Key Data Points

Data Point Description
AD Users We are trying to enumerate valid user accounts we can target for password spraying.
AD Joined Computers Key Computers include Domain Controllers, file servers, SQL servers, web servers, Exchange mail servers, database servers, etc.
Key Services Kerberos, NetBIOS, LDAP, DNS
Vulnerable Hosts and Services Anything that can be a quick win. ( a.k.a an easy host to exploit and gain a foothold)

Identifying Hosts

MDNS example:

image.png

fping active checks

fping -asgq 172.16.5.0/23

Kerbrute - Internal AD Username Enumeration

https://github.com/ropnop/kerbrute