01Enumerate more before you exploit. 90% of the time the path is something you missed, not something you tried. If you've been stuck for 20 minutes, you haven't enumerated enough.
02Document as you go. Screenshot every finding. Log every command. You will not remember what you ran 3 hours later. Your report is built in real-time, not at the end.
03Always check UDP. FTP, SSH, HTTP are obvious. SNMP on 161, TFTP on 69, DNS on 53 · these are UDP and missed by default TCP scans. Run UDP top-1000 on every target.
04Version numbers are your best friends. Every service version is a potential CVE. Copy it into searchsploit and Google before you try anything else.
05Try the obvious first. Default credentials. Anonymous login. Guest shares. Common passwords. Admin/admin. You'd be amazed how often the boring path works.
06Re-enumerate when stuck. Run a new scan. Look at port 631, 873, 2049, 8080, 8443. Check what you dismissed the first time. Run gobuster with a different wordlist.
07Read the source. Web app? View source. JS files matter. API endpoints in comments matter. robots.txt and .git folders matter. Check them all.
08Check internal services. After getting a shell: ss -tlnp, netstat -ano, ps aux. Services running on 127.0.0.1 are invisible externally but are your best PrivEsc leads.
09One shell is never enough. The moment you get a foothold, establish persistence or a second shell before doing anything else. Don't lose access because you closed a terminal.
10If it feels like a rabbit hole, it probably is. CTF and real PT both contain dead ends. Set a 20-minute timer. If no progress, try a completely different vector. Sunk cost kills.