Back to Active Directory

Ad Enumeration

Active Directory cheatsheet — Active Directory enumeration and attack techniques.

Overview

Active Directory Enumeration is the process of discovering AD objects including users, groups, computers, trusts, permissions, and services. It's the foundation of all AD attack paths and is essential for identifying privilege escalation opportunities.

Tools like BloodHound provide graphical visualization of attack paths, making complex permission relationships visible.

Category: Active Directory — Active Directory enumeration and attack techniques.

Key Commands & Payloads

The following commands and payloads are commonly used when testing for or exploiting Ad Enumeration:

Get-NetUser -Username admin (PowerView)
Get-NetGroup -GroupName "Domain Admins" (PowerView)
Get-NetComputer (PowerView)
Find-LocalAdminAccess (PowerView)
Get-NetSession -ComputerName <target> (PowerView)
SharpHound.exe -c All (BloodHound collector)
BloodHound.py -d domain.local -u user -p pass -ns 10.10.10.10
ldapsearch -H ldap://10.10.10.10 -x -b "dc=domain,dc=local"
net user /domain
net group "Domain Admins" /domain

Tools & Techniques

Recommended tools for Ad Enumeration:

  • BloodHound / SharpHound: attack path visualization
  • PowerView: PowerShell AD reconnaissance
  • LDAP queries: raw LDAP enumeration
  • ADSI: PowerShell Active Directory Services Interface
  • CrackMapExec: AD assessment framework
  • PingCastle: AD security auditing

Prevention & Mitigation

Security recommendations to prevent Ad Enumeration:

  • Apply the principle of least privilege for all AD objects
  • Remove unnecessary group memberships and delegation
  • Implement Tier 0/1/2 administrative model
  • Use constrained and resource-based delegation where needed
  • Regularly audit AD permissions with BloodHound
  • Enable Advanced Threat Analytics (ATA) for AD monitoring

References

Additional resources: