FLOW ^: Pentest Workflow

Tool Index

Stage-by-stage CPTS tooling index with locally mirrored, checksum-verified downloads.

intermediate updated 2026-08-29 Multiple

[!dashboard] Attack-flow navigation Dashboard: HTB Pentest Attack Flow

Section: 17 of 17 · Focus: Tool Index

Previous: Appendix — Worked Chains · Next: HTB Pentest Attack Flow


🧰 Tool Index — where each lives in the flow

Local attachments ship offline in attachments/ (integrity: SHA256SUMS (GPG signature)) — see the full inventory on the Dashboard. Everything else links to its canonical repo.

[!tip] One-liner install — the pip-side toolchain

# pipx keeps each tool's venv isolated (apt install pipx first)
pipx install netexec impacket certipy-ad bloodyad
pipx install git+https://github.com/dirkjanm/BloodHound.py.git@bloodhound-ce   # bloodhound-ce-python
# handy extras
pipx install git+https://github.com/ShutdownRepo/targetedKerberoast.git || true  # also ships in attachments/
sudo apt install -y seclists wordlists kerbrute feroxbuster enum4linux-ng

Go binaries (kerbrute, fscan, gowitness, chisel, ligolo-ng agents) already ship in attachments/ — no build needed.

StageToolsLocal attachmentsDeep-dive note
0 Passive Reconcrt.sh, dig, Shodan, google dorks, gitleaks, trufflehog, GrayHatWarfare, theHarvester, subfinder, amass2.0 - Cheatsheet - Infrastructure Enumeration Tools · 2.4 - Cheatsheet - Gitleaks · 2.5 - Cheatsheet - TruffleHog · 01 - Stage 00 - Passive External Recon
1 Recon / Host DiscoveryRustScan, nmap, masscan, naabu, faketime, ntpdateRustScan_Cheatsheet · Nmap Cheatsheet 2026 · faketime-cheatsheet · 02 - Stage 01 - Recon and Host Discovery
2 Webffuf, feroxbuster, gobuster, wpscan, nuclei, sqlmap, Burp/ZAP, hydra, dnSpy, EyeWitness, gowitness, ysoserial, ysoserial.netgowitness_linux_amd64 (SHA-256 · GPG signature) gowitness_windows_amd64.exe (SHA-256 · GPG signature) ysoserial-all.jar (SHA-256 · GPG signature) ysoserial.net_v1.36.zip (SHA-256 · GPG signature) nt-webshell-rosepine.aspx (SHA-256 · GPG signature) rp-shell.asp (SHA-256 · GPG signature) rp-shell.jsp (SHA-256 · GPG signature) rp-shell.php (SHA-256 · GPG signature)Ffuf-Cheatsheet · WPScan · sqlmap · LFI - Cheat Sheet · 12 - Attacking Thick Client Applications · 03 - Stage 02 - Web Enumeration and Exploitation
⚙ Foothold Toolkitreverse shells, msfvenom, Metasploit, file transfer (certutil / smbserver / curl), nishang, nc64, donut, ConPtyShell, RunasCsnc64.exe (SHA-256 · GPG signature) nishang-master.zip (SHA-256 · GPG signature) donut_v1.1.zip (SHA-256 · GPG signature)Impacket-Cheatsheet · meterpreter · smbserver.py · 04 - Foothold Toolkit - File Transfers · 05 - Foothold Toolkit - Shells Payloads and Metasploit
3 SMB/RPC/ServicesNetExec, smbclient, smbmap, enum4linux-ng, rpcclient, Snaffler, Responder, ntlmrelayx, mitm6, Inveigh, fscanSnaffler.exe (SHA-256 · GPG signature) Inveigh.ps1 (SHA-256 · GPG signature) fscan_windows_x64.exe (SHA-256 · GPG signature)SMBMAP · Snaffler · 🔴 Attack · 06 - Stage 03 - Service Enumeration
4 AD EnumerationNetExec, ldapsearch, ldapdomaindump, windapsearch, ldeep, kerbrute, bloodhound-ce-python, RustHound-CE, SharpHound, PowerView, SharpViewkerbrute_linux_amd64 (SHA-256 · GPG signature) kerbrute_windows_amd64.exe (SHA-256 · GPG signature) SharpHound.zip (SHA-256 · GPG signature) PowerView.ps1 (SHA-256 · GPG signature) SharpView.exe (SHA-256 · GPG signature)LDAP Search · bloodhound-ce-python-cheatsheet · Kerbrute · 07 - Stage 04 - Active Directory Enumeration
