Once you land on a machine. Source is https://www.youtube.com/watch?v=dO2cZu7090A&ab_channel=SecureIdeas (goldmine, study it)
tasklistarp -asysteminfotracert 8.8.8.8powershell Get-AdComputer -filter *nltest /DOMAIN_TRUSTS /PRIMARY
nltest /DCLIST <DOMAIN NAME>
nslookupC:\\..\\>nslookup
> set type=srv
> _ldap._tcp.dc._msdcs.DOMAIN.local
...
> _ldap._tcp.gc._msdcs.DOMAIN.local
...
net user /domain
net view /domain
net group /domain
Get Domain Admins