ldap-enumeration.md (11274B)
1 --- 2 title: "LDAP Enumeration" 3 description: "Manual ldapsearch queries to enumerate AD: users, groups, computers, ACLs, SPNs and attributes." 4 category: active-directory 5 subcategory: "Tooling & Recon" 6 tags: [active-directory, ldap, enumeration] 7 tools: [ldapsearch] 8 difficulty: intermediate 9 updated: "2026-08-09" 10 source: "vault:ActiveDirectory/LDAP Search.md" 11 --- 12 13 # LDAP Enumeration 14 15 Manual `ldapsearch` reference against Active Directory. The worked examples below use the credentials from the HTB *Support* box: 16 17 **Example credentials:** 18 - Username: `ldap@support.htb` 19 - Password: `nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz` 20 - Domain: `support.htb` 21 - Base DN: `DC=support,DC=htb` 22 23 ## Basic ldapsearch Syntax 24 25 ### Initial Reconnaissance 26 27 #### Get Naming Contexts (Anonymous) 28 ```bash 29 ldapsearch -x -H ldap://support.htb -b "" -s base namingContexts 30 ``` 31 32 #### Test Authentication 33 ```bash 34 ldapsearch -x -H ldap://support.htb \ 35 -D 'ldap@support.htb' \ 36 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 37 -b "DC=support,DC=htb" \ 38 -s base 39 ``` 40 41 #### Full Domain Dump 42 ```bash 43 ldapsearch -x -H ldap://support.htb \ 44 -D 'ldap@support.htb' \ 45 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 46 -b "DC=support,DC=htb" | less 47 ``` 48 49 #### Clean Output (Recommended) 50 ```bash 51 ldapsearch -LLL -x -H ldap://support.htb \ 52 -D 'ldap@support.htb' \ 53 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 54 -b "DC=support,DC=htb" 55 ``` 56 57 ## User Enumeration 58 59 #### All Users 60 ```bash 61 ldapsearch -x -H ldap://support.htb \ 62 -D 'ldap@support.htb' \ 63 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 64 -b "DC=support,DC=htb" \ 65 "(objectClass=person)" cn mail 66 ``` 67 68 #### All AD User Objects 69 ```bash 70 ldapsearch -x -H ldap://support.htb \ 71 -D 'ldap@support.htb' \ 72 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 73 -b "DC=support,DC=htb" \ 74 "(&(objectClass=user)(objectCategory=person))" \ 75 sAMAccountName mail displayName 76 ``` 77 78 #### Users with Extended Attributes 79 ```bash 80 ldapsearch -x -H ldap://support.htb \ 81 -D 'ldap@support.htb' \ 82 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 83 -b "DC=support,DC=htb" \ 84 "(objectClass=user)" \ 85 sAMAccountName mail userAccountControl description info memberOf 86 ``` 87 88 #### Search for Passwords in Description/Info Fields 89 ```bash 90 # Check description fields 91 ldapsearch -x -H ldap://support.htb \ 92 -D 'ldap@support.htb' \ 93 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 94 -b "DC=support,DC=htb" \ 95 "(description=*)" description cn | grep -i "pass\|pwd" 96 97 # Check info field (critical for this box!) 98 ldapsearch -x -H ldap://support.htb \ 99 -D 'ldap@support.htb' \ 100 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 101 -b "DC=support,DC=htb" \ 102 "(info=*)" info cn sAMAccountName 103 ``` 104 105 #### Find a Specific User 106 ```bash 107 ldapsearch -x -H ldap://support.htb \ 108 -D 'ldap@support.htb' \ 109 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 110 -b "DC=support,DC=htb" \ 111 "(cn=support)" \ 112 cn info memberOf distinguishedName 113 ``` 114 115 #### Active Users Only (Exclude Disabled) 116 ```bash 117 ldapsearch -x -H ldap://support.htb \ 118 -D 'ldap@support.htb' \ 119 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 120 -b "DC=support,DC=htb" \ 121 '(&(objectClass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))' \ 122 sAMAccountName cn 123 ``` 124 125 #### Service Accounts (Kerberoastable) 126 ```bash 127 ldapsearch -x -H ldap://support.htb \ 128 -D 'ldap@support.htb' \ 129 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 130 -b "DC=support,DC=htb" \ 131 "(&(objectClass=user)(servicePrincipalName=*))" \ 132 sAMAccountName servicePrincipalName 133 ``` 134 135 ## Group Enumeration 136 137 #### All Groups 138 ```bash 139 ldapsearch -x -H ldap://support.htb \ 140 -D 'ldap@support.htb' \ 141 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 142 -b "DC=support,DC=htb" \ 143 "(objectClass=group)" cn description member 144 ``` 145 146 #### Groups with "Admin" in Name 147 ```bash 