Domain Discovery

Description

Tools and tactics to discover useful information about an unknown domain.

Discover Domain Name

Use one of the following to discover the domain name on a Windows target.

echo %USERDOMAIN%
echo %USERDNSDOMAIN%
whoami
wmic computersystem get domain

Enumerate DC list

nltest /dclist:<DOMAIN>

Get more info about DC

nltest /dsgetdc:<DOMAIN>

Get forest trust information

nltest /dsgetfti:<DOMAIN>
nltest /server:<DC> /domain_trusts /all_trusts