AD Testing Checklist (Windows)
Below are the things you should check on every Active Directory assessment from a Windows machine
Shortlist
Extra Attacks
Confirm AD Access (Windows)
Search for abusable ACLs (Bloodhound)
Search for passwords in user descriptions
Search for Kerberoastable accounts
Search for As-Rep Roastable accounts
Check for default Machine Account Quota
Check password policy
Check for active WebDAV clients
Check for missing SMB signing
Check for SMBv1 Support
Check for writable shares
Check for sensitive data in shares
Check for anonymous access
Check LDAP Configuration
Check MsSQL Configuration
Check ADCS Configuration
Check SCCM Configuration
Last updated