Domain

Show domain info:

[System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()
$domainObj = [System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()
$PDC = ($domainObj.PdcRoleOwner).Name
$SearchString = "LDAP://"
$SearchString += $PDC + "/"
$DistinguishedName = "DC=$($domainObj.Name.Replace('.',',DC='))"
$SearchString += $DistinguishedName
$Searcher = New-Object System.DirectoryServices.DirectorySearcher([ADSI]$SearchString)
$objDomain = New-Object System.DirectoryServices.DirectoryEntry
$Searcher.SearchRoot=$objDomain
$Searcher.filter="samAccountType=805306369"
$Searcher.FindAll()
$Result=$Searcher.FindAll()
Foreach($obj in $Result){
Foreach($prop in $obj.Properties) {$prop}
Write-Host "---------"}

Source: https://learn.microsoft.com/en-us/windows/win32/adschema/a-samaccounttype

Convert Hex to Decimal: https://www.rapidtables.com/convert/number/hex-to-decimal.html

805306369 = enum all user accounts

805306368 = enum all machines

ADModule

PowerView

Last updated