๐๏ธLDAP
LDAP Queries
Groups
Get-ADObject -LDAPFilter '(objectClass=group)' | select cncn
--
Administrators
Users
Guests
Print Operators
Backup Operators
Replicator
Remote Desktop Users
Network Configuration OperatorsAdministratively Disabled Account
AD Powershell Filters
Filter Installed Software
Filter Out Microsoft Software
Filter for SQL
Filter Administrative Groups
Filter Administrative Users (DoesNotRequiredPreAuth)
Find Administrative Users with the ServicePrincipalName
Operators
Filter
Meaning
Wildcard *
Escaping Characters
Character
Escaped As
Note
LDAP Search Filters
Description Field
Find Trusted Users
Find Trusted Computers
Users With Blank Password
Recursive Match - Powershell
Members Of A Group
User's Group Membership
All Groups of User
Recursvie Match - LDAP Query
All Groups of User
Basic Operators
Operator
Function
Search Criteria
Criteria
Rule
Example
Object Identifiers (OIDs)
Matching rule OID
String identifier
Description
Filter Disabled User Accounts
Find All Groups
Filter Types
Operator
Meaning
Item Types
Escaping Characters
Character
Represented as Hex
SearchScope
Name
Level
Description
Count of All AD Users - PowerShell
Built-in Tools
User Account Control (UAC) - PowerShell
Convert UAC Values - Script
Domain Accounts - PowerView
DS Tools
AD PowerShell Module
Windows Management Instrumentation (WMI)
AD Service Interfaces (ADSI)
LDAP Anonymous Bind
Verify Using Python
Ldapsearch
Windapsearch
Ldapsearch-ad
Asreproast
Pass-pols
Kerberoasting
-t search --search-filter '(objectClass=domainDNS)'
Credentialed LDAP Enumeration
Last updated