[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-kjZY3QxXOkdgPNR0yeYl1wUDzTwcl5jdZiKH8TS6_o":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},275,"How does the C++ tool QueryADObject.exe improve upon Microsoft’s sample code for AD enumeration?","The C++ tool merges features from Microsoft’s sample and Recon-AD, providing an exe format with multiple functions for querying users, computers, and groups. It supports search conditions and offers a `ShortData` output mode for concise name listing, unlike Microsoft’s limited `QueryUser` method. This makes enumeration more efficient and is especially useful during penetration tests where speed matters, similar to the approaches in [obtaining installed programs](\u002Fnews\u002Fpenetration-basics-obtaining-the-list-of-installed-programs-on-the-current-system).","\u003Cp>The C++ tool merges features from Microsoft’s sample and Recon-AD, providing an exe format with multiple functions for querying users, computers, and groups. It supports search conditions and offers a `ShortData` output mode for concise name listing, unlike Microsoft’s limited `QueryUser` method. This makes enumeration more efficient and is especially useful during penetration tests where speed matters, similar to the approaches in [obtaining installed programs](\u002Fnews\u002Fpenetration-basics-obtaining-the-list-of-installed-programs-on-the-current-system).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-obtaining-active-directory-information\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-c-tool-queryadobjectexe-improve-upon-microsofts-sample-code-for-ad--1777484409671","QueryADObject, ADSI, C++ ADSI, Recon-AD, Microsoft samples, custom tool, output modes, efficiency",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},71,"Penetration Basics - Obtaining Active Directory Information","penetration-basics-obtaining-active-directory-information","Learn how to gather Active Directory info from inside and outside the domain using ldapsearch, PowerView, and C++ ADSI interfaces for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In domain penetration, obtaining Active Directory information is essential\u003C\u002Fp>\u003Cp>This article will take obtaining all users, all computers, and all groups in Active Directory as examples to introduce common information acquisition methods\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for obtaining Active Directory information from outside the domain\u003C\u002Fli>\u003Cli>Methods for obtaining Active Directory information from within the domain\u003C\u002Fli>\u003Cli>Methods for obtaining information using C++ to call ADSI interfaces\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basics\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Domain environments use a directory database to store objects such as user accounts, computer accounts, and groups\u003C\u002Fp>\u003Cp>LDAP (Lightweight Directory Access Protocol) is used to query and update the directory database\u003C\u002Fp>\u003Cp>Common Abbreviations\u003C\u002Fp>\u003Cul>\u003Cli>DN: Distinguished Name\u003C\u002Fli>\u003Cli>CN: Common Name\u003C\u002Fli>\u003Cli>OU: Organizational Unit\u003C\u002Fli>\u003Cli>DC: Domain Controller\u003C\u002Fli>\u003C\u002Ful>\u003Cp>A Distinguished Name (DN) consists of three attributes: CN, OU, and DC.\u003C\u002Fp>\u003Cp>Simple Explanation:\u003C\u002Fp>\u003Cp>The Domain Controller typically has port 389 open by default for LDAP services.\u003C\u002Fp>\u003Ch2>0x03 Methods for Obtaining Active Directory Information from Outside the Domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Querying Data Using ldapsearch on Kali Linux\u003C\u002Fh3>\u003Cp>The test environment is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018770092_0_ff0b330586.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 on the Domain Controller (DC), and we have obtained the credentials of at least one regular domain user.\u003C\u002Fp>\u003Cp>In this test environment, we have obtained the password for the regular domain user 'testa' as DomainUser123!\u003C\u002Fp>\u003Cp>The connection command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cul>\u003Cli>-x   Perform simple authentication\u003C\u002Fli>\u003Cli>-H   Server address\u003C\u002Fli>\u003Cli>-D   DN used to bind to the server\u003C\u002Fli>\u003Cli>-w   Password for binding DN\u003C\u002Fli>\u003Cli>-b   Specify the root node to query\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This command will display all information that can be queried, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018785880_1_3ad8067e45.jpeg\">\u003C\u002Fp>\u003Cp>Next, add search conditions to categorize the results\u003C\u002Fp>\u003Ch4>(1) Query all domain users\u003C\u002Fh4>\u003Cp>Add search condition: \"(&amp;(objectClass=user)(objectCategory=person))\"\u003C\u002Fp>\u003Cp>Complete command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectClass=user)(objectCategory=person))\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will output all attributes of all domain users, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018794889_2_7f9edfcc9b.jpeg\">\u003C\u002Fp>\u003Cp>To facilitate name statistics, you can choose to list only CN (Common Name) and use the grep command to filter the output\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectClass=user)(objectCategory=person))\" CN | grep cn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018806075_3_ef7de42491.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Query all computers\u003C\u002Fh4>\u003Cp>Add search condition: \"(&amp;(objectCategory=computer)(objectClass=computer))\"\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectCategory=computer)(objectClass=computer))\" CN | grep cn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018812251_4_634b15a477.