> For the complete documentation index, see [llms.txt](https://playbook.sidthoviti.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://playbook.sidthoviti.com/active-directory-pentest/domain-enumeration/user-enumeration.md).

# User Enumeration

### **User Enumeration**

**Get a list of users in the current domain**

{% code overflow="wrap" %}

```powershell
Get-DomainUser 
Get-DomainUser -Identity student1 
Get-ADUser -Filter * -Properties * 
Get-ADUser -Identity student1 -Properties *
```

{% endcode %}

**Get list of all properties for users in the current domain**

{% code overflow="wrap" %}

```powershell
Get-DomainUser -Identity student1 -Properties *
Get-DomainUser -Properties samaccountname,logonCount
Get-ADUser -Filter * -Properties * | select -First 1 | Get-Member -MemberType *Property | select Name
Get-ADUser -Filter * -Properties * | select name,logoncount,@{expression={[datetime]::fromFileTime($_.pwdlastset)}}
```

{% endcode %}

**Search for a particular string in a user's attributes:**

{% code overflow="wrap" %}

```powershell
Get-DomainUser -LDAPFilter "Description=*built*" | Select name,Description
Get-ADUser -Filter 'Description -like "*built*"' -Properties Description | select name,Description
```

{% endcode %}
