Domain Info
#Domain / DC / Scope
#Domain:
DC-IP:
DC-Hostname:
Initial creds:
Time synced:
Hosts
#| IP Hostname | Role | Access | Notes |
|---|
| | | |
Credentials
#| user | pass/hash/ticket | source | where it works |
|---|
| | | |
Credential Replay / Access Matrix
#One row per credential per target.
| credential | target | smb | winrm | ldap | rdp | mssql | local admin | notes |
|---|
| | | | | | | | |
Logged-on Users / Sessions
#| host | privileged user seen | source (quser/qwinsta/etc) | notes |
|---|
| | | |
Shares / Loot
#| host | share | access | useful files / creds |
|---|
| | | |
Kerberos Findings
#AS-REP:
Kerberoast:
Tickets:
LDAP / BloodyAD Findings
#- interesting groups:
- interesting users:
- writable objects:
- delegation:
gpo / acl path:
Attack Chain
#- current foothold:
- next smallest abuse step:
- blocked by:
Rerun Triggers
#- new credential:
- new host access:
- new reachability:
- what must be replayed now: