what happens after access, covering credential and mapping tools such as Mimikatz, BloodHound, and DCSync, movement techniques like Pivoting, PsExec, and ProxyChains, and stage vocabulary including Foothold and Persistence.
Engagement Management closes the deck with 48 cards for 13%. These fronts deal with methodology, standards, and the working relationship with the client, so you will see PTES, OSSTMM, NIST SP 800-115, OWASP, and MITRE ATT&CK alongside engagement terms like Deconfliction, Purple team, and Gray-box testing.
PenTest+ is dense with tools and techniques — Nmap flags, Metasploit, Burp Suite, attack types, cryptography, and the commands you must apply in the performance-based questions.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
PenTest+ Flashcards by Domain
The cards are organized by the five official PT0-003 domains. Drill the highest-weighted ones first — Attacks & Exploits and Reconnaissance & Enumeration make up over half the exam:[2]
| Domain | Exam weight |
|---|---|
| Attacks & Exploits | 35% |
| Reconnaissance & Enumeration | 21% |
| Vulnerability Discovery & Analysis | 17% |
| Post-exploitation & Lateral Movement | 14% |
| Engagement Management | 13% |
How to Get the Most Out of These Flashcards
- Start with Attacks & Exploits. It is 96 cards and 35% of the exam, so time spent there moves your score more than any other single domain.
- Type-drill the tool names. Fronts like msfvenom and DCSync are easy to recognize on sight but hard to produce from memory, which is exactly what Type mode exposes.
- Use Match for the framework cards. Standards and methodology names in Engagement Management, such as PTES and NIST SP 800-115, blur together fast, and timed pairing forces the distinctions.
- Move to the practice test once Quiz stops surprising you. When a domain’s cards come back clean in Quiz mode, switch to full-length questions and the study guide for scenario practice.
- Keep a steady cadence across 290 cards. Work one domain per session, revisit the previous session’s weakest fronts first, and rotate so Reconnaissance & Enumeration never goes cold.
PenTest+ Flashcards FAQ
Hundreds of free PenTest+ flashcards, organized across all five PT0-003 domains — Engagement Management, Reconnaissance & Enumeration, Vulnerability Discovery & Analysis, Attacks & Exploits, and Post-exploitation & Lateral Movement. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions. PenTest+ references more than 80 tools and over 100 attacks and techniques, and flashcards are the most efficient way to drill which tool and technique fits which job.
All five PT0-003 domains: Engagement Management (scoping, RoE, reporting), Reconnaissance & Enumeration (OSINT, scanning, Nmap), Vulnerability Discovery & Analysis (scanners, CVSS, validation), Attacks & Exploits (network, web, wireless, cloud, social engineering, tools), and Post-exploitation & Lateral Movement (privilege escalation, persistence, pivoting).
Lead with the highest-weighted domain — Attacks & Exploits (35%) — then Reconnaissance & Enumeration (21%), which together are over half the exam. Mix the modes: flip to learn, type to test recall, match for speed, and quiz to check yourself before a full practice test.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to CompTIA's current PT0-003 exam objectives, covering all five scored domains in their official proportions, with heavy coverage of the tools and attacks PT0-003 emphasizes.
PenTest+ flashcard bank
All 290 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Engagement Management (48)
- Rules of Engagement (RoE)
Show answerHide answer
The agreed document that defines what testers may do — scope, timing, targets, allowed techniques, and escalation/communication paths — keeping the test legal and controlled.
- Scope (penetration test)
Show answerHide answer
The explicit boundary of an engagement: which IP ranges, domains, applications, and facilities are in or out of bounds. Testing outside scope can be illegal.
- Statement of Work (SOW)
Show answerHide answer
The contract section defining the deliverables, timeline, and tasks of the engagement — the formal description of work to be performed.
- Master Service Agreement (MSA)
Show answerHide answer
An overarching contract setting the general terms and conditions for an ongoing relationship; individual engagements are governed by SOWs under it.
- Non-Disclosure Agreement (NDA)
Show answerHide answer
A legal agreement that binds the tester to keep client data, findings, and vulnerabilities confidential.
- Authorization / 'get-out-of-jail' letter
Show answerHide answer
Written, signed permission from someone with authority over the target, proving the testing is authorized. Without it, the activity is unauthorized access (a crime).
- Black-box testing
Show answerHide answer
An unknown-environment test: the tester is given no prior internal information and must discover everything, simulating an external attacker.
- White-box testing
Show answerHide answer
A known-environment test: the tester is given full information (source, architecture, credentials) for the most thorough, efficient assessment.
- Gray-box testing
Show answerHide answer
A partially-known test: the tester is given limited information (e.g., a standard user account), balancing realism and coverage.
- Goal of a penetration test report
Show answerHide answer
To clearly communicate findings, risk, and prioritized remediation to the client — including an executive summary, methodology, evidence, and actionable recommendations.
- Executive summary (report)
Show answerHide answer
A non-technical, business-focused overview of the engagement's key risks and recommendations, written for leadership who won't read the technical detail.
- Communication plan / escalation path
Show answerHide answer
The agreed channels and triggers for contacting the client during a test — e.g., who to call immediately if a critical vulnerability or a system outage is found.
- Stop point / safe word
Show answerHide answer
A pre-agreed condition or signal that halts testing immediately — e.g., on detecting illegal content, evidence of a real breach, or production impact.
- Risk appetite / acceptance (scoping)
Show answerHide answer
How much disruption and risk the client will tolerate during testing; it shapes allowed techniques (e.g., whether DoS or social engineering is permitted).
- Remediation recommendation
Show answerHide answer
The actionable fix a report gives for each finding (patch, configuration change, control), prioritized by the risk the vulnerability presents.
- CVSS (Common Vulnerability Scoring System)
Show answerHide answer
A 0.0–10.0 open standard for rating vulnerability severity (None/Low/Medium/High/Critical), used to prioritize findings in a report. Maintained by FIRST.
- Compliance-based assessment
Show answerHide answer
A test driven by a standard or regulation (e.g., PCI DSS, HIPAA) where the scope and required checks are dictated by the framework, not just the client.
- Why third-party permission matters
Show answerHide answer
Cloud and hosted assets may be owned by a provider (AWS, Azure); the client cannot authorize testing of infrastructure it does not own, so provider rules/permission are required.
- PTES
Show answerHide answer
Penetration Testing Execution Standard — a methodology defining 7 phases: pre-engagement, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting.
- OSSTMM
Show answerHide answer
Open Source Security Testing Methodology Manual — a peer-reviewed methodology for repeatable, metric-based security testing.
