AD Domain (OpIndex)
## Domain Info
## Domain / DC / Scope
Domain:
DC-IP:
DC-Hostname:
Initial creds:
Time synced:
## Hosts
| IP Hostname | Role | Access | Notes |
| ----------- | ---- | ------ | ----- |
| | | | |
## Credentials
| user | pass/hash/ticket | source | where it works |
| ---- | ---------------- | ------ | -------------- |
| | | | |
## Credential Replay / Access Matrix
One row per credential per target.
| credential | target | smb | winrm | ldap | rdp | mssql | local admin | notes |
| ---------- | ------ | --- | ----- | ---- | --- | ----- | ----------- | ----- |
| | | | | | | | | |
## Logged-on Users / Sessions
| host | privileged user seen | source (quser/qwinsta/etc) | notes |
| ---- | -------------------- | -------------------------- | ----- |
| | | | |
## Shares / Loot
| host | share | access | useful files / creds |
| ---- | ----- | ------ | -------------------- |
| | | | |
## Kerberos Findings
AS-REP:
Kerberoast:
Tickets:
## LDAP / BloodyAD Findings
- interesting groups:
- interesting users:
- writable objects:
- delegation:
- `gpo` / `acl` path:
## Attack Chain
- current foothold:
- next smallest abuse step:
- blocked by:
## Rerun Triggers
- new credential:
- new host access:
- new reachability:
- what must be replayed now: