docs: overhaul and expand GOAD deployment checklist for clarity and completeness#247
Merged
Conversation
…al use **Added:** - Provided explicit instructions for using the checklist, including marking progress and referencing source of truth files - Added a "How to use" section to guide operators through checklist procedures - Introduced new sections: LDAP Hardening Bypasses, Host Hardening Bypasses, DNS/Trust/Audit Configuration, and GOAD Variants for alternate lab setups - Added per-host ESC configuration notes and template publication context - Included coverage tracking table for each checklist section to support progress tracking - Listed additional variants of GOAD labs for completeness **Changed:** - Rewrote nearly all checklist items to use unchecked `[ ]` boxes by default, so operators can track status for each new operation - Clarified host, domain, group, and user descriptions, removing historical validation checkmarks and focusing on current-state readiness - Reorganized categories for more logical attack chain flow (provisioning, enumeration, poisoning, Kerberos, ADCS, MSSQL, privesc, lateral, trust, CVE, post-ex) - Updated service, user, group, and ACL attack path details for consistency, accuracy, and cross-referencing with Ansible roles and config.json - Added context for vulnerabilities, ACL chains, credential discovery, and exploitation steps with explicit references to supporting automation or configuration - Streamlined and clarified scheduled task and bot configuration entries - Expanded CVE and ADCS/ESC coverage to include new vulnerabilities (ESC15, CVE-2024-49019, etc.) - Refined and reorganized validation summary to support per-section coverage tracking and future operations **Removed:** - Eliminated operation-specific validation checkmarks and timestamps to keep the checklist reusable for future engagements - Removed redundant or outdated explanatory notes that are now covered in the instructions or section headers - Removed detailed per-operation validation summaries in favor of a resettable progress table at the end
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Key Changes:
Added:
Changed:
Removed: