Enumeration is the foundation of every Active Directory attack. AD is a read-heavy service: by design, almost any authenticated principal (and often an unauthenticated one) can read the bulk of the directory over LDAP, which hands an attacker a near-complete map of users, computers, groups, delegations, permissions, and trust relationships. The quality of that map decides which of the later attacks are even reachable, so thorough enumeration comes first.
What you are building#
A picture of the domain detailed enough to pick attacks:
- The terrain: domain and forest names, domain controllers, sites, and the LDAP naming contexts that anchor every query.
- The principals: users, computers, and groups, who is privileged, which accounts are service accounts, and which are stale or mis-set.
- The permissions: the access-control entries on objects that let one principal rewrite another, which are the raw material for privilege escalation.
- The reach: group memberships, Group Policy scope, logged-on sessions, and domain and forest trusts that define lateral and cross-boundary movement.
Collect once, analyze repeatedly#
Modern practice is to collect the directory once and analyze it offline as a graph rather than running ad-hoc queries. BloodHound is the standard for this: it ingests users, groups, ACLs, sessions, and trusts and computes attack paths to a target such as Domain Admins. The pages below cover both the targeted queries and the bulk collection that feeds that graph.
Pages#
- Host and domain discovery: finding domain controllers, the domain and forest, and LDAP naming contexts.
- LDAP enumeration: querying AD objects directly over LDAP with filters.
- BloodHound: bulk collection and attack-path graphing.
- User and group enumeration: users, groups, RID cycling, and valid-user discovery.
- SPN discovery: locating service accounts for roasting.
- ACL enumeration: finding abusable access-control entries.
- GPO and OU enumeration: Group Policy objects, their links, and scope.
- Session enumeration: who is logged on where, for targeting.
- Trust enumeration: mapping domain and forest trusts.
- Password policy: thresholds for safe spraying.
References#
- The Hacker Recipes: Active Directory reconnaissance
- SpecterOps: BloodHound documentation