Enumeration

Domain Information

$ADCLass = [System.DirectoryServices.ActiveDirectory.Domain];$ADClass::GetCurrentDomain();
Get-WmiObject -Namespace root\directory\ldap -Class ds_domain | select ds_dc, ds_distinguishedname, pscomputername

#get DC
Get-WmiObject -Namespace root\directory\ldap -Class ds_computer | where {$_.ds_useraccountcontrol -match 532480} | select ds_cn, ds_dnshostname, ds_operatingsystem

#get servers
Get-WmiObject -Namespace root\directory\ldap -Class ds_computer | where {$_.ds_useraccountcontrol -match 4096} | select ds_cn, ds_dnshostname, ds_operatingsystem

Machines

Get-WmiObject -Namespace root\directory\ldap -Class ds_computer

User Information

net user /domain        #list all
net user <user>/domain  #get info on the user
net accounts /domain    #get info on the account policies

Groups

net group /domain            //list all
net group <group> /domain    //get info on group

Group Policies (GPO)

gpresult /RV        #get set of policies applied on current machine

Last updated