Phase 05 · After the Foothold

Post-Exploitation & Priv-Esc

Initial access is rarely the access that matters. This phase is what a real attacker does next: escalate from a low-privilege shell to full control, establish persistence, move laterally to richer targets, collect evidence of impact — and then clean up so the environment is returned to its original state.

00

About this phase

A foothold as an unprivileged user demonstrates little on its own. Privilege escalation turns it into administrator or root; persistence keeps the access; pivoting uses the compromised host as a stepping stone deeper into the network; and looting gathers the evidence that proves business impact. Meterpreter ties many of these together. Critically, post-engagement cleanup — removing tools, payloads, and accounts — is part of professional practice, not an afterthought.

This phase shares ground with the defensive side of the site — the Kill Chain and Host Forensics describe the very artifacts a tester leaves behind and a defender hunts for.
Lessons
6 live
Phase
05 of 08
Status
Complete
01

Lessons in this phase