Prep references

Penetration testing methodology references

Most exam failures on the practical side are missed enumeration, not missed exploits. These are working references for the methods every offensive-security exam assumes you already have — enumeration order, privilege escalation, web application testing and Active Directory attack paths.

A circular diagram of the offensive-security method: enumerate, identify the version, find the weakness, exploit, escalate and pivot, then repeat until domain admin.
The method these references teach — enumeration first, repeated until you own the domain.