Initial Access
What This Section Covers
Initial access is the "figure out what you're dealing with, then get in" phase. Before any foothold attempt, you want a clear picture of what's live, what's running, and where the obvious gaps are, then use that to land your first set of creds or your first shell. Everything here feeds forward into post-domain compromise, so the target lists and notes you build are what you'll be working off later.
Roughly, this covers:
- Host and service discovery - what's alive on the network, what ports and services are exposed
- SMB enumeration - signing status, null sessions, share access, SMBv1
- LDAP and domain enumeration - anonymous binds, domain structure, users and groups
- Azure AD recon - if the environment is hybrid or cloud-joined
- Foothold techniques - LLMNR/NBT-NS poisoning, NTLM relay, Kerberoasting, AS-REP roasting, password spraying
How to Use It
This isn't a section you do once and move past. You'll circle back to enumeration constantly as new hosts, creds, or access levels open things up that weren't visible before. Rescan when you get a foothold, rescan when you get new creds, rescan whenever the picture changes.
The commands here are starting points, not a checklist to tick off top to bottom. Some environments give you everything from an anonymous LDAP bind, others need heaps of digging before anything useful shows up.