Skip to main content

Ad domain

Domain Info
#

Domain / DC / Scope
#

Domain: DC-IP: DC-Hostname: Initial creds: Time synced:

Hosts
#

IP HostnameRoleAccessNotes

Credentials
#

userpass/hash/ticketsourcewhere it works

Credential Replay / Access Matrix
#

One row per credential per target.

credentialtargetsmbwinrmldaprdpmssqllocal adminnotes

Logged-on Users / Sessions
#

hostprivileged user seensource (quser/qwinsta/etc)notes

Shares / Loot
#

hostshareaccessuseful files / creds

Kerberos Findings
#

AS-REP: Kerberoast: Tickets:

LDAP / BloodyAD Findings
#

  • interesting groups:
  • interesting users:
  • writable objects:
  • delegation:
  • gpo / acl path:

Attack Chain
#

  • current foothold:
  • next smallest abuse step:
  • blocked by:

Rerun Triggers
#

  • new credential:
  • new host access:
  • new reachability:
  • what must be replayed now: