Dsrep

Interacts with Directory Replication Service

Synopsis

Dsrep <subcommand>

Subcommands

Command Description
dcinfo Gets information on domain controllers
rep Requests replica changes
repnc Replicates a naming context

For help on a subcommand, use Dsrep <subcommand> -h

Dsrep dcinfo

Gets information on domain controllers

Synopsis

Dsrep dcinfo [options] <ServerName>

Parameters

Name Aliases Value Description
<ServerName>   <String> RPC server to interact with

Options

Name Aliases Value Description
-Accept2003Deflate   <SwitchParam> Accept data compressed with Windows Server 2003 Deflate
      Default: True
-AuthEpm   <SwitchParam> Authenticates EP mapper requests
-AuthProxy   <EndPoint> Endpoint of auth proxy
-ConsoleOutputStyle -OutputStyle <OutputStyle> Determines the output style
      Possible values:
      Freeform
      Raw
      Table
      List
      Csv
      Tsv
      Json
      TreeTable
-Delegate   <SwitchParam> Requests delegation (sends TGT and key for Kerberos)
-EncryptEpm   <SwitchParam> Encrypts EP mappend requests
-EncryptRpc   <SwitchParam> Encrypts RPC messages
-OutputFields   <String[]> Fields to display in output
      Possible values:
      NetbiosName
      DnsHostName
      SiteName
      SiteObjectName
      ComputerObjectName
      ServerObjectName
      NtdsDsaObjectName
      IsPdc
      IsDsEnabled
      IsGc
      SiteObjectGuid
      ComputerObjectGuid
      ServerObjectGuid
      NtdsDsaObjectGuid
-OutputHeaders   <SwitchParam> Print headers for table/list/CSV/TSV styles
      Default: True
-PreferSmb   <SwitchParam> If the interface supports named pipes, attempt to connect over the named pipe instead of TCP
-RpcCallTimeout   <Duration> Time to wait for RPC calls
-RpcConnectTimeout   <Duration> Time to wait for RPC connections
-Socks5   <host-or-ip:port> End point of SOCKS 5 server to use
-Spnego   <SwitchParam> Uses SP-NEGO for authentication
-SpnOverride   <SpnMapping[]> Specifies an SPN override

Authentication

Name Aliases Value Description
-Anonymous   <SwitchParam> Uses anonymous login
-NtlmHash   <hexadecimal hash> NTLM hash for NTLM authentication
-Password -p <String> Password to authenticate with
-UserDomain -ud <String> Domain of user to authenticate with
-UserName -u <UserPrincipalName> User name to authenticate with, not including the domain

Authentication (Kerberos)

Name Aliases Value Description
-AesKey   <HexString> AES key (128 or 256)
-DelegateTicket   <String[]> Sends the tickets (and keys) to the target for delegation
-DesKey   <HexString> DES key
-Kdc   <host-or-ip:port> KDC endpoint
-Keytab   <String> Name of keytab file
-S4ProxyService   <SecurityPrincipalName> Name of service to proxy through
-S4UserCert   <String> Name of file containing a certificate of a user to impersonate with S4U
-S4UserName   <UserPrincipalName> Name of user to impersonate with S4U
-Tgt   <String> Name of file containing a ticket-granting ticket (.kirbi or ccache)
-TicketCache   <String> Name of ticket cache file
-Tickets -Ticket <String[]> Name of file containing service tickets (.kirbi or ccache)
-U2UserName   <UserPrincipalName> User name to request TGT for U2U
-UserCert   <String> Name of file containing user’s certificate (for PKINIT)
-UserKey   <String> Name of file containing user’s key (for PKINIT)
-UserKeyPassword   <String> Password to decrypt file containing user’s key (for PKINIT)

Authentication (NTLM)

Name Aliases Value Description
-NtlmVersion   <Version> NTLM version number (a.b.c.d)
-Workstation -w <String> Name of workstation to send with NTLM authentication

Client Behavior

Name Aliases Value Description
-DfsReferralBufferSize   <Int32> Specifies the size for the DFS referral buffer (default=4096)
-F, -FollowDfs   <SwitchParam> Checks for and follows DFS referrals (default=true)