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Query all groups\u003C\u002Fh4>\u003Cp>Add search condition: \"(&amp;(objectCategory=group))\"\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectCategory=group))\" CN | grep cn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018818223_5_87f9f0b594.jpeg\">\u003C\u002Fp>\u003Ch3>2. Querying data through PowerView on Windows systems\u003C\u002Fh3>\u003Cp>The test environment is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018824892_6_7d25a2beba.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 of the domain controller (DC), and we have obtained at least the password of one ordinary user within the domain\u003C\u002Fp>\u003Cp>In this test environment, we have obtained the password for the ordinary domain user testa as DomainUser123!\u003C\u002Fp>\u003Cp>PowerView address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Ch4>(1) Query all domain users\u003C\u002Fh4>\u003Cp>Credentials are required here, so the complete command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetUser -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred  \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To facilitate name statistics, you can choose to list only the name field. The complete command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"                                                      \u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force                   \u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetUser -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred | fl name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018828702_7_db70e507ba.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Query all computers\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"                                                      \u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force                   \u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetComputer -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred | fl name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018832623_8_3c6d7b352c.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Query all groups\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"                                                      \u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force                   \u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetGroup -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred | fl name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018835371_9_efd5a101bf.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Methods for obtaining Active Directory information within the domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The prerequisite is that access to a host within the domain has already been obtained\u003C\u002Fp>\u003Cp>The test environment is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018836811_10_1e622f7d1a.jpeg\">\u003C\u002Fp>\u003Cp>Principle: Perform LDAP queries through ADSI (Active Directory Services Interface) to obtain results\u003C\u002Fp>\u003Ch3>1. Implement using PowerShell\u003C\u002Fh3>\u003Cp>Referencing PowerView, URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Ch3>2. Implemented in C#\u003C\u002Fh3>\u003Cp>Referencing SharpView, URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftevora-threat\u002FSharpView\u003C\u002Fp>\u003Ch3>3. Implemented in C++\u003C\u002Fh3>\u003Cp>Reference URLs:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmicrosoft\u002FWindows-classic-samples\u002Ftree\u002Fmaster\u002FSamples\u002FWin7Samples\u002Fnetds\u002Fadsi\u002Factivedir\u002FQueryUsers\u002Fvc\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Foutflanknl\u002FRecon-AD\u003C\u002Fp>\u003Cp>Microsoft's code is in exe format, only introduces the QueryUser method, but supports query conditions (filtering specific users) and displays brief information (outputs only names for easy statistics)\u003C\u002Fp>\u003Cp>Recon-AD's code is in dll format, includes multiple functions, but by default only displays detailed information\u003C\u002Fp>\u003Cp>Therefore, I merged the code from both, and the code supports the following features:\u003C\u002Fp>\u003Cul>\u003Cli>exe format\u003C\u002Fli>\u003Cli>includes multiple functions, supports querying users, computers, groups, etc.\u003C\u002Fli>\u003Cli>supports query conditions and displays brief information\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code can specify ADS path and search conditions, usage as follows:\u003C\u002Fp>\u003Ch4>(1) Query domain users\u003C\u002Fh4>\u003Cp>List all domain users, displaying only brief name information, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectClass=user)(objectCategory=person))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result output as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018837429_11_c6104ba018.jpeg\">\u003C\u002Fp>\u003Cp>Query all information of a specified user, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectClass=user)(objectCategory=person)(name=testa))\" AllData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result output as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018838206_12_22fa2a97e6.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Query computers\u003C\u002Fh4>\u003Cp>List all computer accounts, displaying only brief name information, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=computer)(objectClass=computer))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018839076_13_33d105c46d.jpeg\">\u003C\u002Fp>\u003Cp>To query detailed information about domain controllers, you need to know the ADS path as \"OU=Domain Controllers,DC=test,DC=com\". The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe \"OU=Domain Controllers,DC=test,DC=com\" \"(&amp;(objectCategory=computer)(objectClass=computer))\" AllData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018839862_14_19c0dac0cb.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Query groups\u003C\u002Fh4>\u003Cp>List all groups, displaying only brief name information. The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=group))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>List detailed information of the administrator group. The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=group)(name=Domain Admins))\" Alldata\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018840797_15_4e61617f4a.