#
rpcclient
A neat tool for looking up domain stuff
#
Authenticate to a domain
rpcclient -U 'domain.local/some-user' 192.168.1.1
#
Lookup a user's SID
# From the `rpcclient $>` prompt
lookupnames some-user-you-wanna-lookup