- NIST SP 800-115
Show answerHide answer
NIST's Technical Guide to Information Security Testing and Assessment — defines planning, discovery, attack, and reporting phases for security assessments.
- MITRE ATT&CK
Show answerHide answer
A globally available knowledge base of real-world adversary tactics and techniques, used to model attacks and map findings to attacker behavior.
- OWASP
Show answerHide answer
Open Worldwide Application Security Project — a nonprofit producing the OWASP Top 10, the Web Security Testing Guide, and tools like ZAP for web app security.
- Bug bounty program
Show answerHide answer
An ongoing program (often public) that pays external researchers for responsibly disclosed vulnerabilities, within defined scope and rules.
- Responsible / coordinated disclosure
Show answerHide answer
Reporting a discovered vulnerability privately to the vendor and giving them time to fix it before any public disclosure.
- Threat modeling (pre-engagement)
Show answerHide answer
Identifying likely threat actors, their motivations and capabilities, and the assets they would target — to focus the test on realistic, high-value attack paths.
- Adversary emulation vs. vulnerability scan
Show answerHide answer
Adversary emulation mimics a specific real-world threat actor's TTPs end-to-end; a vulnerability scan just enumerates weaknesses without exploiting or chaining them.
- Time-of-day / window restriction
Show answerHide answer
A scoping constraint limiting when testing may occur (e.g., after business hours) to reduce operational impact on production systems.
- Why scope creep is a problem
Show answerHide answer
Testing assets outside the authorized scope can be illegal, damage trust, and fall outside the signed authorization and insurance — always confirm before expanding.
- Pre-engagement phase
Show answerHide answer
The first PTES phase: agreeing scope, RoE, authorization, timing, and goals with the client before any testing begins.
- Findings prioritization in a report
Show answerHide answer
Ordering vulnerabilities by risk (severity x likelihood x business impact) so the client remediates the most dangerous issues first.
- Attestation of findings
Show answerHide answer
A formal report or letter confirming the testing performed and its results, often required for compliance or third-party assurance.
- Retest / validation engagement
Show answerHide answer
A follow-up test confirming the client's remediations actually closed the reported vulnerabilities.
- Insurance / liability in scoping
Show answerHide answer
Confirming professional liability coverage and clear authorization protects both tester and client if testing causes unintended impact.
- Handling discovered sensitive data
Show answerHide answer
When testing turns up real sensitive data (PII, evidence of a breach, illegal content), follow the RoE escalation/stop-point procedure immediately.
- Pre-engagement vs. discovery
Show answerHide answer
Pre-engagement sets scope, RoE, and authorization; discovery (recon/scanning) is the technical information-gathering that follows. Never start discovery before authorization is signed.
- Target audience of a report
Show answerHide answer
Reports serve two audiences: leadership (executive summary, business risk) and technical staff (detailed findings, evidence, and step-by-step remediation).
- Evidence handling / artifacts
Show answerHide answer
Screenshots, logs, and command output captured during testing that prove each finding; stored securely and included in the report for reproducibility.
- Secure report delivery
Show answerHide answer
Reports contain sensitive vulnerability data, so they must be delivered over an encrypted channel and stored/destroyed per the contract — never sent in clear text.
- PCI DSS penetration testing
Show answerHide answer
PCI DSS requires regular internal and external penetration tests and segmentation testing of the cardholder data environment; the standard dictates scope and frequency.
- Engagement constraints
Show answerHide answer
Limits placed on a test — time windows, excluded systems, no-DoS rules, data-handling requirements — captured in the RoE to keep testing safe and authorized.
- Red team vs. penetration test
Show answerHide answer
A pen test broadly finds and reports vulnerabilities; a red team emulates a specific adversary to test detection and response (the blue team), often stealthy and goal-driven.
- Purple team
Show answerHide answer
Red and blue teams working collaboratively — attackers share techniques in real time so defenders can tune detection and response.
- Why document during the test
Show answerHide answer
Contemporaneous notes (commands, timestamps, findings) ensure the report is accurate, reproducible, and defensible, and support chain-of-custody if needed.
- Confidentiality of findings
Show answerHide answer
Vulnerabilities and client data discovered during testing are highly sensitive; the NDA and contract govern who may see them and for how long they are retained.
- Scoping cloud assets
Show answerHide answer
Confirm which cloud resources the client actually owns and that the provider permits testing; some providers require notification or forbid certain tests.
- Findings severity vs. priority
Show answerHide answer
Severity is the technical danger (CVSS); priority is what the client should fix first given exploitability and business context — they can differ.
- Deconfliction
Show answerHide answer
Coordinating with the client (and any other testers/SOC) so that detected activity can be confirmed as the authorized test, not a real attacker.
Reconnaissance & Enumeration (51)
- Passive reconnaissance
Show answerHide answer
Gathering information without directly touching the target — OSINT, WHOIS, DNS records, search engines, social media. The target sees no probe traffic.
- Active reconnaissance
Show answerHide answer
Directly interacting with the target — port scanning, banner grabbing, service enumeration. More data, but detectable by the target's defenses.
- OSINT
Show answerHide answer
Open-Source Intelligence — collecting publicly available data (websites, social media, leaked credentials, job postings, public records) to profile a target.
- WHOIS
Show answerHide answer
A query that returns domain registration data — registrar, registration/expiry dates, and (when not redacted) registrant contacts and name servers.
- dig / nslookup
Show answerHide answer
DNS query tools used to resolve names, enumerate records (A, MX, NS, TXT), and attempt zone transfers during passive/active recon.
- DNS zone transfer (AXFR)
Show answerHide answer
A misconfiguration where a DNS server hands over its full zone file, exposing every host record at once — a recon goldmine if allowed.
- theHarvester
Show answerHide answer
An OSINT tool that gathers emails, subdomains, hosts, and employee names from public sources (search engines, PGP servers, etc.).
- Recon-ng
Show answerHide answer
A modular OSINT reconnaissance framework (Metasploit-like interface) for automating data collection from many public sources.
- Maltego
Show answerHide answer
A graphical OSINT and link-analysis tool that maps relationships between people, domains, emails, infrastructure, and social media.
- Shodan
Show answerHide answer
A search engine for Internet-connected devices; finds exposed servers, webcams, ICS/SCADA, and services by banner — passive recon of the attack surface.
- Google dorking
Show answerHide answer
Using advanced search operators (site:, filetype:, intitle:, inurl:) to find exposed files, login pages, and sensitive data indexed by search engines.
