Active Directory Enumeration Cheetsheet
Find Name & OS Version of Domain Controllers
PS C:\Users\Administrator\Downloads> Get-ADDomainController
ComputerObjectDN : CN=DOMAIN-CONTROLL,OU=Domain Controllers,DC=CONTROLLER,DC=local
DefaultPartition : DC=CONTROLLER,DC=local
Domain : CONTROLLER.local
Enabled : True
Forest : CONTROLLER.local
HostName : Domain-Controller.CONTROLLER.local
InvocationId : 5669f8e7-9fd9-4eb6-8e27-d54ef7ce9c56
IPv4Address : 10.10.25.57
IPv6Address :
IsGlobalCatalog : True
IsReadOnly : False
LdapPort : 389
Name : DOMAIN-CONTROLL
NTDSSettingsObjectDN : CN=NTDS Settings,CN=DOMAIN-CONTROLL,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=CONTROLLER,DC=local
OperatingSystem : Windows Server 2019 Standard Evaluation
OperatingSystemHotfix :
OperatingSystemServicePack :
OperatingSystemVersion : 10.0 (17763)
OperationMasterRoles : {SchemaMaster, DomainNamingMaster, PDCEmulator, RIDMaster...}
Partitions : {DC=ForestDnsZones,DC=CONTROLLER,DC=local, DC=DomainDnsZones,DC=CONTROLLER,DC=local, CN=Schema,CN=Configuration,DC=CONTROLLER,DC=local,
CN=Configuration,DC=CONTROLLER,DC=local...}
ServerObjectDN : CN=DOMAIN-CONTROLL,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=CONTROLLER,DC=local
ServerObjectGuid : 53e8b62c-8ba0-44b0-92db-62135874abc3
Site : Default-First-Site-Name
SslPort : 636
PS C:\Users\Administrator\Downloads> Get List of All Operating Systems on The Domain
Get List of All Users on Domain
List All Admins
List All Groups
List All Info on Accounts Belonging to a Certain Group
Last updated