Capstone · AD lateral-movement investigation
Build a small authorized lab with a workstation, member server, and domain controller. Starting from a low-privilege test account, produce a written investigation that demonstrates one permitted remote-administration path and one defensive control.
Acceptance criteria
- A diagram names trust boundaries, identities, protocols, and prerequisites.
- Every action has a scope statement and redacted evidence reference.
- The path is reproducible from a clean snapshot without disabling controls.
- At least one failed attempt is explained rather than hidden.
- Detection and mitigation are tested independently.
- The final teach-back distinguishes observation, inference, and verified claim.
The capstone is complete when a reviewer can reproduce the evidence and understand the limits of the conclusion. It is not complete because a command returned a prompt.