Red Team Ops
Ten phases against the environment you built. Every action is journaled, every technique is scored, everything stays inside 10.10.10.0/24.
Reconnaissance
Passive and active discovery of the isolated /24. Map hosts, ports, and services without triggering alerts.
External Enumeration
Probe SMB, LDAP, Kerberos, and DNS to enumerate users, groups, shares, and policies.
Initial Access
Obtain the first foothold. In-lab this simulates a phishing payload landing on WIN01 as a domain user.
Command & Control
Shape traffic so the beacon looks like normal HTTPS. Add persistence at the right integrity level.
Privilege Escalation
Move from standard user to local admin on WIN01 by abusing the weaknesses seeded in Week 7.
AD Enumeration
With a foothold, map the domain: users, groups, ACLs, sessions. Feed the graph to BloodHound.
Lateral Movement
Pivot from WIN01 to FS01 using stolen credentials or ticket material. Do not touch DC01 yet.
Domain Dominance
Escalate to DA in the isolated lab. Practice restraint: no golden ticket without a clear rollback plan.
Detection Review
Swap chairs. Walk through what the blue-team pipeline caught, missed, or fired late.
Remediation & Retest
Fix the specific weaknesses the operation exploited. Restore snapshots. Run the same kill chain again.