> For the complete documentation index, see [llms.txt](https://www.ired.team/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/active-directory-enumeration-with-powerview.md).

# PowerView: Active Directory Enumeration

This lab explores a couple of common cmdlets of PowerView that allows for Active Directory/Domain enumeration.

## Get-NetDomain

Get current user's domain:

![](/files/-LLzd9N9rZOj1zqIhSBF)

## Get-NetForest

Get information about the forest the current user's domain is in:

![](/files/-LLzddnEPdmu7Q8SfouR)

## Get-NetForestDomain

Get all domains of the forest the current user is in:

![](/files/-LLzf0S10E1OSY7T7k9H)

## Get-NetDomainController

Get info about the DC of the domain the current user belongs to:

![](/files/-LLzfOFLgrOxW6Y-bR52)

## Get-NetGroupMember

Get a list of domain members that belong to a given group:

![](/files/-LLzgA_HPmbcYClpCNOt)

## Get-NetLoggedon

Get users that are logged on to a given computer:

![](/files/-LLzhPeRsZfpet96kWuT)

## Get-NetDomainTrust

Enumerate domain trust relationships of the current user's domain:

![](/files/-LLzhpw5yYwcsbZ5Arzk)

## Get-NetForestTrust

Enumerate forest trusts from the current domain's perspective:

![](/files/-LLzi97c12Py-wn6iGz1)

## Get-NetProcess

Get running processes for a given remote machine:

```csharp
Get-NetProcess -ComputerName dc01 -RemoteUserName offense\administrator -RemotePassword 123456 | ft
```

![](/files/-LQIu2VkugNWZBJbC43M)

## Invoke-MapDomainTrust

Enumerate and map all domain trusts:

![](/files/-LLzjb4pR0R0QZFWnSEL)

## Invoke-ShareFinder

Enumerate shares on a given PC - could be easily combines with other scripts to enumerate all machines in the domain:

![](/files/-LLzkAMHWApp9EX94TzE)

## Invoke-UserHunter

Find machines on a domain or users on a given machine that are logged on:

![](/files/-LLzlbfMrGPxEcvbX6E1)

## References

{% embed url="<https://github.com/PowerShellMafia/PowerSploit>" %}