Connection

Name Aliases Value Description
-Dialects   <Smb2Dialect[]> List of SMB2 dialects to negotiate
      Possible values:
      Smb2_0_2
      Smb2_1
      Smb3_0
      Smb3_0_2
      Smb3_1_1
-EncryptSmb   <SwitchParam> Requires an encrypted connection
-HostAddress -ha <String[]> Network address(es) of the server
-RequireSecureNegotiate   <SwitchParam> Requires the client to authenticate the negotiation
-RequireSigning -signreq <SwitchParam> Requires packets to be signed
-UseTcp4Only -4 <SwitchParam> Only use TCP over IPv4 endpoint
-UseTcp6Only -6 <SwitchParam> Only use TCP over IPv6 endpoint

Output

Name Aliases Value Description
-ConsoleLogFormat -LogFormat <LogFormat> Sets the format of log messages written to the console
      Default: 0
      Possible values:
      Text
      TextWithTimestamp
      Json
-DebugLog -vvv <SwitchParam> Prints debug messages
-Diagnostic -vv <SwitchParam> Prints diagnostic messages
-HumanReadable   <SwitchParam> Formats file sizes as human-readable values
-LogLevel   <LogMessageSeverity> Sets the lowest level of messages to log
      Possible values:
      Debug
      Diagnostic
      Verbose
      Info
      Warning
      Error
      Critical
-Verbose -V <SwitchParam> Prints verbose messages

Dsrep rep

Requests replica changes

Synopsis

Dsrep rep [options] <ServerName> [ <ObjectName> ]

Parameters

Name Aliases Value Description
<ServerName>   <String> RPC server to interact with
-ObjectName   <DsobjSpec[]> DN, GUID, or SID of object to retrieve

Options

Name Aliases Value Description
-Accept2003Deflate   <SwitchParam> Accept data compressed with Windows Server 2003 Deflate
      Default: True
-AuthEpm   <SwitchParam> Authenticates EP mapper requests
-AuthProxy   <EndPoint> Endpoint of auth proxy
-ChunkObjectLimit   <Int32> Max number of objects per chunk (approx.)
      Default: 1000
-ChunkSizeLimit   <Int32> Max bytes per chunk (approx.)
      Default: 10485760
-ConsoleOutputStyle -OutputStyle <OutputStyle> Determines the output style
      Possible values:
      Freeform
      Raw
      Table
      List
      Csv
      Tsv
      Json
      TreeTable
-Delegate   <SwitchParam> Requests delegation (sends TGT and key for Kerberos)
-EncryptEpm   <SwitchParam> Encrypts EP mappend requests
-EncryptRpc   <SwitchParam> Encrypts RPC messages
-ExportKeytab   <String> Name of keytab file to export to
-FromUsnvec   <UsnVector> Starting USN vector (as 48 hex bytes)
-ObjectName   <DsobjSpec[]> DN, GUID, or SID of object to retrieve
-OutputHeaders   <SwitchParam> Print headers for table/list/CSV/TSV styles
      Default: True
-Parallelize   <Int32> Number of parallel requests
      Default: 1
-PreferSmb   <SwitchParam> If the interface supports named pipes, attempt to connect over the named pipe instead of TCP
-RpcCallTimeout   <Duration> Time to wait for RPC calls
-RpcConnectTimeout   <Duration> Time to wait for RPC connections
-Socks5   <host-or-ip:port> End point of SOCKS 5 server to use
-Spnego   <SwitchParam> Uses SP-NEGO for authentication
-SpnOverride   <SpnMapping[]> Specifies an SPN override

Authentication

Name Aliases Value Description
-Anonymous   <SwitchParam> Uses anonymous login
-NtlmHash   <hexadecimal hash> NTLM hash for NTLM authentication
-Password -p <String> Password to authenticate with
-UserDomain -ud <String> Domain of user to authenticate with
-UserName -u <UserPrincipalName> User name to authenticate with, not including the domain

Authentication (Kerberos)