5 KerberosImpacket (GetUserSPNs / GetNPUsers / getST / getTGT), Rubeus, hashcat, kekeoRubeus.exe (SHA-256 · GPG signature)Kerberoasting Cheatsheet · Rubeus-Cheatsheet · 08 - Stage 05 - Kerberos Attacks
6 ACL / Object AbusebloodyAD, PowerView, Impacket (dacledit / rbcd / owneredit / addcomputer), autobloody, StandIn, Whisker, pywhisker, targetedKerberoast, PowermadStandIn_v13_Net35_45.zip (SHA-256 · GPG signature) Whisker.exe (SHA-256 · GPG signature) targetedKerberoast.py (SHA-256 · GPG signature)BloodyAD · Autobloody · 09 - Stage 06 - ACL and Object Abuse
7 ADCSCertipy, Certify, PetitPotam, Coercer, DFSCoerce, ShadowCoerce, krbrelayxCertify.exe (SHA-256 · GPG signature) PetitPotam.py (SHA-256 · GPG signature)Certipy-ad · _ADCS Attack Methodology Guide · _ADCS ESC Attack Index · 10 - Stage 07 - ADCS and Certificate Abuse
8 Passwords / Sprayinghashcat, john, NetExec (spray), hydra, kerbrute (spray), Go365, MSOLSpray, o365spray, CredMaster, CeWL/cupp, username-anarchyGo365_linux_amd64.tar.gz (SHA-256 · GPG signature) MSOLSpray.ps1 (SHA-256 · GPG signature) kerbrute_linux_amd64 (SHA-256 · GPG signature)Hashcat-Cheatsheet · john-cheatsheet · Credential Hunting · 11 - Stage 08 - Password Attacks and Credential Hunting
9 Privilege Escalationlinpeas, winPEAS, PrivescCheck, JAWS, PowerUp, SharpUp, Seatbelt, Watson/Sherlock/WES-NG, GTFOBins, pspy, potatoes (GodPotato, PrintSpoofer, SweetPotato, JuicyPotato, RoguePotato)linpeas.sh (SHA-256 · GPG signature) linpeas_linux_amd64 (SHA-256 · GPG signature) winPEASany.exe (SHA-256 · GPG signature) winPEASx64.exe (SHA-256 · GPG signature) PrivescCheck.ps1 (SHA-256 · GPG signature) jaws-enum.ps1 (SHA-256 · GPG signature) PowerUp.ps1 (SHA-256 · GPG signature) SharpUp.exe (SHA-256 · GPG signature) Seatbelt.exe (SHA-256 · GPG signature) GodPotato-NET35.exe (SHA-256 · GPG signature) GodPotato-NET4.exe (SHA-256 · GPG signature) PrintSpoofer64.exe (SHA-256 · GPG signature) SweetPotato.exe (SHA-256 · GPG signature) JuicyPotato.exe (SHA-256 · GPG signature) pspy32 (SHA-256 · GPG signature) pspy64 (SHA-256 · GPG signature)Linux PrivEsc Cheat Sheet · Windows PrivEsc · 12 - Stage 09 - Privilege Escalation
10 Lateral / Pivot / Lootevil-winrm, Impacket (psexec / wmiexec / secretsdump / smbserver), ligolo-ng, chisel, sshuttle, mimikatz, SharpWMI, SharpDPAPI, LaZagne, proxychains-ng, dnscat2, pypykatz, lsassy, nanodumpchisel.exe (SHA-256 · GPG signature) chisel_linux_amd64 (SHA-256 · GPG signature) ligolo-ng_agent_linux_amd64.tar.gz (SHA-256 · GPG signature) ligolo-ng_agent_windows_amd64.zip (SHA-256 · GPG signature) mimikatz_trunk.zip (SHA-256 · GPG signature) SharpWMI.exe (SHA-256 · GPG signature) SharpDPAPI.exe (SHA-256 · GPG signature) LaZagne.exe (SHA-256 · GPG signature)Impacket-Cheatsheet · Ligolo-ng Cheat sheet · Mimikatz-Cheatsheet · 13 - Stage 10 - Lateral Movement Pivoting and Loot
11 Reportingnote-taking, PoC capture, SysReptor/pwndoc, CVSS 4.0 calculator, retest10 - Proof of Concept & Post-Engagement · 15 - Stage 11 - Documentation and Reporting
🌲 Truststicketer/mimikatz (SID history), raiseChild, Rubeus asktgs, nltest, Get-DomainTrust, DSInternalsmimikatz_trunk.zip (SHA-256 · GPG signature) Rubeus.exe (SHA-256 · GPG signature)🔶 Attack · 🔶 Attack · 14 - Domain Trusts and Cross-Forest
🧬 Worked ChainsForest · Resolute · Fluffy · web→AD pattern (step-by-step: 16 - Appendix - Worked Chains)HTB-Forest · Resolute · HTB-Fluffy

Quick-reference tables

Hash → hashcat mode (memorize for the exam)

