http://www.joeware.net/freetools/tools/adfind/ adfind.exe -f "(objectcategory=organizationalUnit)" adfind.exe -gcb -sc trustdmp adfind.exe -f "objectcategory=computer" adfind.exe -sc trustdmp adfind.exe -f "(objectcategory=person)" adfind.exe -subnets -f (objectCategory=subnet) adfind.exe -f "(objectcategory=group)" esentutl /p /o C:\Users\[USER]\AppData\Local\Temp\grabber_temp.edb Nltest / domain_trusts /all_trusts Net view /all Nltest /domain_trusts Net view /all /domain Ipconfig /all Net config workstation Nslookup “-q=srv_kerberos._tcp” dsquery * -filter "(objectClass=trustedDomain)" -attr *