Windows:
Post-Exploitation
Windows post-exploitation enum, creds, loot, and file transfer guides
Transferring Files to and from Windows
Covers techniques for moving files between attacker and Windows targets post-compromise, including common transfer methods like SMB, HTTP, and PowerShell.
Windows File and Data Loot Collection
Techniques for locating and extracting sensitive files, credentials, and user data from compromised Windows systems during post-exploitation reconnaissance.
Windows Local Situational Awareness
Enumerate local Windows system info, users, groups, privileges, network config, and running processes to build situational awareness post-compromise.
Windows Network Reconnaissance Post-Exploitation
Covers post-exploitation network reconnaissance on Windows systems, including enumeration of hosts, shares, active sessions, and domain topology using native tools.
Windows Post-Exploitation Enumeration Tools
Covers key Windows post-exploitation enumeration techniques using tools like WinPEAS, PowerView, and BloodHound to identify privilege escalation paths and lateral movement opportunities.
Windows Token and Credential Harvesting
Covers techniques for extracting Windows access tokens and credentials post-compromise, including token impersonation, LSASS dumping, and privilege escalation.