> For the complete documentation index, see [llms.txt](https://rfc1918.gitbook.io/offsec/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://rfc1918.gitbook.io/offsec/active-directory/enumeration.md).

# Enumeration

- [Active Directory Module](https://rfc1918.gitbook.io/offsec/active-directory/enumeration/active-directory-module.md)
- [Enumerating the Domain](https://rfc1918.gitbook.io/offsec/active-directory/enumeration/active-directory-module/enumerating-the-domain.md)
- [Enumerating ACLs](https://rfc1918.gitbook.io/offsec/active-directory/enumeration/active-directory-module/enumerating-acls.md)
- [PowerView 3.0](https://rfc1918.gitbook.io/offsec/active-directory/enumeration/powerview-3.0.md)
- [Verify connectivity to domain controller](https://rfc1918.gitbook.io/offsec/active-directory/enumeration/verify-connectivity-to-domain-controller.md)
- [WMI domain enumeration through root\directory\ldap](https://rfc1918.gitbook.io/offsec/active-directory/enumeration/wmi-domain-enumeration-through-root-directory-ldap.md)
- [PAM Trust](https://rfc1918.gitbook.io/offsec/active-directory/enumeration/pam-trust.md)
- [DNS discovery](https://rfc1918.gitbook.io/offsec/active-directory/enumeration/dns-discovery.md)
- [Get-DnsServerZone](https://rfc1918.gitbook.io/offsec/active-directory/enumeration/dns-discovery/get-dnsserverzone.md): Gets details of DNS zones on a DNS server.
