Free shipping on orders over $99 · Use code LEARN26 for 10% off
Free Trial available for 5 days!4.9 star average ratingFree chapter every monthShipping to 120+ countries Free Trial available for 5 days!4.9 star average ratingFree chapter every monthShipping to 120+ countries
Support · Partner
Get the full year subscription for unlimited reading — 2 months freeBuy a 3-book bundle — 20% off each book!
Back to the blog
PenTest+10 min read

Post-Exploitation: What Real Attackers Do After They're Already In

Getting the first shell is the beginning, not the end. What happens next — persistence, escalation, lateral movement, exfiltration — is where a real compromise is made, and where PT0-003 spends serious weight.

Beginners celebrate the first shell. Professionals know it is where the real work begins. Landing on a single machine as a low-privileged user is not a compromise — it is a toehold. What you do in the minutes and hours after that first foothold is what turns "we got onto a workstation" into "we could have owned the entire company", and that distinction is the whole point of the engagement.

Post-exploitation is a large, heavily-weighted part of PT0-003 precisely because it is where real attacks live. A criminal who lands on one machine and stops is not a threat; a criminal who parlays that one machine into domain-wide access is a breach. The exam tests whether you understand that progression, because understanding it is what lets you demonstrate real impact to a client.

Why the shell is the start

Think about what a single low-privileged shell actually gives you: the ability to run commands as one ordinary user on one ordinary machine. That is not access to anything a client cares about. The database, the file server, the domain — none of it is yours yet. If you reported "we got a shell on a workstation" and stopped, the client would rightly shrug. So would a real attacker, except they would not stop.

The value comes from what that toehold lets you reach. From one machine you can look for stored credentials, escalate to administrator, and use your new position to move to the next machine, and the next, until you reach something that matters. The first shell is a door into a hallway, not a seat in the vault.

The four moves that follow

Post-exploitation is not random rummaging. It is four recognisable objectives, usually pursued in a loop.

1 Persist survive a reboot 2 Escalate user to admin 3 Move to the next host 4 Exfiltrate prove the impact
Land, dig in, climb, spread, and demonstrate reach. This loop repeats until you touch something that matters.

Persistence means ensuring your access survives — a reboot, a closed session, a changed password — so you do not lose the foothold you worked for. Privilege escalation is the climb from ordinary user to administrator or system, unlocking everything on the machine. Lateral movement is using one compromised host to reach others, hunting for the credentials and trust relationships that let you hop across the network. And exfiltration — in a real attack, stealing data; in a test, proving you could have — is how you demonstrate the actual business impact.

What a tester enumerates first# Who am I, and what can I already do?
whoami /priv                 # my privileges, look for escalation
# What is stored on this machine?
#   cached credentials, config files, keys
# Where can I go from here?
#   mapped drives, trust relationships, sessions
# What would let me become admin?
#   unpatched escalations, weak service configs
Revise in one page, not 800CISSP cheat sheet — all 8 domains on a single sheet, $9.99.
Grab it for $9.99

Doing it without getting caught

Here is the part that separates a skilled tester from a noisy one, and a part the exam increasingly cares about. Real attackers are quiet. Every action on a compromised machine risks tripping a defence — an endpoint tool, a logging system, an alert — and a compromise that gets detected and shut down in ten minutes proves far less than one that persists undetected for a week.

Loud proves less than quiet

A tester who blunders through post-exploitation and gets caught has actually done the client a favour by testing their detection — but a tester who moves quietly and reaches the crown jewels undetected proves the far scarier point: a real attacker could have too, and nobody would have known.

This is why understanding the defender's view matters as much as the offensive technique. Knowing which actions are loud, which logs they generate, and how to achieve the objective with the least noise is a genuine skill, and it reflects how real intrusions unfold — slowly, carefully, below the threshold of the alerts. The exam rewards candidates who grasp that post-exploitation is a game of stealth as much as capability.

Why this is the impact you report

Ultimately, post-exploitation is where you generate the finding that actually motivates the client to act. "We found an unpatched service" is abstract. "We used that unpatched service to move from a reception workstation to the domain controller and access every customer record, and here is the proof" is a sentence that changes budgets. The technical vulnerability is the how; post-exploitation is what demonstrates the so-what.

Demonstrated business impact 44% Clear reproduction 24% Severity justification 20% The raw vulnerability alone 12%
Clients act on impact, not on the existence of a flaw. Post-exploitation is how you show impact.

So when you study post-exploitation for PT0-003, do not treat it as a grab-bag of tricks to run after you are in. Treat it as the phase where an isolated vulnerability becomes a demonstrated breach — the phase that produces the finding your report is built around. Master the loop of persist, escalate, move, and exfiltrate, understand how to do each quietly, and you will understand both why the exam weights it heavily and why it is the part of the job that actually makes clients safer.

Why testers must stop before real damage

There is a critical discipline that separates a professional post-exploitation phase from a criminal one, and the exam expects you to understand it. In a real attack, exfiltration means stealing data; in an authorised test, it means proving you could have and then stopping. A professional demonstrates access to the customer database by, say, retrieving a single innocuous record as evidence — not by downloading the whole thing. They prove they reached the domain controller without dumping every credential in the organisation. The goal is to demonstrate impact convincingly while causing the least possible disruption and touching the least possible sensitive data, because you are working under an authorisation that permits testing, not harvesting. Knowing exactly how far to go — far enough to prove the risk, not so far that you have effectively carried out the breach you were hired to prevent — is a judgment the rules of engagement should define and the tester must respect. Getting this wrong turns an authorised test into the very incident it was meant to guard against.

Land, dig in, climb, spread, prove — and know when to stop. That is post-exploitation, and it is the phase where an isolated flaw becomes the demonstrated breach that finally moves a client to act. Study it as the heart of the engagement it is, because on the exam and in the field, the first shell is only ever the beginning of the real work.

Bundle all three best-sellers and save up to $50

A+ Core 1, A+ Core 2 and PenTest+ in one order — $135 in paperback or $80 for all three ebooks. The cheapest route to both certifications.

See the bundle