daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ldap-enumeration.md (11274B)


      1 ---
      2 title: "LDAP Enumeration"
      3 description: "Manual ldapsearch queries to enumerate AD: users, groups, computers, ACLs, SPNs and attributes."
      4 category: active-directory
      5 subcategory: "Tooling & Recon"
      6 tags: [active-directory, ldap, enumeration]
      7 tools: [ldapsearch]
      8 difficulty: intermediate
      9 updated: "2026-08-09"
     10 source: "vault:ActiveDirectory/LDAP Search.md"
     11 ---
     12 
     13 # LDAP Enumeration
     14 
     15 Manual `ldapsearch` reference against Active Directory. The worked examples below use the credentials from the HTB *Support* box:
     16 
     17 **Example credentials:**
     18 - Username: `ldap@support.htb`
     19 - Password: `nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz`
     20 - Domain: `support.htb`
     21 - Base DN: `DC=support,DC=htb`
     22 
     23 ## Basic ldapsearch Syntax
     24 
     25 ### Initial Reconnaissance
     26 
     27 #### Get Naming Contexts (Anonymous)
     28 ```bash
     29 ldapsearch -x -H ldap://support.htb -b "" -s base namingContexts
     30 ```
     31 
     32 #### Test Authentication
     33 ```bash
     34 ldapsearch -x -H ldap://support.htb \
     35   -D 'ldap@support.htb' \
     36   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     37   -b "DC=support,DC=htb" \
     38   -s base
     39 ```
     40 
     41 #### Full Domain Dump
     42 ```bash
     43 ldapsearch -x -H ldap://support.htb \
     44   -D 'ldap@support.htb' \
     45   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     46   -b "DC=support,DC=htb" | less
     47 ```
     48 
     49 #### Clean Output (Recommended)
     50 ```bash
     51 ldapsearch -LLL -x -H ldap://support.htb \
     52   -D 'ldap@support.htb' \
     53   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     54   -b "DC=support,DC=htb"
     55 ```
     56 
     57 ## User Enumeration
     58 
     59 #### All Users
     60 ```bash
     61 ldapsearch -x -H ldap://support.htb \
     62   -D 'ldap@support.htb' \
     63   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     64   -b "DC=support,DC=htb" \
     65   "(objectClass=person)" cn mail
     66 ```
     67 
     68 #### All AD User Objects
     69 ```bash
     70 ldapsearch -x -H ldap://support.htb \
     71   -D 'ldap@support.htb' \
     72   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     73   -b "DC=support,DC=htb" \
     74   "(&(objectClass=user)(objectCategory=person))" \
     75   sAMAccountName mail displayName
     76 ```
     77 
     78 #### Users with Extended Attributes
     79 ```bash
     80 ldapsearch -x -H ldap://support.htb \
     81   -D 'ldap@support.htb' \
     82   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     83   -b "DC=support,DC=htb" \
     84   "(objectClass=user)" \
     85   sAMAccountName mail userAccountControl description info memberOf
     86 ```
     87 
     88 #### Search for Passwords in Description/Info Fields
     89 ```bash
     90 # Check description fields
     91 ldapsearch -x -H ldap://support.htb \
     92   -D 'ldap@support.htb' \
     93   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     94   -b "DC=support,DC=htb" \
     95   "(description=*)" description cn | grep -i "pass\|pwd"
     96 
     97 # Check info field (critical for this box!)
