Directory design
OUs, users, and attack-surface groups
MCU display names make principals easy to keep straight. The OU and group layout mirrors how real enterprises separate privilege, location, and service identity.
Organizational units
Structure under AVENGERS.LOCAL
AVENGERS.LOCAL ├── Users │ ├── HQ-NewYork │ ├── SHIELD-Washington │ └── Wakanda ├── Groups │ └── Privileged-Groups ├── Computers │ └── Servers ├── Admins │ └── Tier-0 └── Service-Accounts
Sample principals
Accounts you will enumerate.
Includes an intentional over-privileged service account from the Kerberoast vuln pack — labeled for teaching, not as a public credential.
| SAM | Display | Dept / site | Groups |
|---|---|---|---|
| tony.stark | Tony Stark | R&D New York | Avengers, Stark-RnD |
| nick.fury | Nick Fury | Director Washington | SHIELD, SHIELD-Directorate |
| natasha.romanoff | Natasha Romanoff | Intelligence New York | Avengers, SHIELD |
| shuri | Shuri | R&D Tokyo / Wakanda | WakandaCouncil, Stark-RnD |
| carol.danvers | Carol Danvers | Deep Space Mobile | Avengers |
| svc_stark_sql | Stark SQL Service Intentional Kerberoast target (lab vuln pack) | Service Accounts New York | Domain Users, Tier-0-Admins |
Security groups
Memorable names, real privilege scopes.
- Avengers
- SHIELD
- Stark-RnD
- SHIELD-Directorate
- WakandaCouncil
- Tier-0-Admins
Next
Follow the walk-through.
Use these principals as hunting targets while you map trusts and SPNs in the procedure guide.