- Subdomain enumeration
Show answerHide answer
Discovering a target's subdomains (e.g., with Sublist3r, Amass, or certificate transparency logs) to expand the attack surface.
- Banner grabbing
Show answerHide answer
Connecting to a service to read the response banner, revealing the software and version (e.g., 'Apache/2.4.41') to identify likely vulnerabilities.
- Fingerprinting (OS/service)
Show answerHide answer
Analyzing responses to determine the exact operating system or service and version running, so attacks can be matched to known vulnerabilities.
- Nmap SYN scan (-sS)
Show answerHide answer
A 'half-open' TCP scan that sends SYN and reads the SYN-ACK/RST without completing the handshake — fast and stealthier than a full connect scan.
- Nmap service/version scan (-sV)
Show answerHide answer
Probes open ports to identify the service and version running, refining the target list for vulnerability matching.
- Nmap Scripting Engine (NSE)
Show answerHide answer
Nmap's Lua scripting system that automates discovery, version detection, and even vulnerability checks (e.g., --script vuln).
- Masscan
Show answerHide answer
An extremely fast Internet-scale port scanner that can scan large IP ranges quickly, often used for initial host/port discovery before deeper Nmap scans.
- Wireshark
Show answerHide answer
A GUI packet capture and protocol analyzer used to inspect network traffic, extract credentials sent in clear text, and understand protocols.
- tcpdump
Show answerHide answer
A command-line packet capture tool for sniffing and recording network traffic, common on Linux hosts during recon and post-exploitation.
- ARP scanning (arp-scan)
Show answerHide answer
Discovering live hosts on a local subnet by sending ARP requests and reading replies — reliable on a LAN where ICMP may be blocked.
- ICMP / ping sweep
Show answerHide answer
Sending ICMP echo requests across a range to find which hosts respond — fast host discovery, but often blocked by firewalls.
- SMB enumeration (enum4linux)
Show answerHide answer
Enumerating Windows/Samba shares, users, groups, and password policy over SMB — a rich source of internal targets and footholds.
- SNMP enumeration
Show answerHide answer
Querying devices over SNMP (often with default community string 'public') to extract system info, interfaces, routes, and sometimes credentials.
- War driving / wireless recon
Show answerHide answer
Surveying an area for wireless networks (e.g., with Kismet or airodump-ng) to map SSIDs, encryption, and signal — the wireless attack surface.
- Certificate transparency logs
Show answerHide answer
Public logs of issued TLS certificates (e.g., crt.sh) that reveal subdomains and hostnames an organization has certificates for.
- Wappalyzer / WhatWeb
Show answerHide answer
Tools that fingerprint a website's technology stack — CMS, frameworks, server, and JavaScript libraries — guiding targeted attacks.
- Email harvesting
Show answerHide answer
Collecting employee email addresses from public sources to build phishing target lists and infer the organization's email naming convention.
- Active vs passive — detection trade-off
Show answerHide answer
Passive recon is undetectable but limited; active recon yields far more detail but generates traffic the target can log and alert on.
- Enumeration
Show answerHide answer
Actively extracting detailed information from discovered services — usernames, shares, software versions, hosts — to plan exploitation.
- Nmap output formats (-oA)
Show answerHide answer
Nmap can save results in normal, XML, and grepable formats at once (-oA) so findings can be parsed by other tools and the report.
- Amass
Show answerHide answer
An OWASP tool for in-depth attack-surface mapping and subdomain enumeration using OSINT and active techniques.
- FOCA / metadata analysis
Show answerHide answer
Extracting metadata from public documents (authors, software, paths, usernames) to learn about a target's internal environment.
- Gobuster / dirb / ffuf
Show answerHide answer
Content-discovery tools that brute-force directories, files, and virtual hosts on a web server to find hidden endpoints (ffuf is a fast fuzzer).
- Passive DNS
Show answerHide answer
Historical DNS resolution data from third parties that reveals prior IPs and hostnames for a domain without querying the target directly.
- OSINT framework categories
Show answerHide answer
OSINT spans people (names, emails, social media), infrastructure (domains, IPs, certs), and documents (metadata) — combined to build a full target profile.
- Spiderfoot
Show answerHide answer
An automated OSINT reconnaissance tool that queries many data sources to map a target's footprint — domains, IPs, emails, and leaked data.
- Censys
Show answerHide answer
An Internet-scanning search engine (like Shodan) for discovering hosts, certificates, and services exposed on the public Internet.
- Nmap timing templates (-T0 to -T5)
Show answerHide answer
Control scan speed/stealth: -T0/-T1 are slow and evasive (IDS-friendly), -T4 is fast for reliable networks, -T5 is fastest but noisiest and may miss results.
- UDP scanning (-sU)
Show answerHide answer
Scans UDP ports (DNS, SNMP, TFTP); slower and less reliable than TCP because closed UDP ports may not respond, but it finds services TCP scans miss.
- OS detection (-O)
Show answerHide answer
Nmap analyzes TCP/IP stack behavior to guess the target operating system and version, helping match OS-specific exploits.
- Idle / zombie scan
Show answerHide answer
A stealthy Nmap scan that bounces probes off a third 'zombie' host so the target never sees the attacker's real IP.
- LDAP enumeration
Show answerHide answer
Querying an LDAP/Active Directory service to enumerate users, groups, and organizational structure — valuable for targeting accounts.
- RPC / portmapper enumeration
Show answerHide answer
Querying RPC services (e.g., rpcinfo) to list exposed remote-procedure services that may be exploitable.
- SMTP user enumeration (VRFY/EXPN)
Show answerHide answer
Abusing SMTP VRFY/EXPN/RCPT commands to confirm valid email accounts on a mail server, building a target list.
- Crawling robots.txt / sitemap
Show answerHide answer
Reading a site's robots.txt and sitemap.xml reveals paths the owner tried to hide from crawlers — often interesting admin or staging endpoints.
- Email naming convention discovery
Show answerHide answer
Inferring the format of corporate emails (first.last@, flast@) from a few known addresses to generate likely usernames for spraying or phishing.
- Wayback Machine / archived pages
Show answerHide answer
Reviewing archived versions of a site to find removed pages, old endpoints, and exposed data that still hint at the current architecture.
- OSINT for physical / social engineering
Show answerHide answer
Researching employees, badges, office locations, and vendors to plan pretexting, tailgating, and on-site social-engineering attacks.
- Footprinting
Show answerHide answer
The overall process of building a profile of a target's Internet presence and infrastructure through passive and active information gathering.
