Overview

Fascinating Active Directory environment machine that covers multiple attack vectors like ScriptPath attribute manipulation, ForceChangePassword, Resource Based Constrained Delegation, Read only DC, Tickets forging and much more

Enumeration

starting with nmap enumeration to know what we're dealing with here AD environment or web kinda foothold or mixed machine nmap results with windows are messy and big so I'll just show the results

shell
nmap -sC -sV -vv -oA initial 10.129.25.106 -Pn

...