NLTEST
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Network Logon Test: Windows domain diagnostics tool. Test domain trusts, DC connectivity, and Netlogon status.
DOMAIN CONTROLLER INFO#
FIND DC#
nltest /dsgetdc:domain.com # Find DC for domain nltest /dsgetdc:domain.com /force # Force new lookup nltest /dsgetdc:domain.com /gc # Find Global Catalog nltest /dsgetdc:domain.com /pdc # Find PDC Emulator nltest /dsgetdc:domain.com /ldaponly # LDAP capable DC nltest /dsgetdc:domain.com /kdc # Find KDC nltest /dsgetdc:domain.com /timeserv # Find time server nltest /dsgetdc:domain.com /writable # Find writable DC
DC INFO#
nltest /dclist:domain.com # List all DCs nltest /dcname:domain.com # DC name for domain nltest /dsgetsite # Current site nltest /dsgetsitecov # Site coverage
DOMAIN TRUSTS#
nltest /domain_trusts # List all trusts nltest /domain_trusts /all_trusts # All trusts in forest nltest /domain_trusts /v # Verbose trust info nltest /trusted_domains # Trusted domains
TRUST VERIFICATION#
nltest /sc_query:domain.com # Secure channel status nltest /sc_verify:domain.com # Verify secure channel nltest /sc_reset:domain.com # Reset secure channel nltest /sc_change_pwd:domain.com # Change SC password
TRUST TESTING#
nltest /server:dc.domain.com /query # Query DC status nltest /server:dc.domain.com /sc_query:trusted.com
NETLOGON STATUS#
nltest /query # Query local Netlogon nltest /server:DC /query # Query remote DC nltest /server:DC /dbflag:0x2080ffff # Enable Netlogon debug
USER & COMPUTER INFO#
nltest /user:"username" # User info nltest /whowill:domain username # Which DC will auth user nltest /finduser:username # Find user's DC
PASSWORD INFO#
nltest /server:DC /bdc_query:domain # BDC password replication nltest /sync # Force sync with PDC
FSMO ROLES#
# Find FSMO role holders nltest /dsgetdc:domain.com /pdc # PDC Emulator nltest /dclist:domain.com # All DCs (check roles)
KERBEROS#
nltest /dsgetdc:domain.com /kdc # Find Kerberos DC nltest /server:DC /sc_query:domain # Check Kerberos trust
SITE INFO#
nltest /dsgetsite # Current computer's site nltest /dsgetsitecov # Site coverage by DCs nltest /server:DC /dsgetsite # DC's site
DIAGNOSTICS#
SECURE CHANNEL#
# Check secure channel health nltest /sc_query:domain.com # Healthy output: "Trusted DC Name \\DC.domain.com" # "The command completed successfully" # Reset if broken nltest /sc_reset:domain.com
DC CONNECTIVITY#
nltest /server:dc.domain.com /query nltest /dsgetdc:domain.com /try_next_closest_site
DEBUG LOGGING#
# Enable Netlogon debug logging nltest /dbflag:0x2080ffff # All logging nltest /dbflag:0x0 # Disable logging # Log location: %windir%\debug\netlogon.log
REPLICATION#
nltest /bdc_query:domain.com # BDC replication status nltest /sync # Force sync to PDC nltest /dsregdns # Re-register DC DNS records
COMMON ISSUES#
TRUST PROBLEMS#
# Check trust status nltest /sc_query:trusted.domain.com # If failed, reset: nltest /sc_reset:trusted.domain.com
DC NOT FOUND#
# Force DC discovery nltest /dsgetdc:domain.com /force # Clear DC cache nltest /dsgetdc:domain.com /force /gc
AUTHENTICATION FAILURES#
# Check which DC will authenticate nltest /whowill:domain username # Verify DC is responsive nltest /server:dc.domain.com /query
SECURE CHANNEL BROKEN#
# Common error: "ERROR_NO_TRUST_SAM_ACCOUNT" # Reset secure channel: nltest /sc_reset:domain.com # Or rejoin domain
SECURITY ANALYSIS#
# Enumerate trusts nltest /domain_trusts /all_trusts /v # Find all DCs (for targeting) nltest /dclist:domain.com # Check trust relationships nltest /trusted_domains # Verify authentication path nltest /whowill:domain targetuser
REMOTE EXECUTION#
nltest /server:REMOTEDC /query nltest /server:REMOTEDC /sc_query:domain.com nltest /server:REMOTEDC /dclist:domain.com
OUTPUT EXAMPLES#
# Successful SC query: # Flags: 0 # Trusted DC Name \\DC1.domain.com # Trusted DC Connection Status Status = 0 0x0 NERR_Success # The command completed successfully # Failed SC query: # Flags: 0 # Connection Status = 1311 0x51f ERROR_NO_LOGON_SERVERS
QUICK REFERENCE#
# Find DC nltest /dsgetdc:domain.com nltest /dsgetdc:domain.com /gc # Global Catalog nltest /dsgetdc:domain.com /pdc # PDC # List DCs nltest /dclist:domain.com # Trust info nltest /domain_trusts nltest /domain_trusts /all_trusts # Secure channel nltest /sc_query:domain.com # Check nltest /sc_verify:domain.com # Verify nltest /sc_reset:domain.com # Reset # Site info nltest /dsgetsite # User lookup nltest /whowill:domain username # Debug nltest /dbflag:0x2080ffff # Enable nltest /dbflag:0x0 # Disable