- Active scanning detection risk
Show answerHide answer
Aggressive scans (full port ranges, -T5, vuln scripts) generate IDS/IPS alerts; testers tune timing and scope to balance coverage against stealth and stability.
Vulnerability Discovery & Analysis (41)
- Vulnerability scanning
Show answerHide answer
Automated checking of systems against a database of known weaknesses (missing patches, misconfigurations, weak settings) to produce a prioritized findings list.
- Nessus
Show answerHide answer
A widely used commercial vulnerability scanner (Tenable) that checks hosts and apps against thousands of known vulnerability and configuration checks.
- OpenVAS / Greenbone
Show answerHide answer
An open-source vulnerability scanner that performs networked vulnerability tests against hosts and services.
- Nikto
Show answerHide answer
An open-source web server scanner that checks for dangerous files, outdated software, and common server misconfigurations.
- Wapiti
Show answerHide answer
An open-source black-box web application vulnerability scanner that crawls a site and injects payloads to find injection, XSS, and file-inclusion flaws.
- OWASP ZAP
Show answerHide answer
The OWASP Zed Attack Proxy — a free intercepting proxy and web app scanner, an open-source alternative to Burp Suite.
- sqlmap
Show answerHide answer
An automated tool that detects and exploits SQL injection flaws, enumerating databases, tables, and data, and even gaining a shell.
- Fuzzing
Show answerHide answer
Sending large volumes of malformed or unexpected input to an application to trigger crashes, errors, or unexpected behavior that reveal vulnerabilities.
- False positive
Show answerHide answer
A scanner flagging a vulnerability that doesn't actually exist or isn't exploitable. Testers must validate findings before reporting.
- False negative
Show answerHide answer
A real vulnerability the scanner missed — the more dangerous error, which is why manual testing supplements automated scans.
- Validation (vulnerability)
Show answerHide answer
Manually confirming a scanner finding is real and exploitable (e.g., actually exploiting it in a controlled way) before including it in the report.
- Credentialed vs. non-credentialed scan
Show answerHide answer
A credentialed scan logs in to inspect patch levels and config from the inside (more accurate, fewer false positives); a non-credentialed scan tests from outside only.
- CVE
Show answerHide answer
Common Vulnerabilities and Exposures — a public catalog assigning a unique ID (e.g., CVE-2021-44228) to each known, disclosed vulnerability.
- CWE
Show answerHide answer
Common Weakness Enumeration — a categorized list of software/hardware weakness types (e.g., CWE-89 SQL injection) that underlie specific CVEs.
- CVSS base score components
Show answerHide answer
The base metric set rates exploitability (attack vector, complexity, privileges, user interaction) and impact (confidentiality, integrity, availability).
- NVD (National Vulnerability Database)
Show answerHide answer
NIST's database that enriches CVE entries with CVSS scores, affected products (CPE), and references — the standard lookup for vulnerability detail.
- Exploit database (Exploit-DB)
Show answerHide answer
A public archive of proof-of-concept exploits and shellcode, searchable locally with searchsploit, used to find working exploits for a CVE.
- Prioritizing findings
Show answerHide answer
Ranking vulnerabilities by risk = severity (CVSS) combined with business context and exploitability, so the client fixes the most dangerous issues first.
- SSL/TLS scanning (testssl.sh, sslscan)
Show answerHide answer
Tools that test a TLS endpoint for weak ciphers, protocol versions, expired certs, and known flaws (e.g., Heartbleed, POODLE).
- Web crawler / spider
Show answerHide answer
A tool that automatically follows links to map all pages, parameters, and endpoints of a web app — the input list for vulnerability testing.
- Scan tuning / throttling
Show answerHide answer
Adjusting a scan's intensity and timing to avoid overwhelming fragile systems (e.g., ICS/SCADA, legacy hosts) and triggering outages.
- Attack surface
Show answerHide answer
The total set of points where an attacker could try to enter or extract data — every exposed service, port, app, and interface. Reducing it lowers risk.
- Authenticated web scan
Show answerHide answer
Configuring a scanner with valid session credentials so it can test pages behind login — finding vulnerabilities a guest scan misses.
- Scan scheduling / change control
Show answerHide answer
Coordinating scan windows with the client to avoid business disruption and to respect maintenance and change-control processes.
- Manual testing vs. automated scanning
Show answerHide answer
Automated scans are fast and broad but miss logic flaws and chained attacks; manual testing finds business-logic and complex vulnerabilities scanners can't.
- Business logic vulnerability
Show answerHide answer
A flaw in how an application's intended workflow can be abused (e.g., skipping a payment step) — invisible to signature-based scanners; found by manual testing.
- Compliance scan
Show answerHide answer
A scan that checks systems against a configuration benchmark (e.g., CIS Benchmarks, DISA STIG) rather than just known CVEs.
- Scanner plugin / signature feed
Show answerHide answer
Vulnerability scanners rely on regularly updated plugin/signature databases; an out-of-date feed misses recent CVEs (false negatives).
- Active vs. passive vulnerability scanning
Show answerHide answer
Active scanning sends probes to test for flaws; passive scanning observes existing traffic to infer vulnerabilities without touching the target.
- Web app scan limitations
Show answerHide answer
Automated scanners struggle with authentication flows, multi-step logic, and CAPTCHAs — manual testing is required for full web coverage.
- CVSS temporal & environmental metrics
Show answerHide answer
Beyond base score, temporal metrics adjust for exploit maturity/remediation, and environmental metrics tailor severity to the specific organization's context.
- Proof of concept (PoC)
Show answerHide answer
Minimal code or steps demonstrating a vulnerability is real and exploitable, used to validate findings and convince stakeholders to remediate.
- WPScan
Show answerHide answer
A vulnerability scanner specialized for WordPress — enumerates plugins, themes, users, and known vulnerabilities in them.
- Mobile app testing tools
Show answerHide answer
Tools like MobSF (static/dynamic analysis), Frida, and objection assess Android/iOS apps for insecure storage, weak crypto, and API flaws.
- Container / image scanning
Show answerHide answer
Tools (Trivy, Clair, Grype) scan container images for vulnerable packages and misconfigurations before and after deployment.
- IaC / cloud config scanning
Show answerHide answer
Tools (Prowler, ScoutSuite, Checkov) audit cloud accounts and Infrastructure-as-Code for insecure configurations like open security groups.
- Validating before reporting
Show answerHide answer
Testers manually confirm scanner findings to remove false positives and rate true exploitability — reporting unverified findings erodes client trust.
- Risk = likelihood x impact
Show answerHide answer
Prioritization combines how likely a vulnerability is to be exploited with the business impact if it is — not CVSS severity alone.
