A comprehensive offensive security knowledge base β from initial foothold to full domain compromise.
B00t2R00t is a curated encyclopedia of penetration testing and red teaming techniques, methodologies, tools, and ready-to-use scripts. Spanning Active Directory, Cloud, Web, Network, Wireless, and Red Team operations, it's organized around the real attacker kill chain: Enumerate β Exploit β Escalate β Persist.
β οΈ Disclaimer: This material is provided strictly for authorized security testing, research, and education. Only use these techniques on systems you own or have explicit written permission to test. The author assumes no liability for misuse. Unauthorized access to computer systems is illegal.
- New to a target type? Start in
Methodology/β it's the high-level playbook for what to do and in what order. - Need a specific technique? Jump straight to the relevant domain folder below.
- Looking for a tool's syntax? Head to
Tools/β usage docs are separated from techniques on purpose. - On an engagement? Use the methodology as your checklist, then drill into the technique pages as needed.
| Section | What's Inside |
|---|---|
| πΊοΈ Methodology | Step-by-step playbooks for each target type |
| π° Active Directory | Enumeration, exploitation, Kerberos, ADCS, trusts, persistence |
| βοΈ Cloud | AWS, Azure, GCP, Kubernetes |
| π Web Applications | OWASP-style attacks, injection, auth bypasses, WAF evasion |
| π Network Services | Protocol-by-protocol attack references |
| π‘ Wireless | WEP/WPA/WPS attacks, sniffing, MITM |
| π Red Teaming | Evasion, C2, payloads, phishing, exfiltration |
| β¬οΈ Privilege Escalation | Linux, Windows, and Docker escapes |
| π Pivoting | Tunneling, port forwarding, lateral movement |
| π CVEs | Notable exploits and write-ups |
| π€ AI Pentesting | Prompt injection, jailbreaks, model attacks |
| π οΈ Tools | Usage docs for the offensive toolkit |
| π§© Miscellaneous | File transfers, shells, wordlists, neat tricks |
The playbook layer β start here to understand the flow of an engagement before diving into specific techniques.
- Reconnaissance Β· Enumeration Β· Public Exploit Search
- Active Directory β No Creds / One Credential / Valid Credentials paths
- Cloud β AWS, Azure, GCP, Containers
- Privilege Escalation β Linux & Windows
- Web Applications β full web attack workflow
- Protocols β per-service approach (DNS, SMB, SSH, SQL, etc.)
- Lateral Movement Β· Network Pivoting Β· Password Cracking
The most extensive section β a complete AD attack lifecycle.
| Phase | Topics |
|---|---|
| Enumeration | No Credentials Β· Valid Credentials Β· Username Only |
| Exploitation | Kerberos Β· GPO Β· Known Vulns Β· ACL/ACE |
| ADCS | Certificate Services attacks β ESC1βESC10, theft, persistence, mindmaps |
| Kerberos Delegation | Unconstrained / Constrained / RBCD |
| Lateral Movement | PtH, PtT, Pass-the-Cert, WinRM, WMI, more |
| MITM & Relay | NTLM Relay, Responder, coercion attacks |
| Privilege Escalation | DACL attacks, dangerous groups, LAPS, more |
| Persistence | Golden/Silver/Diamond tickets, DCShadow, Skeleton Key, more |
| Trust Relationships | Cross-domain & cross-forest compromise |
| Domain Admin Access | NTDS dumping, DPAPI backup keys |
| Mitigations | Defensive guidance & Event IDs |
Provider-by-provider attack references, each following enum β exploit β privesc β persistence.
- AWS β IAM, EC2, S3, Lambda, EKS, RDS, Secrets Manager, and more
- Azure β Entra ID, managed identities, Key Vaults, app services, abuse paths
- Google Cloud (GCP) β IAM fuzzing, metadata SSRF, privilege escalation
- Kubernetes β cluster recon, node escapes, secrets
- Cross-Platform β Cloudfox, Trufflehog, and multi-cloud tooling
Comprehensive coverage of web attacks:
- Injection: SQLi Β· Command Injection Β· SSTI Β· XXE Β· NoSQL/LDAP/XPath/ORM
- Client-side: XSS Β· CSRF Β· Prototype Pollution
- Server-side: SSRF Β· LFI/RFI Β· RCE Β· Deserialization
- Auth & Tokens: JWT Β· OAuth Β· MFA bypass
- Bypasses: WAF evasion Β· filter bypasses Β· 403 bypass
- Modern: HTTP Request Smuggling Β· GraphQL Β· Browser Desync
A protocol-by-protocol attack library covering: SMB, LDAP, SSH, FTP, RDP, SNMP, SMTP, MSSQL, MySQL, PostgreSQL, MongoDB, Redis, NFS, RPC, IPMI, VNC, VoIP, Java RMI/JDWP, gRPC, WebDAV, and more β plus CI/CD tooling and database navigation.
Full wireless attack coverage: WEP cracking, WPA2-PSK, PMKID, WPS PIN/Pixie Dust, deauth & fake-auth, packet injection/sniffing, MITM, DNS spoofing, and traffic decryption.
End-to-end adversary simulation tradecraft:
- Evasion Techniques β AMSI bypass, AV/EDR evasion, and a deep AV/EDR Architecture breakdown
- Command & Control Β· Data Exfiltration (DNS / ICMP / HTTPS / TCP)
- Advanced Techniques β process injection, hollowing, HTA/JScript
- Payloads Β· Stagers Β· Shellcode Runners
- Spearphishing β macros, OLE/LNK, XLL, device-code phishing
- LOLBins Β· Offensive PowerShell Β· Password Attacks
- Linux β SUID, capabilities, cron, kernel exploits, sudo abuse, and dozens more
- Windows β service misconfigs, potato exploits, DLL hijacking, token abuse, UAC bypass
- Docker Escapes β privileged containers, exposed daemons, namespace abuse
Tunneling and lateral movement: Chisel, Ligolo-ng, SSH tunneling, Proxychains, DNS/HTTP/ICMP tunneling, double pivots, and ready-to-go scripts.
Curated exploit write-ups: Zerologon, noPAC, PrintNightmare, ProxyShell, Certifried, PetitPotam, Log4j, and more.
- AI Penetration Testing β prompt injection, jailbreaking, model inversion, guardrail bypass
- Exploit Development β buffer overflows, race conditions, reverse engineering
- Data Lake Pentesting β Hadoop, HDFS, Kerberos keytabs
- Bug Bounty Hunting β recon automation & workflow
Usage references for the offensive toolkit, grouped by purpose:
- Active Directory β Impacket, NetExec, BloodHound, Mimikatz, Rubeus, Responder, Certipy, and more
- C2 Frameworks β Cobalt Strike (in depth), Sliver, PowerShell Empire
- Enumeration Β· Network Scanners Β· Fuzzers
- Password Crackers β Hashcat, John, Hydra, Medusa
- Phishing Campaigns β Evilginx + phishlets
- Web Applications Β· Exploitation Frameworks Β· Wireless Β· AV Evasion
Handy operational references: file transfer methods (Linux & Windows), reverse shells, shell stabilization, credential harvesting, wordlist creation, and a big bag of neat tricks.
Contributions, corrections, and additions are welcome! Feel free to open an issue or submit a pull request.
See LICENSE.md for details.
β If you find this useful, consider starring the repo! β
Built and maintained by H3llKa1ser
For educational and authorized testing purposes only.