Active Directory Configuration Related Searchess might be part of the AD DOMAIN or Configuration Directory Partition from the AD Forest
ldapsearch -H ldaps://serverdc.example.com:636 -x -D "adminguy@example.com" -W -b "DC=example,DC=com" -s sub -a always -z 1000 "(objectClass=serviceConnectionPoint)" "serviceClassName" "serviceDNSName" "objectClass"
ldapsearch -H ldaps://serverdc.example.com:636 -x -D "adminguy@example.com" -W -b "DC=example,DC=com" -s sub -a always -z 1000 "(objectClass=trustedDomain)" "cn" "trustType" "trustDirection" "trustAuthIncoming" "trustAuthOutgoing" "trustPartner" "objectClass"
ldapsearch -H ldaps://serverdc.example.com:636 -x -D "adminguy@example.com" -W -b "CN=Configuration,DC=exampleroot,DC=com" -s sub -a always -z 1000 "(&(objectCategory=nTDSDSA)(options:1.2.840.113556.1.4.803:=1))" "objectClass"
ldapsearch -H ldaps://serverdc.example.com:636 -x -D "adminguy@example.com" -W -b "DC=example,DC=com" -s sub -a always -z 1000 "(&(objectCategory=Computer)(userAccountControl:1.2.840.113556.1.4.803:=8192))" "dNSHostName" "objectClass"
ldapsearch -H ldaps://serverdc.example.com:636 -x -D "adminguy@example.com" -W -b "DC=example,DC=com" -s sub -a always -z 1000 "(|(ObjectClass=rIDManager)(ObjectClass=infrastructureUpdate)(ObjectClass=domainDNS))" "fSMORoleOwner" "objectClass"
ldapsearch -H ldaps://serverdc.example.com:636 -x -D "adminguy@example.com" -W -b "CN=Configuration,DC=exampleroot,DC=com" -s sub -a always -z 1000 "(ObjectClass=crossRefContainer)" "fSMORoleOwner" "objectClass
ldapsearch -H ldaps://serverdc.example.com:636 -x -D "adminguy@example.com" -W -b "CN=Schema,CN=Configuration,DC=exampleroot,DC=com" -s sub -a always -z 1000 "(ObjectClass=dMD)" "fSMORoleOwner" "objectClass"
ldapsearch -H ldaps://serverdc.example.com:636 -x -D "adminguy@example.com" -W -b "CN=Policies,CN=System,DC=example,DC=com" -s sub -a always -z 1000 "(objectClass=groupPolicyContainer)" "displayName" "objectClass"
ldapsearch -H ldaps://serverdc.example.com:636 -x -D "adminguy@example.com" -W -b "CN=Sites,CN=Configuration,DC=exampleroot,DC=com" -s sub -a always -z 1000 "(objectclass=site)" "cn" "siteObjectBL" "objectClass"
ldapsearch -H ldaps://serverdc.example.com:636 -x -D "adminguy@example.com" -W -b "CN=Sites,CN=Configuration,DC=exampleroot,DC=com" -s sub -a always -z 1000 "(objectclass=server)" "cn" "distinguishedName" "objectClass"
ldapsearch -H ldaps://serverdc.example.com:636 -x -D "adminguy@example.com" -W -b "CN=Subnets,CN=Sites,CN=Configuration,DC=exampleroot,DC=com" -s sub -a always -z 1000 "(cn=*)" "cn" "siteObject" "objectClass"
ldapsearch -H ldaps://serverdc.example.com:636 -x -D "adminguy@example.com" -W -b "DC=example,DC=com" -s sub -a always -z 1000 "(userAccountControl:1.2.840.113556.1.4.803:=2048)" "sAMAccountName" "pwdLastSet" "objectClass"