Initial Access¶
Getting the first foothold in the target environment, by exploiting an exposed service, a web application, or a person.
Why It Matters¶
Initial access is where recon turns into a foothold. The vector that works is often the most important finding in the report, because it is the one the defender most needs to close.
Pages¶
| Page | Description |
|---|---|
| Phishing | Social engineering for credentials and code execution |
| Web Authentication Bypass | Defeating login and session controls |
| SQL Injection | Injecting SQL to read data or gain execution |
| XSS | Cross-site scripting against web application users |
| Network Services Attacks | Attacking exposed network services |
| Breaching Active Directory | First access into an AD environment |
| Windows Exploits | Exploiting Windows hosts and services |
| Linux Exploits | Exploiting Linux hosts and services |
Tools¶
| Tool | Use |
|---|---|
| Burp Suite | Web application proxy and testing platform |
| OWASP ZAP | Open-source web application scanner and proxy |
| Hydra | Network login brute forcing |
| Metasploit | Exploitation framework |
| Nessus | Vulnerability scanner |
| Wordlists | Wordlists for brute forcing and fuzzing |
How I Use It¶
I work from the recon picture to the lowest-risk, highest-likelihood vector first: a known-vulnerable exposed service or a weak web application before anything noisier. Once a foothold lands, it leads into Discovery.