<aside>
</aside>
<aside>
📌 A basic AD user account with no added privileges can be used to enumerate the majority of objects contained within AD, including but not limited to:
| Domain Computers | Domain Users |
| Domain Group Information | Organizational Units (OUs) |
| Default Domain Policy | Functional Domain Levels |
| Password Policy | Group Policy Objects (GPOs) |
| Domain Trusts | Access Control Lists (ACLs) |
| </aside> |
It's always easier to "break" things if we already know how to build them.
Active Directory (AD) is a centralized directory service used to manage users, computers, groups, and policies in Windows environments.
A Forest is the top-level security boundary in Active Directory.
It contains one or more domains and defines the ultimate administrative scope.
A Domain is the basic administrative and operational unit in AD.
It contains users, computers, groups, Organizational Units (OUs), and Group Policies (GPOs).
The Root Domain is the first domain created in a forest.
The forest usually takes its name from this root domain.
A forest can contain:
Example:
INLANEFREIGHT.LOCAL is a DomainADMIN.INLANEFREIGHT.LOCAL, CORP.INLANEFREIGHT.LOCAL, and DEV.INLANEFREIGHT.LOCAL are child domains within the same forest.Domains are part of a forest, but a forest is larger than any single domain.
From a security perspective:

The graphic below shows two forests, INLANEFREIGHT.LOCAL and FREIGHTLOGISTICS.LOCAL. The two-way arrow represents a bidirectional trust between the two forests, meaning that users in INLANEFREIGHT.LOCAL can access resources in FREIGHTLOGISTICS.LOCAL and vice versa. We can also see multiple child domains under each root domain. In this example, we can see that the root domain trusts each of the child domains, but the child domains in forest A do not necessarily have trusts established with the child domains in forest B. This means that a user that is part of admin.dev.freightlogistics.local would NOT be able to authenticate to machines in the wh.corp.inlanefreight.local domain by default even though a bidirectional trust exists between the top-level inlanefreight.local and freightlogistics.local domains. To allow direct communication from admin.dev.freightlogistics.local and wh.corp.inlanefreight.local, another trust would need to be set up.

<aside>
</aside>