Name Aliases Value Description
-AesKey   <HexString> AES key (128 or 256)
-DelegateTicket   <String[]> Sends the tickets (and keys) to the target for delegation
-DesKey   <HexString> DES key
-Kdc   <host-or-ip:port> KDC endpoint
-Keytab   <String> Name of keytab file
-S4ProxyService   <SecurityPrincipalName> Name of service to proxy through
-S4UserCert   <String> Name of file containing a certificate of a user to impersonate with S4U
-S4UserName   <UserPrincipalName> Name of user to impersonate with S4U
-Tgt   <String> Name of file containing a ticket-granting ticket (.kirbi or ccache)
-TicketCache   <String> Name of ticket cache file
-Tickets -Ticket <String[]> Name of file containing service tickets (.kirbi or ccache)
-U2UserName   <UserPrincipalName> User name to request TGT for U2U
-UserCert   <String> Name of file containing user’s certificate (for PKINIT)
-UserKey   <String> Name of file containing user’s key (for PKINIT)
-UserKeyPassword   <String> Password to decrypt file containing user’s key (for PKINIT)

Authentication (NTLM)

Name Aliases Value Description
-NtlmVersion   <Version> NTLM version number (a.b.c.d)
-Workstation -w <String> Name of workstation to send with NTLM authentication

Client Behavior

Name Aliases Value Description
-DfsReferralBufferSize   <Int32> Specifies the size for the DFS referral buffer (default=4096)
-FollowDfs   <SwitchParam> Checks for and follows DFS referrals (default=true)

Connection

Name Aliases Value Description
-Dialects   <Smb2Dialect[]> List of SMB2 dialects to negotiate
      Possible values:
      Smb2_0_2
      Smb2_1
      Smb3_0
      Smb3_0_2
      Smb3_1_1
-EncryptSmb   <SwitchParam> Requires an encrypted connection
-HostAddress -ha <String[]> Network address(es) of the server
-RequireSecureNegotiate   <SwitchParam> Requires the client to authenticate the negotiation
-RequireSigning -signreq <SwitchParam> Requires packets to be signed
-UseTcp4Only -4 <SwitchParam> Only use TCP over IPv4 endpoint
-UseTcp6Only -6 <SwitchParam> Only use TCP over IPv6 endpoint

Output

Name Aliases Value Description
-ConsoleLogFormat -LogFormat <LogFormat> Sets the format of log messages written to the console
      Default: 0
      Possible values:
      Text
      TextWithTimestamp
      Json
-DebugLog -vvv <SwitchParam> Prints debug messages
-Diagnostic -vv <SwitchParam> Prints diagnostic messages
-HumanReadable   <SwitchParam> Formats file sizes as human-readable values
-LogLevel   <LogMessageSeverity> Sets the lowest level of messages to log
      Possible values:
      Debug
      Diagnostic
      Verbose
      Info
      Warning
      Error
      Critical
-Verbose -V <SwitchParam> Prints verbose messages

Details

This command uses [MS-DRSR] to query attributes of an object by SID, GUID, distinguished name, LDAP query, or object name.

In addition to the standard attributes defined by Active Directory, you may query the special attributes kerberosKeys, kerberosOldKeys, or cleartextPassword. When one of these attributes is specified, Dsrep rep implicitly queries supplementalCredentials and unpacks the credentials contained within.

Dsrep repnc

Replicates a naming context

Synopsis

Dsrep repnc [options] <ServerName> [ <NamingContext> ]

Parameters

Name Aliases Value Description
<ServerName>   <String> RPC server to interact with
-NamingContext   <LdapDistinguishedName[]> DN of naming contexts (partitions) to replicate

Options

Name Aliases Value Description
-Accept2003Deflate   <SwitchParam> Accept data compressed with Windows Server 2003 Deflate
      Default: True
-AuthEpm   <SwitchParam> Authenticates EP mapper requests
-AuthProxy   <EndPoint> Endpoint of auth proxy
-ChunkObjectLimit   <Int32> Max number of objects per chunk (approx.)
      Default: 1000
-ChunkSizeLimit   <Int32> Max bytes per chunk (approx.)
      Default: 10485760
-ConsoleOutputStyle -OutputStyle <OutputStyle> Determines the output style
      Possible values:
      Freeform
      Raw
      Table
      List
      Csv
      Tsv
      Json
      TreeTable
-Delegate   <SwitchParam> Requests delegation (sends TGT and key for Kerberos)
-EncryptEpm   <SwitchParam> Encrypts EP mappend requests
-EncryptRpc   <SwitchParam> Encrypts RPC messages
-ExportKeytab   <String> Name of keytab file to export to
-FromUsnvec   <UsnVector> Starting USN vector (as 48 hex bytes)
-NamingContext   <LdapDistinguishedName[]> DN of naming contexts (partitions) to replicate
-OutputHeaders   <SwitchParam> Print headers for table/list/CSV/TSV styles
      Default: True
-PreferSmb   <SwitchParam> If the interface supports named pipes, attempt to connect over the named pipe instead of TCP
-RpcCallTimeout   <Duration> Time to wait for RPC calls
-RpcConnectTimeout   <Duration> Time to wait for RPC connections
-Socks5   <host-or-ip:port> End point of SOCKS 5 server to use
-Spnego   <SwitchParam> Uses SP-NEGO for authentication
-SpnOverride   <SpnMapping[]> Specifies an SPN override

