> For the complete documentation index, see [llms.txt](https://docs.forestall.io/fsprotect/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/fsprotect/search-and-reports.md).

# Search & Reports

The `Search & Reports` page provides an `Advanced Search` interface to generate reports on Active Directory inventory with builtin and custom queries.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-0dd3527e0001da48e8a7ab676bc7a92f55089a5d%2Fsearch-and-reports-readme-image-1.png?alt=media" alt=""><figcaption><p>Search &#x26; Reports</p></figcaption></figure>

{% hint style="info" %}
You can see object's attributes and descriptions with pages below.
{% endhint %}

{% content-ref url="/pages/JW9nrmsBFoIqCrZ4Gwk8" %}
[Active Directory Entities](/fsprotect/search-and-reports/active-directory-entities.md)
{% endcontent-ref %}

{% content-ref url="/pages/e0OaJ2XmhLpCOdhYD0mD" %}
[Azure Entities](/fsprotect/search-and-reports/azure-entities.md)
{% endcontent-ref %}

{% content-ref url="/pages/03A5n1M3QVCBihuM9SHY" %}
[GCP Entities](/fsprotect/search-and-reports/gcp-entities.md)
{% endcontent-ref %}

{% content-ref url="/pages/dUL4GhGtu451eyEbbjSd" %}
[AWS Entities](/fsprotect/search-and-reports/aws-entities.md)
{% endcontent-ref %}

{% content-ref url="/pages/pbxQGuy89LANIqEklTLM" %}
[GitHub Entities](/fsprotect/search-and-reports/github-entities.md)
{% endcontent-ref %}

{% content-ref url="/pages/Jp5ESYskLsOoJg6AoA0F" %}
[Vulnerability](/fsprotect/search-and-reports/vulnerability.md)
{% endcontent-ref %}

{% content-ref url="/pages/h5voWq3PE9mlBmq8D69s" %}
[Tier0](/fsprotect/search-and-reports/tier0.md)
{% endcontent-ref %}

{% content-ref url="/pages/sPhcNJaVK65E8YwOV02a" %}
[Tier2](/fsprotect/search-and-reports/tier2.md)
{% endcontent-ref %}

## Run On Graph

On the **Search & Reports** page, users can use the **Run on Graph** feature for both saved queries and newly created queries. This allows them to directly visualize the results in the **Visualize** page, offering a clear graphical representation of the data.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-8f6af259163071eba6b42c8b4e7f0f948a101835%2Fsearch-and-report-1.gif?alt=media" alt=""><figcaption><p>Saved Query</p></figcaption></figure>

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-a9fbcc759a6536ea152388deb6a956cb64e9e014%2Fsearch-and-report-2.gif?alt=media" alt=""><figcaption><p>New Query</p></figcaption></figure>

## New Query

The `New Query` interface provides a query builder to create complex queries. You can create custom queries by using `Object Type`, `Object Attributes`, `And/Or` logics,<kbd>Relation Direction</kbd>and `Groupings`. You can also save these queries for later use.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-5fdac6d0492eea062bbd89008b9b1672a8bc72d6%2Fsearch-and-report-3%20(1).gif?alt=media" alt=""><figcaption><p>Relation Direction</p></figcaption></figure>

## Active Directory Querys

### Example 1 - Create Query - Risky Groups with No Member

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-b70223a6703657bf8148d0dcc8d7e7faa130051e%2Fsearch-and-report-4.gif?alt=media" alt=""><figcaption><p>Example - 1</p></figcaption></figure>

### Example 2 - Create Query - Users with Group Delegated Admin Right on more than 1 Computer

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-85963afb813ea39d98e11a3e884d6cea0f51f774%2Fsearch-and-report-5.gif?alt=media" alt=""><figcaption><p>Example - 2</p></figcaption></figure>

### Example 3 - Saving Query - Local Admin Accounts created in the last 1 month

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-840624b47a5c3fe51e8bb30f08d85c01fdf32b95%2Fsearch-and-report-6.gif?alt=media" alt=""><figcaption><p>Example - 3</p></figcaption></figure>

### Example 4 - Using Groups - Stealth Admins in forestall.labs or windomain.labs Domains

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-a86f0e2148b764405efb79d4a2539ad839b84b71%2Fsearch-and-report-7.gif?alt=media" alt=""><figcaption><p>Example - 4</p></figcaption></figure>

## Azure (Entra ID) Queries

### Example 1 - Create Query - Stealth Admin in Azure

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-38e859e341338f88d38ce3aeb2f7168635a2439e%2Fsearch-and-report-8.gif?alt=media" alt=""><figcaption><p>Example - 1</p></figcaption></figure>

### Example 2 - Saving Query - Azure User With Tier 0 Accounts created in the last 4 Month

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-1148b1ab17d7c310b4e981575da325ea9c381314%2Fsearch-and-report-9.gif?alt=media" alt=""><figcaption><p>Example - 2</p></figcaption></figure>

## Saved Queries

`Saved Queries` contains a list of various built-in queries and custom queries created by the user.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-da029be08c29b04690643a09d2a5379e4ad7d26f%2Fsearch-and-reports-readme-image-2.png?alt=media" alt=""><figcaption><p>Saved Queries</p></figcaption></figure>