- Searchsploit
Show answerHide answer
A command-line search tool for the local copy of Exploit-DB, used to quickly find public exploits matching a discovered service/version.
- Heartbleed (CVE-2014-0160)
Show answerHide answer
A classic OpenSSL flaw that let attackers read server memory (keys, sessions); often used as an example of a high-impact, scanner-detectable CVE.
- Web Security Testing Guide (WSTG)
Show answerHide answer
OWASP's comprehensive methodology for testing web app security, organized by category (auth, session, input validation, etc.).
Attacks & Exploits (96)
- Nmap
Show answerHide answer
The de facto network scanner — discovers live hosts, open ports, services, and OS fingerprints. Core tool for the recon and enumeration phase.
- Metasploit Framework
Show answerHide answer
An exploitation framework that bundles exploits, payloads (e.g., Meterpreter), and post-exploitation modules to deliver and manage attacks against vulnerable targets.
- Burp Suite
Show answerHide answer
An intercepting web proxy used to capture, modify, and replay HTTP/S traffic; its scanner, Repeater, and Intruder tools test web apps for vulnerabilities.
- Exploit
Show answerHide answer
Code or a technique that takes advantage of a specific vulnerability to make a system behave unexpectedly — e.g., run attacker code or grant access.
- Payload
Show answerHide answer
The code delivered and executed after a successful exploit — e.g., a reverse shell, Meterpreter session, or command execution.
- SQL injection (SQLi)
Show answerHide answer
Inserting malicious SQL into an input so the database runs unintended commands — read/modify data or bypass authentication. Fix: parameterized queries.
- Cross-site scripting (XSS)
Show answerHide answer
Injecting script into a trusted site that runs in another user's browser (stored, reflected, or DOM-based). Steals cookies/sessions. Fix: output encoding + CSP.
- Cross-site request forgery (CSRF)
Show answerHide answer
Tricking an authenticated user's browser into sending an unwanted state-changing request to a site they're logged into. Fix: anti-CSRF tokens, SameSite cookies.
- Command injection
Show answerHide answer
Injecting OS commands into input passed to a system shell so the server executes the attacker's commands. Fix: avoid shell calls, validate/escape input.
- Directory / path traversal
Show answerHide answer
Using sequences like '../' in input to access files outside the web root (e.g., /etc/passwd). Fix: canonicalize and validate file paths.
- Local / remote file inclusion (LFI/RFI)
Show answerHide answer
Abusing dynamic file-include functionality to load local files (LFI) or attacker-hosted remote files (RFI), often leading to code execution.
- Server-side request forgery (SSRF)
Show answerHide answer
Tricking a server into making requests to internal resources the attacker can't reach directly — e.g., cloud metadata endpoints. Fix: allow-list outbound URLs.
- XML external entity (XXE)
Show answerHide answer
Abusing an XML parser that processes external entities to read local files or perform SSRF. Fix: disable external entity resolution.
- Insecure direct object reference (IDOR)
Show answerHide answer
Accessing another user's data by changing an identifier in a request (e.g., id=124 → id=125) because the app fails to check authorization.
- Buffer overflow
Show answerHide answer
Writing more data than a buffer holds, overwriting adjacent memory (including the return address) to redirect execution to attacker code.
- Race condition (TOCTOU)
Show answerHide answer
Exploiting the timing gap between a security check and the use of a resource (time-of-check to time-of-use) to slip in a malicious change.
- On-path (man-in-the-middle) attack
Show answerHide answer
Secretly relaying or altering traffic between two parties to eavesdrop or modify data — e.g., via ARP spoofing or a rogue access point.
- ARP poisoning / spoofing
Show answerHide answer
Sending forged ARP replies on a LAN so traffic for another host flows through the attacker — the basis of many on-path attacks.
- DNS poisoning / spoofing
Show answerHide answer
Corrupting DNS responses so a victim resolves a domain to an attacker-controlled IP, redirecting them to a malicious server.
- Denial of service (DoS) / DDoS
Show answerHide answer
Overwhelming a system or network with traffic/requests so legitimate users can't access it. Often out of scope unless explicitly authorized.
- Password spraying
Show answerHide answer
Trying one or a few common passwords against many accounts to avoid lockout — quieter than brute-forcing a single account.
- Credential stuffing
Show answerHide answer
Using username/password pairs leaked from one breach to log in elsewhere, exploiting password reuse.
- Brute-force attack
Show answerHide answer
Systematically trying every possible password/key until one works; mitigated by lockouts, rate limiting, and strong/complex secrets.
- Hydra / Medusa
Show answerHide answer
Network login brute-force tools that attempt credentials against services like SSH, RDP, FTP, and HTTP forms.
- John the Ripper
Show answerHide answer
An offline password-cracking tool that recovers plaintext from password hashes using dictionary, rule-based, and brute-force attacks.
- Hashcat
Show answerHide answer
A fast, GPU-accelerated password-cracking tool that recovers plaintext from many hash types using wordlists, rules, and masks.
- Zero-day exploit
Show answerHide answer
An exploit for a vulnerability unknown to the vendor (no patch exists yet) — highly valuable and hard to defend against.
- Social engineering
Show answerHide answer
Manipulating people into revealing information or taking actions that compromise security — the human attack vector.
- Phishing
Show answerHide answer
Fraudulent messages (usually email) that trick victims into revealing credentials, clicking links, or running malware. Spear phishing targets a specific person.
- Vishing / smishing
Show answerHide answer
Voice phishing (vishing) over phone calls and SMS phishing (smishing) over text — social-engineering variants of phishing.
- Pretexting
Show answerHide answer
Inventing a believable scenario or false identity (e.g., posing as IT support) to manipulate a target into cooperating.
- Tailgating / piggybacking
Show answerHide answer
Following an authorized person through a secure door to gain unauthorized physical entry without their challenge.
- SET (Social-Engineer Toolkit)
Show answerHide answer
A framework for crafting social-engineering attacks — phishing pages, malicious attachments, and credential-harvesting clones.
- Evil twin / rogue access point
Show answerHide answer
A fake Wi-Fi access point impersonating a legitimate SSID to capture credentials or perform on-path attacks on connecting clients.
- WPA/WPA2 handshake capture + crack
Show answerHide answer
Capturing the 4-way handshake (e.g., with airodump-ng) and cracking the pre-shared key offline with a wordlist (aircrack-ng/hashcat).
- Aircrack-ng suite
Show answerHide answer
A set of wireless tools to monitor, capture, inject, and crack Wi-Fi (airmon-ng, airodump-ng, aireplay-ng, aircrack-ng).
