OSCP Skylark Relia Guide: Lab Methodology and Attack Path Analysis

The OSCP Skylark Relia Guide focuses on the methodology behind two PEN-200 Challenge Labs: Relia and Skylark. Rather than treating them as collections of individual machines, the most useful approach is to understand how hosts, credentials, network segments, services, and Active Directory relationships connect to form an attack path.

Relia and Skylark are valuable because they force you to move beyond the familiar pattern of scanning one machine, finding an exploit, obtaining a shell, and moving on. Enumeration becomes continuous. A compromised host can reveal credentials, another subnet, an internal service, or a route toward a completely different part of the environment.

This guide focuses on that process and the lessons you can carry into OSCP preparation.

What Are Relia and Skylark in PEN-200?

Relia and Skylark are Challenge Labs included in OffSec’s PEN-200 training environment.

Unlike isolated practice machines, Challenge Labs are designed around larger environments where information discovered on one system may become relevant somewhere else.

This changes the way you should approach them.

Instead of asking:

“How do I exploit this machine?”

start asking:

“What does this machine reveal about the rest of the environment?”

That distinction is central to both Relia and Skylark.

The official OffSec PEN-200 Learning Plan includes Relia and Skylark among its Challenge Labs, making them useful environments for practicing the enumeration and attack-path methodology developed throughout PEN-200.

Start With an Asset Map

Before attempting exploitation, map what you can actually see.

For every discovered system, record:

  • IP address
  • hostname
  • operating system
  • exposed ports
  • detected services
  • web applications
  • discovered users
  • credentials
  • network interfaces
  • possible relationships with other hosts

Do not rely entirely on tool output.

Maintain your own attack map.

A simple table such as:

Host → Service → User → Credential → Access → Next Host

can become extremely useful once the environment grows.

The goal of the OSCP Skylark Relia Guide methodology is to turn enumeration results into relationships rather than maintain an increasingly long list of disconnected findings.

How to Approach Relia

Relia should be approached as a multi-host penetration test.

Begin with the externally reachable attack surface and identify which systems provide realistic entry points.

Your first enumeration phase should answer several basic questions:

  • Which machines are reachable?
  • Which services are exposed?
  • Are any web applications present?
  • Can usernames be identified?
  • Are file shares accessible?
  • Are authentication portals exposed?
  • Are there unusual services worth investigating?

Avoid immediately searching every service version for an exploit.

Enumeration should come first.

Initial Foothold in Relia

The first foothold is important, but gaining a shell does not mean the enumeration phase has ended.

In fact, it often means a new enumeration phase has started.

After compromising a system, investigate:

  • local users
  • running services
  • configuration files
  • stored credentials
  • shell history
  • scheduled tasks
  • interesting files
  • network interfaces
  • routing information
  • internal DNS information
  • connections to other systems

One overlooked network interface can be more valuable than a privilege escalation vulnerability.

If the compromised machine has access to another subnet, it may be functioning as a bridge into an internal network.

That makes it a potential pivot point.

Pivoting and Internal Network Discovery OSCP Skylark Relia Guide

Pivoting is one of the most important concepts to practice in Relia.

Suppose your attacking machine can reach:

192.168.XX.0/24

but a compromised host can additionally reach:

172.16.XX.0/24

That second network should immediately become part of your attack map.

Your workflow becomes:

Initial foothold

↓

Inspect network interfaces and routes

↓

Identify another network

↓

Establish a pivot

↓

Enumerate the internal network

↓

Identify new services

↓

Continue the attack path

Do not assume that the next target must be directly accessible from Kali.

In multi-host environments, the route to the next system may exist only through a machine you already compromised.

Re-Enumerate After Every Foothold OSCP Skylark Relia Guide

One of the most important habits in Relia is re-enumeration.

Use this cycle:

Enumerate → Exploit → Enumerate Again → Correlate → Pivot → Repeat

Every new level of access changes what you can see.

A low-privileged shell might reveal a credential.

That credential might work against another service.

The second system might reveal another subnet.

The internal subnet might expose Active Directory infrastructure.

Your attack path develops through these relationships.

