๐ŸŽฏ What You'll Learn

  • Enumerate users, groups, computers and OUs
  • Map ACLs and delegation
  • Hunt user sessions and local admin rights
  • Discover trusts and GPO links

Overview

Before you attack AD you have to understand it. PowerView gives granular visibility into objects, permissions and live sessions โ€” the raw material for an attack plan.

Core Topics

  • Domain object enumeration
  • ACL/DACL discovery
  • Session hunting
  • Trust and GPO mapping

Prerequisites

A working KaliRange lab environment and comfort with the Linux command line.

Recommended Workflow

  1. Spin up the target in your KaliRange lab environment and confirm connectivity.
  2. Enumerate the target thoroughly before touching any exploit โ€” information first.
  3. Reproduce each technique by hand so you understand why it works, not just the command.
  4. Capture evidence (commands, output, screenshots) as you go.
  5. Write a short note on how a defender would detect or prevent what you just did.
๐Ÿ’ก
Only ever run these techniques against systems you own or have explicit written permission to test. Practise inside your own KaliRange lab.

Your Goal

Work through every task in your own lab, document your findings as you would on a real engagement, then note the defensive takeaways.

โœ…
Ready to practise. Work through the steps above at your own pace, then move on to a related lab.
โ† All LabsBrowse Workbooks โ†’