- Deauthentication attack
Show answerHide answer
Sending forged deauth frames to knock clients off a Wi-Fi network — used to capture handshakes or to set up an evil twin.
- Cloud attacks (metadata service)
Show answerHide answer
Abusing a cloud instance's metadata endpoint (e.g., 169.254.169.254) — often via SSRF — to steal temporary credentials and pivot in the cloud.
- Misconfigured S3 bucket
Show answerHide answer
A publicly readable/writable cloud storage bucket that exposes data — a common cloud finding due to the shared-responsibility model.
- Reverse shell vs. bind shell
Show answerHide answer
A reverse shell connects from the victim back to the attacker (beats inbound firewalls); a bind shell listens on the victim for the attacker to connect in.
- Meterpreter
Show answerHide answer
Metasploit's advanced, in-memory payload providing a feature-rich session — file access, privilege escalation, pivoting, and credential dumping.
- msfvenom
Show answerHide answer
Metasploit's payload generator/encoder — builds standalone payloads (e.g., a Windows reverse-shell executable) for delivery outside the framework.
- Netcat
Show answerHide answer
The 'Swiss army knife' of networking — reads/writes raw TCP/UDP; used for banner grabbing, file transfer, port listening, and simple shells.
- Default / weak credentials
Show answerHide answer
Unchanged factory passwords (admin/admin) or weak secrets on devices and apps — a fast, high-impact initial-access finding.
- Deserialization attack
Show answerHide answer
Supplying crafted serialized objects that, when deserialized by the app, execute attacker code or alter logic. Fix: avoid native deserialization of untrusted data.
- VLAN hopping
Show answerHide answer
Escaping an assigned VLAN to reach others — via switch-spoofing or double-tagging — bypassing network segmentation.
- LLMNR/NBT-NS poisoning (Responder)
Show answerHide answer
Answering Windows name-resolution broadcasts (LLMNR/NBT-NS) to capture NTLM hashes from victims, then relay or crack them.
- BeEF
Show answerHide answer
Browser Exploitation Framework — 'hooks' a victim browser via XSS to run commands, gather data, and pivot through the browser.
- Web shell
Show answerHide answer
A malicious script (e.g., PHP/ASP) uploaded to a web server that gives the attacker remote command execution through the browser.
- API attacks (broken object-level auth)
Show answerHide answer
Abusing API endpoints that fail to authorize per-object access (BOLA/IDOR) to read or modify other users' data — top of the OWASP API Top 10.
- JWT attacks
Show answerHide answer
Abusing JSON Web Tokens — e.g., 'alg:none', weak signing keys, or unverified signatures — to forge tokens and escalate access.
- OWASP Top 10
Show answerHide answer
The list of the most critical web application security risks (e.g., Broken Access Control, Injection, Security Misconfiguration), updated periodically.
- Clickjacking
Show answerHide answer
Overlaying invisible UI so a victim clicks something different from what they see; mitigated with X-Frame-Options / frame-ancestors CSP.
- Session hijacking
Show answerHide answer
Stealing or predicting a valid session token (cookie) to impersonate a logged-in user. Mitigated with HTTPS, HttpOnly/Secure cookies, and rotation.
- Rainbow table
Show answerHide answer
A precomputed table of hash-to-plaintext mappings used to reverse unsalted password hashes quickly. Defeated by per-password salting.
- Wordlist (e.g., rockyou.txt)
Show answerHide answer
A list of likely passwords/inputs fed to cracking and fuzzing tools; rockyou.txt is a famous leaked-password wordlist.
- Burp Intruder
Show answerHide answer
Burp Suite's automated request-fuzzing tool used for brute-forcing parameters, enumerating values, and testing injection at scale.
- SMB relay attack
Show answerHide answer
Capturing NTLM authentication and relaying it to another host to authenticate as the victim — mitigated by SMB signing.
- Initial access vector
Show answerHide answer
How an attacker first gets in — phishing, exposed service, weak credentials, or exploiting an Internet-facing vulnerability.
- Bind vs. staged vs. stageless payload
Show answerHide answer
A staged payload sends a small stager that pulls the rest; a stageless payload is fully self-contained — chosen based on size limits and detection.
- Server-side template injection (SSTI)
Show answerHide answer
Injecting template syntax into a server-side template engine so it evaluates attacker input, often leading to remote code execution.
- HTTP request smuggling
Show answerHide answer
Exploiting differences in how front-end and back-end servers parse request boundaries to sneak in or hijack requests.
- CRLF injection
Show answerHide answer
Injecting carriage-return/line-feed characters into headers to split responses, poison logs, or set rogue headers/cookies.
- Open redirect
Show answerHide answer
Abusing a redirect parameter that isn't validated to send victims to an attacker site — useful in phishing and OAuth token theft.
- Broken authentication
Show answerHide answer
Weaknesses in login/session handling — weak passwords, no MFA, predictable tokens, no lockout — that let attackers take over accounts.
- Security misconfiguration
Show answerHide answer
Insecure defaults, verbose errors, open cloud storage, unnecessary services — one of the most common and exploitable web findings.
- Privilege escalation via misconfig
Show answerHide answer
Exploiting weak file permissions, writable services, unquoted service paths, or sudo misconfigurations to gain higher privileges on a host.
- Spear phishing vs. whaling
Show answerHide answer
Spear phishing targets a specific individual with a tailored lure; whaling targets high-value executives (the 'big fish').
- USB drop attack
Show answerHide answer
Leaving malicious USB drives where targets will find and plug them in, executing a payload — a physical social-engineering vector.
- Watering hole attack
Show answerHide answer
Compromising a website a target group frequently visits so the targets are infected when they browse to the trusted site.
- Card cloning / RFID attacks
Show answerHide answer
Copying badge/RFID credentials (e.g., with a Proxmark) to clone access cards for physical entry during a physical pen test.
- Bluetooth attacks
Show answerHide answer
Bluejacking (unsolicited messages), bluesnarfing (data theft), and bluebugging (control) target Bluetooth-enabled devices.
- WPS PIN attack
Show answerHide answer
Brute-forcing the 8-digit Wi-Fi Protected Setup PIN (e.g., with Reaver) to recover the WPA passphrase on routers with WPS enabled.
- Karma / known-beacon attack
Show answerHide answer
A rogue AP that answers clients' probe requests for any remembered SSID, tricking devices into auto-connecting to the attacker.
