Enumeration — Hub
Concepts for understanding what you find during recon — how services work, AD fundamentals, and what to look for.
Pair these notes with Recon tools (Nmap, Gobuster) and UseCases for ports for the full picture.
📌 Notes in This Folder
| Note | Purpose |
|---|---|
| Networking | IP, subnets, routing, dual-homed hosts |
| AD | Active Directory concepts & attack overview |
| Kerberos | Kerberos auth, tickets, roasting — sync time first |
| Time Sync-Clock Skew | Clock skew / NTP sync with DC — Clock skew too great fix |
| Time Sync | Redirect → Time Sync-Clock Skew |
| Kerberos Setup - krb5.conf | /etc/krb5.conf — nxc --generate-krb5-file, required before -k / getTGT |
| RPC | MSRPC, rpcbind, enumeration |
| General | General enum tips & misc |
Decision trees: Attack Path Graph · Credential Graph (Reference folder)
📌 Enum → Tool Mapping
| Found | Concept | Tool |
|---|---|---|
| Open ports | UseCases for ports | Nmap |
| Web server | Web Servers, General | Gobuster, Nikto |
| SMB / 445 | AD, RPC | SMB, enum4linux |
| Mail / 25, 110, 143 | General | Mail (SMTP POP3 IMAP), Hydra |
| LDAP / 389 | AD | ldapsearch, enum4linux |
| SNMP / 161 | Networking | snmpwalk |
| Kerberos / 88 | Kerberos, Time Sync | Kerbrute |
| XMPP / 5222 | Kerberos, AD | Pidgin |
| Domain | AD | Bloodhound + Sharphound |