> For the complete documentation index, see [llms.txt](https://lyethar.gitbook.io/methodology/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://lyethar.gitbook.io/methodology/readme/active-directory/attack-vectors/building-userbase.md).

# Building Userbase

In order to first be able to attack an active directory env and we aren't able to gather credentials through NULL sessions, we can possibly make our own naming convention with a website like how we did with the box sauna.

{% embed url="<https://github.com/urbanadventurer/username-anarchy>" %}

This can be done with this script. Once the list is generated we can try to authenticate them using kerbrute.&#x20;
