image.png

To generate a list of common usernames format using real names: Username Anarchy

Enumerating valid usernames with Kerbrute

./kerbrute_linux_amd64 userenum --dc 10.129.201.57 --domain inlanefreight.local names.txt

Then brute force with nxc etc.

Generate many event logs

Capturing NTDS.dit

NT Dir Services is the directory service used in AD to find & organize network resources.

Primary DB associated with AD, stoores usernames, password hashes etc.

Check user perms:

net user user