Solo su macchine tue o lab (THM/HTB). Segue la struttura di MITRE ATT&CK.
| Tecnica | Come funziona | Tool / comando |
| sudo misconfig | Binari eseguibili come root → shell (GTFOBins) | sudo -l |
| sudo NOPASSWD su binario | Escape del binario a shell root | GTFOBins |
| sudo LD_PRELOAD/env_keep | Libreria malevola caricata da root | manuale |
| SUID/SGID abuse | Binario gira come owner root | find / -perm -4000 |
| SUID custom binary | Reversi/abusi un SUID non standard | ghidra/strings |
| Capabilities abuse | cap_setuid su python/perl → root | getcap -r / |
| Cron job scrivibile | Script root modificabile → reverse shell | cat /etc/crontab |
| Cron wildcard injection | tar/rsync con * → argument injection | manuale |
| PATH hijacking | Binario chiamato senza path assoluto | manuale |
| Writable /etc/passwd | Aggiungi utente root con hash noto | openssl passwd |
| Writable /etc/shadow | Sostituisci l'hash di root | manuale |
| Writable service/systemd unit | Modifichi un servizio eseguito da root | manuale |
| Writable systemd timer | Persistenza+privesc via timer | manuale |
| NFS no_root_squash | Crei SUID root da un client montato | manuale |
| Docker group abuse | Utente in gruppo docker → root host | docker run -v /:/mnt |
| lxd/lxc group abuse | Container privilegiato monta l'host | manuale |
| disk group abuse | Accesso raw ai dischi | debugfs |
| Kernel exploit | CVE del kernel (DirtyPipe, DirtyCow) | searchsploit |
| Password/hash nei file | Credenziali in config/history/backup | grep -r password |
| SSH key riutilizzate | Chiavi private trovate riusate altrove | manuale |
| Sudo CVE-2021-3156 | Baron Samedit heap overflow di sudo | exploit |
| pkexec (PwnKit) | CVE-2021-4034 polkit → root locale | exploit |
| Polkit/D-Bus abuse | Servizi privilegiati richiamabili | manuale |
| MySQL UDF privesc | User Defined Function → comando come mysql | raptor_udf |
| Enumerazione automatica | Trova tutti i vettori sopra | linpeas.sh |
| Tecnica | Come funziona | Tool / comando |
| SeImpersonate (Potato) | Abusa impersonation → SYSTEM | PrintSpoofer · JuicyPotato |
| SeBackup/SeRestore | Leggi SAM/SYSTEM o scrivi file protetti | manuale |
| SeDebug | Accesso a processi privilegiati | mimikatz |
| SeTakeOwnership | Prendi possesso di file/servizi | manuale |
| Unquoted service path | Spazio nel path senza virgolette | wmic service |
| Weak service permissions | Puoi modificare il binario/config del servizio | accesschk |
| Weak registry (service) | Modifichi ImagePath del servizio | reg |
| DLL hijacking | DLL malevola in un path di ricerca | manuale |
| AlwaysInstallElevated | MSI installati come SYSTEM | reg query |
| Autorun/startup abuse | Eseguibile scrivibile in Run key | autoruns |
| Scheduled task abuse | Task di alto privilegio modificabile | schtasks |
| Stored credentials | cmdkey, Credential Manager, unattend.xml | cmdkey /list |
| SAM/SYSTEM hive dump | Estrai hash dalle hive | reg save+secretsdump |
| Token impersonation | Ruba/duplica token privilegiati | incognito |
| UAC bypass | Eleva senza prompt (fodhelper, ecc.) | UACME |
| PrintNightmare | CVE-2021-34527 spooler → SYSTEM | exploit |
| HiveNightmare/SeriousSAM | SAM leggibile da utente | CVE-2021-36934 |
| Registry autoelevate | Chiavi scrivibili di servizi privilegiati | winPEAS |
| Named pipe impersonation | Server pipe malevolo | manuale |
| Enumerazione automatica | Trova i vettori sopra | winPEAS · PowerUp |
| Tecnica | Come funziona | Tool / comando |
| Domain enumeration | Utenti, gruppi, trust, ACL | bloodhound-python |
| PowerView recon | Query AD da host compromesso | PowerView |
| BloodHound path | Percorso più breve a Domain Admin | SharpHound |
