AUTOMATED ACTIVE DIRECTORY ENUMERATION
Archana S, Harish Kumar N, Keerthi Raghavan K, Liyander Rishwanth L · Zenodo (CERN European Organization for Nuclear Research) · 2026
Active Directory remains a critical infrastructure component in enterprise environments, yet its comprehensive security assessment often requires multiple disparate tools and frameworks. This paper presents an automated Active Directory enumeration tool designed to streamline security assessments and penetration testing operations. Our lightweight, modular Python-based utility leverages the impacket library to conduct native reconnaissance across multiple attack vectors including SMB, LDAP, WinRM, MSSQL, FTP, ADCS, and SSH protocols. The tool supports multiple authentication mechanisms including credentialed access, pass-the-hash authentication, and null session enumeration, enabling comprehensive domain reconnaissance from various privilege levels. Key capabilities include domain password policy extraction, user and computer enumeration, LDAP-based privilege attribute analysis, Active Directory Certificate Services vulnerability detection, and automated multi-threaded port scanning with service identification. Our implementation demonstrates reduced assessment overhead compared to larger frameworks while maintaining granular control and cross-platform compatibility. Evaluation against standard enterprise AD configurations shows significant improvements in enumeration efficiency and coverage of common misconfigurations. This tool addresses the critical need for lightweight, modular reconnaissance utilities in modern security operations and red team engagements.