Reconnaissance

Almost everything in Active Directory is readable by any authenticated account, and much of it from an unauthenticated network position. Before attacking authentication, you read the domain to find what to attack: which accounts have weak or roastable credentials, which permissions are delegable, where privileged users are logged on, and how domains trust each other. This reconnaissance feeds every other technique, so it comes first.

What you are mapping#

  • The domain and its hosts: domain controllers, naming contexts, functional levels, and reachable machines.
  • Objects and attributes: users, computers, groups, and the LDAP attributes that reveal SPNs, delegation flags, and secrets left in fields.
  • Sessions: where users, especially admins, are currently logged on, for targeting.
  • Policy: the password and lockout policy that bounds spraying.
  • Attack paths: the graph of permissions and relationships that BloodHound turns into a route to Domain Admin.

Pages#

References#

  • The Hacker Recipes: Active Directory recon
  • Microsoft: Active Directory Domain Services documentation

Cookie Consent

We use cookies to enhance your experience. Learn more