AD Enum
Live Host Enumeration
User Enumeration
Get Foothold
Enumeration
Without Active Directory module installed
Enumerate Domain Users
Using Active Directory PowerShell module
AD User Enumeration
AD Group Commands
AD Computer Commands
Using PowerView
Using BloodHound
Group Policy
Enumeration using nltest and .Net
Get Domain Information
Get Current Domain Info
View Domain Forest Info
View Domain Trust Information
View All Domain Controllers
View DC for Current Session
Kerberos
Get domain name and DC the user authenticated to
Get All Logged on Sessions, Includes NTLM & Kerberos
View Current Kerberos Tickets
View Cached Krbtgt
Other useful AD enumeration tools
Last updated