Step-by-step enumeration and pillaging checklist for every Windows box.
Who you are, what privileges you hold, and the first commands on every Windows box.
Key directories, writable paths, and the filesystem layout that shapes every attack.
ACLs, icacls, and finding misconfigurations that lead to privilege escalation.
CMD, PowerShell, and the shell techniques you need from first access onward.
Running processes, services, scheduled tasks, and their attack surface.
RDP, WinRM, SMB, and PsExec for moving to and between Windows hosts.
Enumerate and access SMB shares for credentials, configs, and sensitive files.
Persistence keys, credential storage, and config secrets hidden in the registry.
Defender, AppLocker, UAC, and the defenses that shape your approach.
Extract credentials, secrets, and sensitive data once you have access.