<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://book.ghanim.no/index.php?action=history&amp;feed=atom&amp;title=Offensive_Security%2FOSEP_Checklist</id>
	<title>Offensive Security/OSEP Checklist - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://book.ghanim.no/index.php?action=history&amp;feed=atom&amp;title=Offensive_Security%2FOSEP_Checklist"/>
	<link rel="alternate" type="text/html" href="https://book.ghanim.no/index.php?title=Offensive_Security/OSEP_Checklist&amp;action=history"/>
	<updated>2026-04-21T13:25:31Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.1</generator>
	<entry>
		<id>https://book.ghanim.no/index.php?title=Offensive_Security/OSEP_Checklist&amp;diff=1209&amp;oldid=prev</id>
		<title>imported&gt;Aghanim at 14:23, 9 November 2023</title>
		<link rel="alternate" type="text/html" href="https://book.ghanim.no/index.php?title=Offensive_Security/OSEP_Checklist&amp;diff=1209&amp;oldid=prev"/>
		<updated>2023-11-09T14:23:31Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[https://github.com/In3x0rabl3/OSEP/blob/main/osep_checklistv2.md OSEP/osep_checklistv2.md at main · In3x0rabl3/OSEP · GitHub]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Web Application:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Unrestricted File upload (ASPX)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* SQL Injection&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Server Side Template Injection&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* RFI&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* LFI&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Web Service&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* BruteForce&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* CVE&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Phishing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Code Exec&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* BAD PDF&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;MSSQL:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Linked Servers&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Priv Esc&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Enable Shell&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Code Exec&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Relay netv2 hash&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Privilege Escalation:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Windows&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* PowerUP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* LinPeas&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Creds in Config Files&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* SEimpersonation (PrintSpoofer,Spooler,etc)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* ShadowCopy&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Hivenightmare&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Mimikatz&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* UAC&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* MSSQL&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Listening Services&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Kernel&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Linux&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Shared Library&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Sudo&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Groups&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Listening Services&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Ansible (Unix)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* lse / Linpeas&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* JFROG&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Lateral Movement:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* LAPS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Unconstrained Delegation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Constrained Delegation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Resource Based Constrained Delegation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* MSSQL Linked Servers&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Pass the Ticket&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Tickets in /tmp&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Pass The Hash&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Relay The Hash&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Crack the Hash&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* RDP / SharpRDP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Web Application&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Fileless Lateral Movement&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Mimikatz&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Ligolo-ng/chisel/Proxychains / Autoroute / SSH (Port Fowarding)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Bloodhound/SharpHound[.exe/.ps1]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* JFROG&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* KEYTAB (Kerberos)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* SSH&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Ansible&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* SPOOLSS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Reuse of passwords (.\administrator NOT domain\administrator)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* adPeas.ps1&lt;br /&gt;
&lt;br /&gt;
[[Category:Offensive Security]]&lt;/div&gt;</summary>
		<author><name>imported&gt;Aghanim</name></author>
	</entry>
</feed>