[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsy76q06HYytAdonTsMlf4Am3WRU5eLZHQglYkzO_q8I":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},271,"What are the prerequisites for querying Active Directory information from outside the domain using LDAP?","To query AD from outside the domain, you need network access to the Domain Controller’s port 389 (LDAP) and valid credentials for at least one regular domain user. As described in [this article](\u002Fnews\u002Fpenetration-basics-obtaining-active-directory-information), tools like ldapsearch on Kali can then be used with the DN and password to bind and query objects like users, computers, and groups. For environments where AV might interfere, see [Bypass AV techniques](\u002Fnews\u002Fpenetration-basics-active-directory-information-gathering-2-bypass-av).","\u003Cp>To query AD from outside the domain, you need network access to the Domain Controller’s port 389 (LDAP) and valid credentials for at least one regular domain user. As described in [this article](\u002Fnews\u002Fpenetration-basics-obtaining-active-directory-information), tools like ldapsearch on Kali can then be used with the DN and password to bind and query objects like users, computers, and groups. For environments where AV might interfere, see [Bypass AV techniques](\u002Fnews\u002Fpenetration-basics-active-directory-information-gathering-2-bypass-av).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-obtaining-active-directory-information\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-prerequisites-for-querying-active-directory-information-from-outsid-1777484409290","LDAP, port 389, domain credentials, ldapsearch, Active Directory enumeration, penetration testing",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},71,"Penetration Basics - Obtaining Active Directory Information","penetration-basics-obtaining-active-directory-information","Learn how to gather Active Directory info from inside and outside the domain using ldapsearch, PowerView, and C++ ADSI interfaces for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In domain penetration, obtaining Active Directory information is essential\u003C\u002Fp>\u003Cp>This article will take obtaining all users, all computers, and all groups in Active Directory as examples to introduce common information acquisition methods\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for obtaining Active Directory information from outside the domain\u003C\u002Fli>\u003Cli>Methods for obtaining Active Directory information from within the domain\u003C\u002Fli>\u003Cli>Methods for obtaining information using C++ to call ADSI interfaces\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basics\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Domain environments use a directory database to store objects such as user accounts, computer accounts, and groups\u003C\u002Fp>\u003Cp>LDAP (Lightweight Directory Access Protocol) is used to query and update the directory database\u003C\u002Fp>\u003Cp>Common Abbreviations\u003C\u002Fp>\u003Cul>\u003Cli>DN: Distinguished Name\u003C\u002Fli>\u003Cli>CN: Common Name\u003C\u002Fli>\u003Cli>OU: Organizational Unit\u003C\u002Fli>\u003Cli>DC: Domain Controller\u003C\u002Fli>\u003C\u002Ful>\u003Cp>A Distinguished Name (DN) consists of three attributes: CN, OU, and DC.\u003C\u002Fp>\u003Cp>Simple Explanation:\u003C\u002Fp>\u003Cp>The Domain Controller typically has port 389 open by default for LDAP services.\u003C\u002Fp>\u003Ch2>0x03 Methods for Obtaining Active Directory Information from Outside the Domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Querying Data Using ldapsearch on Kali Linux\u003C\u002Fh3>\u003Cp>The test environment is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018770092_0_ff0b330586.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 on the Domain Controller (DC), and we have obtained the credentials of at least one regular domain user.\u003C\u002Fp>\u003Cp>In this test environment, we have obtained the password for the regular domain user 'testa' as DomainUser123!\u003C\u002Fp>\u003Cp>The connection command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cul>\u003Cli>-x   Perform simple authentication\u003C\u002Fli>\u003Cli>-H   Server address\u003C\u002Fli>\u003Cli>-D   DN used to bind to the server\u003C\u002Fli>\u003Cli>-w   Password for binding DN\u003C\u002Fli>\u003Cli>-b   Specify the root node to query\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This command will display all information that can be queried, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018785880_1_3ad8067e45.jpeg\">\u003C\u002Fp>\u003Cp>Next, add search conditions to categorize the results\u003C\u002Fp>\u003Ch4>(1) Query all domain users\u003C\u002Fh4>\u003Cp>Add search condition: \"(&amp;(objectClass=user)(objectCategory=person))\"\u003C\u002Fp>\u003Cp>Complete command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectClass=user)(objectCategory=person))\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will output all attributes of all domain users, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018794889_2_7f9edfcc9b.jpeg\">\u003C\u002Fp>\u003Cp>To facilitate name statistics, you can choose to list only CN (Common Name) and use the grep command to filter the output\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectClass=user)(objectCategory=person))\" CN | grep cn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018806075_3_ef7de42491.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Query all computers\u003C\u002Fh4>\u003Cp>Add search condition: \"(&amp;(objectCategory=computer)(objectClass=computer))\"\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectCategory=computer)(objectClass=computer))\" CN | grep cn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018812251_4_634b15a477.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Query all groups\u003C\u002Fh4>\u003Cp>Add search condition: \"(&amp;(objectCategory=group))\"\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectCategory=group))\" CN | grep cn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018818223_5_87f9f0b594.jpeg\">\u003C\u002Fp>\u003Ch3>2. Querying data through PowerView on Windows systems\u003C\u002Fh3>\u003Cp>The test environment is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018824892_6_7d25a2beba.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 of the domain controller (DC), and we have obtained at least the password of one ordinary user within the domain\u003C\u002Fp>\u003Cp>In this test environment, we have obtained the password for the ordinary domain user testa as DomainUser123!\u003C\u002Fp>\u003Cp>PowerView address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Ch4>(1) Query all domain users\u003C\u002Fh4>\u003Cp>Credentials are required here, so the complete command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetUser -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred  \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To facilitate name statistics, you can choose to list only the name field. The complete command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"                                                      \u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force                   \u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetUser -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred | fl name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018828702_7_db70e507ba.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Query all computers\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"                                                      \u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force                   \u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetComputer -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred | fl name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018832623_8_3c6d7b352c.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Query all groups\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"                                                      \u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force                   \u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetGroup -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred | fl name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018835371_9_efd5a101bf.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Methods for obtaining Active Directory information within the domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The prerequisite is that access to a host within the domain has already been obtained\u003C\u002Fp>\u003Cp>The test environment is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018836811_10_1e622f7d1a.jpeg\">\u003C\u002Fp>\u003Cp>Principle: Perform LDAP queries through ADSI (Active Directory Services Interface) to obtain results\u003C\u002Fp>\u003Ch3>1. Implement using PowerShell\u003C\u002Fh3>\u003Cp>Referencing PowerView, URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Ch3>2. Implemented in C#\u003C\u002Fh3>\u003Cp>Referencing SharpView, URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftevora-threat\u002FSharpView\u003C\u002Fp>\u003Ch3>3. Implemented in C++\u003C\u002Fh3>\u003Cp>Reference URLs:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmicrosoft\u002FWindows-classic-samples\u002Ftree\u002Fmaster\u002FSamples\u002FWin7Samples\u002Fnetds\u002Fadsi\u002Factivedir\u002FQueryUsers\u002Fvc\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Foutflanknl\u002FRecon-AD\u003C\u002Fp>\u003Cp>Microsoft's code is in exe format, only introduces the QueryUser method, but supports query conditions (filtering specific users) and displays brief information (outputs only names for easy statistics)\u003C\u002Fp>\u003Cp>Recon-AD's code is in dll format, includes multiple functions, but by default only displays detailed information\u003C\u002Fp>\u003Cp>Therefore, I merged the code from both, and the code supports the following features:\u003C\u002Fp>\u003Cul>\u003Cli>exe format\u003C\u002Fli>\u003Cli>includes multiple functions, supports querying users, computers, groups, etc.\u003C\u002Fli>\u003Cli>supports query conditions and displays brief information\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code can specify ADS path and search conditions, usage as follows:\u003C\u002Fp>\u003Ch4>(1) Query domain users\u003C\u002Fh4>\u003Cp>List all domain users, displaying only brief name information, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectClass=user)(objectCategory=person))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result output as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018837429_11_c6104ba018.jpeg\">\u003C\u002Fp>\u003Cp>Query all information of a specified user, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectClass=user)(objectCategory=person)(name=testa))\" AllData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result output as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018838206_12_22fa2a97e6.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Query computers\u003C\u002Fh4>\u003Cp>List all computer accounts, displaying only brief name information, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=computer)(objectClass=computer))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018839076_13_33d105c46d.jpeg\">\u003C\u002Fp>\u003Cp>To query detailed information about domain controllers, you need to know the ADS path as \"OU=Domain Controllers,DC=test,DC=com\". The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe \"OU=Domain Controllers,DC=test,DC=com\" \"(&amp;(objectCategory=computer)(objectClass=computer))\" AllData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018839862_14_19c0dac0cb.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Query groups\u003C\u002Fh4>\u003Cp>List all groups, displaying only brief name information. The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=group))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>List detailed information of the administrator group. The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=group)(name=Domain Admins))\" Alldata\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018840797_15_4e61617f4a.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Query OUs\u003C\u002Fh4>\u003Cp>List all OUs, displaying only brief name information. The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=organizationalUnit))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018842087_16_4e491fdffe.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article takes obtaining all users, all computers, and all groups in Active Directory as examples, introducing methods for acquiring information from outside and inside the domain respectively.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In domain penetration, obtaining Active Directory information is essential\u003C\u002Fp>\u003Cp>This article will take obtaining all users, all computers, and all groups in Active Directory as examples to introduce common information acquisition methods\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for obtaining Active Directory information from outside the domain\u003C\u002Fli>\u003Cli>Methods for obtaining Active Directory information from within the domain\u003C\u002Fli>\u003Cli>Methods for obtaining information using C++ to call ADSI interfaces\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basics\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Domain environments use a directory database to store objects such as user accounts, computer accounts, and groups\u003C\u002Fp>\u003Cp>LDAP (Lightweight Directory Access Protocol) is used to query and update the directory database\u003C\u002Fp>\u003Cp>Common Abbreviations\u003C\u002Fp>\u003Cul>\u003Cli>DN: Distinguished Name\u003C\u002Fli>\u003Cli>CN: Common Name\u003C\u002Fli>\u003Cli>OU: Organizational Unit\u003C\u002Fli>\u003Cli>DC: Domain Controller\u003C\u002Fli>\u003C\u002Ful>\u003Cp>A Distinguished Name (DN) consists of three attributes: CN, OU, and DC.\u003C\u002Fp>\u003Cp>Simple Explanation:\u003C\u002Fp>\u003Cp>The Domain Controller typically has port 389 open by default for LDAP services.\u003C\u002Fp>\u003Ch2>0x03 Methods for Obtaining Active Directory Information from Outside the Domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Querying Data Using ldapsearch on Kali Linux\u003C\u002Fh3>\u003Cp>The test environment is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018770092_0_ff0b330586-1.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 on the Domain Controller (DC), and we have obtained the credentials of at least one regular domain user.\u003C\u002Fp>\u003Cp>In this test environment, we have obtained the password for the regular domain user 'testa' as DomainUser123!\u003C\u002Fp>\u003Cp>The connection command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cul>\u003Cli>-x   Perform simple authentication\u003C\u002Fli>\u003Cli>-H   Server address\u003C\u002Fli>\u003Cli>-D   DN used to bind to the server\u003C\u002Fli>\u003Cli>-w   Password for binding DN\u003C\u002Fli>\u003Cli>-b   Specify the root node to query\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This command will display all information that can be queried, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018785880_1_3ad8067e45-1.jpeg\">\u003C\u002Fp>\u003Cp>Next, add search conditions to categorize the results\u003C\u002Fp>\u003Ch4>(1) Query all domain users\u003C\u002Fh4>\u003Cp>Add search condition: \"(&amp;(objectClass=user)(objectCategory=person))\"\u003C\u002Fp>\u003Cp>Complete command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectClass=user)(objectCategory=person))\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will output all attributes of all domain users, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018794889_2_7f9edfcc9b-1.jpeg\">\u003C\u002Fp>\u003Cp>To facilitate name statistics, you can choose to list only CN (Common Name) and use the grep command to filter the output\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectClass=user)(objectCategory=person))\" CN | grep cn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018806075_3_ef7de42491-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Query all computers\u003C\u002Fh4>\u003Cp>Add search condition: \"(&amp;(objectCategory=computer)(objectClass=computer))\"\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectCategory=computer)(objectClass=computer))\" CN | grep cn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018812251_4_634b15a477-1.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Query all groups\u003C\u002Fh4>\u003Cp>Add search condition: \"(&amp;(objectCategory=group))\"\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectCategory=group))\" CN | grep cn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018818223_5_87f9f0b594-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Querying data through PowerView on Windows systems\u003C\u002Fh3>\u003Cp>The test environment is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018824892_6_7d25a2beba-1.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 of the domain controller (DC), and we have obtained at least the password of one ordinary user within the domain\u003C\u002Fp>\u003Cp>In this test environment, we have obtained the password for the ordinary domain user testa as DomainUser123!\u003C\u002Fp>\u003Cp>PowerView address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Ch4>(1) Query all domain users\u003C\u002Fh4>\u003Cp>Credentials are required here, so the complete command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetUser -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred  \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To facilitate name statistics, you can choose to list only the name field. The complete command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"                                                      \u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force                   \u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetUser -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred | fl name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018828702_7_db70e507ba-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Query all computers\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"                                                      \u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force                   \u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetComputer -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred | fl name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018832623_8_3c6d7b352c-1.