Active Directory Enumeration
Active Directory is a hierarchical database (LDAP) describing the whole organization: users, groups, computers, policies, and the relationships between them. The decisive fact is that any authenticated domain user can read almost everything: who’s an admin, which machines exist, which accounts have SPNs, which ACLs rule. Enumerating AD is mapping the terrain before attacking; Kerberoasting, ACL paths, delegations, and the road to Domain Admin all come from here.
Threat model
Section titled “Threat model”AD’s design favors interoperability: reading the directory is a default right of any domain account. That mass read —objects, attributes, memberships, ACLs— gives the attacker the full privilege map without touching anything “broken.” The defender sees seemingly legitimate LDAP queries; telling recon from normal use is the challenge.
Starting point
Section titled “Starting point”With any domain credentials (or even none for part of it), you can already enumerate. Without credentials: limited “unauth” enumeration (null sessions, LLMNR, users via Kerberos).
Red Team
Section titled “Red Team”Without credentials (pre-auth)
Section titled “Without credentials (pre-auth)”# valid users via Kerberos (no password needed)kerbrute userenum -d domain.local --dc <DC> users.txt# null session / RID cycling (if SMB allows)enum4linux-ng -A <DC>rpcclient -U "" -N <DC> # enumdomusers, querydispinfo# anonymous LDAP (rare today)ldapsearch -x -H ldap://<DC> -s base namingcontextsWith domain credentials
Section titled “With domain credentials”The modern reference tool, NetExec (nxc):
nxc smb <DC> -u user -p pass --users --groups --shares --pass-polnxc ldap <DC> -u user -p pass --kerberoasting out.txt --asreproast out.txtnxc smb <range> -u user -p pass # host sweep and signingDeep LDAP enumeration:
# ldapdomaindump: dumps the WHOLE domain to HTML/JSON/CSVldapdomaindump -u 'domain\user' -p pass ldap://<DC># windapsearch / ldapsearch for one-off queriesldapsearch -x -H ldap://<DC> -D 'user@domain' -w pass -b "DC=domain,DC=local" "(objectClass=user)"From Windows with credentials, PowerView:
Get-DomainUser -Properties samaccountname,description # descriptions with passwordsGet-DomainGroup -MemberIdentity userGet-DomainComputer -Properties dnshostname,operatingsystemGet-DomainUser -SPN # Kerberoastable accountsGet-DomainUser -PreauthNotRequired # ASREProastableFind-DomainShare -CheckShareAccessGet-NetGPO; Get-DomainGPOLocalGroup # who's local admin via GPOWhat to look for (the recon targets)
Section titled “What to look for (the recon targets)”- Users and descriptions: passwords in the
description/infofield (classic). - Privileged groups: Domain Admins, Enterprise Admins, Account Operators, DnsAdmins, Backup Operators.
- SPNs (Kerberoasting) and accounts without preauth (ASREProasting).
- Delegations (unconstrained/constrained/RBCD) — see ad-delegation.
- Dangerous ACLs (GenericAll, WriteDacl, GenericWrite) over users/groups/OUs — BloodHound’s raw material.
- Trusts between domains/forests, GPOs granting local admin, unpatched machines, readable LAPS.
- Password policy (for spraying without locking accounts) and
adminCount=1.
- NetExec (nxc) — swiss-army knife (SMB/LDAP/WinRM/MSSQL): enum, spray, roasting, shares.
- BloodHound / SharpHound — relationship graph and attack paths (its own card).
- ldapdomaindump, windapsearch, enum4linux-ng, rpcclient, kerbrute.
- PowerView (PowerShell) and the AD module (
Get-ADUser, etc.). - adPEAS, PingCastle (also a defensive view).
Impact
Section titled “Impact”Enumeration doesn’t compromise, but it defines the whole attack: the accounts to roast, the ACLs to abuse, the delegations to exploit, and the shortest road to DA all come from here. Complete recon often makes any exploit unnecessary.
Blue Team
Section titled “Blue Team”Detection
Section titled “Detection”- Mass/anomalous LDAP queries (SharpHound, ldapdomaindump) from a user workstation.
- Mass kerbrute/AS-REQ (many 4768/4771), null sessions (enum4linux), reads of
ms-Mcs-AdmPwd(LAPS). - Access to many objects/attributes in a short time by a single account.
Telemetry
Section titled “Telemetry”- 4662 (operations on directory objects) with fine auditing on sensitive objects.
- DC LDAP logs (Directory Service), events 4768/4769 (Kerberos), 5140/5145 (shares).
- Honeytokens: decoy accounts/SPNs that, if queried/roasted, expose recon.
Hardening
Section titled “Hardening”- Reduce what a normal user can read where feasible; clean descriptions holding secrets.
- Remove unneeded SPNs and preauth; apply LAPS with a restricted read ACL.
- Review and minimize dangerous ACLs and privileged group memberships (tiering/PAW).
- Monitor with PingCastle/Purple Knight; deploy honeytokens and recon alerts.
Response
Section titled “Response”If recon is detected, correlate the source account, review what it queried (to anticipate the next step), and accelerate closing the vectors that recon would have revealed (roasting, ACLs).
CVEs and real-world cases
Section titled “CVEs and real-world cases”- LDAP enumeration is a base TTP in nearly every AD intrusion (MITRE T1087, T1069, T1482 trust discovery).
- SharpHound/BloodHound appears in countless ransomware reports (Conti, LockBit) as the mapping phase before DA.
- Passwords in
descriptionand GPP (cpassword, MS14-025) remain common real findings.
Testing checklist
Section titled “Testing checklist”- No creds: userenum via Kerberos, null sessions, LLMNR?
- With creds: users, groups, shares, password policy (nxc)
- User descriptions with passwords
- SPNs (Kerberoasting) and accounts without preauth (ASREProast)
- Privileged groups and
adminCount=1 - Delegations (unconstrained/constrained/RBCD)
- Dangerous ACLs (GenericAll/WriteDacl) — dump to BloodHound
- Trusts, GPOs with local admin, readable LAPS