Dsrep
Interacts with Directory Replication Service
Synopsis
Subcommands
| Command |
Description |
| dcinfo |
Gets information on domain controllers |
| rep |
Requests replica changes |
| repnc |
Replicates a naming context |
For help on a subcommand, use Dsrep <subcommand> -h
Dsrep dcinfo
Gets information on domain controllers
Synopsis
Dsrep dcinfo [options] <ServerName>
Parameters
| Name |
Aliases |
Value |
Description |
| <ServerName> |
|
<String> |
RPC server to interact with |
Options
| Name |
Aliases |
Value |
Description |
| -Accept2003Deflate |
|
<SwitchParam> |
Accept data compressed with Windows Server 2003 Deflate |
| |
|
|
Default: True |
| -AuthEpm |
|
<SwitchParam> |
Authenticates EP mapper requests |
| -AuthProxy |
|
<EndPoint> |
Endpoint of auth proxy |
| -ConsoleOutputStyle |
-OutputStyle |
<OutputStyle> |
Determines the output style |
| |
|
|
Possible values: |
| |
|
|
Freeform |
| |
|
|
Raw |
| |
|
|
Table |
| |
|
|
List |
| |
|
|
Csv |
| |
|
|
Tsv |
| |
|
|
Json |
| |
|
|
TreeTable |
| -Delegate |
|
<SwitchParam> |
Requests delegation (sends TGT and key for Kerberos) |
| -EncryptEpm |
|
<SwitchParam> |
Encrypts EP mappend requests |
| -EncryptRpc |
|
<SwitchParam> |
Encrypts RPC messages |
| -OutputFields |
|
<String[]> |
Fields to display in output |
| |
|
|
Possible values: |
| |
|
|
NetbiosName |
| |
|
|
DnsHostName |
| |
|
|
SiteName |
| |
|
|
SiteObjectName |
| |
|
|
ComputerObjectName |
| |
|
|
ServerObjectName |
| |
|
|
NtdsDsaObjectName |
| |
|
|
IsPdc |
| |
|
|
IsDsEnabled |
| |
|
|
IsGc |
| |
|
|
SiteObjectGuid |
| |
|
|
ComputerObjectGuid |
| |
|
|
ServerObjectGuid |
| |
|
|
NtdsDsaObjectGuid |
| -OutputHeaders |
|
<SwitchParam> |
Print headers for table/list/CSV/TSV styles |
| |
|
|
Default: True |
| -PreferSmb |
|
<SwitchParam> |
If the interface supports named pipes, attempt to connect over the named pipe instead of TCP |
| -RpcCallTimeout |
|
<Duration> |
Time to wait for RPC calls |
| -RpcConnectTimeout |
|
<Duration> |
Time to wait for RPC connections |
| -Socks5 |
|
<host-or-ip:port> |
End point of SOCKS 5 server to use |
| -Spnego |
|
<SwitchParam> |
Uses SP-NEGO for authentication |
| -SpnOverride |
|
<SpnMapping[]> |
Specifies an SPN override |
Authentication
| Name |
Aliases |
Value |
Description |
| -Anonymous |
|
<SwitchParam> |
Uses anonymous login |
| -NtlmHash |
|
<hexadecimal hash> |
NTLM hash for NTLM authentication |
| -Password |
-p |
<String> |
Password to authenticate with |
| -UserDomain |
-ud |
<String> |
Domain of user to authenticate with |
| -UserName |
-u |
<UserPrincipalName> |
User name to authenticate with, not including the domain |
Authentication (Kerberos)
| Name |
Aliases |
Value |
Description |
| -AesKey |
|
<HexString> |
AES key (128 or 256) |
| -DelegateTicket |
|
<String[]> |
Sends the tickets (and keys) to the target for delegation |
| -DesKey |
|
<HexString> |
DES key |
| -Kdc |
|
<host-or-ip:port> |
KDC endpoint |
| -Keytab |
|
<String> |
Name of keytab file |
| -S4ProxyService |
|
<SecurityPrincipalName> |
Name of service to proxy through |
| -S4UserCert |
|
<String> |
Name of file containing a certificate of a user to impersonate with S4U |
| -S4UserName |
|
<UserPrincipalName> |
Name of user to impersonate with S4U |
| -Tgt |
|
<String> |
Name of file containing a ticket-granting ticket (.kirbi or ccache) |
| -TicketCache |
|
<String> |
Name of ticket cache file |
| -Tickets |
-Ticket |
<String[]> |
Name of file containing service tickets (.kirbi or ccache) |
| -U2UserName |
|
<UserPrincipalName> |
User name to request TGT for U2U |
| -UserCert |
|
<String> |
Name of file containing user’s certificate (for PKINIT) |
| -UserKey |
|
<String> |
Name of file containing user’s key (for PKINIT) |
| -UserKeyPassword |
|
<String> |
Password to decrypt file containing user’s key (for PKINIT) |
