← Active Directory Range

Enumeration & Lateral Movement

The range runs three hosts on one isolated network with no gateway: dc01, ws01, and your attacker box. Hosts resolve by name.

Methodology, in order:

1. Map — who is on this network? nmap -sn

2. Enumerate — what do they run? Banners, versions, anonymous access.

3. Notice — an over-permissioned account, a readable description, a note left behind.

4. Pivot — credentials found in one place unlock a service elsewhere.

Step 4 is credential reuse, the most common real-world lateral movement path. It's rarely an exploit; it's someone reusing a password.

The discipline that matters: enumerate exhaustively before you touch anything. Most failed engagements are failures of enumeration, not of exploitation.