Enumeration
Domain Information
$ADCLass = [System.DirectoryServices.ActiveDirectory.Domain];$ADClass::GetCurrentDomain();
Get-WmiObject -Namespace root\directory\ldap -Class ds_domain | select ds_dc, ds_distinguishedname, pscomputername
#get DC
Get-WmiObject -Namespace root\directory\ldap -Class ds_computer | where {$_.ds_useraccountcontrol -match 532480} | select ds_cn, ds_dnshostname, ds_operatingsystem
#get servers
Get-WmiObject -Namespace root\directory\ldap -Class ds_computer | where {$_.ds_useraccountcontrol -match 4096} | select ds_cn, ds_dnshostname, ds_operatingsystem
Machines
Get-WmiObject -Namespace root\directory\ldap -Class ds_computer
User Information
net user /domain #list all
net user <user>/domain #get info on the user
net accounts /domain #get info on the account policies
Groups
net group /domain //list all
net group <group> /domain //get info on group
Group Policies (GPO)
gpresult /RV #get set of policies applied on current machine
Last updated