Domain Reconnaissance on Windows
GPO
Check GPOs which enable group of users to have remote access (PsExec, WMI, WinRM, RDP, etc) to specific hosts.
Kerberoasting
ASREPRoasting
Unconstrained Delegation
Constrained Delegation
Resource Based Constrained Delegation
Internal Web Service
If it is not accessible directly, use SOCKS to access it.
Any computer/users' name contain "web", "svc", etc.
Send a phishing email
Send a document
Execute command
Ping a host
DevOps
Last updated