
OSCP field notebook: merged technique vault and numbered notes. MIT.

Port-indexed pentest methodology notebook: decision trees, copy-paste command patterns, and lessons from authorized practice boxes (HTB / PG / personal labs). Merged from the older finalnotes-vault into this single tree.
A workflow you can run under time pressure. Commands and decision trees first.
Public study notes for authorized practice only (your labs, HTB/PG, courses you own). No exam keys, no live engagement dumps, no OffSec course content dump.
Repo: https://gitlab.com/WattoCyber/oscp-notes-2026
| What | OSCP-style field notes: decision trees, command patterns, technique cards. |
| Who it is for | OSCP candidates and lab operators who want a workflow they can run under time pressure. |
git clone https://gitlab.com/WattoCyber/oscp-notes-2026.git
cd oscp-notes-2026
# optional: bind placeholders to your lab IPs
# edit 00-Start-Here/Variables.md
python fill-variables.py apply
python fill-variables.py status
python fill-variables.py reset # restore placeholders
Success signal: python fill-variables.py status prints Status: PLACEHOLDERS (before apply) or Status: FILLED (after apply with real IPs in Variables.md). Open Home.md or Find.md (every note, GitLab-clickable). Wikilinks still work in Obsidian. Refresh the catalog with python3 scripts/build-find.py.
Requires Python 3 only (stdlib). No pip install.
Exam/lab scripts (bash first, tables in scripts/data/):
ls scripts/
bash scripts/recon/host-scan.sh TARGET
python3 scripts/recon/nmap-next.py scans/TARGET/svc.xml
bash scripts/shells/rev.sh ATTACKER_IP 443 linux
Find.md Generated catalog of every note (GitLab links)
00-Start-Here/ INDEX.md + Quick-Start, Methodology, Variables, Im-Stuck
Exam/ Cheatsheets/ Charts/
01-Enumeration/ Enumeration-Index.md at root
Automated-Scanners/ Network-Protocols/ Web-Applications/
02-Web-Attacks/ Web-Index.md, Web-Methodology.md at root
Recon/ Injection/ File-Attacks/ HTTP-Techniques/ CMS/
03-Active-Directory/ AD-Index.md, First-User-Playbook.md at root
Enum/ Kerberos/ Credential-Theft/ ACL-Abuse/ ADCS/
Lateral/ Persistence/ CVE-One-Shots/
04-Linux-PrivEsc/ Linux-Index.md + walkthrough at root
CVE-One-Shots/ Filesystem/ Hijacking/ Scheduled-and-Services/
Persistence/ Tools/
05-Windows-PrivEsc/ Windows-Index.md + 3 topic indexes at root
Checklists/ Local-Techniques/ Persistence/ Service-Abuse/
Token-Manipulation/ Tools/
06-Pivoting/ Pivoting-Index.md at root + Tools/
07-File-Transfers/ File-Transfers.md at root + Methods/
08-Shells/ Reverse-Shells.md, Msfvenom.md at root
Shells/ Web/
09-Password-Attacks/ Brute-Forcing-Guide.md at root
Cracking/ Spraying/ Wordlists/
10-Reporting/ Report-Template.md at root + Exam/
11-Tools/ Tools-Index.md at root
Payload/ Recon/ Network/ Code/ CVE/ Custom/
scripts/ exam/lab helpers (data/*.tsv + bash; python for parsers)
fill-variables.py placeholder IP binder
_attachments/ images
In scope
Out of scope (deliberately)
Verify current exam rules on OffSec's exam guide. Scoring tables here are study aids and can go stale.
Placeholders used across notes: ATTACKER_IP, TARGET_IP, DC_IP, MS01_IP, MS02_IP, STANDALONE1..3, INTERNAL_IP, INTERNAL_NET, DOMAIN.
python3 fill-variables.py apply # write your IPs into every .md
python3 fill-variables.py reset # restore tokens (uses .variables-backup.json)
Do not commit applied IPs. Keep Variables.md as placeholders in git.
Samson Laird (SamsonCyber / WattoCyber). Built while grinding OSCP-style labs.
The older standalone finalnotes-vault repo is archived. This tree is the living copy.
MIT for original structure, scripts, and original prose. Technique knowledge is public security tradecraft. Box names refer to public HTB/PG machines; respect each platform's rules.
| What it is not | Not a payload dump, not exam keys, not OffSec course content, and not a substitute for official materials. |
| Size | 512+ markdown notes in numbered engagement order. |