Command Prompt (cmd)

cmd can be a useful tool when enumerating AD, as it is not commonly monitored by defence systems such as antivirus or the blue team. Moreover, it can be embedded in phishing payloads such as with VBScript, or any other macro languages to perform initial enumeration.

net command

For the full list of available options, refer to the official documentation in the link below:

1. USERS

2. GROUPS

Example

3. ACCOUNTS

Example

Options overview

  • /DOMAIN

Performs the operation on a domain controller of the current domain. Otherwise, the operation is performed on the local computer.

Last updated