Active Directory Enumeration
Privileged Groups
AD Recycle Bin
Get-ADObject -filter 'isDeleted -eq $true' -includeDeletedObjects -Properties *Remote Management Users
Get-NetGroupMember -Identity "Remote Management Users" -Recurse
Get-NetLocalGroupMember -ComputerName <pc_name> -GroupName "Remote Management Users"AD Backup Operators
# Import libraries
Import-Module .\SeBackupPrivilegeUtils.dll
Import-Module .\SeBackupPrivilegeCmdLets.dll
# Enable SeBackupPrivilege
Set-SeBackupPrivilege
Get-SeBackupPrivilegeGet Hashes from .dit File
gMSA
Get Password (locally)
impacket-ntlmrelayx
GMSAPasswordReader
Interesting Account Names
AD Support Accounts
BloodHound
Ingestors
SharpHound
bloodhound.py
Powerview
Enumeration
Last updated