Active Directory enumeration (MITRE ATT&CK T1018) is the discovery of AD objects, permissions, and topology to map a Windows domain for privilege escalation and lateral movement.
Overview
Active Directory enumeration (MITRE ATT&CK T1018) is the discovery of AD objects, permissions, and topology to map a Windows domain for privilege escalation and lateral movement. Attackers use this reconnaissance to identify targets, access paths, and trust relationships, making it a high-value pre-exploitation activity in enterprise networks. Recent activity highlights the ongoing relevance of AD-focused reconnaissance as part of broader attacker campaigns.
Related Threat Clusters
-
Gootloader Malware Resurgence Leads to Domain Controller Compromise
Recent Gootloader attacks have resulted in a Domain Controller compromise within 17 hours, as reported by Huntress. The Gootloader malware, which has been active since 2020, was previously inactive but saw a resurgence…
2 articles · Updated November 6, 2025 -
Gootloader Malware Resurfaces, Compromises Domain Controllers
Gootloader malware has re-emerged after a period of reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard intrusions, leading to domain…
4 articles · Updated November 7, 2025
Recent Intelligence Reports
- New Gootloader attacks drop Supper SOCKS5 backdoor — Scmagazine · November 6, 2025