Metodoloji
Sızma testi, rastgele araç çalıştırmak değil; kapsamı bilinen bir saldırı yüzeyini sistematik olarak genişletip daraltmaktır. Bu bölüm fazlı metodolojiyi Türkçe olarak özetler; modern keşif araçları (bbot, httpx, katana, naabu, nuclei, nxc) ve kimlik odaklı phishing ile birlikte kullanılır.
Bağlam
Section titled “Bağlam”Başlangıç: RoE / kapsam / engelleme listesi / iletişim kanalıDış: varlık → canlı HTTP → crawl → CVE/misconfig → phishingİç: host → servis → kimlik → shell → privesc → loot → persist → pivotAraçlar: bbot, httpx, katana, naabu, nuclei, nmap, nxc, frida, hashcatÜst düzey akış
Section titled “Üst düzey akış”-
Kapsam & fiziksel — RoE, fiziksel erişim varsa BIOS/boot/USB vektörleri.
-
Varlık & recon — dış subdomain/cloud/kod sızıntısı veya iç host keşfi.
-
Port & servis — naabu/nmap, sürüm, NSE; web için katana + nuclei.
-
Sömürü / phishing — servis misconfig, CVE veya kimlik avı ile ilk erişim.
-
İçeride — shell stabilize, privesc, loot, persistence, pivot; gerekirse faz 1’e dön.
Bölümler
Section titled “Bölümler”- Pentest Metodolojisi — faz 0–12 (fizikselden pivot’a)
- Dış Recon Pipeline — subdomain/asset → httpx → katana → naabu → nuclei
- Phishing Metodolojisi — AiTM, device code, clone, kimlik iş akışı
- Fuzzing Metodolojisi — protokol/girdi fuzz’ına genel bakış
İlgili bölümler
Section titled “İlgili bölümler”- Web — uygulama zafiyetleri ve içerik keşfi
- Network — iç ağ tarama, SMB, relay, pivoting
- Active Directory — domain enum, Kerberos, lateral
- Cloud — AWS / Azure / GCP yüzeyi
- Mobile — Android / iOS uygulama testi
Tipik zincir
Section titled “Tipik zincir”bbot + httpx → canlı varlıklar → katana + nuclei (auth sonrası tekrar) → zayıf servis / phishing → shell → privesc → loot → ligolo pivot → AD / cloudTüm konu başlıkları
Section titled “Tüm konu başlıkları”- Adaptixc2 Config Extraction And Ttps
- Android Malware Post-Exploitation
- Anti-Forensic Techniques
- Docker Forensics
- Baseline Monitoring
- Image Acquisition & Mount
- Basic Forensic Methodology
- Ios Backup Forensics
- Linux Forensics
- Malware Analysis
- Memory dump analysis
- Volatility - CheatSheet
- File/Data Carving & Recovery Tools
- Partitions/File Systems/Carving
- DNSCat pcap analysis
- Pcap Inspection
- Suricata & Iptables cheatsheet
- USB Keystrokes
- Wifi Pcap Analysis
- Wireshark tricks
- Decompile compiled python binaries (exe, elf) - Retreive from .pyc
- Browser Artifacts
- Deofuscation vbs (cscript.exe)
- Discord Cache Forensics
- Specific Software/File-Type Tricks
- Local Cloud Storage
- Mach O Entitlements And Ipsw Indexing
- Office file analysis
- PDF File analysis
- PNG tricks
- Structural File Format Exploit Detection
- Svg Font Glyph Analysis And Web Drm Deobfuscation
- Video and Audio file analysis
- ZIPs tricks
- Windows Artifacts
- Interesting Windows Registry Keys
- Defi/AMM Hook Precision
- Defi Amm Virtual Balance Cache Exploitation
- Erc 4337 Smart Account Security Pitfalls
- Blockchain & Crypto
- Value Centric Web3 Red Teaming
- Web3 Signing Workflow Compromise Safe Delegatecall Proxy Takeover
- Mutation Testing With Slither
- Database Leaks
- Github Dorks & Leaks
- External Recon Methodology
- Wide Source Code Search
- Lua Sandbox Escape
- DHCPv6
- EIGRP Attacks
- GLBP & HSRP Attacks
- IDS and IPS Evasion
- Pentesting Network
- Lateral VLAN Segmentation Bypass
- Network Protocols Explained (ESP)
- Nmap Summary (ESP)
- Pentesting IPv6
- Spoofing LLMNR, NBT-NS, mDNS/DNS and WPAD and Relay Attacks
- Spoofing SSDP and UPnP Devices with EvilSSDP
- Telecom Network Exploitation
- WebRTC DoS
- Enable Nexmon Monitor And Injection On Android
- Evil Twin EAP-TLS
- Pentesting Wifi
- Ai Agent Abuse Local Ai Cli Tools And Mcp
- Ai Agent Mode Phishing Abusing Hosted Agent Browsers
- Clipboard Hijacking
- Clone a Website
- Detecting Phishing
- Discord Invite Hijacking
- Homograph Attacks
- Phishing Methodology
- Mobile Phishing Malicious Apps
- Phishing Files & Documents
- Basic Python
- Bruteforce hash (few chars)
- Bypass Python sandboxes
- Js2py Sandbox Escape Cve 2024 28397
- LOAD_NAME / LOAD_CONST opcode OOB Read
- Reportlab Xhtml2pdf Triple Brackets Expression Evaluation Rce Cve 2023 33733
- Class Pollution (Python’s Prototype Pollution)
- Python Sandbox Escape & Pyscript
- Keras Model Deserialization Rce And Gadget Hunting
- Pyscript
- Python Internal Read Gadgets
- venv
- Web Requests
- Side Channel Attacks On Messaging Protocols
- Threat Modeling