Authentication

Name Aliases Value Description
-Anonymous   <SwitchParam> Uses anonymous login
-NtlmHash   <hexadecimal hash> NTLM hash for NTLM authentication
-Password -p <String> Password to authenticate with
-UserDomain -ud <String> Domain of user to authenticate with
-UserName -u <UserPrincipalName> User name to authenticate with, not including the domain

Authentication (Kerberos)

Name Aliases Value Description
-AesKey   <HexString> AES key (128 or 256)
-DelegateTicket   <String[]> Sends the tickets (and keys) to the target for delegation
-DesKey   <HexString> DES key
-Kdc   <host-or-ip:port> KDC endpoint
-Keytab   <String> Name of keytab file
-S4ProxyService   <SecurityPrincipalName> Name of service to proxy through
-S4UserCert   <String> Name of file containing a certificate of a user to impersonate with S4U
-S4UserName   <UserPrincipalName> Name of user to impersonate with S4U
-Tgt   <String> Name of file containing a ticket-granting ticket (.kirbi or ccache)
-TicketCache   <String> Name of ticket cache file
-Tickets -Ticket <String[]> Name of file containing service tickets (.kirbi or ccache)
-U2UserName   <UserPrincipalName> User name to request TGT for U2U
-UserCert   <String> Name of file containing user’s certificate (for PKINIT)
-UserKey   <String> Name of file containing user’s key (for PKINIT)
-UserKeyPassword   <String> Password to decrypt file containing user’s key (for PKINIT)

Authentication (NTLM)

Name Aliases Value Description
-NtlmVersion   <Version> NTLM version number (a.b.c.d)
-Workstation -w <String> Name of workstation to send with NTLM authentication

Client Behavior

Name Aliases Value Description
-DfsReferralBufferSize   <Int32> Specifies the size for the DFS referral buffer (default=4096)
-FollowDfs   <SwitchParam> Checks for and follows DFS referrals (default=true)

Connection

Name Aliases Value Description
-Dialects   <Smb2Dialect[]> List of SMB2 dialects to negotiate
      Possible values:
      Smb2_0_2
      Smb2_1
      Smb3_0
      Smb3_0_2
      Smb3_1_1
-EncryptSmb   <SwitchParam> Requires an encrypted connection
-HostAddress -ha <String[]> Network address(es) of the server
-RequireSecureNegotiate   <SwitchParam> Requires the client to authenticate the negotiation
-RequireSigning -signreq <SwitchParam> Requires packets to be signed
-UseTcp4Only -4 <SwitchParam> Only use TCP over IPv4 endpoint
-UseTcp6Only -6 <SwitchParam> Only use TCP over IPv6 endpoint

Output

Name Aliases Value Description
-ConsoleLogFormat -LogFormat <LogFormat> Sets the format of log messages written to the console
      Default: 0
      Possible values:
      Text
      TextWithTimestamp
      Json
-DebugLog -vvv <SwitchParam> Prints debug messages
-Diagnostic -vv <SwitchParam> Prints diagnostic messages
-HumanReadable   <SwitchParam> Formats file sizes as human-readable values
-LogLevel   <LogMessageSeverity> Sets the lowest level of messages to log
      Possible values:
      Debug
      Diagnostic
      Verbose
      Info
      Warning
      Error
      Critical
-Verbose -V <SwitchParam> Prints verbose messages

Details

This command uses [MS-DRSR] to query attributes of an object by SID, GUID, distinguished name, LDAP query, or object name.

In addition to the standard attributes defined by Active Directory, you may query the special attributes kerberosKeys, kerberosOldKeys, or cleartextPassword. When one of these attributes is specified, Dsrep repnc implicitly queries supplementalCredentials and unpacks the credentials contained within.