9.9.1. 域
- adidnsdump Active Directory Integrated DNS dump tool
- BloodHound Six Degrees of Domain Admin
- windapsearch Python script to enumerate users, groups and computers from a Windows domain through LDAP queries
- ldapdomaindump Active Directory information dumper via LDAP
9.9.2. Azure AD
- ROADtools Azure AD exploration framework
9.9.3. Exchange
- ruler A tool to abuse Exchange services
- MailSniper
9.9.5. 内网信息收集
- SharpShares Quick and dirty binary to list network share information from all machines in the current domain and if they're readable
- WinShareEnum Windows Share Enumerator
- HackBrowserData 全平台的浏览器数据导出工具