Pentest methodology and enumeration checklist
A phase-by-phase attack lifecycle for CTFs and OSCP-style labs. Work through the phases in order, and branch by service when you find web, file sharing, database or remote access ports.
Phase 01: Host Discovery & Surface Mapping
4 items. Reconnaissance & Port Sweep
Phase 02: Protocol & Service Enumeration
18 items. Deep Non-Exploitative Service Inspection
Phase 03: Vulnerability Identification & Threat Modeling
4 items. CVE Correlation & Attack Surface Mapping
Phase 04: Foothold Execution & Initial Access
5 items. Weaponization & Shell Acquisition
Phase 05: Shell Stabilization & Context Triage
4 items. Interactive TTY & Environment Audit
Phase 06: Internal System & Network Reconnaissance
4 items. Automated Enumeration & Artifact Discovery
Phase 07: Privilege Escalation & Lateral Movement
11 items. Gaining Root / SYSTEM Privileges
Phase 08: Post-Exploitation, Flag Vault & Artifact Collection
4 items. Root Looting & Documentation
Track progress per machine. Open the checklist in ZeroBox