Track Every Credential OSCP Skylark Relia Guide

Never leave discovered credentials buried inside your notes.

Create a credential matrix.

For example:

UserCredential SourceTested ServiceResult
user1Configuration fileSMBValid
user1Configuration fileSSHInvalid
svc_accountApplicationWinRMValid

Whenever you discover a new credential, ask:

Where else could this logically work?

Potential authentication surfaces can include:

  • SMB
  • SSH
  • WinRM
  • RDP
  • web applications
  • databases
  • internal APIs
  • Active Directory services

This does not mean blindly trying every password against every service.

Credential testing should follow evidence gathered during enumeration.

Active Directory in Relia

When Active Directory becomes part of the environment, your methodology should shift again.

Start mapping relationships between:

  • users
  • groups
  • computers
  • service accounts
  • administrators
  • accessible shares
  • remote management services
  • Kerberos services
  • permissions

A username alone is not particularly valuable.

A relationship is.

For example:

User → Group → Computer → Permission

or:

Credential → Service Account → Host → Privileged Access

These relationships help turn Active Directory enumeration into an actual attack path.

How to Approach Skylark

Skylark requires the same fundamental methodology but places even more importance on organization.

The larger your attack surface becomes, the easier it is to waste time.

Start by building an inventory instead of immediately attacking whichever service looks most interesting.

For each host, determine:

  1. What can I access?
  2. What information does it expose?
  3. Does it connect to another system?
  4. Do I have credentials associated with it?
  5. Does it expose another network?
  6. Have I already discovered something elsewhere that is relevant here?

This prevents random exploitation.

Prioritize the Skylark Attack Surface

Not every exposed service deserves equal attention.

Prioritize systems that provide information or access capable of expanding your attack surface.

Examples include:

  • web applications
  • file shares
  • remote administration services
  • source-code repositories
  • databases
  • authentication services
  • Active Directory infrastructure
  • development systems
  • management interfaces

A service does not need to produce a shell to be valuable.

It might instead reveal:

  • a username
  • password
  • internal hostname
  • configuration file
  • network path
  • software relationship
  • additional application

That information may unlock another system later.

Correlate Findings Across Skylark

Consider three discoveries made at different times:

Host A reveals a username.

Host B exposes a configuration file.

Host C requires authentication.

Individually, none may provide immediate access.

But if the configuration file contains credentials belonging to the user found on Host A and those credentials work on Host C, you have discovered an attack path.

This is why good notes matter.

The attack path may not become obvious until hours after the original information was discovered.

Build an Attack Graph

Instead of maintaining only a list like:

Host A - HTTP

Host B - SMB

Host C - SSH

record relationships:

Host A → username

Host B → credential

credential → user

user → Host C

Host C → internal subnet

internal subnet → domain controller

Now you can see where the assessment is moving.

This is one of the most important lessons from the OSCP Skylark Relia Guide methodology.

The relationship between assets is often more important than the individual vulnerability.

Attack Path Analysis

A typical multi-host methodology can be represented as:

External Attack Surface

↓

Initial Foothold

↓

Local Enumeration

↓

Credential Discovery

↓

Privilege Escalation

↓

Network Discovery

↓

Pivot

↓

Internal Enumeration

↓

Additional Authentication

↓

Active Directory Enumeration

↓

Privilege Relationship

↓

Further Compromise

This is a methodology model rather than an exact Relia or Skylark solution.

Your actual attack path should always come from evidence discovered during the lab.

Memorizing a walkthrough teaches you where someone else went.

Understanding why they went there teaches you penetration testing.

How to Know Where to Go Next

Getting stuck in Relia or Skylark does not always mean you need another exploit.

Sometimes you need to revisit information you already collected.

When you are unsure what to do next, ask:

What access do I currently have?

List every compromised machine and credential.

What changed after my last foothold?

Check network interfaces, routes, files, users, services, and credentials again.

Did I discover another network?

A new subnet may indicate that pivoting is required.

Did I discover credentials?

Test them against logically related authentication surfaces.

Did I identify another hostname?

Resolve it and determine whether it exposes a new application or service.

Did my Active Directory visibility change?

