常见的方法有:
389
53
net group "domain controllers" /domain
nslookup redteam.red; nslookup -type=SRV _ldap._tcp
net time /domain