Here are my notes for Zero Point Security’s Red Team Ops (RTO) course. Note that many notes linked below may have been combined with notes from other sources.
Messy notes alert
Currently my notes (especially attack vectors) aren’t organized in a very hierarchical manner. While this makes note-taking easy, it tends to also make locating what I need a pain. I’m thinking of building a better map of content later, along with a better tagging system.
- Cite this note as source in all notes referenced below.
- Getting Started
- Cobalt Strike & C2
- External Reconnaissance
- Initial compromise
- Host Reconnaissance
- Host Persistence
- Host Privilege Escalation
- Elevated Host Persistence
- Credential Theft
- Common Password Attacks
- Domain Reconnaissance
- User Impersonation
- Lateral Movement (to-do)
- Session Passing (to-do)
- Pivoting (to-do)
- Data Protection API
- Kerberos
- Active Directory Certificate Services
- Group Policy (to-do)
- MS SQL Servers
- Microsoft Configuration Manager (to-do)
- Domain Dominance
- Trusts
- Local Administrator Password Solution
- Microsoft Defender Antivirus (to-do)
- Application Whitelisting (to-do)
- Data Hunting & Exfiltration (to-do)
- Extending Cobalt Strike (to-do)
- Exam Preparation (to-do)