Domain User Enumeration
Remote
Multi-Protocol
SMB RPC ldapldapsearch -x -b "DC=HTB,DC=LOCAL" -s sub "(&(objectclass=user))" -H ldap://<IP> | grep -i samaccountname: | cut -f 2 -d " "
Brute force usernames
kerbrute userenum -d EGOTISTICAL-BANK.LOCAL /usr/share/seclists/Usernames/xato-net-10-million-usernames.txt --dc 10.10.10.175
Generate userlists
Username Anarchy
sudo apt install ruby -y
git clone https://github.com/urbanadventurer/username-anarchy.git
cd username-anarchy
Validate Known Usernames
Add a known negative user to make sure the server is properly validating.