Reconnaissance
This page discusses ways of finding Domain names and Domain Controllers ... with or without a domain user, depending on the situation you're in.
Using simple CMD
Domain name
ipconfig /allDomain Controllers
nslookup <domain>nltest /dclist:{domainname}echo %logonserver%On Linux
Domain name
cat /etc/resolv.confcme smb 192.168.12.0/24Domain controller
PreviousOraganizational Units, Namespaces, domains, domain trees, forests and trust relationshipsNextInitial attack vectors
Last updated