Domain Account Discovery
Mapping users, groups, permissions, and Active Directory structure.
Term
description · examples · notesMapping users, groups, permissions, and Active Directory structure.
Description
Uses LDAP queries, BloodHound, or standard Windows commands.
Identifies privilege escalation and lateral movement paths.
Does not require privileged access — any domain user can enumerate AD.
BloodHound visualizes AD relationships and suggests attack paths.
Examples
- BloodHound for mapping AD attack paths
- SharpHound collector for gathering AD data
Notes
- Specific to Active Directory environments.
Threats
used by 2Threats that use it. Select one to open its page.
Defenses
countered by 5How it is countered. Select one to open its page.