Authentication (NTLM)
| Name |
Aliases |
Value |
Description |
| -NtlmVersion |
|
<Version> |
NTLM version number (a.b.c.d) |
| -Workstation |
-w |
<String> |
Name of workstation to send with NTLM authentication |
Client Behavior
| Name |
Aliases |
Value |
Description |
| -DfsReferralBufferSize |
|
<Int32> |
Specifies the size for the DFS referral buffer (default=4096) |
| -F, -FollowDfs |
|
<SwitchParam> |
Checks for and follows DFS referrals (default=true) |
Connection
| Name |
Aliases |
Value |
Description |
| -Dialects |
|
<Smb2Dialect[]> |
List of SMB2 dialects to negotiate |
| |
|
|
Possible values: |
| |
|
|
Smb2_0_2 |
| |
|
|
Smb2_1 |
| |
|
|
Smb3_0 |
| |
|
|
Smb3_0_2 |
| |
|
|
Smb3_1_1 |
| -EncryptSmb |
|
<SwitchParam> |
Requires an encrypted connection |
| -HostAddress |
-ha |
<String[]> |
Network address(es) of the server |
| -RequireSecureNegotiate |
|
<SwitchParam> |
Requires the client to authenticate the negotiation |
| -RequireSigning |
-signreq |
<SwitchParam> |
Requires packets to be signed |
| -UseTcp4Only |
-4 |
<SwitchParam> |
Only use TCP over IPv4 endpoint |
| -UseTcp6Only |
-6 |
<SwitchParam> |
Only use TCP over IPv6 endpoint |
Output
| Name |
Aliases |
Value |
Description |
| -ConsoleLogFormat |
-LogFormat |
<LogFormat> |
Sets the format of log messages written to the console |
| |
|
|
Default: 0 |
| |
|
|
Possible values: |
| |
|
|
Text |
| |
|
|
TextWithTimestamp |
| |
|
|
Json |
| -DebugLog |
-vvv |
<SwitchParam> |
Prints debug messages |
| -Diagnostic |
-vv |
<SwitchParam> |
Prints diagnostic messages |
| -HumanReadable |
|
<SwitchParam> |
Formats file sizes as human-readable values |
| -LogLevel |
|
<LogMessageSeverity> |
Sets the lowest level of messages to log |
| |
|
|
Possible values: |
| |
|
|
Debug |
| |
|
|
Diagnostic |
| |
|
|
Verbose |
| |
|
|
Info |
| |
|
|
Warning |
| |
|
|
Error |
| |
|
|
Critical |
| -Verbose |
-V |
<SwitchParam> |
Prints verbose messages |
Dsrep rep
Requests replica changes
Synopsis
Dsrep rep [options] <ServerName> [ <ObjectName> ]
Parameters
| Name |
Aliases |
Value |
Description |
| <ServerName> |
|
<String> |
RPC server to interact with |
| -ObjectName |
|
<DsobjSpec[]> |
DN, GUID, or SID of object to retrieve |
Options
| Name |
Aliases |
Value |
Description |
| -Accept2003Deflate |
|
<SwitchParam> |
Accept data compressed with Windows Server 2003 Deflate |
| |
|
|
Default: True |
| -AuthEpm |
|
<SwitchParam> |
Authenticates EP mapper requests |
| -AuthProxy |
|
<EndPoint> |
Endpoint of auth proxy |
| -ChunkObjectLimit |
|
<Int32> |
Max number of objects per chunk (approx.) |
| |
|
|
Default: 1000 |
| -ChunkSizeLimit |
|
<Int32> |
Max bytes per chunk (approx.) |
| |
|
|
Default: 10485760 |
| -ConsoleOutputStyle |
-OutputStyle |
<OutputStyle> |
Determines the output style |
| |
|
|
Possible values: |
| |
|
|
Freeform |
| |
|
|
Raw |
| |
|
|
Table |
| |
|
|
List |
| |
|
|
Csv |
| |
|
|
Tsv |
| |
|
|
Json |
| |
|
|
TreeTable |
| -Delegate |
|
<SwitchParam> |
Requests delegation (sends TGT and key for Kerberos) |
| -EncryptEpm |
|
<SwitchParam> |
Encrypts EP mappend requests |
| -EncryptRpc |
|
<SwitchParam> |
Encrypts RPC messages |
| -ExportKeytab |
|
<String> |
Name of keytab file to export to |
| -FromUsnvec |
|
<UsnVector> |
Starting USN vector (as 48 hex bytes) |
| -ObjectName |
|
<DsobjSpec[]> |
DN, GUID, or SID of object to retrieve |
| -OutputHeaders |
|
<SwitchParam> |
Print headers for table/list/CSV/TSV styles |
| |
|
|
Default: True |
| -Parallelize |
|
<Int32> |
Number of parallel requests |
| |
|
|
Default: 1 |
| -PreferSmb |
|
<SwitchParam> |
If the interface supports named pipes, attempt to connect over the named pipe instead of TCP |
| -RpcCallTimeout |
|
<Duration> |
Time to wait for RPC calls |
| -RpcConnectTimeout |
|
<Duration> |
Time to wait for RPC connections |
| -Socks5 |
|
<host-or-ip:port> |
End point of SOCKS 5 server to use |
| -Spnego |
|
<SwitchParam> |
Uses SP-NEGO for authentication |
| -SpnOverride |
|
<SpnMapping[]> |
Specifies an SPN override |
Authentication
| Name |
Aliases |
Value |
Description |
| -Anonymous |
|
<SwitchParam> |
Uses anonymous login |
| -NtlmHash |
|
<hexadecimal hash> |
NTLM hash for NTLM authentication |
| -Password |
-p |
<String> |
Password to authenticate with |
| -UserDomain |
-ud |
<String> |
Domain of user to authenticate with |
| -UserName |
-u |
<UserPrincipalName> |
User name to authenticate with, not including the domain |
Authentication (Kerberos)
| Name |
Aliases |
Value |
Description |
| -AesKey |
|
<HexString> |
AES key (128 or 256) |
| -DelegateTicket |
|
<String[]> |
Sends the tickets (and keys) to the target for delegation |
| -DesKey |
|
<HexString> |
DES key |
| -Kdc |
|
<host-or-ip:port> |
KDC endpoint |
| -Keytab |
|
<String> |
Name of keytab file |
| -S4ProxyService |
|
<SecurityPrincipalName> |
Name of service to proxy through |
| -S4UserCert |
|
<String> |
Name of file containing a certificate of a user to impersonate with S4U |
| -S4UserName |
|
<UserPrincipalName> |
Name of user to impersonate with S4U |
| -Tgt |
|
<String> |
Name of file containing a ticket-granting ticket (.kirbi or ccache) |
| -TicketCache |
|
<String> |
Name of ticket cache file |
| -Tickets |
-Ticket |
<String[]> |
Name of file containing service tickets (.kirbi or ccache) |
| -U2UserName |
|
<UserPrincipalName> |
User name to request TGT for U2U |
| -UserCert |
|
<String> |
Name of file containing user’s certificate (for PKINIT) |
| -UserKey |
|
<String> |
Name of file containing user’s key (for PKINIT) |
| -UserKeyPassword |
|
<String> |
Password to decrypt file containing user’s key (for PKINIT) |
Authentication (NTLM)
| Name |
Aliases |
Value |
Description |
| -NtlmVersion |
|
<Version> |
NTLM version number (a.b.c.d) |
| -Workstation |
-w |
<String> |
Name of workstation to send with NTLM authentication |
Client Behavior
| Name |
Aliases |
Value |
Description |
| -DfsReferralBufferSize |
|
<Int32> |
Specifies the size for the DFS referral buffer (default=4096) |
| -FollowDfs |
|
<SwitchParam> |
Checks for and follows DFS referrals (default=true) |
Connection
| Name |
Aliases |
Value |
Description |
| -Dialects |
|
<Smb2Dialect[]> |
List of SMB2 dialects to negotiate |
| |
|
|
Possible values: |
| |
|
|
Smb2_0_2 |
| |
|
|
Smb2_1 |
| |
|
|
Smb3_0 |
| |
|
|
Smb3_0_2 |
| |
|
|
Smb3_1_1 |
| -EncryptSmb |
|
<SwitchParam> |
Requires an encrypted connection |
| -HostAddress |
-ha |
<String[]> |
Network address(es) of the server |
| -RequireSecureNegotiate |
|
<SwitchParam> |
Requires the client to authenticate the negotiation |
| -RequireSigning |
-signreq |
<SwitchParam> |
Requires packets to be signed |
| -UseTcp4Only |
-4 |
<SwitchParam> |
Only use TCP over IPv4 endpoint |
| -UseTcp6Only |
-6 |
<SwitchParam> |
Only use TCP over IPv6 endpoint |
Output
| Name |
Aliases |
Value |
Description |
| -ConsoleLogFormat |
-LogFormat |
<LogFormat> |
Sets the format of log messages written to the console |
| |
|
|
Default: 0 |
| |
|
|
Possible values: |
| |
|
|
Text |
| |
|
|
TextWithTimestamp |
| |
|
|
Json |
| -DebugLog |
-vvv |
<SwitchParam> |
Prints debug messages |
| -Diagnostic |
-vv |
<SwitchParam> |
Prints diagnostic messages |
| -HumanReadable |
|
<SwitchParam> |
Formats file sizes as human-readable values |
| -LogLevel |
|
<LogMessageSeverity> |
Sets the lowest level of messages to log |
| |
|
|
Possible values: |
| |
|
|
Debug |
| |
|
|
Diagnostic |
| |
|
|
Verbose |
| |
|
|
Info |
| |
|
|
Warning |
| |
|
|
Error |
| |
|
|
Critical |
| -Verbose |
-V |
<SwitchParam> |
Prints verbose messages |
Details
This command uses [MS-DRSR] to query attributes of an object by SID, GUID,
distinguished name, LDAP query, or object name.
