Active Directory Inventory
Docusnap automatically collects all relevant Active Directory data, including users, groups, organizational units, and containers.
Active Directory inventory in Docusnap
Permissions
- A full ADS scan requires you to log in as a domain administrator.
- Specified in NetBIOS or UPN notation
- As a domain user, a query is also possible — provided that the standard configuration has not been changed,
- It is not possible to read out the configuration partition
- It is not possible to collect Bitlocker recovery keys. The AD class MSFVE_RecoveryInformation is reserved for domain administrators
- Optional inventory of GPOs requires access to the domain controller via PsExec.exe
- Only one domain user is required for the ADDS reconciliation.
Requirements
- Inventory via script is possible
- Transparent firewall configuration
- PsExec can be blocked by a virus scanner
Supported systems
- LDAP v.2
Logs used
Protokoll
Port
LDAP - Lightweight Directory Access Protocol, unsecured (LDAP)
389
TCP/UDP
LDAP - Lightweight Directory Access Protocol, TLS-secured (LDAPS)
636
TCP/UDP
DCE Endpoint Solution, Microsoft-DS Active Directory, Windows Shares (CIFS) - Group Policy Only
135, 445
TCP