A working/living curated checklist that can be modified as needed for various penetration testing engagements. Please feel free to build, modify and edit this list as you like.
Note taking: OneNote, GoogleDocs, GitBook, notepad++, Joplin, Obsidian
Screen shots: Snipping tool, Greenshot, ShareX (GIF/video creation)
Network Screenshots: Eyewitness, Gowitness, Aquatone
PROJECT LINKS:
DATE RANGE: October 28st 2022 - November 28, 2022
EXTRA NOTES:
Passive Enumeration | Task Completion |
---|---|
Websites: | |
☐ | |
☐ | |
☐ | |
☐ | |
DNS: | |
☐ | |
☐ | |
☐ | |
☐ |
OSINT | Task Completion |
---|---|
Social Media Checks: | |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
Cross-Platform Checks: | |
☐ | |
☐ | |
Email: | |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
Google Dorks: | |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
Breaches & Business: | |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
Images: | |
☐ | |
☐ | |
☐ |
External Enumeration | Task Completion |
---|---|
Major scanners: | ☐ |
☐ | |
☐ | |
☐ | |
Directory Searches: | |
☐ | |
☐ | |
☐ | |
☐ | |
Web: | ☐ |
☐ | |
☐ | |
☐ | |
☐ | |
WAF: | ☐ |
☐ | |
☐ | |
Scans: | ☐ |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
☐ |
Internal Enumeration | Task Completion |
---|---|
Basic Setup: | ☐ |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
Metasploit: | ☐ |
☐ | |
☐ | |
☐ | |
☐ | |
DNS: | ☐ |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
Kerberos Abuse/NTLM: | ☐ |
☐ | |
☐ | |
☐ | |
☐ | |
MS-RPRN RPC: | ☐ |
☐ | |
☐ | |
SMB/SNMP/RPC: | ☐ |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
Brute-Forcing: | ☐ |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
Specific Scans: | ☐ |
☐ | |
☐ | |
☐ | |
☐ | |
Specialized Scans: | ☐ |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
Fuzzers: | ☐ |
☐ | |
☐ | |
Create Lists for: | ☐ |
☐ | |
Information Disclosures: | ☐ |
☐ | |
☐ | |
☐ | |
☐ |
Post Exploitation | Task Completion |
---|---|
Tools: | ☐ |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
Permissions/Information: | ☐ |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
☐ | |
Writeable Checks: | ☐ |
☐ | |
☐ | |
☐ | |
☐ | |
☐ |
Please feel free to hit me up on Mastodon @apiratemoo if you have any questions, comments or concerns. You are free to use/edit/improve this list as you wish.
Happy Hacking 😄