Skip to main content

Ad domain ( op index)

AD Domain (OpIndex)
#

# Domain Info

## Domain / DC / Scope
Domain:
DC-IP:
DC-Hostname:
Initial creds:
Time synced:

## Hosts

| IP Hostname | Role | Access | Notes |
| ----------- | ---- | ------ | ----- |
|             |      |        |       |


## Credentials

| user | pass/hash/ticket | source | where it works |
| ---- | ---------------- | ------ | -------------- |
|      |                  |        |                |


## Credential Replay / Access Matrix

One row per credential per target.


| credential | target | smb | winrm | ldap | rdp | mssql | local admin | notes |
| ---------- | ------ | --- | ----- | ---- | --- | ----- | ----------- | ----- |
|            |        |     |       |      |     |       |             |       |

## Logged-on Users / Sessions

| host | privileged user seen | source (quser/qwinsta/etc) | notes |
| ---- | -------------------- | -------------------------- | ----- |
|      |                      |                            |       |


## Shares / Loot

| host | share | access | useful files / creds |
| ---- | ----- | ------ | -------------------- |
|      |       |        |                      |

## Kerberos Findings
AS-REP:
Kerberoast:
Tickets:

## LDAP / BloodyAD Findings
- interesting groups:
- interesting users:
- writable objects:
- delegation:
- `gpo` / `acl` path:

## Attack Chain
- current foothold:
- next smallest abuse step:
- blocked by:

## Rerun Triggers
- new credential:
- new host access:
- new reachability:
- what must be replayed now: