what do you have?
Start where you are.
Tell the atlas what you hold and it routes you to the exact next moves, in order, with byte-exact commands. Or browse the whole map below.
- I have External access only / 5 moves
- I have Web injection point / 6 moves
- I have Local File Inclusion / 1 move
- I have Foothold (Linux) / 8 moves
- I have Foothold (Windows) / 8 moves
- I have Low-priv domain creds / 6 moves
- I have Crackable hash / 1 move
- I have NT hash / 2 moves
- I have Kerberos ticket / 2 moves
- I have Replication rights / 1 move
- I have krbtgt hash / 1 move
- I have Domain Admin / 2 moves
grab and go
Libraries
- Payloads & Shells Reverse, web, bind shells + listeners + msfvenom. Auto-filled with your IP and port.
- Command Library Linux & Windows, grouped by intent, in the order you need them. Auto-filled with your target.
- CVE Vault The CVEs worth knowing cold · what they are, why they mattered, and working exploitation.
- OWASP Top 10 The ten web-risk categories, each a working reference · how it works, where to look, and copy-ready exploitation.
- Cloud AWS, Azure & GCP offensive security · enumerate, harvest credentials, escalate, and persist, the way you move through a tenant.
- Tools The tools operators actually reach for · the modern recon chain, AD toolkit, C2s, cracking, pivoting, and the reporting stack, each with when to use it.
- Wordlists The other half of every fuzz, crack, and spray · the lists operators reach for, each with the exact path it lives at on Kali.
- External References The wikis, live tools, and cheat sheets worth bookmarking · HackTricks, GTFOBins, PayloadsAllTheThings, RevShells, and more, each with what to use it for.
how to operate
Playbooks
- How to Use Atlas Not a wiki you read, a tool you operate · set your variables, start where you are, pin what works, record as you go, from first recon to the report.
- Methodologies The ordered thinking behind an engagement · enumeration, privesc, lateral movement, AD, and web, each cross-linked to the exact commands.
- What to Record The documentation checklist · scope, hosts, credentials, access, evidence, and cleanup, captured as you go so the report writes itself.
the whole map
Browse the atlas / 97 techniques across 6 domains
+Essentials / 13
+Network / 11
+Web / 20
- Web Application PT
- Fingerprinting & Tech Stack Identification
- Directory & File Enumeration
- Manual Exploration with Burp Suite
- File Upload Exploitation
- Authentication Bypass
- CMS-Specific Attacks
- Endpoint Mapping (Python Crawler)
- Server-Side Template Injection (SSTI)
- Insecure Deserialization
- XML External Entity (XXE)
- JWT Attacks
- NoSQL Injection
- Decision Tree: Web Injection Point → What First?
- SQL Injection (SQLi)
- Cross-Site Scripting (XSS)
- Broken Access Control / IDOR
- Command Injection
- File Inclusion (LFI / RFI)
- Server-Side Request Forgery (SSRF)
+Active Directory / 17
- Active Directory
- Decision Tree: Low-Priv Domain Creds → What First?
- Initial Enumeration
- BloodHound
- Kerberoasting
- AS-REP Roasting
- Password Spraying (Safe)
- Pass-the-Hash (PTH)
- Pass-the-Ticket (PTT)
- Lateral Movement
- DCSync
- NTDS.dit Extraction (Offline)
- Golden Ticket
- ACL / Misconfiguration Exploitation
- AD CS Abuse (ESC1)
- NTLM Relay & Coercion
- Delegation Abuse (Constrained / RBCD)
+Linux / 18
- Linux PrivEsc
- Decision Tree: Shell on Linux → What First?
- Linux Escalation Priorities
- Shell Stabilization
- System Enumeration
- sudo -l → GTFOBins Workflow
- SUID Binary Exploitation
- Cron Job Exploitation
- Password Hunting
- Writable /etc/passwd
- Kernel Exploits
- Linux Capabilities
- NFS Misconfiguration (no_root_squash)
- LinPEAS & pspy Usage
- Container Escapes & Privileged Groups
- One-Shot Local Root: PwnKit & Baron Samedit
- LD_PRELOAD, LD_LIBRARY_PATH & Wildcard Injection
- Writable systemd Services & Timers
+Windows / 18
- Windows PrivEsc & Post-Exploitation
- Decision Tree: Shell on Windows → What First?
- Windows Escalation Priorities
- Immediate Situational Awareness
- SeImpersonatePrivilege → Potato Attack Chain
- Service Misconfigurations
- Registry Password Hunting
- Unattend.xml / Sysprep Credentials
- AlwaysInstallElevated
- Stored Credentials
- Token Impersonation (Incognito)
- WinPEAS
- Mimikatz
- File Transfer Methods
- Windows Loot & Proof
- UAC Bypass
- LSASS Dumping (Offline)
- DPAPI & Browser Credentials