Attack Flow Diagram
A chained internal pentest flow from foothold to privilege expansion, designed for walkthroughs and operator planning.
Open the site's visual references from one place, whether you need threat-model sketches, attack-path diagrams, protocol views, or methodology walkthroughs.
Interactive diagrams available to open in dedicated views.
Topic groupings spanning methodology, architecture, AD, malware, and post-exploitation.
Inline previews on this page, with dedicated detail routes for the full set.
Preview a few representative diagrams inline before opening the full-size views.
A chained internal pentest flow from foothold to privilege expansion, designed for walkthroughs and operator planning.
A compact view of the Active Directory lab layout, including domain controller, member systems, and operator footholds.
A high-level operator map covering looting, privilege expansion, pivoting, and cleanup decisions.
A cross-functional architecture map for secure delivery, design reviews, and security activities across the SDLC.
Each card opens a dedicated route for the diagram and links back to the page where it currently appears in context.
Internal Pentest
A chained internal pentest flow from foothold to privilege expansion, designed for walkthroughs and operator planning.
Lab & Infrastructure
A compact view of the Active Directory lab layout, including domain controller, member systems, and operator footholds.
Red Team Ops
A visual map of command-and-control staging, redirectors, team servers, and operator traffic paths.
Threat Modeling
A data-flow style diagram for framing trust boundaries, processing nodes, and threat-modeling discussions.
Active Directory
A privilege and dependency map for showing how attackers chain AD relationships into full domain control.
Methodology
A stage-by-stage overview of the internal pentest lifecycle, from pretext and access to cleanup and reporting.
IoT & Hardware
An end-to-end diagram for IoT assessments covering field devices, gateways, message paths, and cloud services.
Active Directory
A concise view of ticket flows, service accounts, and common Kerberos abuse paths in Windows environments.
Red Team Ops
A simple offensive sequence map for modeling initial access, execution, and follow-on tradecraft.
Post Exploitation
A route map through Linux escalation paths, service abuse, misconfigurations, and local privilege expansion.
Malware Analysis
A workflow diagram for moving from triage into static analysis, dynamic analysis, and deeper reverse engineering.
Architecture
An architecture view for Model Context Protocol deployments, connectors, and trust boundaries.
Network Security
A layered model of the OSI stack with attack references, useful for grounding network-security content.
Methodology
A reconnaissance workflow showing how sources, pivots, enrichment, and attribution fit together.
Malware Analysis
A Portable Executable map for malware reversing, section parsing, and binary triage.
Post Exploitation
A post-exploitation view of scheduled tasks, autoruns, services, and long-term foothold options.
Physical Security
A physical assessment map covering entry points, defensive controls, and operator techniques.
Post Exploitation
A high-level operator map covering looting, privilege expansion, pivoting, and cleanup decisions.
Threat Intel
A visual explanation of adversary indicators, ordered by how much pressure defenders apply when they detect them.
Architecture
A cross-functional architecture map for secure delivery, design reviews, and security activities across the SDLC.
Methodology
A visual sequence of the web testing lifecycle, from recon to exploit validation and reporting.
Post Exploitation
An escalation map for token abuse, service paths, local misconfigurations, and Windows foothold expansion.
Methodology
A wireless assessment map covering discovery, capture, attack decision points, and validation flows.