     98 ldapsearch -x -H ldap://support.htb \
     99   -D 'ldap@support.htb' \
    100   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    101   -b "DC=support,DC=htb" \
    102   "(info=*)" info cn sAMAccountName
    103 ```
    104 
    105 #### Find a Specific User
    106 ```bash
    107 ldapsearch -x -H ldap://support.htb \
    108   -D 'ldap@support.htb' \
    109   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    110   -b "DC=support,DC=htb" \
    111   "(cn=support)" \
    112   cn info memberOf distinguishedName
    113 ```
    114 
    115 #### Active Users Only (Exclude Disabled)
    116 ```bash
    117 ldapsearch -x -H ldap://support.htb \
    118   -D 'ldap@support.htb' \
    119   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    120   -b "DC=support,DC=htb" \
    121   '(&(objectClass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))' \
    122   sAMAccountName cn
    123 ```
    124 
    125 #### Service Accounts (Kerberoastable)
    126 ```bash
    127 ldapsearch -x -H ldap://support.htb \
    128   -D 'ldap@support.htb' \
    129   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    130   -b "DC=support,DC=htb" \
    131   "(&(objectClass=user)(servicePrincipalName=*))" \
    132   sAMAccountName servicePrincipalName
    133 ```
    134 
    135 ## Group Enumeration
    136 
    137 #### All Groups
    138 ```bash
    139 ldapsearch -x -H ldap://support.htb \
    140   -D 'ldap@support.htb' \
    141   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    142   -b "DC=support,DC=htb" \
    143   "(objectClass=group)" cn description member
    144 ```
    145 
    146 #### Groups with "Admin" in Name
    147 ```bash
    148 ldapsearch -LLL -x -H ldap://support.htb \
    149   -D 'ldap@support.htb' \
    150   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    151   -b "DC=support,DC=htb" \
    152   "(&(objectClass=group)(name=*admin*))" name sAMAccountName member
    153 ```
    154 
    155 #### A Named Group's Members
    156 ```bash
    157 ldapsearch -x -H ldap://support.htb \
    158   -D 'ldap@support.htb' \
    159   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    160   -b "DC=support,DC=htb" \
    161   "(cn=Remote Management Users)" member
    162 ```
    163 
    164 #### Domain Admins
    165 ```bash
    166 ldapsearch -x -H ldap://support.htb \
    167   -D 'ldap@support.htb' \
    168   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    169   -b "DC=support,DC=htb" \
    170   "(cn=Domain Admins)" member
    171 ```
    172 
    173 #### A User's Group Memberships
    174 ```bash
    175 ldapsearch -x -H ldap://support.htb \
    176   -D 'ldap@support.htb' \
    177   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    178   -b "DC=support,DC=htb" \
    179   "(sAMAccountName=support)" memberOf
    180 ```
    181 
    182 ## Computer Enumeration
    183 
    184 #### All Computers
    185 ```bash
    186 ldapsearch -x -H ldap://support.htb \
    187   -D 'ldap@support.htb' \
    188   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    189   -b "DC=support,DC=htb" \
    190   "(objectClass=computer)" cn operatingSystem dNSHostName
    191 ```
    192 
    193 #### Domain Controllers Only
    194 ```bash
    195 ldapsearch -x -H ldap://support.htb \
    196   -D 'ldap@support.htb' \
    197   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    198   -b "DC=support,DC=htb" \
    199   "(userAccountControl:1.2.840.113556.1.4.803:=8192)" cn dNSHostName
    200 ```
    201 
    202 #### Computers with Unconstrained Delegation
    203 ```bash
    204 ldapsearch -x -H ldap://support.htb \
    205   -D 'ldap@support.htb' \
    206   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    207   -b "DC=support,DC=htb" \
    208   "(userAccountControl:1.2.840.113556.1.4.803:=524288)" cn
    209 ```
    210 
    211 ## Organizational Units
    212 
    213 ```bash
    214 ldapsearch -x -LLL -H ldap://support.htb \
    215   -D 'ldap@support.htb' \
    216   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    217   -b "DC=support,DC=htb" \
    218   -s sub \
    219   "(|(objectClass=organizationalUnit)(objectClass=group))"
    220 ```
    221 
    222 ## Operational Attributes
    223 
    224 ```bash
    225 # Get all operational attributes
    226 ldapsearch -x -H ldap://support.htb \
    227   -D 'ldap@support.htb' \
    228   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    229   -b "DC=support,DC=htb" \
    230   "(objectClass=*)" '+'
    231 
    232 # Specific operational attributes
    233 ldapsearch -x -H ldap://support.htb \
