AD DNS Records

By default any user in Active Directory can enumerate all DNS records in the Domain or Forest DNS zones, similar to a zone transfer (users can list the child objects of a DNS zone in an AD environment).
The tool adidnsdump enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks.
git clone
cd adidnsdump
pip install .
adidnsdump -u domain_name\\username ldap:// -r
cat records.csv