Scenario · mcu-avengers

MCU tenant · AVENGERS.LOCAL

Familiar MCU organizations map to a multi-site Active Directory forest. The names are mnemonic; the skills are real enumeration, trusts, and privilege paths.

Topology

Three sites, one AD forest.

HQ identity in New York, a SHIELD trust edge in Washington, and a Tokyo research segment — a topology you can read in one glance.

SITE · NEW YORKAVENGERS.LOCAL10.66.10.0/24 · HQ identitythor-dc01 · DCstark-fs01 · filesSITE · WASHINGTONSHIELD.GOVExternal trust edgefury-dc01SITE · TOKYOResearch lab10.66.30.0/24 · app tierweb-tokyoSTUDENT BOXAttacker / Kali

Domains & trusts

Identity boundaries worth enumerating.

MCU organization names label the domains; treat them as security boundaries the same way you would in any multi-domain enterprise.

AVENGERS.LOCALPrimary domainHQ identity plane — leadership, operations, and shared services
SHIELD.GOVExternal trustHigh-security government contractor boundary
STARK-INDUSTRIES.COMPartner corpR&D and industrial systems adjacent to HQ
WAKANDA.GOVSovereign segmentStrict access — isolated research division

Locations

Multi-site enterprise layout.

HQ · 10.66.10.0/24

New York Metro

Stark Tower (R&D) · Avengers Compound · Sanctum Sanctorum

thor-dc01 (Domain Controller) · stark-fs01 (File Server)

SHIELD HQ · 10.66.20.0/24

Washington D.C.

S.H.I.E.L.D. Headquarters

fury-dc01 (Secondary / trust edge)

Lab segment · 10.66.30.0/24

Tokyo Research

Stark Industries JP R&D

web-tokyo (Vulnerable app tier)