Discovery
- Host discovery and full port scanning
- Service and version fingerprinting
- Map the network and trust boundaries
Enumeration
- Per-service enumeration (SMB, LDAP, SNMP, RDP, DBs)
- Default and weak credentials
- Known-vulnerability mapping
Exploitation & pivoting
- Gain a foothold, then pivot deeper
- Credential reuse across hosts
- Tunnelling into segmented networks
Post-exploitation
- Loot, persistence where in scope, and clean reporting