UI
Search…
dcFinder v1.0
Find Domain Controllers using SRV records
dcFinder is basic python script that detects domain controllers in forest enviroinment using scapy module and DNS SRV records. In addition to detect hostname of domain controller, you can find Primary DC that is included in a specific site.
Query types: site, primarydc, globalcatalogdc, nonglobalcatalogdc, kerberos
1
SRV Records:
2
_ldap._tcp.<SiteName>._sites.dc.<DNSDomainName>
3
_ldap._tcp.pdc._msdcs.<DNSDomainName>
4
_ldap._tcp.gc._msdcs.<DNSDomainName>
5
_ldap._tcp.dc._msdcs.<DNSDomainName>
6
_kerberos._tcp.dc._msdcs.<DNSDomainName>
Copied!

Usage:

1
​Use globalcatalogdc option to detect DCs in the Forest.
2
Example : python3 dcFinder.py --lookup --domain offensive.local --query globalcatalogdc
3
Use nonglobalcatalogdc option to check if there are Domain Controller(s) non-global catalog or not.
4
Example : python3 dcFinder.py --lookup --domain offensive.local --query nonglobalcatalogdc
5
Use site option to detect DC in the site.
6
Example : python3 dcFinder.py --lookup --domain offensive.local --query site --sitename gotham
7
Use kerberos option, if you have issue with ldap srv query for finding domain controller.
8
Example : python3 dcFinder.py --lookup --domain offensive.local --query kerberos
9
Copied!
Last modified 1yr ago
Copy link
Contents