Skip to content

Active Directory Enumeration

Active Directory is a hierarchical database (LDAP) describing the whole organization: users, groups, computers, policies, and the relationships between them. The decisive fact is that any authenticated domain user can read almost everything: who’s an admin, which machines exist, which accounts have SPNs, which ACLs rule. Enumerating AD is mapping the terrain before attacking; Kerberoasting, ACL paths, delegations, and the road to Domain Admin all come from here.

AD’s design favors interoperability: reading the directory is a default right of any domain account. That mass read —objects, attributes, memberships, ACLs— gives the attacker the full privilege map without touching anything “broken.” The defender sees seemingly legitimate LDAP queries; telling recon from normal use is the challenge.

With any domain credentials (or even none for part of it), you can already enumerate. Without credentials: limited “unauth” enumeration (null sessions, LLMNR, users via Kerberos).

# valid users via Kerberos (no password needed)
kerbrute userenum -d domain.local --dc <DC> users.txt
# null session / RID cycling (if SMB allows)
enum4linux-ng -A <DC>
rpcclient -U "" -N <DC> # enumdomusers, querydispinfo
# anonymous LDAP (rare today)
ldapsearch -x -H ldap://<DC> -s base namingcontexts

The modern reference tool, NetExec (nxc):

nxc smb <DC> -u user -p pass --users --groups --shares --pass-pol
nxc ldap <DC> -u user -p pass --kerberoasting out.txt --asreproast out.txt
nxc smb <range> -u user -p pass # host sweep and signing

Deep LDAP enumeration:

# ldapdomaindump: dumps the WHOLE domain to HTML/JSON/CSV
ldapdomaindump -u 'domain\user' -p pass ldap://<DC>
# windapsearch / ldapsearch for one-off queries
ldapsearch -x -H ldap://<DC> -D 'user@domain' -w pass -b "DC=domain,DC=local" "(objectClass=user)"

From Windows with credentials, PowerView:

Get-DomainUser -Properties samaccountname,description # descriptions with passwords
Get-DomainGroup -MemberIdentity user
Get-DomainComputer -Properties dnshostname,operatingsystem
Get-DomainUser -SPN # Kerberoastable accounts
Get-DomainUser -PreauthNotRequired # ASREProastable
Find-DomainShare -CheckShareAccess
Get-NetGPO; Get-DomainGPOLocalGroup # who's local admin via GPO
  • Users and descriptions: passwords in the description/info field (classic).
  • Privileged groups: Domain Admins, Enterprise Admins, Account Operators, DnsAdmins, Backup Operators.
  • SPNs (Kerberoasting) and accounts without preauth (ASREProasting).
  • Delegations (unconstrained/constrained/RBCD) — see ad-delegation.
  • Dangerous ACLs (GenericAll, WriteDacl, GenericWrite) over users/groups/OUs — BloodHound’s raw material.
  • Trusts between domains/forests, GPOs granting local admin, unpatched machines, readable LAPS.
  • Password policy (for spraying without locking accounts) and adminCount=1.
  • NetExec (nxc) — swiss-army knife (SMB/LDAP/WinRM/MSSQL): enum, spray, roasting, shares.
  • BloodHound / SharpHound — relationship graph and attack paths (its own card).
  • ldapdomaindump, windapsearch, enum4linux-ng, rpcclient, kerbrute.
  • PowerView (PowerShell) and the AD module (Get-ADUser, etc.).
  • adPEAS, PingCastle (also a defensive view).

Enumeration doesn’t compromise, but it defines the whole attack: the accounts to roast, the ACLs to abuse, the delegations to exploit, and the shortest road to DA all come from here. Complete recon often makes any exploit unnecessary.

  • Mass/anomalous LDAP queries (SharpHound, ldapdomaindump) from a user workstation.
  • Mass kerbrute/AS-REQ (many 4768/4771), null sessions (enum4linux), reads of ms-Mcs-AdmPwd (LAPS).
  • Access to many objects/attributes in a short time by a single account.
  • 4662 (operations on directory objects) with fine auditing on sensitive objects.
  • DC LDAP logs (Directory Service), events 4768/4769 (Kerberos), 5140/5145 (shares).
  • Honeytokens: decoy accounts/SPNs that, if queried/roasted, expose recon.
  • Reduce what a normal user can read where feasible; clean descriptions holding secrets.
  • Remove unneeded SPNs and preauth; apply LAPS with a restricted read ACL.
  • Review and minimize dangerous ACLs and privileged group memberships (tiering/PAW).
  • Monitor with PingCastle/Purple Knight; deploy honeytokens and recon alerts.

If recon is detected, correlate the source account, review what it queried (to anticipate the next step), and accelerate closing the vectors that recon would have revealed (roasting, ACLs).

  • LDAP enumeration is a base TTP in nearly every AD intrusion (MITRE T1087, T1069, T1482 trust discovery).
  • SharpHound/BloodHound appears in countless ransomware reports (Conti, LockBit) as the mapping phase before DA.
  • Passwords in description and GPP (cpassword, MS14-025) remain common real findings.
  • No creds: userenum via Kerberos, null sessions, LLMNR?
  • With creds: users, groups, shares, password policy (nxc)
  • User descriptions with passwords
  • SPNs (Kerberoasting) and accounts without preauth (ASREProast)
  • Privileged groups and adminCount=1
  • Delegations (unconstrained/constrained/RBCD)
  • Dangerous ACLs (GenericAll/WriteDacl) — dump to BloodHound
  • Trusts, GPOs with local admin, readable LAPS