Attacking an Active Directory domain on an authorized HTB box/lab. Trigger this when you detect a Domain Controller (ports 88 Kerberos, 389/636 LDAP, 445 SMB, 5985 WinRM) or a .htb domain. Covers: enumeration (BloodHound, netexec, ldapdomaindump), AS-REP roasting and Kerberoasting (impacket), password spraying, ACL and delegation abuse, Pass-the-Hash, secret extraction (secretsdump), and access via evil-winrm. Produces an escalation path to Domain Admin.