148 ldapsearch -LLL -x -H ldap://support.htb \ 149 -D 'ldap@support.htb' \ 150 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 151 -b "DC=support,DC=htb" \ 152 "(&(objectClass=group)(name=*admin*))" name sAMAccountName member 153 ``` 154 155 #### A Named Group's Members 156 ```bash 157 ldapsearch -x -H ldap://support.htb \ 158 -D 'ldap@support.htb' \ 159 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 160 -b "DC=support,DC=htb" \ 161 "(cn=Remote Management Users)" member 162 ``` 163 164 #### Domain Admins 165 ```bash 166 ldapsearch -x -H ldap://support.htb \ 167 -D 'ldap@support.htb' \ 168 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 169 -b "DC=support,DC=htb" \ 170 "(cn=Domain Admins)" member 171 ``` 172 173 #### A User's Group Memberships 174 ```bash 175 ldapsearch -x -H ldap://support.htb \ 176 -D 'ldap@support.htb' \ 177 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 178 -b "DC=support,DC=htb" \ 179 "(sAMAccountName=support)" memberOf 180 ``` 181 182 ## Computer Enumeration 183 184 #### All Computers 185 ```bash 186 ldapsearch -x -H ldap://support.htb \ 187 -D 'ldap@support.htb' \ 188 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 189 -b "DC=support,DC=htb" \ 190 "(objectClass=computer)" cn operatingSystem dNSHostName 191 ``` 192 193 #### Domain Controllers Only 194 ```bash 195 ldapsearch -x -H ldap://support.htb \ 196 -D 'ldap@support.htb' \ 197 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 198 -b "DC=support,DC=htb" \ 199 "(userAccountControl:1.2.840.113556.1.4.803:=8192)" cn dNSHostName 200 ``` 201 202 #### Computers with Unconstrained Delegation 203 ```bash 204 ldapsearch -x -H ldap://support.htb \ 205 -D 'ldap@support.htb' \ 206 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 207 -b "DC=support,DC=htb" \ 208 "(userAccountControl:1.2.840.113556.1.4.803:=524288)" cn 209 ``` 210 211 ## Organizational Units 212 213 ```bash 214 ldapsearch -x -LLL -H ldap://support.htb \ 215 -D 'ldap@support.htb' \ 216 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 217 -b "DC=support,DC=htb" \ 218 -s sub \ 219 "(|(objectClass=organizationalUnit)(objectClass=group))" 220 ``` 221 222 ## Operational Attributes 223 224 ```bash 225 # Get all operational attributes 226 ldapsearch -x -H ldap://support.htb \ 227 -D 'ldap@support.htb' \ 228 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 229 -b "DC=support,DC=htb" \ 230 "(objectClass=*)" '+' 231 232 # Specific operational attributes 233 ldapsearch -x -H ldap://support.htb \ 234 -D 'ldap@support.htb' \ 235 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 236 -b "DC=support,DC=htb" \ 237 "(objectClass=*)" \ 238 creatorsName createTimestamp modifiersName modifyTimestamp 239 ``` 240 241 ## Modern Tools 242 243 ### ldapdomaindump 244 ```bash 245 # Comprehensive domain dump 246 ldapdomaindump -u 'support.htb\ldap' \ 247 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 248 support.htb \ 249 -o ldap_output 250 251 # Output creates: 252 # - domain_users.json/html 253 # - domain_groups.json/html 254 # - domain_computers.json/html 255 # - domain_trusts.json/html 256 # - domain_policy.json/html 257 ``` 258 259 ### BloodHound Python 260 ```bash 261 bloodhound-python -c All \ 262 -u ldap \ 263 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 264 -d support.htb \ 265 -ns 10.10.11.174 266 ``` 267 268 ### NetExec (formerly CrackMapExec) 269 ```bash 270 # Verify credentials 271 nxc smb support.htb \ 272 -u ldap \ 273 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' 274 275 # LDAP enumeration 276 nxc ldap support.htb \ 277 -u ldap \ 278 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 279 --users --groups --computers 280 ``` 281 282 ## Secure Alternative (Password Prompt) 283 284 Instead of putting the password in the command, use `-W` for a prompt: 285 286 ```bash 287 ldapsearch -x -H ldap://support.htb \ 288 -D 'ldap@support.htb' \ 289 -W \ 290 -b "DC=support,DC=htb" 291 ``` 292 293 ## LDAPS (Secure LDAP) 294 295 ```bash 296 ldapsearch -x -H ldaps://support.htb:636 \ 297 -D 'ldap@support.htb' \ 298 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 299 -b "DC=support,DC=htb" 300 ``` 301 302 ## Key Takeaways 303 304 1. **Always use `-H ldap://`** instead of the deprecated `-h` hostname flag 305 2. **Add `-x`** for simple authentication in modern versions 306 3. **Use `-LLL`** for cleaner output 307 4. **The `info` field** contained the password for the support user in this box 308 5. **Check group memberships** — `Remote Management Users` = WinRM access 309 310 --- 311 312 ## Command-Line Flags Reference 313 314 | Flag | Long Form | Description | Example | 315 |------|-----------|-------------|---------| 316 | `-H` | `--uri` | LDAP URI to connect to (replaces deprecated `-h`) | `-H ldap://support.htb` | 317 | `-h` | `--host` | **DEPRECATED** hostname (use `-H` instead) | `-h support.htb` | 318 | `-p` | `--port` | Port number (default: 389 for LDAP, 636 for LDAPS) | `-p 389` | 319 | `-D` | `--binddn` | Bind Distinguished Name for authentication | `-D 'ldap@support.htb'` | 320 | `-w` | `--bindpw` | Bind password (plaintext — visible in process list) | `-w 'password'` | 321 | `-W` | `--bindpw-prompt` | Prompt for bind password (more secure) | `-W` | 322 | `-y` | `--bindpw-file` | Read password from file | `-y /path/to/passfile` | 323 | `-b` | `--basedn` | Base Distinguished Name for search | `-b "DC=support,DC=htb"` | 324 | `-s` | `--scope` | Search scope: `base`, `one`, `sub`, `children` | `-s sub` | 325 | `-x` | `--simple` | Use simple authentication instead of SASL | `-x` | 326 | `-Z` | `--starttls` | Issue StartTLS extended operation | `-Z` | 327 | `-L` | N/A | LDIFv1 format (one `-L`) | `-L` | 328 | `-LL` | N/A | Disable comments in output (two `-L`) | `-LL` | 329 | `-LLL` | N/A | Disable comments and version (three `-L`, cleanest) | `-LLL` | 330 | `-v` | `--verbose` | Verbose output | `-v` | 331 | `-d` | `--debug` | Debug level (0-9, higher = more verbose) | `-d 1` | 332 | `-A` | N/A | Retrieve attribute names only (no values) | `-A` | 333 | `-l` | `--timelimit` | Time limit for search in seconds | `-l 30` | 334 | `-z` | `--sizelimit` | Size limit for number of entries returned | `-z 100` | 335 | `-S` | N/A | Sort results by specified attribute | `-S cn` | 336 | `-E` | `--extensions` | LDAP extensions (e.g. paging) | `-E pr=1000/noprompt` | 337 | `-o` | N/A | Set general options | `-o ldif-wrap=no` | 338 | `-n` | N/A | Show what would be done (dry run) | `-n` | 339 | `-M` | N/A | Enable Manage DSA IT control | `-M` | 340 | `-C` | N/A | Chase referrals | `-C` | 341 | `-c` | N/A | Continuous operation mode (ignore errors) | `-c` | 342 343 ### Search Scope Values 344 345 | Scope | Description | 346 |-------|-------------| 347 | `base` | Search only the base DN itself | 348 | `one` | Search immediate children of base DN only (one level) | 349 | `sub` | Search base DN and all descendants (subtree — most common) | 350 | `children` | Search all descendants but not the base DN itself | 351 352 ### Common Attribute Shortcuts 353 354 | Shortcut | Meaning | 355 |----------|---------| 356 | `*` | All regular (non-operational) attributes | 357 | `+` | All operational attributes | 358 | `1.1` | No attributes (DN only) | 359 | `* +` | All attributes (regular + operational) | 360 361 ### LDAP URI Format 362 363 | Format | Description | 364 |--------|-------------| 365 | `ldap://host` | Standard LDAP on port 389 | 366 | `ldap://host:port` | LDAP on custom port | 367 | `ldaps://host` | LDAP over SSL/TLS on port 636 | 368 | `ldaps://host:port` | LDAPS on custom port | 369 | `ldapi://` | LDAP over Unix domain socket (local) | 370 371 ### Common Exit Codes 372 373 | Code | Meaning | 374 |------|---------| 375 | `0` | Success | 376 | `1` | Operations error | 377 | `2` | Protocol error | 378 | `32` | No such object | 379 | `49` | Invalid credentials | 380 | `50` | Insufficient access rights | 381 382 --- 383 384 ## Pro Tips 385 386 1. **Always use `-LLL`** for clean, parseable output 387 2. **Use `-W`** instead of `-w` to avoid the password in shell history 388 3. **The `info` field** in AD often contains sensitive data 389 4. **Check group memberships** — `Remote Management Users` = WinRM access 390 5. **Operational attributes** (`+`) reveal creation/modification metadata 391 6. **Use `sub` scope** for comprehensive searches 392 7. **Combine filters** with `&` (AND) and `|` (OR) for precise queries 393 8. **Save output** to files for offline analysis with `> output.txt`