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Query all groups\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"                                                      \u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force                   \u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetGroup -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred | fl name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018835371_9_efd5a101bf-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Methods for obtaining Active Directory information within the domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The prerequisite is that access to a host within the domain has already been obtained\u003C\u002Fp>\u003Cp>The test environment is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018836811_10_1e622f7d1a-1.jpeg\">\u003C\u002Fp>\u003Cp>Principle: Perform LDAP queries through ADSI (Active Directory Services Interface) to obtain results\u003C\u002Fp>\u003Ch3>1. Implement using PowerShell\u003C\u002Fh3>\u003Cp>Referencing PowerView, URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Ch3>2. Implemented in C#\u003C\u002Fh3>\u003Cp>Referencing SharpView, URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftevora-threat\u002FSharpView\u003C\u002Fp>\u003Ch3>3. Implemented in C++\u003C\u002Fh3>\u003Cp>Reference URLs:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmicrosoft\u002FWindows-classic-samples\u002Ftree\u002Fmaster\u002FSamples\u002FWin7Samples\u002Fnetds\u002Fadsi\u002Factivedir\u002FQueryUsers\u002Fvc\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Foutflanknl\u002FRecon-AD\u003C\u002Fp>\u003Cp>Microsoft's code is in exe format, only introduces the QueryUser method, but supports query conditions (filtering specific users) and displays brief information (outputs only names for easy statistics)\u003C\u002Fp>\u003Cp>Recon-AD's code is in dll format, includes multiple functions, but by default only displays detailed information\u003C\u002Fp>\u003Cp>Therefore, I merged the code from both, and the code supports the following features:\u003C\u002Fp>\u003Cul>\u003Cli>exe format\u003C\u002Fli>\u003Cli>includes multiple functions, supports querying users, computers, groups, etc.\u003C\u002Fli>\u003Cli>supports query conditions and displays brief information\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code can specify ADS path and search conditions, usage as follows:\u003C\u002Fp>\u003Ch4>(1) Query domain users\u003C\u002Fh4>\u003Cp>List all domain users, displaying only brief name information, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectClass=user)(objectCategory=person))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result output as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018837429_11_c6104ba018-1.jpeg\">\u003C\u002Fp>\u003Cp>Query all information of a specified user, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectClass=user)(objectCategory=person)(name=testa))\" AllData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result output as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018838206_12_22fa2a97e6-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Query computers\u003C\u002Fh4>\u003Cp>List all computer accounts, displaying only brief name information, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=computer)(objectClass=computer))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018839076_13_33d105c46d-1.jpeg\">\u003C\u002Fp>\u003Cp>To query detailed information about domain controllers, you need to know the ADS path as \"OU=Domain Controllers,DC=test,DC=com\". The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe \"OU=Domain Controllers,DC=test,DC=com\" \"(&amp;(objectCategory=computer)(objectClass=computer))\" AllData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018839862_14_19c0dac0cb-1.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Query groups\u003C\u002Fh4>\u003Cp>List all groups, displaying only brief name information. The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=group))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>List detailed information of the administrator group. The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=group)(name=Domain Admins))\" Alldata\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018840797_15_4e61617f4a-1.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Query OUs\u003C\u002Fh4>\u003Cp>List all OUs, displaying only brief name information. The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>QueryADObject.exe Current \"(&amp;(objectCategory=organizationalUnit))\" ShortData\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018842087_16_4e491fdffe-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article takes obtaining all users, all computers, and all groups in Active Directory as examples, introducing methods for acquiring information from outside and inside the domain respectively.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1449,"Onedaysec",5,"published","2026-02-02T08:06:59.473Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Active Directory Info Gathering: LDAP & PowerView Methods","Active Directory, LDAP, penetration testing, domain users, PowerView, ldapsearch, ADSI, domain controllers",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,47,4],275,274,273,272,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.444Z","2026-07-23T16:01:18.388Z","draft","2026-07-23T16:04:56.645Z"]