Active Directory Inventory

Docusnap automatically collects all relevant Active Directory data, including users, groups, organizational units, and containers.

Permissions

  • A full ADS scan requires you to log in as a domain administrator.
    • Specified in NetBIOS or UPN notation
  • As a domain user, a query is also possible — provided that the standard configuration has not been changed,
    • It is not possible to read out the configuration partition
    • It is not possible to collect Bitlocker recovery keys. The AD class MSFVE_RecoveryInformation is reserved for domain administrators
  • Optional inventory of GPOs requires access to the domain controller via PsExec.exe
  • Only one domain user is required for the ADDS reconciliation.

Requirements

  • Inventory via script is possible
  • Transparent firewall configuration
  • PsExec can be blocked by a virus scanner

Supported systems

  • LDAP v.2

Logs used

Protokoll

Port

LDAP - Lightweight Directory Access Protocol, unsecured (LDAP)

389

TCP/UDP

LDAP - Lightweight Directory Access Protocol, TLS-secured (LDAPS)

636

TCP/UDP

DCE Endpoint Solution, Microsoft-DS Active Directory, Windows Shares (CIFS) - Group Policy Only

135, 445

TCP