1. Used WinRM to sign in to the Shanghai Domain controller, authenticated using compromised employee credentials. 2. Enumerated AD domain/forest structure, trust relationships, all Domain Controllers ...