MaterialSample prefixhashcat -mjohn format
Kerberoast RC4 TGS$krb5tgs$23$13100krb5tgs
Kerberoast AES128 / AES256$krb5tgs$17$ / $18$19600 / 19700krb5tgs
AS-REP roast$krb5asrep$23$18200krb5asrep
NetNTLMv2 (Responder/Inveigh)user::DOMAIN:...5600netntlmv2
NTLM (from DCSync/SAM)32-hex1000nt
MSSQL 2012+0x0200...1731mssql12

GhostPack / SharpCollection family — which binary does what

Binary (ships in attachments/)JobStage
Rubeus.exe (SHA-256 · GPG signature)Kerberos: roast, asktgt/asktgs, delegation, ticket injectStage 05
Certify.exe (SHA-256 · GPG signature)ADCS template/CA enum + ESC abuseStage 07
Seatbelt.exe (SHA-256 · GPG signature)Host situational awarenessStage 09
SharpUp.exe (SHA-256 · GPG signature)Privesc misconfigs (C# PowerUp)Stage 09
SharpDPAPI.exe (SHA-256 · GPG signature)DPAPI masterkeys / credential blobsStage 10
SharpWMI.exe (SHA-256 · GPG signature)WMI lateral movementStage 10
SharpView.exe (SHA-256 · GPG signature)C# PowerView port (AD enum)Stage 04

[!warning] No official GhostPack releases These binaries come via the SharpCollection builds — verify each against SHA256SUMS (GPG signature) and expect AMSI/Defender to flag them (AMSI-bypass or obfuscate via donut_v1.1.zip (SHA-256 · GPG signature) shellcode only where authorized).

Pivot picker — which tunnel when

SituationReach forWhy
Full TUN interface through one footholdligolo-ng (ligolo-ng_agent_windows_amd64.zip (SHA-256 · GPG signature))Real routes; nmap/nxc work natively, no proxychains
Quick SOCKS over one TCP stream, HTTP-friendly egresschisel (chisel.exe (SHA-256 · GPG signature) / chisel_linux_amd64 (SHA-256 · GPG signature))Single binary, works through proxies/WAFs
SSH available on the pivotsshuttleNo binary on target needed
Only DNS egressdnscat2 / iodineLast resort; slow

Potato picker — SeImpersonate/SeAssignPrimaryToken → SYSTEM

Target OSFirst tryFallback
Server 2016 / Win10 <1809 (or anything old)JuicyPotato.exe (SHA-256 · GPG signature)SweetPotato.exe (SHA-256 · GPG signature)
Server 2019/2022, Spooler runningPrintSpoofer64.exe (SHA-256 · GPG signature)SweetPotato.exe (SHA-256 · GPG signature)
Server 2019/2022+, Spooler disabledGodPotato-NET4.exe (SHA-256 · GPG signature) (.NET 4) or GodPotato-NET35.exe (SHA-256 · GPG signature) (.NET 3.5)SweetPotato.exe (SHA-256 · GPG signature) (EfsRpc mode)

[!tip] CPTS exam tip whoami /priv is the first command on any Windows foothold. SeImpersonatePrivilege + any potato = SYSTEM in under a minute; SeDebugPrivilege → mimikatz/procdump LSASS; SeBackupPrivilege → copy SAM/SYSTEM/ntds.dit.

[!tools] Modern toolchain (2026) — quick reference

  • cmeNetExec (nxc) — CrackMapExec is legacy.
  • BloodHound Legacy → BloodHound CE + bloodhound-ce-python / RustHound-CE collectors.
  • ADCS by hand → Certipy (certipy-ad find -vulnerable) / on-host Certify.
  • Missing a Go binary? kerbrute, fscan, gowitness, chisel and ligolo-ng agents are already in attachments/.

[!opsec] Before staging any attachment Every binary in attachments/ is signatured by modern AV/EDR (Rubeus, mimikatz, Snaffler especially). Verify hashes against SHA256SUMS (GPG signature), stage only on in-scope lab hosts, and delete artifacts on cleanup (Stage 11).

[!info] Companion notes

  • Most-Used-Commands — the raw per-tool syntax reference this guide leans on.
  • Attack-Flow-Guide — service-by-service enumeration playbooks + decision trees (built from the 0xdf CPTS-prep boxes).
  • AD_Pentest_Tools_Cheat_Sheet — one-line summary of every AD tool.
  • The AD-Attack category folders (#1–#78) are the exhaustive per-technique deep dives; this guide links the relevant one at each step.

[!abstract] > USING_THIS Work the spine (recon → enum → the AD stages), and every time loot drops a new credential, restart from STAGE 4 as that identity — new user = new BloodHound edges = new surface. Keep /etc/hosts and the clock in sync the whole way. Reverse every AD write you make (STAGE 6 OPSEC). Flags on HTB usually fall at foothold and DA; the stages between are the grind this playbook is for.

Authorized HTB lab / CPTS practice only.


[!navigation] Continue the attack flow Previous: Appendix — Worked Chains

Dashboard: HTB Pentest Attack Flow

Next: HTB Pentest Attack Flow