Tools / Operator Flow
Red Team Playbooks
Practical operator references with prerequisites, command templates, decision points, evidence, common failures, and related learning paths. EXO cites these canonical pages from Chat and Engagements.
Active Directory Initial Enumeration
Establish domain, DC, LDAP, SMB, DNS, Kerberos, and trust context before choosing credential or graph collection paths.
3 command templates · 3 decision points
LDAP Enumeration
Collect naming contexts, users, groups, computers, delegation hints, and policy data with correct LDAP syntax.
3 command templates · 3 decision points
AS-REP Roasting
Identify accounts with Kerberos pre-authentication disabled and request AS-REP material for approved offline audit.
2 command templates · 3 decision points
Kerberoasting
Find SPN-bearing users and request service tickets for authorized password-strength auditing.
3 command templates · 3 decision points
BloodHound Collection
Collect AD graph data after credentials are available and scope permits collection.
2 command templates · 3 decision points
NTLM Relay
Assess relay viability only when active relay testing is in scope and explicitly approved.
2 command templates · 3 decision points
ADCS Enumeration
Discover certificate authorities and risky templates before any certificate request testing.
2 command templates · 3 decision points
Ligolo Pivoting
Use Ligolo tun routing for scoped internal access through an approved pivot host.
3 command templates · 3 decision points
Windows Privilege Escalation
Triage Windows local privilege escalation with evidence-first checks before exploit selection.
3 command templates · 3 decision points
Linux Privilege Escalation
Triage Linux privilege escalation through identity, sudo, SUID, capabilities, cron, and writable-path evidence.
3 command templates · 3 decision points
OT/ICS Discovery
Perform low-impact OT discovery that identifies protocols and roles without unsafe writes.
2 command templates · 3 decision points