Active Directory
ldapsearch / windapsearch
Query LDAP/Active Directory directory data.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Domain-joined recon for users, groups, computers, policies.
How
Bind with creds; query attributes; dump for offline analysis.
Why
AD is an LDAP directory — query it like a database.
Commands & usage
ldapsearch -x -H ldap://10.0.0.10 -D 'user@domain.local' -w 'pass' -b 'dc=domain,dc=local'
windapsearch -d domain.local -u user -p pass --users
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Comparisons
Tags
Related in Active Directory
Impacket
Python collection for Windows network protocols (SMB, WMI, Kerberos, etc.).
CrackMapExec / NetExec
Swiss army knife for pentesting Windows/Active Directory networks (NetExec successor).
BloodHound / SharpHound / AzureHound
Maps Active Directory attack paths using graph theory.
Rubeus
C# toolset for Kerberos abuse (AS-REP, kerberoast, tickets, etc.).
enum4linux-ng
SMB/Windows enumeration tool wrapping common Samba tools.
SMBMap
Enumerates Samba share drives across networks with permissions.