Quick, high-signal ways to enumerate DCs, trusts, and privileged groups in Active Directory plus how to detect them.
Overview
- Why it matters: these commands are common during early recon.
- What you get: exact commands, sample output, Sigma detections, and in-the-wild cases.
- Defend: pair command-line telemetry with parent/child process context and alert tuning.
Known in-the-wild incidents
| Source Title | Source (with link) | Publish Date | Commands referred |
|---|---|---|---|
| Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs | The DFIR Report | 8 Sep, 2025 | nltest for AD/DC enumeration |
| From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira | The DFIR Report | 5 Aug, 2025 | nltest /dclist:; nltest /domain_trusts; whoami /groups; net group "domain admins" /dom; net group "enterprise admins" /dom |
| SharePoint ToolShell – Zero-Day Exploited in-the-Wild Targets Enterprise Servers | SentinelLabs | 21 Jul, 2025 | whoami (captured via webshell command execution) |
| #StopRansomware: Play Ransomware | CISA | 4 Jun, 2025 | nltest used for network discovery (behavior described, exact switches not quoted) |
| QSC: new modular framework in CloudComputating campaigns | Securelist | 8 Nov, 2024 | net group "domain admins" /domain; whoami |
| Attack Cases Against HTTP File Server (HFS) (CVE-2024-23692) | AhnLab ASEC | 28 Jun, 2024 | whoami during post-exploitation reconnaissance |
| Operation Crimson Palace: A Technical Deep Dive | Sophos X-Ops | 5 Jun, 2024 | net group "domain admins" /domain; nltest /domain_trusts (plus related domain enumeration) |
Sigma Rules
Visual mapping
Command-to-rule mapping for nltest, whoami, and net.
Elastic Sigma alerts
Potential Recon Activity Via Nltest.EXE
Nltest is a Windows command-line utility used to list domain controllers and enumerate domain trusts.
nltest.exe /dclist: domain
nltest.exe /domain_trusts
Example output
C:\Users\john>nltest /dclist:DC1
Get list of DCs in domain 'DC1' from '\\HOME-DC'.
HOME-DC.DC1.local [PDC] [DS] Site: Default-First-Site-Name
The command completed successfully
C:\Users\john>nltest /domain_trusts
List of domain trusts:
0: DC1 DC1.local (NT 5) (Forest Tree Root) (Primary Domain) (Native)
The command completed successfully
Suspicious Group And Account Reconnaissance Activity Using Net.EXE
net.exe group "domain admins" /dom
net.exe group "enterprise admins" /dom
Example output
net group "domain admins" /dom
C:\Users\john>net group "domain admins" /dom
The request will be processed at a domain controller for domain DC1.local.
Group name Domain Admins
Comment Designated administrators of the domain
Members
-------------------------------------------------------------------------------
Administrator MSSQLService user2
The command completed successfully.
net group "enterprise admins" /dom
C:\Users\john>net group "enterprise admins" /dom
The request will be processed at a domain controller for domain DC1.local.
Group name Enterprise Admins
Comment Designated administrators of the enterprise
Members
-------------------------------------------------------------------------------
Administrator MSSQLService user1
The command completed successfully.
Group Membership Reconnaissance Via Whoami.EXE
whoami.exe /groups
Example output
C:\Users\john>whoami /groups
GROUP INFORMATION
-----------------
Group Name Type SID Attributes
========================================== ================ ============ ==================================================
Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group
BUILTIN\Administrators Alias S-1-5-32-544 Group used for deny only
BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\INTERACTIVE Well-known group S-1-5-4 Mandatory group, Enabled by default, Enabled group
CONSOLE LOGON Well-known group S-1-2-1 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
....
SIEM Detections
These queries were generated by converting the Sigma rule with pySigma backends.
Potential Recon Activity Via Nltest.EXE
Detects nltest commands that can be used for information discovery
DeviceProcessEvents
| where (FolderPath endswith "\\nltest.exe" or ProcessVersionInfoOriginalFileName =~ "nltestrk.exe") and ((ProcessCommandLine contains "server" and ProcessCommandLine contains "query") or (ProcessCommandLine contains "/user" or ProcessCommandLine contains "all_trusts" or ProcessCommandLine contains "dclist:" or ProcessCommandLine contains "dnsgetdc:" or ProcessCommandLine contains "domain_trusts" or ProcessCommandLine contains "dsgetdc:" or ProcessCommandLine contains "parentdomain" or ProcessCommandLine contains "trusted_domains"))
(process.executable:*\\nltest.exe OR process.pe.original_file_name:nltestrk.exe) AND ((process.command_line:*server* AND process.command_line:*query*) OR (process.command_line:(*\/user* OR *all_trusts* OR *dclist\:* OR *dnsgetdc\:* OR *domain_trusts* OR *dsgetdc\:* OR *parentdomain* OR *trusted_domains*)))
Suspicious Group And Account Reconnaissance Activity Using Net.EXE
Detects suspicious reconnaissance command line activity on Windows systems using Net.EXE Check if the user that executed the commands is suspicious (e.g. service accounts, LOCAL_SYSTEM)
DeviceProcessEvents
| where ((FolderPath endswith "\\net.exe" or FolderPath endswith "\\net1.exe") or (ProcessVersionInfoOriginalFileName in~ ("net.exe", "net1.exe"))) and ((((ProcessCommandLine contains " group " or ProcessCommandLine contains " localgroup ") and (ProcessCommandLine contains "domain admins" or ProcessCommandLine contains " administrator" or ProcessCommandLine contains " administrateur" or ProcessCommandLine contains "enterprise admins" or ProcessCommandLine contains "Exchange Trusted Subsystem" or ProcessCommandLine contains "Remote Desktop Users" or ProcessCommandLine contains "Utilisateurs du Bureau à distance" or ProcessCommandLine contains "Usuarios de escritorio remoto" or ProcessCommandLine contains " /do")) and (not(ProcessCommandLine contains " /add"))) or (ProcessCommandLine contains " accounts " and ProcessCommandLine contains " /do"))
((process.executable:(*\\net.exe OR *\\net1.exe)) OR (process.pe.original_file_name:(net.exe OR net1.exe))) AND ((((process.command_line:(*\ group\ * OR *\ localgroup\ *)) AND (process.command_line:(*domain\ admins* OR *\ administrator* OR *\ administrateur* OR *enterprise\ admins* OR *Exchange\ Trusted\ Subsystem* OR *Remote\ Desktop\ Users* OR *Utilisateurs\ du\ Bureau\ à\ distance* OR *Usuarios\ de\ escritorio\ remoto* OR *\ \/do*))) AND (NOT process.command_line:*\ \/add*)) OR (process.command_line:*\ accounts\ * AND process.command_line:*\ \/do*))
Group Membership Reconnaissance Via Whoami.EXE
Detects the execution of whoami.exe with the /group command line flag to show group membership for the current user, account type, security identifiers (SID), and attributes.
DeviceProcessEvents
| where (FolderPath endswith "\\whoami.exe" or ProcessVersionInfoOriginalFileName =~ "whoami.exe") and (ProcessCommandLine contains " /groups" or ProcessCommandLine contains " -groups")
(process.executable:*\\whoami.exe OR process.pe.original_file_name:whoami.exe) AND (process.command_line:(*\ \/groups* OR *\ \-groups*))
Thanks to @svch0st, Craig Young, @cyb3rops, Georg Lauenstein, @nas_bench, omkar72, and oscd.community for publishing the awesome Sigma rules and helping the community.





