Overview
Fascinating Active Directory environment machine that covers multiple attack vectors like ScriptPath attribute manipulation, ForceChangePassword, Resource Based Constrained Delegation, Read only DC, Tickets forging and much more
Enumeration
starting with nmap enumeration to know what we're dealing with here AD environment or web kinda foothold or mixed machine nmap results with windows are messy and big so I'll just show the results
nmap -sC -sV -vv -oA initial 10.129.25.106 -Pn
...
