A reviewer calls Active Directory enumeration 'read-only, not a vulnerability' — what is your rebuttal?
answer
- concede the read, move the finding
- the graph is the vulnerability
- reconnaissance that costs nothing
- first action is the successful one
- report paths and entries, not the query
basics
~20 sThe finding is not the read; it is the graph the read reveals. Because authorisation data is readable by design, an attacker computes a working two-hop route at zero cost, with no failed attempts and nothing modified, and then acts once.
solid answer
~50 sAgree with the premise and then move the finding. Yes, the read is authorised, changes nothing and cannot sensibly be revoked — that is the problem, not the defence. What the read produces is a ranked list of routes from ordinary accounts to the highest-value groups, computed offline before anything is touched. So there is no clumsy probing stage to get wrong: the first privileged action the attacker takes is one already proven to work on paper. The precondition is the cheapest thing in the estate, one valid credential, which every real intrusion obtains. And the query is the same one a joiners-movers-leavers script, a licence reconciliation job and an auditor run every week, so it is authorised by design and costs the attacker nothing. Write the finding as the paths and the specific entries that create them, and remediate the edges.
go deeper
Understand the distinction being argued: reading who can control whom grants no rights, but it tells an attacker exactly which of the rights they already have will work.
Be able to explain why free reconnaissance changes the attack economics — no failed attempts, an authorised query, and a route that is derived rather than guessed.
Show that you can carry the argument in a review: concede the premise, restate the finding as ranked routes with the specific entries behind them, and name the removals that shorten or delete each one.
Own the standard the estate is measured against — the shortest path from an arbitrary account to a domain-administrative group — and defend spending on delegation hygiene against work that produces more visible results.
## Concede the premise, then reframe The reviewer is right about the mechanics and wrong about the conclusion. Reading the directory grants no new right, modifies no object and needs no flaw. Arguing that the read is itself the vulnerability loses the argument, because it is not. The rebuttal is that the vulnerability is the shape of the authorisation graph, and the read is what makes that shape free to obtain. ## Why free reconnaissance changes the risk, not just the convenience In most attack chains, reconnaissance costs something. Probing what you can write means attempts that either fail or succeed, and failures accumulate. Here the authorisation model is published to every authenticated principal by design, so the attacker performs the reconnaissance as a computation rather than as a series of attempts. The practical consequences are: - **No trial and error.** The attacker does not try seventeen things and get lucky on the eighteenth. The route is derived, then walked. - **The precondition is trivially cheap.** Any single valid credential is enough — a starter account, a contractor, a service account with no rights, a domain-joined machine account. Every intrusion begins with at least one of those. - **The read blends into normal business.** The same enumeration runs weekly from a joiners-movers-leavers script, a licence reconciliation tool and an auditor's review. It is authorised traffic performing an authorised operation. - **The shortest route is usually legitimate.** In a long-lived estate the two-hop paths run through rights somebody granted deliberately: a help-desk reset delegation, an application owner given control of a group, a group nested for convenience. Nothing in the chain is an exploit, so nothing in the chain has a patch. ## Rate the graph, not the query The risk quantity to argue about is the closure: from the set of accounts an attacker can plausibly obtain, how many distinct routes reach the highest-value groups, and how short are they? An estate where the shortest route from an arbitrary user account to a domain-administrative group is two hops is in a materially different position from one where it is nine hops or does not exist. That number is measurable, it is a property of your grants rather than of anyone's tooling, and it is the sentence to put in front of the reviewer. ## What the finding should actually say Not *authenticated users can read the directory*. That reads as a complaint about Windows and will be closed as by design. Instead: *these N routes reach a domain-administrative group in two hops from ordinary user accounts; each route is created by the following specific entries — this inherited delegation on this organisational unit, this ownership record, this nesting — and each is individually removable.* Now the reviewer has something with an owner and a fix. ## Which control class actually removes it Since the read cannot be revoked, the control class is edge removal and privilege partitioning, not visibility restriction: - delete inherited delegations that no longer have a business owner; - reset ownership of privileged objects to an administrative principal; - flatten nesting that quietly promotes a group into an administrative one; - separate accounts into tiers such that no control edge crosses a tier boundary, so that even a complete map contains no route; - give accounts advertising a service principal name long random passwords, since that edge is priced by password strength. Each of those shortens or deletes paths. None of them depends on the attacker not knowing. ## The concessions to make honestly Read access alone is not compromise, and a report that lists enumeration with no path behind it deserves the reviewer's scepticism. Some paths are only theoretically walkable, and some cross a boundary the attacker cannot actually reach. Rank them, and be willing to say which ones you would not spend money on. That is what makes the two-hop ones impossible to argue away.
- So what do you actually write in the finding?The routes, not the query. State how many distinct paths reach a domain-administrative group from ordinary accounts, how many hops each takes, and the exact entries that create them — this inherited delegation, this ownership record, this nested membership. Each line then has an owner and a removal. A finding phrased as 'authenticated users can read the directory' is correct and will be closed as by design.
- If the read cannot be removed, which class of control does close this?Edge removal and privilege partitioning. Delete delegations that no longer have a business owner, reset ownership of privileged objects, flatten convenience nesting, and tier accounts so that no control relationship crosses a tier boundary. Long random passwords on accounts advertising a service principal name remove the one edge whose cost is a crack rather than a grant. None of these rely on the attacker being ignorant.
- Does the attacker need to enumerate the whole estate to benefit?No, and saying otherwise weakens the argument. One route is enough, and a short one is preferred precisely because fewer steps mean fewer opportunities to go wrong. The full enumeration is a convenience for choosing the best route; a targeted read of one organisational unit's delegations can be sufficient on its own.
saying these in an interview costs you the question
- Argues the read itself is the vulnerability
- Proposes denying directory read as the remediation
- Says nothing was modified so nothing happened
- Rates it low because no exploit or patch exists
- Reports enumeration with no concrete path behind it