Active Directory enumeration - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 6, 2025
Last Seen
November 6, 2025

Active Directory enumeration (MITRE ATT&CK T1018) is the discovery of AD objects, permissions, and topology to map a Windows domain for privilege escalation and lateral movement.

Overview

Active Directory enumeration (MITRE ATT&CK T1018) is the discovery of AD objects, permissions, and topology to map a Windows domain for privilege escalation and lateral movement. Attackers use this reconnaissance to identify targets, access paths, and trust relationships, making it a high-value pre-exploitation activity in enterprise networks. Recent activity highlights the ongoing relevance of AD-focused reconnaissance as part of broader attacker campaigns.

Related Threat Clusters

  • Gootloader Malware Resurgence Leads to Domain Controller Compromise

    Recent Gootloader attacks have resulted in a Domain Controller compromise within 17 hours, as reported by Huntress. The Gootloader malware, which has been active since 2020, was previously inactive but saw a resurgence…

    2 articles · Updated November 6, 2025
  • Gootloader Malware Resurfaces, Compromises Domain Controllers

    Gootloader malware has re-emerged after a period of reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard intrusions, leading to domain…

    4 articles · Updated November 7, 2025

Recent Intelligence Reports

  • New Gootloader attacks drop Supper SOCKS5 backdoor — Scmagazine · November 6, 2025

CVSS v3.1 Breakdown