Back to Mission Brief
Public Launch
Tier 02
Advanced
Lv.4

Mission launch sequence armed

Public operators can step into the live sandbox immediately. The start route now frames the run as a checkpoint mission with visible reward pressure and the next unlock already in view.

Mission HUD

Confirm the domain foothold

Checkpoint Progress
0 / 5
Reward Bar89% primed

Before touching the directory, verify which principal the workstation actually gave you.

XP Cache

+400 XP

Mission Window

~90 min

Final Proof

Domain compromise proof, path graph, and priority remediation list.

What You Earn

Completion Badge

Domain Breach Architect

Clearance Upgrade

Enterprise Pivot Clearance

Next Unlock

AWS Cloud Security - Misconfigurations

Objective Count

5 checkpoints

Unlock Requirement

Recommended after clearing the OWASP strike run.

Live Mission Workspace
Browser sandbox is live
Booting
Public
Mission booting

One move is live at a time. Stage the current command, read the result, and earn the next unlock.

Active Stage
Stage 1/5
XP Banked

0/400 XP

Chain Streak

No chain yet

Mission Level

Lv.4 • Stage 1/5

Reward Meter

20% charged

0 min in session
10.10.32.14
Booting
mission-console@kyveraad-attack-paths
[bootstrap] Active Directory Attack Paths session requested
[objective] Enumerate the domain, roast the exposed service account, and capture the proof artifact from the DA path.
[connect] evil-winrm -i 10.10.32.14 -u analyst -p 'Spring2026!'
Toolkit Drop • Stage 1
Confirm the domain foothold

Only one move is armed. Stage it, read the output, then verify the exact clue you extracted.

Next Unlock
Domain foothold logged
+80 XP
Intel Packet

Before touching the directory, verify which principal the workstation actually gave you.

Reward Drop
Domain foothold logged
Lv.4
Toolkit Command
whoami
Field Notes

Notes persist in this browser immediately. Save the mission later if you want the protected member handoff.

Mission HUD
Enumerate the domain, roast the exposed service account, and capture the proof artifact from the DA path.
Checkpoint Chain
0/5

No chain yet

Reward Charge
Artifact unlock20%
First Reward

Clear the first checkpoint to unlock your first debrief badge, XP drop, and the next sealed stage.

Confirm the domain foothold
Live
Domain foothold logged

Before touching the directory, verify which principal the workstation actually gave you.

Start by verifying which principal the workstation session is using.

whoami
Enumerate service accounts
Locked
Roast target found

Future stage stays sealed until the current checkpoint is verified.

Use the recovered material
Locked
Pivot landed

Future stage stays sealed until the current checkpoint is verified.

Confirm the elevated path
Locked
DA path exposed

Future stage stays sealed until the current checkpoint is verified.

Capture the domain-admin proof
Locked
DA proof secured

Future stage stays sealed until the current checkpoint is verified.

Toolkit + Intel
What You Earn
Badge
Domain Breach Architect
Clearance
Enterprise Pivot Clearance
Proof Artifact
proof.txt
Completion Unlock
Domain compromise proof, path graph, and priority remediation list.
Target
Attack workstation in CYBERFORGE.LAB
Connection
evil-winrm -i 10.10.32.14 -u analyst -p 'Spring2026!'
Access
Domain user: analyst / password: Spring2026!
Success Artifact
proof.txt
Current Objective
Confirm the domain foothold

Before touching the directory, verify which principal the workstation actually gave you.

Streak Continuity
Sign in after the run if you want checkpoint history and future streak preservation.
Continue in Member App

Sign in only if you want to continue inside the protected workspace after this public sandbox run.

Launch Sequence
1

Stage one checkpoint at a time instead of dumping the whole walkthrough at once.

2

Read the terminal output closely. Each checkpoint stays sealed until the verification signal matches.

3

Clear this mission to unlock the next queue tile: AWS Cloud Security - Misconfigurations.

Session Access

This public start flow lands in the same live mission workspace a member uses after auth. Authentication only gates saved notes, streak continuity, and the protected handoff inside /app/labs/ad-attack-paths.

Member Extras

Sign in when you want recruiter-facing proof, checkpoint history, saved streaks, and the protected next-mission queue.

Queue AWS Cloud Security - Misconfigurations