OPERATOR CONSOLE
Isolated AD Red-Team Lab Dashboard
Build, attack, detect, and remediate inside the isolated 10.10.10.0/24 segment.
Network Topology
SUB 10.10.10.0/24Kill Chain Progress
Event Log
Phase 03: Initial Access
0% COMPLETEObtain the first foothold. In-lab this simulates a phishing payload landing on WIN01 as a domain user.
operator@linux01 ~ /ops/access
[*] Session 1 opened: WIN01\jsmith (Medium)
sliver (WIN01) > shell whoami /all
USER INFORMATION: lab\jsmith
PRIVILEGES: SeShutdownPrivilege, SeChangeNotifyPrivilege ...
$
Quick Snapshots
apprenticeship-final
—
pre-exploit-clean
—
Apprenticeship — W4 FS01 Hardening
OPEN →Provision shares, model NTFS + share ACLs, enable access-based enumeration.
FS01.LAB