Skip to content

Latest commit

 

History

History
152 lines (89 loc) · 2.87 KB

l01-Enum.md

File metadata and controls

152 lines (89 loc) · 2.87 KB

Hands-On 1: Basic Enumeration


Tasks

Enumerate following for the us.techcorp.local domain:

  • Users
  • Computers
  • Domain Administrators
  • Enterprise Administrators
  • Kerberos Policy


Preparation - Import AD Module

To import AD Module:

Import-Module C:\AD\Tools\ADModule-master\Microsoft.ActiveDirectory.Management.dll; Import-Module C:\AD\Tools\ADModule-master\ActiveDirectory\ActiveDirectory.psd1


Enumerate Users

Get-ADUser -Filter * -Properties *
Get-ADUser -Filter * -Properties CN, Description, PrimaryGroup, LastLogonDate, pwdLastSet | Select CN, Description, PrimaryGroup, LastLogonDate, pwdLastSet

picture 19



Enumerate Computers

Get-ADComputer -Filter * -Properties DNSHostName | Select DNSHostName

picture 18



Enumerate Domain Admins

  • To get information of the Domain Admins group:
Get-ADGroup -Filter 'Name -like "*Domain Admins*"' -Properties *

picture 17

  • To get members in the Domain Admins group:
Get-ADGroupMember -Identity "Domain Admins" -Recursive

picture 16



Enumerate Enterprise Admins

  • To get information of the Enterprise Admins group:
Get-ADGroup -Identity "Enterprise Admins" -Properties * -Server techcorp.local

picture 15

  • To get members in the Enterprise Admins group:
Get-ADGroupMember -Identity "Enterprise Admins" -Server techcorp.local -Recursive

picture 14



Enumerate Kerberos Policy

To enumerate Kerberos Policy, we need to use PowerView.

First use InviShell:

cd C:\AD\Tools\InviShell; .\RunWithRegistryNonAdmin.bat

Then import PowerView:

cd ..; . .\PowerView.ps1

picture 13


To get Kerberos Policy:

(Get-DomainPolicyData).KerberosPolicy

picture 12