- Cloud IAM privilege escalation
Show answerHide answer
Abusing over-permissive cloud IAM policies (e.g., iam:PassRole, policy attachment) to grant yourself higher privileges in the cloud account.
- Container escape
Show answerHide answer
Breaking out of a container to the host — via a privileged container, exposed Docker socket, or kernel exploit — to compromise the underlying node.
- Kubernetes attacks
Show answerHide answer
Abusing exposed kubelet/API server, over-permissive RBAC, or service-account tokens to take over pods and the cluster.
- Antivirus / EDR evasion
Show answerHide answer
Modifying payloads (obfuscation, encoding, packing, in-memory execution) so endpoint defenses don't detect them — tested to assess detection gaps.
- Obfuscation / encoding payloads
Show answerHide answer
Encoding (Base64), encrypting, or obfuscating a payload to bypass signature-based detection and content filters.
- Macro / malicious document attack
Show answerHide answer
Embedding a malicious macro or object in an Office/PDF document that runs a payload when the victim opens and enables it.
- DLL hijacking / search-order abuse
Show answerHide answer
Placing a malicious DLL where a program will load it before the legitimate one, executing attacker code with that program's privileges.
- Reflected vs. stored XSS
Show answerHide answer
Reflected XSS bounces injected script back in the response (needs a crafted link); stored XSS persists in the app and runs for every viewer.
- DOM-based XSS
Show answerHide answer
XSS where untrusted data is written into the page by client-side JavaScript (the DOM) without a server round trip.
- Blind SQL injection
Show answerHide answer
SQLi where the app gives no direct error/data, so the attacker infers results from boolean responses or time delays (time-based blind SQLi).
- Second-order injection
Show answerHide answer
Malicious input is stored and only triggers the attack later when it is used by a different part of the application.
- Default credentials in IoT/ICS
Show answerHide answer
Embedded and industrial devices often ship with documented default logins that are never changed — a high-impact, easy initial-access finding.
- BadUSB / HID attack (Rubber Ducky)
Show answerHide answer
A USB device that emulates a keyboard to type and run commands the instant it's plugged in, bypassing autorun protections.
- Replay attack
Show answerHide answer
Capturing valid data (e.g., an authentication token) and re-sending it to gain access; mitigated with nonces, timestamps, and TLS.
- DNS rebinding
Show answerHide answer
Tricking a browser into treating an attacker domain as a local one by rapidly changing DNS, letting it reach internal services.
- Race condition exploitation (web)
Show answerHide answer
Sending many simultaneous requests to exploit a timing gap — e.g., redeeming a single-use coupon multiple times before the balance updates.
- Impacket
Show answerHide answer
A Python library and toolset (psexec.py, wmiexec.py, secretsdump.py) for crafting and using network protocols — heavily used for Windows lateral movement.
- CrackMapExec / NetExec
Show answerHide answer
A swiss-army tool for pentesting Windows/AD networks at scale — spray credentials, enumerate shares, and execute commands across many hosts.
- Wireless: WPA3 vs WPA2
Show answerHide answer
WPA3 adds SAE (Simultaneous Authentication of Equals), resisting the offline handshake-cracking that works against WPA2-PSK.
- Log4Shell (CVE-2021-44228)
Show answerHide answer
A critical remote code execution flaw in the Log4j library via JNDI lookups in logged input — a widely exploited, easy-to-trigger vulnerability.
- Relay vs. crack (captured hashes)
Show answerHide answer
A captured NTLM hash can be relayed to another host (SMB relay) or cracked offline; relaying needs no cracking but requires SMB signing to be off.
- Phishing pretext quality
Show answerHide answer
Effective phishing uses authority, urgency, and familiarity; a believable pretext and a convincing cloned login page drive higher click/credential rates.
Post-exploitation & Lateral Movement (54)
- Post-exploitation
Show answerHide answer
Everything after gaining initial access: escalating privileges, maintaining persistence, harvesting credentials, moving laterally, and collecting evidence/data.
- Privilege escalation
Show answerHide answer
Gaining higher rights than granted — vertical (user → admin/root) or horizontal (to another user's access) — to deepen control of a host.
- Persistence
Show answerHide answer
Establishing a way to keep access across reboots/credential changes — e.g., scheduled tasks, services, cron jobs, or new accounts.
- Lateral movement
Show answerHide answer
Using a compromised host to reach and compromise other systems on the internal network, expanding the foothold toward high-value targets.
- Pivoting
Show answerHide answer
Routing traffic through a compromised host to reach networks the attacker can't access directly — e.g., a SOCKS proxy or SSH tunnel.
- Pass-the-hash (PtH)
Show answerHide answer
Authenticating to a Windows system using a captured NTLM hash directly, without ever cracking the plaintext password.
- Pass-the-ticket / Kerberos abuse
Show answerHide answer
Stealing or forging Kerberos tickets (e.g., Golden/Silver tickets) to impersonate users and access services across an AD domain.
- Kerberoasting
Show answerHide answer
Requesting Kerberos service tickets for accounts with SPNs, then cracking the ticket offline to recover the service account's password.
- Mimikatz
Show answerHide answer
A Windows post-exploitation tool that dumps plaintext passwords, hashes, Kerberos tickets, and performs pass-the-hash/pass-the-ticket.
- LSASS dumping
Show answerHide answer
Extracting credentials from the Windows LSASS process memory (e.g., with Mimikatz or comsvcs.dll) to harvest hashes and tickets.
- PsExec
Show answerHide answer
A Sysinternals tool (and Metasploit module) that executes commands on a remote Windows host over SMB — common for lateral movement.
- WMI for remote execution
Show answerHide answer
Using Windows Management Instrumentation (e.g., wmiexec) to run commands on a remote host without dropping a service binary — stealthier lateral movement.
- Windows scheduled task (persistence)
Show answerHide answer
Creating a scheduled task (schtasks) that re-runs the attacker's payload on a trigger or interval to survive reboots.
- Linux cron job (persistence)
Show answerHide answer
Adding a cron entry that periodically executes the attacker's payload — the Linux analog of a Windows scheduled task.
- SUID binary abuse (Linux)
Show answerHide answer
Exploiting a root-owned binary with the SUID bit set so its actions run as root, enabling privilege escalation (see GTFOBins).
- GTFOBins / LOLBAS
Show answerHide answer
Catalogs of legitimate binaries (Linux: GTFOBins; Windows: LOLBAS) that can be abused for privilege escalation, persistence, or bypassing controls.
- BloodHound
Show answerHide answer
A tool that maps Active Directory relationships to find the shortest attack paths to Domain Admin, visualizing privilege escalation routes.
