An assumed-breach internal assessment. From a single seeded credential, Pentest Copilot discovered all five Windows hosts across both forests, proved code execution and SYSTEM on the member servers, and worked the directory's own permissions the rest of the way — with an evidence tier on every weakness the lab documents.