In addition to the standard attributes defined by Active Directory, you may
query the special attributes kerberosKeys, kerberosOldKeys, or
cleartextPassword. When one of these attributes is specified, Dsrep rep
implicitly queries supplementalCredentials and unpacks the credentials
contained within.
Dsrep repnc
Replicates a naming context
Synopsis
Dsrep repnc [options] <ServerName> [ <NamingContext> ]
Parameters
| Name |
Aliases |
Value |
Description |
| <ServerName> |
|
<String> |
RPC server to interact with |
| -NamingContext |
|
<LdapDistinguishedName[]> |
DN of naming contexts (partitions) to replicate |
Options
| Name |
Aliases |
Value |
Description |
| -Accept2003Deflate |
|
<SwitchParam> |
Accept data compressed with Windows Server 2003 Deflate |
| |
|
|
Default: True |
| -AuthEpm |
|
<SwitchParam> |
Authenticates EP mapper requests |
| -AuthProxy |
|
<EndPoint> |
Endpoint of auth proxy |
| -ChunkObjectLimit |
|
<Int32> |
Max number of objects per chunk (approx.) |
| |
|
|
Default: 1000 |
| -ChunkSizeLimit |
|
<Int32> |
Max bytes per chunk (approx.) |
| |
|
|
Default: 10485760 |
| -ConsoleOutputStyle |
-OutputStyle |
<OutputStyle> |
Determines the output style |
| |
|
|
Possible values: |
| |
|
|
Freeform |
| |
|
|
Raw |
| |
|
|
Table |
| |
|
|
List |
| |
|
|
Csv |
| |
|
|
Tsv |
| |
|
|
Json |
| |
|
|
TreeTable |
| -Delegate |
|
<SwitchParam> |
Requests delegation (sends TGT and key for Kerberos) |
| -EncryptEpm |
|
<SwitchParam> |
Encrypts EP mappend requests |
| -EncryptRpc |
|
<SwitchParam> |
Encrypts RPC messages |
| -ExportKeytab |
|
<String> |
Name of keytab file to export to |
| -FromUsnvec |
|
<UsnVector> |
Starting USN vector (as 48 hex bytes) |
| -NamingContext |
|
<LdapDistinguishedName[]> |
DN of naming contexts (partitions) to replicate |
| -OutputHeaders |
|
<SwitchParam> |
Print headers for table/list/CSV/TSV styles |
| |
|
|
Default: True |
| -PreferSmb |
|
<SwitchParam> |
If the interface supports named pipes, attempt to connect over the named pipe instead of TCP |
| -RpcCallTimeout |
|
<Duration> |
Time to wait for RPC calls |
| -RpcConnectTimeout |
|
<Duration> |
Time to wait for RPC connections |
| -Socks5 |
|
<host-or-ip:port> |
End point of SOCKS 5 server to use |
| -Spnego |
|
<SwitchParam> |
Uses SP-NEGO for authentication |
| -SpnOverride |
|
<SpnMapping[]> |
Specifies an SPN override |
Authentication
| Name |
Aliases |
Value |
Description |
| -Anonymous |
|
<SwitchParam> |
Uses anonymous login |
| -NtlmHash |
|
<hexadecimal hash> |
NTLM hash for NTLM authentication |
| -Password |
-p |
<String> |
Password to authenticate with |
| -UserDomain |
-ud |
<String> |
Domain of user to authenticate with |
| -UserName |
-u |
<UserPrincipalName> |
User name to authenticate with, not including the domain |
Authentication (Kerberos)
| Name |
Aliases |
Value |
Description |
| -AesKey |
|
<HexString> |
AES key (128 or 256) |
| -DelegateTicket |
|
<String[]> |
Sends the tickets (and keys) to the target for delegation |
| -DesKey |
|
<HexString> |
DES key |
| -Kdc |
|
<host-or-ip:port> |
KDC endpoint |
| -Keytab |
|
<String> |
Name of keytab file |
| -S4ProxyService |
|
<SecurityPrincipalName> |
