Handbook

AD Enumeration

Updated 29 Sept 2026Services✎ Suggest a change
On this page

Attack Flow

plain text
Low-priv creds obtained → ldapdomaindump (readable AD snapshot)
+ bloodhound-python (graph data) → import to BloodHound → identify path to DA

Tool 1 - Ldapdomaindump

Output Files

FileContents
domain_users.htmlAll domain users, group memberships
domain_groups.htmlAll groups and members
domain_computers.htmlAll computers, OS, last logon
domain_policy.htmlPassword policy, lockout threshold
domain_trusts.htmlDomain trusts
domain_users_by_group.htmlUsers organised by group

Execution

bash
mkdir <domain-name>
cd <domain-name>

sudo ldapdomaindump ldap://<dc-ip> -u '<DOMAIN>\<username>' -p '<password>'
sudo ldapdomaindump ldaps://<dc-ip> -u '<DOMAIN>\<username>' -p '<password>'

firefox domain_users.html
firefox domain_groups.html
firefox domain_computers.html

Grep Output for Quick Wins

bash
grep -i "Domain Admins" domain_groups.grep

grep -i "Never" domain_users.grep

grep -i "DONT_EXPIRE_PASSWORD" domain_users.grep

grep -i "disabled" domain_users.grep

Tool 2 - BloodHound

Installation

bash
sudo apt update && sudo apt install -y bloodhound
sudo bloodhound-setup

Starting BloodHound

bash
# Terminal 1 — start neo4j (use the password set during bloodhound-setup)
sudo neo4j console

# Terminal 2 — launch BloodHound
sudo bloodhound-start

Reset admin password if needed:

bash
sudo env bhe_recreate_default_admin=true bloodhound

Collecting AD Data (Ingestor)

bash
sudo bloodhound-python -d '<domain.local>' -u '<username>' -p '<password>' -ns <dc-ip> -c all

# Output: computers.json, users.json, groups.json, domains.json, gpos.json

Importing Data

plain text
BloodHound UI → Upload Data → select JSON files / zip → wait for import

Key Queries

Shortest path:

plain text
Find Shortest Paths to Domain Admins
Find Shortest Path from Owned Principals
Find Principals with DCSync Rights
Find Computers where Domain Users are Local Admin

High value targets:

plain text
Find All Domain Admins
Find Kerberoastable Users with DA Privileges
Find AS-REP Roastable Users
Find Computers with Unconstrained Delegation
Find Computers with Constrained Delegation

ACL abuse:

plain text
Find Shortest Paths to Domain Admins via ACL Abuse
Principals with WriteDACL on Domain
Principals with GenericAll on Domain

Mark owned:

plain text
Right click node → Mark as Owned
Then run: Find Shortest Path from Owned Principals
bash
# Terminal 1 — dump AD to readable files
mkdir <domain-name> && cd <domain-name>
sudo ldapdomaindump ldaps://<dc-ip> -u '<DOMAIN>\<username>' -p '<password>'

# Terminal 2 — collect BloodHound data
sudo bloodhound-python -d '<domain.local>' -u '<username>' -p '<password>' -ns <dc-ip> -c all

# Start BloodHound
sudo neo4j console
sudo bloodhound

# Import JSON files, review HTML output alongside
firefox domain_users.html &
firefox domain_groups.html &

What Each Finding Tells You

FindingImplication
Domain Admin members identifiedFocus lateral movement here
Short path to DA via ACLACL abuse viable — follow BloodHound path
Kerberoastable DA accountKerberoast immediately
Unconstrained delegation computerHigh value relay/coercion target
Domain Users are local admin somewherePass the hash target
Stale accounts in privileged groupsSpray candidate — less monitored
Low lockout thresholdSpray carefully — one attempt per window
Trust relationships presentOther domains reachable