| AS-REP roasting | Utenti senza pre-auth → hash crackabile | GetNPUsers |
| Kerberoasting | TGS di service account → crack offline | GetUserSPNs |
| Targeted Kerberoast | Setti un SPN via ACL poi roast | PowerView |
| Pass-the-Hash | Autentichi con l'hash NTLM | psexec -hashes |
| Pass-the-Ticket | Riusi un ticket Kerberos rubato | mimikatz |
| Overpass-the-Hash | Hash NTLM → ticket Kerberos | Rubeus |
| Golden Ticket | TGT forgiato con hash krbtgt | mimikatz |
| Silver Ticket | TGS forgiato per un servizio specifico | mimikatz |
| Diamond/Sapphire Ticket | Ticket forgiati più furtivi | Rubeus |
| DCSync | Ti spacci per DC e chiedi gli hash | secretsdump -just-dc |
| DCShadow | Registri un DC finto per scrivere in AD | mimikatz |
| Unconstrained delegation | Cattura TGT su host delegato | Rubeus |
| Constrained delegation abuse | S4U per impersonare utenti | getST |
| Resource-based delegation (RBCD) | Scrivi msDS-Allowed... per impersonare | rbcd.py |
| ACL abuse (GenericAll) | Reset password/aggiungi a gruppo | PowerView |
| WriteDACL/WriteOwner | Ti concedi diritti sull'oggetto | PowerView |
| AddMember abuse | Ti aggiungi a un gruppo privilegiato | net group |
| GPO abuse | Modifichi una GPO per eseguire su molti host | SharpGPOAbuse |
| Zerologon | CVE-2020-1472: reset password del DC | exploit |
| noPac (sAMAccountName) | CVE-2021-42278/42287 → DA | noPac.py |
| PetitPotam | Coercizione auth del DC → relay ADCS | PetitPotam.py |
| PrinterBug (SpoolSample) | Coercizione via spooler | printerbug.py |
| LLMNR/NBNS poisoning | Cattura hash NTLM in rete | responder |
| NTLM relay a LDAP/SMB | Relay per privilegi/DCSync | ntlmrelayx |
| ADCS ESC1-ESC8 | Abuso template certificati → DA | Certipy |
| Shadow Credentials | Scrivi msDS-KeyCredentialLink | pywhisker |
| Password spray dominio | Una password su tutti gli utenti | kerbrute |
| Trust abuse (inter-domain) | SID history / cross-forest | mimikatz |
| Tecnica | Come funziona | Tool / comando |
| PsExec | Esegue comandi su host remoto via SMB | psexec.py |
| WMI exec | Esecuzione remota via WMI | wmiexec.py |
| WinRM/Evil-WinRM | Shell via gestione remota Windows | evil-winrm |
| SMB exec / at / schtasks | Task remoti per eseguire | smbexec.py |
| DCOM lateral | Esecuzione via oggetti DCOM | dcomexec.py |
| SSH lateral | Riuso chiavi/credenziali su altri host | ssh |
| RDP hijack/pivot | Sessioni RDP per muoversi | xfreerdp |
| CrackMapExec sweep | Testa credenziali su tutta la subnet | nxc smb |
| Living-off-the-land (LOLBins) | Usa binari legittimi (certutil, bitsadmin) | LOLBAS |
| SCM remote (services) | Crea servizio remoto | sc \\host |
| Tecnica | Come funziona | Tool / comando |
| Cron / systemd timer | Riesecuzione periodica su Linux | crontab |
| Registry Run keys | Avvio automatico su Windows | reg |
| Scheduled task | Task pianificato di persistenza | schtasks |
| New/backdoor account | Utente nascosto con privilegi | net user |
| SSH authorized_keys | Aggiungi la tua chiave pubblica | manuale |
| Web shell | Backdoor persistente nella webroot | manuale |
| WMI event subscription | Persistenza fileless su Windows | PowerShell |
| Service creation | Nuovo servizio che riavvia il payload | sc create |
| Startup folder | Eseguibile nella cartella Startup | manuale |
| BITS job | Persistenza via Background Intelligent Transfer | bitsadmin |
| Accessibility backdoor | sethc.exe/utilman sostituiti | manuale |
| Golden Ticket (dominio) | Accesso persistente a tutto l'AD | mimikatz |
| Skeleton key | Password master su tutto il dominio | mimikatz |
| SID history injection | Aggiungi SID privilegiati a un utente | mimikatz |
| Bootkit/rootkit | Persistenza a basso livello | avanzato |