Dit artikel is alleen in het Engels beschikbaar.
Enumeration is the quiet foundation of every internal assessment. Before any weakness is exploited, a tester builds a picture of the host, the domain, and the identities that hold power. This is a current view of Windows enumeration in 2026, and, as with every technique here, a view a defender can watch for. Only run this against systems you are authorised to test.
The local host
The first questions are simple: who am I, what can I do, and where am I. The built-in tools answer all three without installing anything.
whoami /all # user, groups, and privileges in one view
systeminfo # OS build, patch level, domain membership
net user; net localgroup administrators
The privileges list matters most. A token that holds SeImpersonatePrivilege or SeBackupPrivilege often changes what is possible on the host, which is why it is one of the first things a tester reads.
Active Directory
On a domain host, the interesting surface is the directory. The classic questions are which accounts exist, which groups are privileged, and which paths lead to them.
# Domain, users, and privileged groups
Get-ADDomain
Get-ADGroupMember "Domain Admins"
# Service accounts with a Service Principal Name are Kerberoast candidates
Get-ADUser -Filter {ServicePrincipalName -like "*"} -Properties ServicePrincipalName
The modern approach maps relationships rather than lists. Tooling such as BloodHound turns a directory into a graph of who can reach what, which surfaces indirect paths to high-value accounts that a flat list hides.
Enumeration in 2026 is about relationships, not lists; the shortest path to Domain Admin is rarely a direct one.
Entra ID and the hybrid boundary
Few environments are domain-only now. Most are hybrid, joining an on-premises directory to Entra ID, and the identity boundary is where interesting findings live. A tester checks how identities sync, which roles are held in the cloud tenant, and whether a foothold on premises can reach cloud-privileged accounts.
The point is the join. A device or account that bridges the on-premises directory and the cloud tenant is worth more than either side alone, because it can carry access across the boundary.
Living off the land, and what defenders see
Everything above uses signed, legitimate Windows tooling. That is deliberate; it avoids dropping files and blends into normal administration. It is also detectable, because the behaviour is unusual even when the tool is not.
| Activity | What a defender can watch for |
|---|---|
whoami /all, net commands in sequence |
Recon-style command bursts from a single session |
| PowerShell AD queries | Script block logging and LDAP queries from unusual hosts |
| Directory graphing tools | Large, fast LDAP enumeration across the domain |
| Cross-boundary identity use | Sign-ins that link an on-premises account to cloud-privileged roles |
The defensive takeaway: enable PowerShell script block logging, alert on bulk LDAP queries, tier administrative accounts so a workstation foothold cannot reach Domain Admin directly, and treat the on-premises to cloud identity bridge as a critical control point.
Closing
Enumeration decides the rest of an internal test. Done well, it finds the short path that turns a single foothold into domain-wide access, and it does so with tools already present on the host. That is also the reason it is worth watching for; the tools are trusted, but the pattern is not.
For how this fits into a full internal assessment, see the infrastructure penetration testing service page.