Pillaging

🌐 Network

  • Interfaces

  • Subnets

  • Routing

  • DNS

  • ARP

  • Ports - connections

  • VPN

  • Shares


πŸ–₯ System Role

  • Hostname

  • Domain

  • Roles

  • GPOs

  • Auth Type

  • Sessions


πŸ” Identity

  • Users

  • Groups

  • Admins

  • Services

  • Tasks

  • Tokens

  • SSH Keys

  • Stored Creds


πŸ›‘ Security

  • Password Policy

  • Lockout Policy

  • LAPS

  • AV/EDR

  • Firewall

  • MSI Policy

  • Service Paths

  • Binary Permissions


πŸ“‚ Sensitive Data

  • Scripts

  • Configs

  • Backups

  • Documents

  • DB Strings

  • Mail Archives

  • Vaults

  • Registry Creds

  • SAM/SYSTEM

  • Share Data


πŸ”„ Lateral Movement

  • Cached Creds

  • Kerberos

  • RDP History

  • Mounted Drives

  • Admin Logons

  • Remote Tools

Last updated