I passed with 100 points on second attempt AMA

This page summarizes the projects mentioned and recommended in the original post on /r/oscp

Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
  • PEASS-ng

    PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)

  • Adding link to PEAS: https://github.com/carlospolop/PEASS-ng

  • Priv2Admin

    Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.

  • Other than that it was just practice, hacktricks, payload all the things, https://github.com/gtworek/Priv2Admin, and reading writeups even if I rooted a box to make see if there were other ways that it could have been done. Hopefully that helps!

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • AutoRecon

    AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.

  • I used AutoRecon (thanks tibs) and PEAS for both linux and windows privesc. But again, the reason I failed the first time was because I relied to heavily on these tools. I really like the disclaimer on the autorecon github:

  • linux-smart-enumeration

    Linux enumeration tool for pentesting and CTFs with verbosity levels

  • Linux privesc is a bunch of manual checks from my notes that I have built over time. I also like https://github.com/diego-treitos/linux-smart-enumeration (lse.sh) which is similar to linpeas but the output is less busy.

  • OSCP-Priv-Esc

    Mind maps / flow charts to help with privilege escalation on the OSCP.

  • PrivEsc-MindMap

  • pspy

    Monitor linux processes without root permissions

  • I also forgot https://github.com/DominicBreuker/pspy obviously for linux privesc

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • PrivescCheck

    Privilege Escalation Enumeration Script for Windows

  • Seatbelt

    Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts