Collection of tips and procedures when pentesting a target. Collected through various sources as well as from own experience, updated with every interesting finding I encounter.

Reconnaissance

Portscanning

Dorking

OSINT

Asset discovery

Testing

Web Application

API testing

SMTP

Active Directory

Password cracking

Misc

Wordlists

Android Application Pentesting

Useful links

Pentest Book - This book contains a bunch of info, scripts and knowledge used during my pentests, by six2dez

Penetration Testing Execution Standard - A new standard designed to provide both businesses and security service providers with a common language and scope for performing penetration testing (i.e. Security evaluations)

PayloadAllTheThings - A list of useful payloads and bypass' for Web Application Security and Pentest/CTF

Mobile Application Cheatsheet - The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics