Skip to content

M-Ihsan/PwnPath

Repository files navigation

PwnPath 🔴

Red Team Lab Guide — Zero to Domain Admin

A practical offensive security resource built from real hands-on lab experience. Every technique documented here was executed in a real home lab.

What's Inside

Section Topics Status
Windows Exploitation Payload, Meterpreter, SYSTEM, Hashdump, Pass-the-Hash
Active Directory AS-REP Roasting, Kerberoasting, Mimikatz, Lateral Movement
Web Application SQLi, XSS, Command Injection, Filter Bypass
Cheatsheets Quick reference commands 🔄
Report Templates Professional pentest report formats 🔄
Internship — Week 1 Passive OSINT, subdomain enumeration, Google/GitHub dorking, visual recon ✅ Done

Who This Is For

  • Beginners building their first home lab
  • Students preparing for CEH or eJPT
  • Anyone learning offensive security hands-on

Tools Covered

msfvenom · Metasploit · Nmap · Impacket · Hashcat · Mimikatz/Kiwi · NetExec · Burp Suite · Python3 HTTP Server · Hydra · Gobuster

Home Lab Setup

  • Attacker: Parrot OS on VMware
  • Target 1: Windows 7 SP1 x64
  • Target 2: Windows Server 2012 R2 (Domain Controller)
  • Network: VMware Bridged

Built with real breaks, real errors, and real fixes. Not a tutorial copy. Every command was typed by hand.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors