[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fdN2eWa6v3zkDcGcFC5a0EXdbxSgl_iJr__RTxelkdG0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":49,"createdAt":49,"_status":48},10,"What is the main goal of the article 'Penetration Basics - Active Directory Information Gathering 2: Bypass AV'?","The article focuses on gathering Active Directory information while bypassing antivirus software. It builds on the methods introduced in [Penetration Basics - Obtaining Active Directory Information](\u002Fnews\u002Fpenetration-basics-obtaining-active-directory-information) but addresses the problem that some tools may be blocked by AV. It covers using `csvde`, `ldifde`, `AdFind`, and a custom lightweight C# tool as alternatives that are less likely to trigger AV.","\u003Cp>The article focuses on gathering Active Directory information while bypassing antivirus software. It builds on the methods introduced in [Penetration Basics - Obtaining Active Directory Information](\u002Fnews\u002Fpenetration-basics-obtaining-active-directory-information) but addresses the problem that some tools may be blocked by AV. It covers using `csvde`, `ldifde`, `AdFind`, and a custom lightweight C# tool as alternatives that are less likely to trigger AV.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-active-directory-information-gathering-2-bypass-av\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-main-goal-of-the-article-penetration-basics-active-directory-informa-1777485554050","bypass antivirus, Active Directory, information gathering, csvde, ldifde, AdFind, C# tool",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":20,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":45,"updatedAt":46,"createdAt":47,"_status":48},5,"Penetration Basics - Active Directory Information Gathering 2: Bypass AV","penetration-basics-active-directory-information-gathering-2-bypass-av","Learn to bypass AV for Active Directory info gathering using csvde, ldifde, AdFind, and C# tools. Export users, computers, groups securely.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Penetration Basics - Active Directory Information Gathering', common information gathering methods were introduced using examples of obtaining all users, all computers, and all groups in Active Directory.\u003C\u002Fp>\u003Cp>However, in practical use, some tools may be blocked by antivirus software.\u003C\u002Fp>\u003Cp>Therefore, this article will supplement the gathering methods while bypassing antivirus software interception.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Using csvde to obtain Active Directory information\u003C\u002Fli>\u003Cli>Using ldifde to obtain Active Directory information\u003C\u002Fli>\u003Cli>Using AdFind to obtain Active Directory information\u003C\u002Fli>\u003Cli>Using a lightweight gathering tool developed in C#\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Using csvde to obtain Active Directory information\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2012-r2-and-2012\u002Fcc732101(v=ws.11)\u003C\u002Fp>\u003Cp>Files exported using csvde are in CSV format and can be viewed with Microsoft Excel\u003C\u002Fp>\u003Cp>By default, it can only be used on the following systems, for example:\u003C\u002Fp>\u003Cul>\u003Cli>Windows Server 2003\u003C\u002Fli>\u003Cli>Windows Server 2008\u003C\u002Fli>\u003Cli>Windows Server 2003 R2\u003C\u002Fli>\u003Cli>Windows Server 2008 R2\u003C\u002Fli>\u003Cli>Windows Server 2012,\u003C\u002Fli>\u003Cli>Windows Server 2003 with SP1\u003C\u002Fli>\u003Cli>Windows 8\u003C\u002Fli>\u003Cli>...\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Example of exporting Active Directory information from the current domain\u003C\u002Fh3>\u003Cp>Export all information from the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>csvde -f all.csv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all user information in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>csvde -f user.csv -r \"(&amp;(objectCategory=person))\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all machine information in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>csvde -f machine.csv -r \"(&amp;(objectCategory=computer))\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all group information in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>csvde -f group.csv -r \"(&amp;(objectCategory=group))\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all user information in the Domain Admins group in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>csvde -f admin.csv -r \"(&amp;(objectCategory=group)(name=Domain Admins))\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all OU information in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>csvde -f ou.csv -r \"(&amp;(objectCategory=organizationalUnit))\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all domain usernames in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>csvde -f username.csv -r \"(&amp;(objectCategory=person))\" -l SamAccountName\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all computer names in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>csvde -f machinename.csv -r \"(&amp;(objectCategory=computer))\" -l name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Example of remotely exporting Active Directory information from outside the domain\u003C\u002Fh3>\u003Cp>Export all information from the remote domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>csvde -s 192.168.1.1 -a test\\admin Password -f all.csv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Using ldifde to obtain Active Directory information\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2012-r2-and-2012\u002Fcc731033(v=ws.11)\u003C\u002Fp>\u003Cp>The file format exported using ldifde is LDIF, which can be viewed with notepad.exe\u003C\u002Fp>\u003Ch3>1. Example of exporting Active Directory information from the current domain\u003C\u002Fh3>\u003Cp>Export all information from the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldifde -f all.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all user information from the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldifde -r \"(&amp;(objectCategory=person))\" -f user.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all machine information from the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldifde -r \"(&amp;(objectCategory=computer))\" -f machine.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all group information from the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldifde -r \"(&amp;(objectCategory=group))\" -f group.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export user information for all administrator groups in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldifde -r \"(&amp;(objectCategory=group)(name=Domain Admins))\" -f admin.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all OU information in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldifde -r \"(&amp;(objectCategory=organizationalUnit))\" -f ou.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all domain usernames in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldifde -r \"(&amp;(objectCategory=person))\" -l SamAccountName -f username.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all computer names in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldifde -r \"(&amp;(objectCategory=computer))\" -l name -f machinename.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Example of remotely exporting Active Directory information from outside the domain\u003C\u002Fh3>\u003Cp>Export all information from the remote domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldifde -s 192.168.1.1 -a test\\admin Password -f all.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Using AdFind to obtain Active Directory information\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.joeware.net\u002Ffreetools\u002Ftools\u002Fadfind\u002F\u003C\u002Fp>\u003Ch3>1. Example of Exporting Active Directory Information from Current Domain\u003C\u002Fh3>\u003Cp>Export all information from current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>adfind.exe -h 127.0.0.1&gt;all.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all user information from current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>adfind.exe -h 127.0.0.1 -f objectcategory=person&gt;user.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all machine information from current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>adfind.exe -h 127.0.0.1 -f objectcategory=computer&gt;machine.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all group information from current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>adfind.exe -h 127.0.0.1 -f objectcategory=group&gt;group.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all user information from Domain Admins group in current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>adfind.exe -h 127.0.0.1 -f \"(&amp;(objectCategory=group)(name=Domain Admins))\"&gt;admin.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all OU information from current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>adfind.exe -h 127.0.0.1 -f objectcategory=organizationalUnit&gt;ou.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all domain usernames from current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>adfind.exe -h 127.0.0.1 -f objectcategory=person SamAccountName&gt;username.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all computer names in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>adfind.exe -h 127.0.0.1 -f objectcategory=computer name&gt;machinename.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Example of remotely exporting Active Directory information from outside the domain\u003C\u002Fh3>\u003Cp>Export all information from the remote domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>adfind.exe -h 192.168.1.1 -u test\\admin -up Password&gt;all.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Lightweight acquisition tool developed in C#\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SharpView implements the functionality of PowerView for obtaining Active Directory information through .Net, with comprehensive features, but it may be intercepted by antivirus software.\u003C\u002Fp>\u003Cp>By calling the System.DirectoryServices namespace, we can easily implement simple functions to meet basic needs, and typically, it will not be intercepted by antivirus software.\u003C\u002Fp>\u003Cp>Here, the previous code ListUserMailbyLDAP.cs can be used as a template, and only the query statement needs to be modified.\u003C\u002Fp>\u003Cp>I have implemented a lightweight tool based on the basic functionality of AdFind as a reference. The complete code has been uploaded to GitHub, and the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>SharpADFindDemo can be directly compiled on Windows systems with .Net 3.5 or .Net 4\u003C\u002Fp>\u003Cp>The compilation method is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe SharpADFindDemo.cs \u002Fr:System.DirectoryServices.dll\u003Cbr>or\u003Cbr>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe SharpADFindDemo.cs \u002Fr:System.DirectoryServices.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Supports exporting the following AD information:\u003C\u002Fp>\u003Cul>\u003Cli>user, all domain user information\u003C\u002Fli>\u003Cli>machine, all domain computer information\u003C\u002Fli>\u003Cli>group, all domain group information\u003C\u002Fli>\u003Cli>ou, all domain OU information\u003C\u002Fli>\u003Cli>username, export only domain usernames\u003C\u002Fli>\u003Cli>machinename, export only domain computer names\u003C\u002Fli>\u003Cli>groupname, export only domain group names\u003C\u002Fli>\u003Cli>ouname, export only domain OU names\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Note that the default maximum number of exports is 1000\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article supplements the methods for obtaining Active Directory information, introduces three commonly used tools, develops a lightweight acquisition tool SharpADFindDemo using C#, and suggests that it can serve as a template to integrate additional features with SharpView in the future.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",4,"published","2026-02-02T08:21:21.083Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Bypass AV for Active Directory Info Gathering: csvde, ldifde, AdFind","Active Directory, information gathering, bypass antivirus, csvde, ldifde, AdFind, penetration testing, AD tools",false,[],{"docs":41,"hasNextPage":38},[42,43,44,4],13,12,11,{"title":30,"description":30,"image":30},"2026-07-24T02:07:31.011Z","2026-07-23T16:00:53.579Z","draft","2026-07-23T16:02:52.828Z"]