Domain Goodness – How I Learned to LOVE AD Explorer
ID: ecc54190-a6a5-5264-b708-71f8e5886986
STIX ID: report--ecc54190-a6a5-5264-b708-71f8e5886986
Feed Name: Black Hills Infosec Blog
### Executive Summary This article demonstrates how pentesters and red-teamers can use Microsoft Sysinternals AD Explorer for Active Directory reconnaissance and post-compromise operations. It covers live enumeration of users, computers, and attributes; searching for high-value targets (privileged accounts, servers named by function); extracting potentially sensitive attributes (e.g., UserPassword, unicodePwd); creating and diffing snapshots (including command-line snapshot creation); and leveraging Shodan to identify internet-exposed domain controllers and potentially weakly configured groups useful for phishing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
