BloodHound, smbmap and enum4linux-ng: Essential Tools for Starting Active Directory Penetration Testing
Internal penetration testing almost always leads to the same destination. No matter how access is initially obtained—through leaked credentials, infostealer logs, or an exposed legacy server—Active Directory is usually the next target. Most corporate networks are built around a domain, and even environments with significant Linux or macOS presence ultimately rely on domain controllers for management.
Beginners often lose the most time here. Dozens of overlapping AD tools exist, and without a clear understanding of when and why to run each one, reconnaissance generates excessive noise, triggers detectors, and produces data that is difficult to act upon. In practice, domains are frequently compromised without exploiting vulnerabilities at all—simply by methodically collecting small pieces of information.
Reconnaissance begins with domain name and domain controller location
Once inside the network, possibly without domain credentials and on a Linux host with only local privileges, directly attacking the domain controller is rarely effective. The first step is to locate basic landmarks: the domain name, the location of the domain controller, and its IP address. Standard port scanning with nmap revealing open ports 88 (Kerberos) and 389 (LDAP) strongly indicates a domain controller. Native Windows utilities can also extract this information from a domain-joined host without noisy network sweeps.
Old, unpatched hosts such as Windows XP machines remain attractive targets when discovered near the domain, as public exploits can grant quick access.
Significant information can be gathered without credentials
A common misconception is that valid domain credentials are required for reconnaissance. Tools such as enum4linux-ng can retrieve the domain name, user lists, groups, and password policy via null sessions. Although null sessions are less common on modern domain controllers, they still appear regularly and provide enough material to plan subsequent attacks. Password policy details, such as minimum length and history requirements, help attackers tune brute-force attempts to avoid account lockouts.
SMB shares often contain overlooked sensitive data
Few techniques deliver results as consistently as enumerating network shares. smbmap leverages SMB on port 445 to list shares across the domain and identify read or write access. Careful examination frequently uncovers SSH keys, certificates, plaintext passwords, password-manager databases, and service account configuration files. Real-world examples include KeePass files that were brute-forced or quarterly pentest reports left in accessible folders containing still-valid credentials.
BloodHound provides a map rather than an automated attack button
After initial data collection, BloodHound helps determine the next steps. Collectors such as SharpHound gather information about users, groups, computers, and relationships, which BloodHound visualizes as a graph. The resulting map shows concrete paths from a low-privileged account to Domain Admins. In mature environments with active SOC monitoring, quieter collectors are preferred over the default noisy SharpHound to reduce detection risk.
Protocol understanding separates script users from effective attackers
Techniques such as Kerberoasting and AS-REP Roasting rely on tools from the impacket suite, including GetADUsers. However, success depends on understanding the underlying Kerberos and NTLM protocols. An obtained NTLM hash can be reused directly via pass-the-hash rather than cracked, opening additional movement options that are invisible to operators who only copy commands.
Network attacks require caution and stealth
Tools such as mitm6 and ntlmrelayx enable relay attacks in networks without protocol encryption. These techniques must be executed carefully to avoid disrupting availability or alerting defenders. Heavy scanners like Nessus are generally avoided during pentests because they are noisy; experienced operators prefer targeted, low-noise actions.
Beginner checklist for Active Directory reconnaissance
- Locate domain name, domain controller, and IP address via port scanning (88, 389).
- Collect initial data without credentials using enum4linux-ng and null sessions.
- Enumerate SMB shares with smbmap for keys, certificates, and passwords.
- Map attack paths with SharpHound and BloodHound.
- Apply protocol-aware techniques such as Kerberoasting and pass-the-hash.
- Maintain stealth by filtering data collection and minimizing noisy actions.
Additional resources include an interactive AD pentest map from Orange Cyberdefense and the Red September CyberED course on Active Directory attacks covering Kerberos, NTLM, DACL abuse, delegation, and certificate services.
Related articles
LibreOffice and Apache OpenOffice Flaws Enable Remote Code Execution via Malicious Spreadsheets Without Macro Warnings
Two vulnerabilities, CVE-2026-63277 in LibreOffice Calc and CVE-2026-59265 in Apache OpenOffice, allow attackers to execute arbitrary code simply by tricking users into opening specially crafted spreadsheet files. The flaws exploit Java integration and class path handling, bypassing traditional macro security prompts entirely. LibreOffice has already released fixes in versions 26.2.5 and 26.8.0 that restrict class path entries to local file URLs only. Apache OpenOffice 4.1.16 and earlier remain vulnerable, with the stable patch expected in 4.1.17; interim mitigation requires disabling Java integration. The issues highlight risks in office suites that process untrusted documents containing external data connections or JDBC references. Organizations are advised to enforce least-privilege execution and avoid opening files from unknown sources until patches are applied.
Web Application Vulnerabilities Surge as AI-Driven Development Outpaces Security Testing
The number of vulnerabilities in web applications continues to grow each quarter, driven in part by the rapid adoption of artificial intelligence in software development pipelines. While integrating AI tools boosts productivity and shortens release cycles, many organizations fail to match this speed with equivalent security testing and validation processes. As a result, increasing amounts of code reach production environments without ever being assessed from an attacker’s perspective. Cybercriminals have quickly recognized this gap, exploiting repeated flaw patterns in applications that skip security reviews. The article emphasizes that pentesting must become a recurring part of the development cycle, conducted weekly or monthly to match the pace of updates. Continuous security testing allows teams to identify and remediate issues before they can be weaponized. Developing rapidly with AI is not inherently risky, but releasing unvalidated code transforms speed into exposure.
Microsoft Fixes CVE-2026-96940 in Exchange Server Allowing Authenticated Mailbox Access
Microsoft has patched CVE-2026-96940, a CVSS 8.8 vulnerability in Exchange Server that lets any authenticated user read other users' mailboxes without administrative rights. The flaw exposes full message content and attachments including contracts, spreadsheets, and sensitive documents. Affected on-premises versions include Exchange Server Subscription Edition RTM, Exchange 2016 CU23, Exchange 2019 CU15, and Exchange 2019 CU14. Exchange Online users are protected because the fix was applied server-side. Microsoft rates exploitation as likely but reports no confirmed attacks in the wild at disclosure time. The issue turns a single low-privilege credential into broad access to executive, legal, and financial correspondence.
New Spectre-v2 Variant Uses JIT Compiler Branch Target Reuse for Cross-Process Data Extraction
Researchers from the Netherlands and Italy have published a paper detailing a fresh Spectre-v2 attack that reuses branch predictor state instead of injecting new instructions. The technique leverages the JIT compiler cBPF inside the Linux kernel to train the branch target predictor, enabling speculative execution that leaks sensitive data such as hashed root passwords. Practical demonstrations extracted credentials from the su process in an average of three to five minutes on AMD, Intel, and ARM processors. Partial success was shown with SpiderMonkey in Firefox and GraalVM, although realistic end-to-end attacks were not achieved with those engines. The work also covers additional topics including forensic detection of attacks against 1C servers, a record Debian Linux kernel patch set, zero-day fixes in TeamViewer and Apple Core Graphics, and critical flaws in Dell Container Storage Modules.