New domain credentials may expose users, groups, shares, services, and relationships that were previously unavailable.

Have I re-enumerated everything?

A service that appeared useless earlier may become important after obtaining new credentials.

Recognizing Dead Ends

Not every system leads directly to the next target.

That is intentional in realistic environments.

If you spend a long time attacking a service without obtaining new information, reconsider its role in your attack map.

Ask whether you have:

  • missed another exposed service
  • ignored a credential
  • overlooked an internal hostname
  • failed to enumerate a new network interface
  • forgotten to test newly obtained access
  • skipped authenticated enumeration
  • missed useful information on an already compromised machine

Enumeration gaps frequently look like exploitation problems.

Relia vs. Skylark

Relia and Skylark should both be treated as multi-system penetration testing environments rather than collections of unrelated machines.

Relia is useful for practicing the transition from an initial foothold into broader network enumeration, credential tracking, pivoting, and attack-path development.

Skylark reinforces the same principles across a larger attack surface where maintaining structured notes and correlating discoveries becomes increasingly important.

In both environments, the essential skills are:

  • disciplined enumeration
  • credential management
  • re-enumeration
  • pivoting
  • service correlation
  • Active Directory analysis
  • attack-path mapping

The objective should not simply be to compromise every host.

You should understand why each compromise made the next one possible.

Common Relia and Skylark Mistakes

Exploiting Before Enumerating

Do not assume every open port requires an exploit.

Understand the service first.

Treating Every Host Independently

Information from one system may unlock another.

Always correlate findings.

Forgetting Network Interfaces

After compromising a host, check its interfaces and routes.

It may expose an entirely new network.

Ignoring Credentials

Maintain a credential matrix and update it continuously.

Failing to Re-Enumerate

New access should trigger new enumeration.

Focusing Only on Privilege Escalation

Root or SYSTEM is not always the immediate objective.

A low-privileged host with access to another network may be more strategically valuable.

Searching for the Exact Walkthrough Too Early

When stuck, identify the missing stage first:

Enumeration?

Foothold?

Privilege escalation?

Credential discovery?

Pivoting?

Active Directory?

This helps you solve the underlying problem rather than copy the next command.

A Better PEN-200 Challenge Lab Workflow

Use the following process throughout Relia and Skylark.

1. Enumerate

Identify hosts, ports, services, users, applications, and technologies.

2. Build the Attack Map

Record relationships between discovered assets.

3. Prioritize

Investigate services most likely to expand your access or knowledge.

4. Gain a Foothold

Exploit only after you understand why the target is interesting.

5. Re-Enumerate Locally

Look for users, credentials, configuration, routes, interfaces, and internal services.

6. Escalate When Necessary

Determine whether additional privileges reveal useful access.

7. Pivot

Use compromised systems to reach previously inaccessible networks when required.

8. Re-Enumerate Internally

Treat the newly accessible network as a new penetration test.

9. Correlate Credentials and Identities

Map credentials to users, services, systems, and Active Directory relationships.

10. Update the Attack Path

Continuously document:

How did I get here, and what did this access reveal next?

Why Relia and Skylark Matter for OSCP Preparation

Relia and Skylark help develop a skill that individual practice machines cannot always reproduce: maintaining methodology across a larger environment.

The technical vulnerability is only one part of the problem.

You also need to know when to enumerate, when to pivot, when to test credentials, when to revisit an old service, and when apparently unrelated information should be connected.

This is why the OSCP Skylark Relia Guide


Stuck on OSCP+ or feeling the pressure of the exam clock? Stop wasting hours. Download our fully verified OSCP+ Exam Preparation Pack now and pass on your first attempt!”

Check our services lists : https://cyberservices.store/certifications/offsec/

Vendor : https://www.offsec.com/

OSCP Skylark Relia Guide
oscp exam dump

Limited offer$2,279 $990Save 57%Ends in less than 24 hours

Sitting the OSCP exam?

43 products for the OSCP exam from $125. Walkthroughs, lab sets and ready-to-submit reports, delivered by email within about thirty seconds of payment.

OSCP exam materialHow it works


All OSCP guides

error: Content is protected !!
Contact Us - TG