Most pentest training stops at the scan. You learn to run a tool, read the output, and then the lesson ends right where the real work begins. This session takes one target from a cold start all the way to a shell, the way you would on a real engagement, and then asks the question the client is actually paying for: what does this mean, and what should they do about it?
This post is the read-ahead and the takeaway. Use it to prep before the meetup, then come back to it for the commands and the method.
What a pentester actually does
A penetration test is not “run a scanner and send the report.” It’s a structured engagement with a shape that rarely changes:
- Scope and rules of engagement. Before any scan, you agree on what you’re allowed to touch: the IP ranges and network segments in scope, what’s off limits, and who your point of contact is if something breaks. A working email thread that spells out the scope is usually enough to start; a signed authorization letter is better to have.
- Recon and enumeration. Passive first (what’s exposed to the world without touching them), then active (scanning the in-scope hosts). You split your findings into external and internal.
- From finding to foothold. You identify vulnerabilities, decide which are worth attacking, and work toward access on the one service that’s actually exploitable.
- The report. The report matters more than the findings. The client needs to know what each finding means for them and what to do next. A critical marked “critical” has to explain why, and a one-page summary for stakeholders is often worth more than the 40-page appendix.
The attack methodology that never changes
One line runs through every engagement, and it’s the same for attackers and defenders:
Identify hosts → identify open ports → identify the services on those ports → identify the vulnerabilities in those services.
From there the attacker tries to take advantage of a vulnerability; the defender makes sure it’s logged and alerted. Same map, two seats. (That’s exactly where the next meetup, Attack & Defend, picks up.)
A few rules of thumb from the session:
- Vulnerable is not exploitable. A service can show an old, scary version and still be a honeypot, a patched build, or simply not reachable the way you’d need. Confirm before you spend time on it.
- Mind the scope. Something juicy that isn’t in scope is a trap. Trying it is one thing; putting findings about it in the report is scope creep. Stay inside the lines and ask your point of contact when in doubt.
- Access is a spectrum. When you exploit a machine you often land as whoever is logged in. If that happens to be an admin, you’re an admin. If it’s a limited user, that’s where the next phase begins.
The commands we ran on stream
Everything below was run against lab targets Cover6 owns and has marked as authorized to attack. Only ever run these against systems you own or have written permission to test.
Start narrow. Scan the most common ports, show only what’s open, and grab service versions:
nmap -v -T4 -sV -Pn --top-ports 10 --open target
Reading the flags: -v is verbose (show results as they come in), -T4 is the speed, -sV is a service-version scan, -Pn assumes the host is up and skips the ping, --top-ports 10 checks the ten most common ports, and --open shows only the ports that are open — which is what you care about most.
Widen the net when the first pass is thin. The same target on the top 100 ports surfaced a service the top 10 missed:
nmap -v -T4 -sV -Pn --top-ports 100 --open target
Go all the way when you need to:
nmap -v -T4 -sV -Pn -p- --open target
-p- scans all 65535 ports. It’s slower, so kick it off and keep working while it runs.
Once you have a service and a version, the mental database starts. Your first entry, when the version is new to you, is a plain search: how to exploit [service] [version]. If an exploit exists, there’s usually a write-up, a proof of concept, and an author behind it. If there are 200 results showing how to exploit a version, that version probably shouldn’t be on anyone’s network.
Why we like a scan database
For anything past one host, keeping findings in a workspace saves the engagement. In Metasploit you can organize targets into named workspaces (external vs internal, per client), and then query what you’ve collected:
hosts
services
services -p 22
vulns
services -p 22 lists every host with SSH open — which becomes the target list for your next step, instead of copying IPs by hand. On a real engagement you might have hundreds or a thousand hosts after the first week of enumeration, and this is how you stay on top of them.
Vulnerability, exploit, payload
Three words you’ll use constantly once you cross from scanning into exploitation:
- Vulnerability — the weakness in the service.
- Exploit — the code that takes advantage of that weakness.
- Payload — the communication channel it rides on, plus what happens once you’re connected.
One more distinction worth knowing early: a bind shell means you connect to the target; a reverse shell means the target connects back to you. The reverse shell is usually quieter, because outbound traffic (especially over 443) looks more like normal communication in the logs. Hold that thought — it’s the whole point of the defender’s seat in the next session.
Land your first shell
The exploitation half of the night was hands-on, and the best way to learn it is to do it yourself, not read it. First Shell is the free Cover6 lab that runs in your browser with nothing to install. You get a set of credentials and a target you’re authorized to attack, and the challenge is simple: get 6 of the 10 shells.
👉 Start here, free: https://www.cover6solutions.com/product/cover6-first-shell-free-access/
As you work, remember the loop: scan narrow, widen when it’s thin, read the version, confirm it’s really exploitable, then pick your exploit and payload. The green plus at the end is anticlimactic on purpose — most of the time there are no fireworks, just a prompt. Type whoami, and if it says root, the machine is yours, and in the logs it looks like the machine did it to itself.
Where this path leads
Pentester Fundamentals is the Penetration Tester stop on the Chrysalus career paths, right after SOC Analyst Fundamentals. Build your free Chrysalus profile to show employers what you can do, and add your First Shell run as a project.
- Read the Pentester Roadmap 2026.
- Not sure this is your lane? Take the free career path assessment.
- Use the Cover6 Field Manual as a free reference while you work.
- Browse every Cover6 course.
Want the deeper version? The Pentester Prep Labs take this from fundamentals to exam-ready. Join The 6, our free newsletter, to hear what’s next.
Watch the replay
We ran this live in the Cover6 Community. The full session walks the methodology end to end and shows the recon and the foothold on a lab target we own, then hands it to you in First Shell. Planning to attend a future meetup? Use this post as your read-ahead. The replay is above, and the next session, Attack & Defend, takes the same attack and watches it from the defender’s seat.
