useful tools
initial domain enumeration
dig $domain TXTfping -asgq 172.16.5.0/24use the second initial scan on the hosts gathered from fping
information gathering
kerbrute userenum /usr/share/wordlists/seclists/Usernames/Names/names.txt -d oscp.exam --dc dc01.oscp.exam -o valid_ad_usersnetexec smb 172.16.5.5 -u htb-student -p Academy_student_AD! --usersnetexec smb $target -u avazquez -p Password123 --pass-polenum4linux -P $target