Reconnaissance
This page discusses ways of finding Domain names and Domain Controllers ... with or without a domain user, depending on the situation you're in.
This section can be used before and after the initial attack vectors
Using simple CMD
Domain name
Domain Controllers
On Linux
Domain name
Or scan machines with CrackMapExec:
Domain controller
As domain controllers are often DNS Servers, you can simply use these commands:
or :
For more, i suggest to visit @aas notebook here :
PreviousOraganizational Units, Namespaces, domains, domain trees, forests and trust relationshipsNextInitial attack vectors
Last updated