> For the complete documentation index, see [llms.txt](https://docs.forestall.io/fsprotect/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/fsprotect/search-and-reports.md).

# Search & Reports

The `Search & Reports` page provides an `Advanced Search` interface to generate reports on Active Directory inventory with builtin and custom queries.

<figure><img src="/files/9Mtxr49DdzBhX0WMsy0B" alt=""><figcaption><p>Search &#x26; Reports</p></figcaption></figure>

{% hint style="info" %}
You can see object's attributes and descriptions with pages below.
{% endhint %}

{% content-ref url="/pages/JW9nrmsBFoIqCrZ4Gwk8" %}
[Active Directory Entities](/fsprotect/search-and-reports/active-directory-entities.md)
{% endcontent-ref %}

{% content-ref url="/pages/e0OaJ2XmhLpCOdhYD0mD" %}
[Azure Entities](/fsprotect/search-and-reports/azure-entities.md)
{% endcontent-ref %}

{% content-ref url="/pages/Jp5ESYskLsOoJg6AoA0F" %}
[Vulnerability](/fsprotect/search-and-reports/vulnerability.md)
{% endcontent-ref %}

{% content-ref url="/pages/h5voWq3PE9mlBmq8D69s" %}
[Tier0](/fsprotect/search-and-reports/tier0.md)
{% endcontent-ref %}

{% content-ref url="/pages/sPhcNJaVK65E8YwOV02a" %}
[Tier2](/fsprotect/search-and-reports/tier2.md)
{% endcontent-ref %}

{% content-ref url="/pages/5zbDiteHK82JtrHHWSp7" %}
[IAM User](/fsprotect/search-and-reports/aws-entities/aws-iam-user.md)
{% endcontent-ref %}

{% content-ref url="/pages/khMeYJxbJetghaW4k0at" %}
[IAM Group](/fsprotect/search-and-reports/aws-entities/aws-iam-group.md)
{% endcontent-ref %}

{% content-ref url="/pages/fFbPtFnTeteyxfFEaUTY" %}
[IAM Role](/fsprotect/search-and-reports/aws-entities/aws-iam-role.md)
{% endcontent-ref %}

{% content-ref url="/pages/d8vnBpblrNGbwiRLvFVF" %}
[IAM Policy](/fsprotect/search-and-reports/aws-entities/aws-iam-policy.md)
{% endcontent-ref %}

{% content-ref url="/pages/eTATg6ZMFaLW8FOO6myx" %}
[IAM Access Key](/fsprotect/search-and-reports/aws-entities/aws-iam-access-key.md)
{% endcontent-ref %}

{% content-ref url="/pages/FrJBH379sQ4p7Z6q53YN" %}
[IAM Account](/fsprotect/search-and-reports/aws-entities/aws-iam-account.md)
{% endcontent-ref %}

{% content-ref url="/pages/21cxE3YG5Jx3U8VqjTyh" %}
[Organization](/fsprotect/search-and-reports/aws-entities/aws-organization.md)
{% endcontent-ref %}

## Run On Graph

On the **Search & Reports** page, users can use the **Run on Graph** feature for both saved queries and newly created queries. This allows them to directly visualize the results in the **Visualize** page, offering a clear graphical representation of the data.

<figure><img src="/files/p8VwqhZZg2pCVLy9MupY" alt=""><figcaption><p>Saved Query</p></figcaption></figure>

<figure><img src="/files/wm9FzYVVdb8nHh6A3OC8" alt=""><figcaption><p>New Query</p></figcaption></figure>

## New Query

The `New Query` interface provides a query builder to create complex queries. You can create custom queries by using `Object Type`, `Object Attributes`, `And/Or` logics,<kbd>Relation Direction</kbd>and `Groupings`. You can also save these queries for later use.

<figure><img src="/files/8LmZO9VDQebYDI69FaVm" alt=""><figcaption><p>Relation Direction</p></figcaption></figure>

## Active Directory Querys

### Example 1 - Create Query - Risky Groups with No Member

<figure><img src="/files/IQPXgk9XiCTQmvhQ97Xb" alt=""><figcaption><p>Example - 1</p></figcaption></figure>

### Example 2 - Create Query - Users with Group Delegated Admin Right on more than 1 Computer

<figure><img src="/files/XsdfVKuESETc2zDv8Bi6" alt=""><figcaption><p>Example - 2</p></figcaption></figure>

### Example 3 - Saving Query - Local Admin Accounts created in the last 1 month

<figure><img src="/files/BdcR8jlqnOzazuwzgs6J" alt=""><figcaption><p>Example - 3</p></figcaption></figure>

### Example 4 - Using Groups - Stealth Admins in forestall.labs or windomain.labs Domains

<figure><img src="/files/8luifxQYN4U1mvkX78Ia" alt=""><figcaption><p>Example - 4</p></figcaption></figure>

## Azure (Entra ID) Queries

### Example 1 - Create Query - Stealth Admin in Azure

<figure><img src="/files/U3d2u7s6OdKEGATRXKJE" alt=""><figcaption><p>Example - 1</p></figcaption></figure>

### Example 2 - Saving Query - Azure User With Tier 0 Accounts created in the last 4 Month

<figure><img src="/files/76YTIcvBGJ39TuO3WDs5" alt=""><figcaption><p>Example - 2</p></figcaption></figure>

## Saved Queries

`Saved Queries` contains a list of various built-in queries and custom queries created by the user.

<figure><img src="/files/UrEQjzoRmgoDBQN4Ro0s" alt=""><figcaption><p>Saved Queries</p></figcaption></figure>
