Active Directory Enumeration Cheetsheet

Find Name & OS Version of Domain Controllers

PS C:\Users\Administrator\Downloads> Get-ADDomainController                                  


ComputerObjectDN           : CN=DOMAIN-CONTROLL,OU=Domain Controllers,DC=CONTROLLER,DC=local                                                                          
DefaultPartition           : DC=CONTROLLER,DC=local                                                                                                                   
Domain                     : CONTROLLER.local                                                                                                                         
Enabled                    : True                                                                                                                                     
Forest                     : CONTROLLER.local                                                                                                                         
HostName                   : Domain-Controller.CONTROLLER.local                                                                                                       
InvocationId               : 5669f8e7-9fd9-4eb6-8e27-d54ef7ce9c56                                                                                                     
IPv4Address                : 10.10.25.57                                                                                                                              
IPv6Address                :                                                                                                                                          
IsGlobalCatalog            : True                                                                                                                                     
IsReadOnly                 : False                                                                                                                                    
LdapPort                   : 389                                                                                                                                      
Name                       : DOMAIN-CONTROLL                                                                                                                          
NTDSSettingsObjectDN       : CN=NTDS Settings,CN=DOMAIN-CONTROLL,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=CONTROLLER,DC=local               
OperatingSystem            : Windows Server 2019 Standard Evaluation                                                                                                  
OperatingSystemHotfix      :                                                                                                                                          
OperatingSystemServicePack :                                                                                                                                          
OperatingSystemVersion     : 10.0 (17763)                                                                                                                             
OperationMasterRoles       : {SchemaMaster, DomainNamingMaster, PDCEmulator, RIDMaster...}                                                                            
Partitions                 : {DC=ForestDnsZones,DC=CONTROLLER,DC=local, DC=DomainDnsZones,DC=CONTROLLER,DC=local, CN=Schema,CN=Configuration,DC=CONTROLLER,DC=local,  
                             CN=Configuration,DC=CONTROLLER,DC=local...}                                                                                              
ServerObjectDN             : CN=DOMAIN-CONTROLL,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=CONTROLLER,DC=local                                
ServerObjectGuid           : 53e8b62c-8ba0-44b0-92db-62135874abc3                                                                                                     
Site                       : Default-First-Site-Name                                                                                                                  
SslPort                    : 636                                                                                                                                      
                                                                                                                                                                      
                                                                                                                                                                      
                                                                                                                                                                      
PS C:\Users\Administrator\Downloads>   

Get List of All Operating Systems on The Domain

Get List of All Users on Domain

List All Admins

List All Groups

List All Info on Accounts Belonging to a Certain Group

Last updated