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Query OUs\u003C\u002Fh4>\u003Cp>List all OUs, displaying only brief name information. The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=organizationalUnit))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018842087_16_4e491fdffe.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article takes obtaining all users, all computers, and all groups in Active Directory as examples, introducing methods for acquiring information from outside and inside the domain respectively.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In domain penetration, obtaining Active Directory information is essential\u003C\u002Fp>\u003Cp>This article will take obtaining all users, all computers, and all groups in Active Directory as examples to introduce common information acquisition methods\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for obtaining Active Directory information from outside the domain\u003C\u002Fli>\u003Cli>Methods for obtaining Active Directory information from within the domain\u003C\u002Fli>\u003Cli>Methods for obtaining information using C++ to call ADSI interfaces\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basics\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Domain environments use a directory database to store objects such as user accounts, computer accounts, and groups\u003C\u002Fp>\u003Cp>LDAP (Lightweight Directory Access Protocol) is used to query and update the directory database\u003C\u002Fp>\u003Cp>Common Abbreviations\u003C\u002Fp>\u003Cul>\u003Cli>DN: Distinguished Name\u003C\u002Fli>\u003Cli>CN: Common Name\u003C\u002Fli>\u003Cli>OU: Organizational Unit\u003C\u002Fli>\u003Cli>DC: Domain Controller\u003C\u002Fli>\u003C\u002Ful>\u003Cp>A Distinguished Name (DN) consists of three attributes: CN, OU, and DC.\u003C\u002Fp>\u003Cp>Simple Explanation:\u003C\u002Fp>\u003Cp>The Domain Controller typically has port 389 open by default for LDAP services.\u003C\u002Fp>\u003Ch2>0x03 Methods for Obtaining Active Directory Information from Outside the Domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Querying Data Using ldapsearch on Kali Linux\u003C\u002Fh3>\u003Cp>The test environment is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018770092_0_ff0b330586-1.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 on the Domain Controller (DC), and we have obtained the credentials of at least one regular domain user.\u003C\u002Fp>\u003Cp>In this test environment, we have obtained the password for the regular domain user 'testa' as DomainUser123!\u003C\u002Fp>\u003Cp>The connection command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cul>\u003Cli>-x   Perform simple authentication\u003C\u002Fli>\u003Cli>-H   Server address\u003C\u002Fli>\u003Cli>-D   DN used to bind to the server\u003C\u002Fli>\u003Cli>-w   Password for binding DN\u003C\u002Fli>\u003Cli>-b   Specify the root node to query\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This command will display all information that can be queried, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018785880_1_3ad8067e45-1.jpeg\">\u003C\u002Fp>\u003Cp>Next, add search conditions to categorize the results\u003C\u002Fp>\u003Ch4>(1) Query all domain users\u003C\u002Fh4>\u003Cp>Add search condition: \"(&amp;(objectClass=user)(objectCategory=person))\"\u003C\u002Fp>\u003Cp>Complete command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectClass=user)(objectCategory=person))\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will output all attributes of all domain users, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018794889_2_7f9edfcc9b-1.jpeg\">\u003C\u002Fp>\u003Cp>To facilitate name statistics, you can choose to list only CN (Common Name) and use the grep command to filter the output\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectClass=user)(objectCategory=person))\" CN | grep cn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018806075_3_ef7de42491-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Query all computers\u003C\u002Fh4>\u003Cp>Add search condition: \"(&amp;(objectCategory=computer)(objectClass=computer))\"\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectCategory=computer)(objectClass=computer))\" CN | grep cn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018812251_4_634b15a477-1.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Query all groups\u003C\u002Fh4>\u003Cp>Add search condition: \"(&amp;(objectCategory=group))\"\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectCategory=group))\" CN | grep cn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018818223_5_87f9f0b594-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Querying data through PowerView on Windows systems\u003C\u002Fh3>\u003Cp>The test environment is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018824892_6_7d25a2beba-1.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 of the domain controller (DC), and we have obtained at least the password of one ordinary user within the domain\u003C\u002Fp>\u003Cp>In this test environment, we have obtained the password for the ordinary domain user testa as DomainUser123!\u003C\u002Fp>\u003Cp>PowerView address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Ch4>(1) Query all domain users\u003C\u002Fh4>\u003Cp>Credentials are required here, so the complete command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetUser -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred  \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To facilitate name statistics, you can choose to list only the name field. The complete command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"                                                      \u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force                   \u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetUser -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred | fl name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018828702_7_db70e507ba-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Query all computers\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"                                                      \u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force                   \u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetComputer -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred | fl name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018832623_8_3c6d7b352c-1.