Fase 1 active: SIEM agent enrollment on DC01-2022, DC01-SEC, WIN11-22H2-1, WIN11-22H2-2. All other categories below require Fase 2 (ADCS, MSSQL, OPS VMs). AD, Linux PrivEsc, and Reverse Shell techniques are tracked in the external Vulnerabilities matrix and are not yet implemented as ThruntOps roles.
Lab Coverage
All attack techniques, vulnerability classes, and test scenarios available in ThruntOps.
mindmap
root((ThruntOps))
Active Directory
Credential Reuse
RDP to DC
RDP to ADCS
ADCS / PKI
ESC1 Enrollee SAN
ESC2 Any Purpose EKU
ESC3 Cert Request Agent
ESC4 Template Write
ESC5 PKI Object Control
ESC6 EDITF SubjectAltName
ESC7 CA Officer
ESC8 NTLM Relay HTTP
ESC9 GenericWrite no SAN
ESC11 NTLM Relay RPC
ESC13 OID Group Link
ESC14 Weak Mapping
ESC15 Schema v1
ESC16 SecurityExtension Off
MSSQL
xp_cmdshell RCE
NTLM Hash Capture
DBA to Sysadmin
Linux PrivEsc ops
sudo ansible-playbook
sudo ansible-test
sudo certbot
sudo watch
cap_gdb
Reverse Shells
Linux PHP Ruby Python
Linux Node tclsh Perl
Windows PowerShell mshta
Windows certutil cscript wscript
LOLBins Windows
Module installed
Checklist TBD