From OSCP course
ALWAYS ASK YOURSELF WHY IT EXISTS
offsec discord
https://www.emmanuelsolis.com/oscp.html https://notes.l1nuxkid.dev/oyecp-active-directory-checklist
https://michalszalkowski.com/\
https://nored0x.github.io/red-teaming/windows-enumeration/#find-all-passwords-in-all-files
run winpeas as admin
include root admin, password, and lowercase usernames in the passwords file
Do a new enumeration from one internal machine, sometimes more ports are available from an internal machine which might grant access to a vulnerable webserver that can be exploited for rce and them root access granting you even more right and then start dumping creds again.
if stuck nmap twice
make a tiny metyholody checky using below
always check os inject aswelll ; osscomannd