Internal Reconnaissance
Internal reconnaissance focuses on understanding the network topology, identifying Active Directory structure, and discovering high-value targets before active exploitation begins. Balance stealth with thoroughness.
Information
Reconnaissance Phases
Passive Reconnaissance
Network traffic analysis, ARP discovery, DHCP/mDNS monitoring, and stealthy enumeration.
Active Discovery
Nmap scanning, host discovery, service enumeration, and OS fingerprinting techniques.
AD Enumeration
Domain discovery, LDAP queries, BloodHound analysis, and trust relationship mapping.
User Hunting
Admin identification, session tracking, high-value target discovery, and logged-on user enumeration.
Reconnaissance Workflow
| Phase | Techniques | Detection Risk | Key Outputs |
|---|---|---|---|
| Passive | Traffic capture, ARP table, broadcast listening | Low | Network layout, active hosts, naming conventions |
| Active | Port scanning, service detection, OS fingerprint | Medium | Open ports, services, vulnerabilities |
| AD Enum | LDAP queries, BloodHound, GPO analysis | Medium | Domain structure, attack paths, privileges |
| User Hunting | Session enumeration, admin locating | Medium-High | Target systems, admin sessions |
Quick Reference
Essential Commands
nmap -sn 10.0.0.0/24bloodhound-python -c AllGet-DomainUser -AdminCount 1
Key Tools
- • Nmap / Masscan
- • BloodHound
- • PowerView / SharpView
Priority Targets
- • Domain Controllers
- • Admin workstations
- • Service accounts