Discovery using nltest, net and whoami
turned_in_notelasticsearch, kql, kusto, nltest, sigma rules, t1016, t1033, t1087-001, t1087-002, t1482, whoami
Quick, high-signal ways to enumerate DCs, trusts, and privileged groups in Active Directory plus how to detect them. Overview Why it matters: these commands are common during early recon. What you get: exact commands, sample output, Sigma detections, and in-the-wild cases. Defend: pair command-line telemetry with parent/child process context and…
Read More
