Directory design

OUs, users, and attack-surface groups

MCU display names make principals easy to keep straight. The OU and group layout mirrors how real enterprises separate privilege, location, and service identity.

Organizational units

Structure under AVENGERS.LOCAL

AVENGERS.LOCAL
├── Users
│   ├── HQ-NewYork
│   ├── SHIELD-Washington
│   └── Wakanda
├── Groups
│   └── Privileged-Groups
├── Computers
│   └── Servers
├── Admins
│   └── Tier-0
└── Service-Accounts

Sample principals

Accounts you will enumerate.

Includes an intentional over-privileged service account from the Kerberoast vuln pack — labeled for teaching, not as a public credential.

SAMDisplayDept / siteGroups
tony.starkTony StarkR&D
New York
Avengers, Stark-RnD
nick.furyNick FuryDirector
Washington
SHIELD, SHIELD-Directorate
natasha.romanoffNatasha RomanoffIntelligence
New York
Avengers, SHIELD
shuriShuriR&D
Tokyo / Wakanda
WakandaCouncil, Stark-RnD
carol.danversCarol DanversDeep Space
Mobile
Avengers
svc_stark_sqlStark SQL Service
Intentional Kerberoast target (lab vuln pack)
Service Accounts
New York
Domain Users, Tier-0-Admins

Security groups

Memorable names, real privilege scopes.

  • Avengers
  • SHIELD
  • Stark-RnD
  • SHIELD-Directorate
  • WakandaCouncil
  • Tier-0-Admins

Next

Follow the walk-through.

Use these principals as hunting targets while you map trusts and SPNs in the procedure guide.