DNS
Dig -t SRV _gc._tcp.<FQDN>
Dig -t SRV _ldap._tcp.<FQDN>
Dig -t SRV _kerberos._tcp.<FQDN>
Dig -t SRV _kpasswd._tcp.<FQDN>nmap --script dns-srv-enum -script-args "dns-srv-enum.domain='<FQDN>'"nslookup <DOMAIN.COM>
nslookup -type=srv _kerberos._tcp.DOMAIN.COM
nslookup -type=srv _kpasswd._tcp.DOMAIN.COM
nslookup -type=srv _ldap._tcp.DOMAIN.COM
nslookup -type=srv _ldap._tcp.dc._msdcs.DOMAIN.COMLast updated