Active Directory
Read-only inventory of an on-premises Active Directory domain over LDAP. Collects users, groups, and computers straight from a domain controller — no Windows host, no WinRM, no PowerShell — and decodes what AD returns raw: FILETIME timestamps, binary SIDs and GUIDs, userAccountControl and groupType bitmasks. Handles paged searches and member range retrieval, so domains over 1000 objects and groups over 1500 members are not silently truncated. Methods: inventory, list_users, list_groups, list_computers.
Initial release. Read-only inventory of an on-premises Active Directory domain over LDAP: users, groups, and computers, collected straight from a domain controller with no Windows host, WinRM, or PowerShell required.
Decodes what AD returns raw — FILETIME timestamps, binary objectSid and objectGUID, userAccountControl and groupType bitmasks — and handles the three ways a directory read silently under-reports: paged searches past the 1000-entry response cap, member range retrieval past the 1500-value attribute cap, and unfollowed referrals in a multi-domain forest. Each is reported in the output rather than hidden.
Methods: inventory (all three in one bind, plus a summary), list_users, list_groups, list_computers.
Read-only by construction: the LDAP transport exposes only search operations, so no method can modify a domain. Refuses a cleartext simple bind unless explicitly overridden.
- Has README or module doc2/2earned
- README has a code example1/1earned
- README is substantive1/1earned
- Most symbols documented1/1earned
- No slow types (deprecated)1/1earned
- Dependencies pass trust audit2/2earned
- Has description1/1earned
- Platform support declared (or universal)2/2earned
- License declared1/1earned
- Verified public repository2/2earned