Cybersecurity students and OSCP candidates
Preparing for the OSCP exam or practicing in the PWK labs to internalize AD attack vectors
The OSCP Active Directory mind map is a specialized technical resource designed for cybersecurity professionals and students preparing for the Offensive Security Certified Professional exam. This template covers 82 distinct nodes of critical security assessment data, providing a structured workflow for evaluating Windows domain environments. It serves as a comprehensive OSCP Active Directory cheat sheet, detailing specific command-line syntax for tools like Mimikatz and Hashcat. The map is organized into high-level attack phases, starting with the verification of Local Administrator/System Privileges and moving through advanced exploitation techniques. By mapping out the relationship between AD Enumeration and Lateral Movement, users can visualize the path from initial access to domain compromise. This OSCP Active Directory template is an essential reference for documenting penetration testing steps and ensuring no critical enumeration vector is overlooked during time-sensitive lab or exam scenarios.
Terms and ConditionsPreparing for the OSCP exam or practicing in the PWK labs to internalize AD attack vectors
Conducting a professional internal penetration test on a Windows-based corporate network
Building a standardized methodology for red team operations involving Active Directory exploitation
Download and open the .xmind file in Xmind desktop to view the full 82-node Active Directory exploitation tree.
Replace the generic tool commands in the Mimikatz and Hashcat branches with your preferred flags or specific lab IP addresses.
Use Xmind markers or checkboxes to highlight which AD Enumeration steps you have completed during your live security assessment.
This template includes a structured methodology for AD exploitation, covering initial enumeration, privilege escalation, credential harvesting with Mimikatz, and lateral movement techniques like Pass the Ticket and Overpass the Hash.
Navigate to the Lateral Movement branch to decide your next step based on whether you have obtained a hash or cleartext credentials. It provides specific tools like pth-winexe and evil-winrm for different scenarios.
Yes, the template is fully editable. You can add your own custom PowerShell scripts, update Hashcat flags, or include personal notes from your OSCP lab experience to customize the workflow.
Follow the Kerberoasting branch to find the exact PowerShell command for Invoke-Kerberoast.ps1, then transition to the Cracking node to see how to format the output for Hashcat mode 13100.
Share your mind map templates with creators around the world and start earning from your work.