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Query all groups\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"                                                      \u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force                   \u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetGroup -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred | fl name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018835371_9_efd5a101bf-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Methods for obtaining Active Directory information within the domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The prerequisite is that access to a host within the domain has already been obtained\u003C\u002Fp>\u003Cp>The test environment is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018836811_10_1e622f7d1a-1.jpeg\">\u003C\u002Fp>\u003Cp>Principle: Perform LDAP queries through ADSI (Active Directory Services Interface) to obtain results\u003C\u002Fp>\u003Ch3>1. Implement using PowerShell\u003C\u002Fh3>\u003Cp>Referencing PowerView, URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Ch3>2. Implemented in C#\u003C\u002Fh3>\u003Cp>Referencing SharpView, URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftevora-threat\u002FSharpView\u003C\u002Fp>\u003Ch3>3. Implemented in C++\u003C\u002Fh3>\u003Cp>Reference URLs:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmicrosoft\u002FWindows-classic-samples\u002Ftree\u002Fmaster\u002FSamples\u002FWin7Samples\u002Fnetds\u002Fadsi\u002Factivedir\u002FQueryUsers\u002Fvc\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Foutflanknl\u002FRecon-AD\u003C\u002Fp>\u003Cp>Microsoft's code is in exe format, only introduces the QueryUser method, but supports query conditions (filtering specific users) and displays brief information (outputs only names for easy statistics)\u003C\u002Fp>\u003Cp>Recon-AD's code is in dll format, includes multiple functions, but by default only displays detailed information\u003C\u002Fp>\u003Cp>Therefore, I merged the code from both, and the code supports the following features:\u003C\u002Fp>\u003Cul>\u003Cli>exe format\u003C\u002Fli>\u003Cli>includes multiple functions, supports querying users, computers, groups, etc.\u003C\u002Fli>\u003Cli>supports query conditions and displays brief information\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code can specify ADS path and search conditions, usage as follows:\u003C\u002Fp>\u003Ch4>(1) Query domain users\u003C\u002Fh4>\u003Cp>List all domain users, displaying only brief name information, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectClass=user)(objectCategory=person))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result output as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018837429_11_c6104ba018-1.jpeg\">\u003C\u002Fp>\u003Cp>Query all information of a specified user, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectClass=user)(objectCategory=person)(name=testa))\" AllData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result output as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018838206_12_22fa2a97e6-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Query computers\u003C\u002Fh4>\u003Cp>List all computer accounts, displaying only brief name information, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=computer)(objectClass=computer))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018839076_13_33d105c46d-1.jpeg\">\u003C\u002Fp>\u003Cp>To query detailed information about domain controllers, you need to know the ADS path as \"OU=Domain Controllers,DC=test,DC=com\". The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe \"OU=Domain Controllers,DC=test,DC=com\" \"(&amp;(objectCategory=computer)(objectClass=computer))\" AllData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018839862_14_19c0dac0cb-1.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Query groups\u003C\u002Fh4>\u003Cp>List all groups, displaying only brief name information. The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=group))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>List detailed information of the administrator group. The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=group)(name=Domain Admins))\" Alldata\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018840797_15_4e61617f4a-1.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Query OUs\u003C\u002Fh4>\u003Cp>List all OUs, displaying only brief name information. The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=organizationalUnit))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018842087_16_4e491fdffe-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article takes obtaining all users, all computers, and all groups in Active Directory as examples, introducing methods for acquiring information from outside and inside the domain respectively.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1449,"Onedaysec",5,"published","2026-02-02T08:06:59.473Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Active Directory Info Gathering: LDAP & PowerView Methods","Active Directory, LDAP, penetration testing, domain users, PowerView, ldapsearch, ADSI, domain controllers",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],274,273,272,271,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.444Z","2026-07-23T16:01:18.388Z","draft","2026-07-23T16:04:58.414Z"]