Using AD to find hosts that aren't in AD – fun with the [IPAddress] construct!, (Wed, Mar 20th)

In many internal assessments or “recon mission” style engagements, you’ll need to figure out what all the internal subnets are before you can start assessing that address space for issues, targets or whatever you are looking for in that project.  Or, as I had this week, the request was for enumeration of all the hosts that AREN’T in AD.

