fleet/schema/tables/ntdomains.yml
Josh Brower 4c73ccb338
Add additional Windows tables to schema (#8817)
* Add dns_cache

* Add ntdomains

* Add userassist

* add shimcache

* Spacing
2022-11-28 10:00:23 -05:00

14 lines
532 B
YAML

name: ntdomains
examples: >-
If the system is joined to a domain, this query will return the domain name as well as all known domain controllers and their IP addresses.
```
SELECT domain_name, domain_controller_name, domain_controller_address, status FROM ntdomains WHERE domain_name != "";
```
notes: >-
This table returns a row even if the local system is not joined to a domain - in this case, the `status` column will be `Unknown` and the `name` column will contain `Domain: $Hostname of local system`.