AD Pentesting
Start with a Simple Nmap scan
nmap -O -sS -sV 142.168.168.20/24enumerate port 139/445
enum4linux -n 10.49.160.26
enum4linux -A spookysec.localEnumerating Users via Kerberos
./kerbrute_linux_amd64 userenum userslist.txt -d Domain-name.local --dc Domain-name.localFind the hash of the valid Users
Last updated