Network // Internal Operations

Internal Operations

Internal enterprise testing across discovery, trust mapping, credential pressure and controlled operator movement.

15 notesselected referencestechnical reference map

Domain overview

Internal work is rarely about a single exploit. It is about how hosts, services, credentials, protocols and trust assumptions combine into movement paths. This domain is designed to keep that picture coherent.

Related certification context

These certifications are useful orientation points for this domain and are included as context, not as gatekeeping.

Selected public references

Topic index

brief

Introduction

This domain is about internal enterprise work: host and service discovery, trust mapping, credential abuse, lateral movement, pivoting, command infrastructure and evidence capture. The objective is controlled movement with a clear explanation of what enabled it.

2 focus points0 links
brief

Network Pentesting Theory

This domain is about internal enterprise work: host and service discovery, trust mapping, credential abuse, lateral movement, pivoting, command infrastructure and evidence capture. The objective is controlled movement with a clear explanation of what enabled it.

7 focus points2 links
brief

Network Pentesting Practice

This domain is about internal enterprise work: host and service discovery, trust mapping, credential abuse, lateral movement, pivoting, command infrastructure and evidence capture. The objective is controlled movement with a clear explanation of what enabled it.

10 focus points6 links
brief

Password Cracking

Offline and online credential recovery, hash handling and validation trade-offs.

9 focus points0 links
brief

Active Directory Pentesting

Trust mapping, authentication abuse and attack-path validation inside Windows estates.

10 focus points8 links
brief

C2 Frameworks

Operator infrastructure, beacon behaviour and command tradecraft in defended environments.

10 focus points21 link
brief

Thick Client Pentesting

This domain is about internal enterprise work: host and service discovery, trust mapping, credential abuse, lateral movement, pivoting, command infrastructure and evidence capture. The objective is controlled movement with a clear explanation of what enabled it.

8 focus points0 links
brief

Exploit Pack

This domain is about internal enterprise work: host and service discovery, trust mapping, credential abuse, lateral movement, pivoting, command infrastructure and evidence capture. The objective is controlled movement with a clear explanation of what enabled it.

2 focus points2 links
brief

Persistence

Mechanisms that retain execution or access after the first foothold, and how to validate them cleanly.

10 focus points3 links
brief

Pivoting & Portforwarding

Movement through constrained network paths, tunnelling choices and access extension logic.

10 focus points2 links
brief

PowerView Quick Reference

Trust mapping, authentication abuse and attack-path validation inside Windows estates.

1 focus point0 links
brief

Quick Reference

This domain is about internal enterprise work: host and service discovery, trust mapping, credential abuse, lateral movement, pivoting, command infrastructure and evidence capture. The objective is controlled movement with a clear explanation of what enabled it.

10 focus points0 links
brief

Eptp - Pentesting Certification

This domain is about internal enterprise work: host and service discovery, trust mapping, credential abuse, lateral movement, pivoting, command infrastructure and evidence capture. The objective is controlled movement with a clear explanation of what enabled it.

2 focus points1 link