AD Tools: Repadmin /KCC Repadmin /PRP Repadmin /queue
AD Tools: Repadmin /KCC Repadmin /PRP Repadmin /queue
OU Tools
net user /add name - to add user
net computer\\name /add - to add computer
redir username redir cmp dsadd ou= ,dc= ,dc= - to add ou
dsrm ou= ,dc= ,dc= - to remove ou
dsmove ou= ,dc= ,dc= -newparent ou= ,dc= ,dc= - to move one ou to other
dsmove cn= ,ou= ,dc= ,dc= -newparent cn= ,ou= ,dc= ,dc= - to move and rename a user from one ou to
other
GPO Tools
gptool - to check the total group policies in dc
gpresult - shows the entire group policy settings for a user
gpupdate - updates changes made in group policy
dcgpofix - to restore default default domain policy and default domain controller policy to the state that
exists immediately after a clean install
gpupdate /force - updates group policy by force
ntfrsutl ds - fixs the replication problems
replmon - to view active directory replication monitor we can check the replication errors
Dsquery server -isgc - to know the Global Catalog Servers
FSMO Roles
whoami /user - to know user information and SID of the user
dcdiag /domain:ridmanager - to run domain controller diagnostics
netdom query fsmo - to see all operational masters in DC
IP Tools
ipconfig- to check the ip address, subnet mask, default gateway address
ipconfig /? - for all available ip addresses
ipconfig /all - shows ip configuration like windows ip configuration, ethernet adapter, wifi, bluetooth
ipconfig /release ipconfig /renew ipconfig /displaydns ipconfig /flushdns - clears DNS Resolver cache
ipconfig /registerdns - we can register a fresh DNS Server
arp -a - to know MAC address of different DNS Server
arp -d - to clear arp cache
nbtstat -r - it shows any netbios names resolution
nbtstat -R - Purge & Preload NBT Remote cache name table
nbtstat -RR - it will refresh the registered netbios names
netstat -a - shows all ports
netstat -a -n - shows the ip address ports
APIPA (Automatic Private IP Address) - if DHCP sever goes down, APIPA allocates a IP address
tracert webname - to check whether the lines are passing through routes within time or not
DNS Tools
dnscmd /clear cache - to clear cache
nslookup - to check the current dnsserver
dnscmd servername /create directory partition FQDN - to custom directory partition(to replicate for only
some servers)
dnscmd servername /enlist directory partition FQDN - to replicate the data above created
dnscmd servername /unenlist directory partition FQDN - to disappear
dnscmd servername /delete directory partition FQDN - to remove from created server
DHCP Tools
netsh dhcp show server - shows no. of authorized dhcp servers
dhcploc - to identify rouge dhcp servers active on the subnet
Groups Tools
ldifde(LDAP data interchange format) dsadd group cn= ,ou= ,dc= ,dc= -scope - to add a group along with its scope
Certificate Tools
certutil.exe - to see the sanitized name
certutil.exe -v -ds - to see all of the CA related ADnames
certreq.exe - Requests Certificates from CA
kerberos tools:
kerbtray.exe:
Consoles
Domain.msc:
Ports
Protocol
TCP
TCP & UDP
TCP & UDP
TCP & UDP
UDP
TCP
UDP
UDP
TCP
TCP
&
UD
P
TCP
TCP
TCP
TCP
&
UD
P
UD
P
TCP
TCP
TCP
UD
P
TCP
&
UD
P
TCP
Port Number
25
53
88
464
123
135
137
138
139
389
Services
SMTP
DNS
Kerberos
Kerberos Password Change
Windows Time
RPC
NetLogon / NETBIOS Resolution
DFSN, NetLogon, NETBIOS Datagram Service
DFSN, NetLogon, NETBIOS Session Service
LDAP
636
3268
3269
445
LDAP SSL
LDAP GC
LDAP GC SSL (Secured Socket Layer)
SMB (Sever Message Block)
66/67
DHCP
5722
1723
465
1701
SYSVOL, FRS
PPTP (Point to Point Tunnel Protocol)
SMTP SSL
L2TP (Layer 2 Tunnel Protocol)
80
HTTP
443
HTTPS
&
UD
P
TCP
TCP
TCP
&
UD
P
UD
P
TCP
&
UD
P
20/21
23
22
FTP
Telnet
SSH(Secure Shell)
69
3389
REMOTE DESKTOP