Name of service to proxy through |
| -S4UserCert |
|
<String> |
Name of file containing a certificate of a user to impersonate with S4U |
| -S4UserName |
|
<UserPrincipalName> |
Name of user to impersonate with S4U |
| -Tgt |
|
<String> |
Name of file containing a ticket-granting ticket (.kirbi or ccache) |
| -TicketCache |
|
<String> |
Name of ticket cache file |
| -Tickets |
-Ticket |
<String[]> |
Name of file containing service tickets (.kirbi or ccache) |
| -U2UserName |
|
<UserPrincipalName> |
User name to request TGT for U2U |
| -UserCert |
|
<String> |
Name of file containing user’s certificate (for PKINIT) |
| -UserKey |
|
<String> |
Name of file containing user’s key (for PKINIT) |
| -UserKeyPassword |
|
<String> |
Password to decrypt file containing user’s key (for PKINIT) |
Authentication (NTLM)
| Name |
Aliases |
Value |
Description |
| -NtlmVersion |
|
<Version> |
NTLM version number (a.b.c.d) |
| -Workstation |
-w |
<String> |
Name of workstation to send with NTLM authentication |
Client Behavior
| Name |
Aliases |
Value |
Description |
| -DfsReferralBufferSize |
|
<Int32> |
Specifies the size for the DFS referral buffer (default=4096) |
| -FollowDfs |
|
<SwitchParam> |
Checks for and follows DFS referrals (default=true) |
Connection
| Name |
Aliases |
Value |
Description |
| -Dialects |
|
<Smb2Dialect[]> |
List of SMB2 dialects to negotiate |
| |
|
|
Possible values: |
| |
|
|
Smb2_0_2 |
| |
|
|
Smb2_1 |
| |
|
|
Smb3_0 |
| |
|
|
Smb3_0_2 |
| |
|
|
Smb3_1_1 |
| -EncryptSmb |
|
<SwitchParam> |
Requires an encrypted connection |
| -HostAddress |
-ha |
<String[]> |
Network address(es) of the server |
| -RequireSecureNegotiate |
|
<SwitchParam> |
Requires the client to authenticate the negotiation |
| -RequireSigning |
-signreq |
<SwitchParam> |
Requires packets to be signed |
| -UseTcp4Only |
-4 |
<SwitchParam> |
Only use TCP over IPv4 endpoint |
| -UseTcp6Only |
-6 |
<SwitchParam> |
Only use TCP over IPv6 endpoint |
Output
| Name |
Aliases |
Value |
Description |
| -ConsoleLogFormat |
-LogFormat |
<LogFormat> |
Sets the format of log messages written to the console |
| |
|
|
Default: 0 |
| |
|
|
Possible values: |
| |
|
|
Text |
| |
|
|
TextWithTimestamp |
| |
|
|
Json |
| -DebugLog |
-vvv |
<SwitchParam> |
Prints debug messages |
| -Diagnostic |
-vv |
<SwitchParam> |
Prints diagnostic messages |
| -HumanReadable |
|
<SwitchParam> |
Formats file sizes as human-readable values |
| -LogLevel |
|
<LogMessageSeverity> |
Sets the lowest level of messages to log |
| |
|
|
Possible values: |
| |
|
|
Debug |
| |
|
|
Diagnostic |
| |
|
|
Verbose |
| |
|
|
Info |
| |
|
|
Warning |
| |
|
|
Error |
| |
|
|
Critical |
| -Verbose |
-V |
<SwitchParam> |
Prints verbose messages |
Details
This command uses [MS-DRSR] to query attributes of an object by SID, GUID,
distinguished name, LDAP query, or object name.
In addition to the standard attributes defined by Active Directory, you may
query the special attributes kerberosKeys, kerberosOldKeys, or
cleartextPassword. When one of these attributes is specified, Dsrep repnc
implicitly queries supplementalCredentials and unpacks the credentials
contained within.