- SSH tunneling / port forwarding
Show answerHide answer
Using SSH (e.g., 'ssh -D' for a SOCKS proxy, or -L/-R) to tunnel and forward traffic through a compromised host for pivoting.
- ProxyChains
Show answerHide answer
A tool that forces other programs' TCP connections through a proxy (e.g., a SOCKS tunnel), letting attacker tools reach internal hosts via a pivot.
- Credential harvesting
Show answerHide answer
Collecting passwords, hashes, tokens, and keys from a compromised host (memory, files, browser stores) to enable lateral movement.
- Data exfiltration (testing)
Show answerHide answer
Demonstrating that sensitive data could leave the network — done carefully and within scope, often with sanitized or proof-only data.
- Anti-forensics / log clearing (caution)
Show answerHide answer
Techniques to hide activity (clearing logs, timestomping). On an authorized test, testers usually document rather than destroy, preserving evidence.
- Cleanup / restoring state
Show answerHide answer
Removing tools, payloads, accounts, and persistence after the engagement so the environment is returned to its original, secure state.
- Living off the land (LOTL)
Show answerHide answer
Using built-in, trusted tools (PowerShell, WMI, certutil) instead of malware to evade detection during post-exploitation.
- Token impersonation
Show answerHide answer
Stealing or duplicating a Windows access token from a process to act with another (often higher-privileged) user's rights.
- DCSync
Show answerHide answer
Abusing replication rights in Active Directory to request password hashes for any account directly from a domain controller (often via Mimikatz).
- Foothold
Show answerHide answer
The initial access point an attacker establishes on a target network — the base from which escalation and lateral movement proceed.
- Dual-homed host (pivot)
Show answerHide answer
A host connected to two networks; compromising it lets an attacker bridge from one segment to an otherwise unreachable one.
- Empire / Covenant (C2)
Show answerHide answer
Command-and-control frameworks that manage compromised hosts (agents) for post-exploitation tasking, often over HTTP/S.
- Beacon (C2)
Show answerHide answer
An implant on a compromised host that periodically calls back to the C2 server for instructions, blending in with normal traffic.
- UAC bypass (Windows)
Show answerHide answer
Techniques to elevate from a medium-integrity process to high integrity without a UAC prompt, abusing auto-elevating binaries or registry keys.
- Hash dumping (SAM/NTDS.dit)
Show answerHide answer
Extracting local password hashes from the Windows SAM, or domain hashes from NTDS.dit on a domain controller, for offline cracking or PtH.
- Enumeration scripts (linPEAS/winPEAS)
Show answerHide answer
Post-exploitation scripts that automatically enumerate a host for privilege-escalation opportunities (misconfigs, SUID, services, credentials).
- Lateral movement techniques (overview)
Show answerHide answer
Pass-the-hash, pass-the-ticket, PsExec, WMI, RDP, and SSH reuse are common ways to move from one compromised host to others.
- Golden ticket
Show answerHide answer
A forged Kerberos TGT signed with the domain's KRBTGT hash, granting an attacker domain-wide access that persists until KRBTGT is reset twice.
- Silver ticket
Show answerHide answer
A forged Kerberos service ticket (TGS) for a specific service, signed with that service account's hash — stealthier and more scoped than a golden ticket.
- AS-REP roasting
Show answerHide answer
Requesting AS-REP responses for accounts that don't require Kerberos pre-authentication, then cracking the response offline for the password.
- Scheduled persistence via registry (Run keys)
Show answerHide answer
Adding the payload path to a Windows Run/RunOnce registry key so it launches at user logon — a classic persistence mechanism.
- Service creation (persistence)
Show answerHide answer
Installing a new Windows service that runs the payload at boot with SYSTEM privileges — durable persistence.
- SSH key persistence (Linux)
Show answerHide answer
Adding the attacker's public key to a user's authorized_keys so they can log back in over SSH without a password.
- Backdoor account
Show answerHide answer
Creating a new (often hidden or innocuously named) account so the attacker retains access even if the original foothold is closed.
- Port forwarding (chisel)
Show answerHide answer
Chisel is a fast TCP/UDP tunnel over HTTP/S used to forward ports and create pivots through firewalls during post-exploitation.
- Dynamic vs. local vs. remote forwarding
Show answerHide answer
SSH -D = dynamic (SOCKS proxy); -L = local forward (reach a remote service locally); -R = remote forward (expose a local service to the pivot).
- Network pivoting with Metasploit (autoroute)
Show answerHide answer
After a Meterpreter session, autoroute adds the victim's subnets to Metasploit's routing so other modules can reach internal hosts through it.
- Data collection / staging
Show answerHide answer
Gathering target files into a single location (staging) before exfiltration; testers limit this to proof and avoid moving real sensitive data.
- Covering tracks (test ethics)
Show answerHide answer
Real attackers clear logs; authorized testers instead document actions and timestamps so the blue team can correlate — destroying evidence is out of scope.
- Maintaining situational awareness
Show answerHide answer
After landing on a host, enumerate users, privileges, network, running processes, and defenses before acting — to avoid detection and pick the right path.
- Trust relationships / domain trusts
Show answerHide answer
Abusing trust between AD domains/forests to move from a compromised domain into a trusting one and expand access.
- Local privilege escalation enumeration
Show answerHide answer
Checking for unpatched kernels, weak service permissions, stored credentials, and misconfigured sudo/SUID to climb from user to admin/root.
- RDP for lateral movement
Show answerHide answer
Using harvested credentials to log in over Remote Desktop to other Windows hosts — effective but noisy and often logged.
- Token / session theft
Show answerHide answer
Stealing active session tokens or cookies from a compromised host to impersonate a user without their password.
- Cloud pivot via stolen keys
Show answerHide answer
Using credentials/keys harvested from a host (env vars, config files, metadata) to pivot into the organization's cloud environment.
- Cleanup checklist
Show answerHide answer
Remove payloads, accounts, persistence, scheduled tasks, and tools; restore changed settings; confirm with the client that the environment is clean.
- secretsdump.py
Show answerHide answer
An Impacket tool that remotely dumps password hashes from the SAM and from the domain's NTDS.dit (via DRSUAPI) for offline cracking or PtH.
References
- 1.CompTIA. “CompTIA PenTest+ (PT0-003) Certification.” comptia.org. ↑
- 2.CompTIA. “PenTest+ (PT0-003) Exam Objectives / Content Guide.” comptia.org. ↑
- 3.National Institute of Standards and Technology. “SP 800-115, Technical Guide to Information Security Testing.” csrc.nist.gov. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
