← Back to feed
Threat Actors & CampaignsEmerging1 sourceApr 8, 2026 · 14:00via Huntress Blog

The ADWS Architecture That Hides PowerShell AD Enumeration

Brief

A threat actor enumerated our entire AD with Get-ADComputer, and none of our detections fired. The problem wasn't their evasion - it was an architectural blind spot in how PowerShell talks to Active Directory.

Read more on Huntress Blog