What is csvde and why would I want to run it on a Windows 7 system during penetration testing?

csvde is a built-in Windows Server command-line tool that exports Active Directory data in CSV format, making the output easy to view and process. While it's natively available on Windows Server, running it on a Windows 7 client can expand your information gathering capabilities during a penetration test, as shown in the article [Penetration Basics - Running csvde on Windows 7](/news/penetration-basics-running-csvde-on-windows-7). This technique pairs well with methods covered in [Penetration Basics - Active Directory Information Gathering 2: Bypass AV](/news/penetration-basics-active-directory-information-gathering-2-bypass-av) for stealthy AD reconnaissance.