Enumeration & Lateral Movement
The range runs three hosts on one isolated network with no gateway: dc01, ws01, and your attacker box. Hosts resolve by name.
Methodology, in order:
1. Map — who is on this network? nmap -sn
2. Enumerate — what do they run? Banners, versions, anonymous access.
3. Notice — an over-permissioned account, a readable description, a note left behind.
4. Pivot — credentials found in one place unlock a service elsewhere.
Step 4 is credential reuse, the most common real-world lateral movement path. It's rarely an exploit; it's someone reusing a password.
The discipline that matters: enumerate exhaustively before you touch anything. Most failed engagements are failures of enumeration, not of exploitation.