Skip to content

Discovery

Enumerating the environment from a foothold: hosts, users, privileges, and the Active Directory layout.

Why It Matters

Discovery turns a single foothold into an understanding of the whole environment. Mapping users, groups, trusts, and reachable hosts reveals the path from where you landed to where you want to go, and most of it has to be done carefully to avoid tripping detection.

Pages

Page Description
Nmap Network and service discovery
Other Scanning Methods Additional scanning and enumeration techniques
Active Directory Enumeration Mapping users, groups, trusts, and objects in AD
PowerView PowerShell AD reconnaissance
Windows Post-Exploitation Discovery Enumerating a compromised Windows host
Linux Post-Exploitation Discovery Enumerating a compromised Linux host

How I Use It

From a foothold I enumerate locally first (the host, its users, its privileges), then outward into the domain with AD enumeration and PowerView. What I find here sets up Privilege Escalation and Movement.