← All cheat sheets

NLTEST

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Network Logon Test: Windows domain diagnostics tool.
Test domain trusts, DC connectivity, and Netlogon status.

DOMAIN CONTROLLER INFO#


    

FIND DC#

nltest /dsgetdc:domain.com           # Find DC for domain
nltest /dsgetdc:domain.com /force    # Force new lookup
nltest /dsgetdc:domain.com /gc       # Find Global Catalog
nltest /dsgetdc:domain.com /pdc      # Find PDC Emulator
nltest /dsgetdc:domain.com /ldaponly # LDAP capable DC
nltest /dsgetdc:domain.com /kdc      # Find KDC
nltest /dsgetdc:domain.com /timeserv # Find time server
nltest /dsgetdc:domain.com /writable # Find writable DC

DC INFO#

nltest /dclist:domain.com            # List all DCs
nltest /dcname:domain.com            # DC name for domain
nltest /dsgetsite                    # Current site
nltest /dsgetsitecov                 # Site coverage

DOMAIN TRUSTS#

nltest /domain_trusts                # List all trusts
nltest /domain_trusts /all_trusts    # All trusts in forest
nltest /domain_trusts /v             # Verbose trust info
nltest /trusted_domains              # Trusted domains

TRUST VERIFICATION#

nltest /sc_query:domain.com          # Secure channel status
nltest /sc_verify:domain.com         # Verify secure channel
nltest /sc_reset:domain.com          # Reset secure channel
nltest /sc_change_pwd:domain.com     # Change SC password

TRUST TESTING#

nltest /server:dc.domain.com /query  # Query DC status
nltest /server:dc.domain.com /sc_query:trusted.com

NETLOGON STATUS#

nltest /query                        # Query local Netlogon
nltest /server:DC /query             # Query remote DC
nltest /server:DC /dbflag:0x2080ffff # Enable Netlogon debug

USER & COMPUTER INFO#

nltest /user:"username"              # User info
nltest /whowill:domain username      # Which DC will auth user
nltest /finduser:username            # Find user's DC

PASSWORD INFO#

nltest /server:DC /bdc_query:domain  # BDC password replication
nltest /sync                         # Force sync with PDC

FSMO ROLES#

# Find FSMO role holders
nltest /dsgetdc:domain.com /pdc      # PDC Emulator
nltest /dclist:domain.com            # All DCs (check roles)

KERBEROS#

nltest /dsgetdc:domain.com /kdc      # Find Kerberos DC
nltest /server:DC /sc_query:domain   # Check Kerberos trust

SITE INFO#

nltest /dsgetsite                    # Current computer's site
nltest /dsgetsitecov                 # Site coverage by DCs
nltest /server:DC /dsgetsite         # DC's site

DIAGNOSTICS#


    

SECURE CHANNEL#

# Check secure channel health
nltest /sc_query:domain.com
# Healthy output: "Trusted DC Name \\DC.domain.com"
# "The command completed successfully"

# Reset if broken
nltest /sc_reset:domain.com

DC CONNECTIVITY#

nltest /server:dc.domain.com /query
nltest /dsgetdc:domain.com /try_next_closest_site

DEBUG LOGGING#

# Enable Netlogon debug logging
nltest /dbflag:0x2080ffff            # All logging
nltest /dbflag:0x0                   # Disable logging

# Log location: %windir%\debug\netlogon.log

REPLICATION#

nltest /bdc_query:domain.com         # BDC replication status
nltest /sync                         # Force sync to PDC
nltest /dsregdns                     # Re-register DC DNS records

COMMON ISSUES#


    

TRUST PROBLEMS#

# Check trust status
nltest /sc_query:trusted.domain.com
# If failed, reset:
nltest /sc_reset:trusted.domain.com

DC NOT FOUND#

# Force DC discovery
nltest /dsgetdc:domain.com /force

# Clear DC cache
nltest /dsgetdc:domain.com /force /gc

AUTHENTICATION FAILURES#

# Check which DC will authenticate
nltest /whowill:domain username

# Verify DC is responsive
nltest /server:dc.domain.com /query

SECURE CHANNEL BROKEN#

# Common error: "ERROR_NO_TRUST_SAM_ACCOUNT"
# Reset secure channel:
nltest /sc_reset:domain.com

# Or rejoin domain

SECURITY ANALYSIS#

# Enumerate trusts
nltest /domain_trusts /all_trusts /v

# Find all DCs (for targeting)
nltest /dclist:domain.com

# Check trust relationships
nltest /trusted_domains

# Verify authentication path
nltest /whowill:domain targetuser

REMOTE EXECUTION#

nltest /server:REMOTEDC /query
nltest /server:REMOTEDC /sc_query:domain.com
nltest /server:REMOTEDC /dclist:domain.com

OUTPUT EXAMPLES#

# Successful SC query:
# Flags: 0
# Trusted DC Name \\DC1.domain.com
# Trusted DC Connection Status Status = 0 0x0 NERR_Success
# The command completed successfully

# Failed SC query:
# Flags: 0
# Connection Status = 1311 0x51f ERROR_NO_LOGON_SERVERS

QUICK REFERENCE#

# Find DC
nltest /dsgetdc:domain.com
nltest /dsgetdc:domain.com /gc       # Global Catalog
nltest /dsgetdc:domain.com /pdc      # PDC

# List DCs
nltest /dclist:domain.com

# Trust info
nltest /domain_trusts
nltest /domain_trusts /all_trusts

# Secure channel
nltest /sc_query:domain.com          # Check
nltest /sc_verify:domain.com         # Verify
nltest /sc_reset:domain.com          # Reset

# Site info
nltest /dsgetsite

# User lookup
nltest /whowill:domain username

# Debug
nltest /dbflag:0x2080ffff            # Enable
nltest /dbflag:0x0                   # Disable