Outdated was a medium rated windows machine which involved enumerating smb shares, from there getting a list of cve’s and an email, using follina by sending an email on smtp, getting a shell on a container as btables, by running sharphound to enumerate the domain, btables can add shadow credentials…