    234   -D 'ldap@support.htb' \
    235   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    236   -b "DC=support,DC=htb" \
    237   "(objectClass=*)" \
    238   creatorsName createTimestamp modifiersName modifyTimestamp
    239 ```
    240 
    241 ## Modern Tools
    242 
    243 ### ldapdomaindump
    244 ```bash
    245 # Comprehensive domain dump
    246 ldapdomaindump -u 'support.htb\ldap' \
    247   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    248   support.htb \
    249   -o ldap_output
    250 
    251 # Output creates:
    252 # - domain_users.json/html
    253 # - domain_groups.json/html
    254 # - domain_computers.json/html
    255 # - domain_trusts.json/html
    256 # - domain_policy.json/html
    257 ```
    258 
    259 ### BloodHound Python
    260 ```bash
    261 bloodhound-python -c All \
    262   -u ldap \
    263   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    264   -d support.htb \
    265   -ns 10.10.11.174
    266 ```
    267 
    268 ### NetExec (formerly CrackMapExec)
    269 ```bash
    270 # Verify credentials
    271 nxc smb support.htb \
    272   -u ldap \
    273   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz'
    274 
    275 # LDAP enumeration
    276 nxc ldap support.htb \
    277   -u ldap \
    278   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    279   --users --groups --computers
    280 ```
    281 
    282 ## Secure Alternative (Password Prompt)
    283 
    284 Instead of putting the password in the command, use `-W` for a prompt:
    285 
    286 ```bash
    287 ldapsearch -x -H ldap://support.htb \
    288   -D 'ldap@support.htb' \
    289   -W \
    290   -b "DC=support,DC=htb"
    291 ```
    292 
    293 ## LDAPS (Secure LDAP)
    294 
    295 ```bash
    296 ldapsearch -x -H ldaps://support.htb:636 \
    297   -D 'ldap@support.htb' \
    298   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    299   -b "DC=support,DC=htb"
    300 ```
    301 
    302 ## Key Takeaways
    303 
    304 1. **Always use `-H ldap://`** instead of the deprecated `-h` hostname flag
    305 2. **Add `-x`** for simple authentication in modern versions
    306 3. **Use `-LLL`** for cleaner output
    307 4. **The `info` field** contained the password for the support user in this box
    308 5. **Check group memberships** — `Remote Management Users` = WinRM access
    309 
    310 ---
    311 
    312 ## Command-Line Flags Reference
    313 
    314 | Flag | Long Form | Description | Example |
    315 |------|-----------|-------------|---------|
    316 | `-H` | `--uri` | LDAP URI to connect to (replaces deprecated `-h`) | `-H ldap://support.htb` |
    317 | `-h` | `--host` | **DEPRECATED** hostname (use `-H` instead) | `-h support.htb` |
    318 | `-p` | `--port` | Port number (default: 389 for LDAP, 636 for LDAPS) | `-p 389` |
    319 | `-D` | `--binddn` | Bind Distinguished Name for authentication | `-D 'ldap@support.htb'` |
    320 | `-w` | `--bindpw` | Bind password (plaintext — visible in process list) | `-w 'password'` |
    321 | `-W` | `--bindpw-prompt` | Prompt for bind password (more secure) | `-W` |
    322 | `-y` | `--bindpw-file` | Read password from file | `-y /path/to/passfile` |
    323 | `-b` | `--basedn` | Base Distinguished Name for search | `-b "DC=support,DC=htb"` |
    324 | `-s` | `--scope` | Search scope: `base`, `one`, `sub`, `children` | `-s sub` |
    325 | `-x` | `--simple` | Use simple authentication instead of SASL | `-x` |
    326 | `-Z` | `--starttls` | Issue StartTLS extended operation | `-Z` |
    327 | `-L` | N/A | LDIFv1 format (one `-L`) | `-L` |
    328 | `-LL` | N/A | Disable comments in output (two `-L`) | `-LL` |
    329 | `-LLL` | N/A | Disable comments and version (three `-L`, cleanest) | `-LLL` |
    330 | `-v` | `--verbose` | Verbose output | `-v` |
    331 | `-d` | `--debug` | Debug level (0-9, higher = more verbose) | `-d 1` |
    332 | `-A` | N/A | Retrieve attribute names only (no values) | `-A` |
    333 | `-l` | `--timelimit` | Time limit for search in seconds | `-l 30` |
    334 | `-z` | `--sizelimit` | Size limit for number of entries returned | `-z 100` |
    335 | `-S` | N/A | Sort results by specified attribute | `-S cn` |
    336 | `-E` | `--extensions` | LDAP extensions (e.g. paging) | `-E pr=1000/noprompt` |
    337 | `-o` | N/A | Set general options | `-o ldif-wrap=no` |
    338 | `-n` | N/A | Show what would be done (dry run) | `-n` |
    339 | `-M` | N/A | Enable Manage DSA IT control | `-M` |
    340 | `-C` | N/A | Chase referrals | `-C` |
    341 | `-c` | N/A | Continuous operation mode (ignore errors) | `-c` |
    342 
    343 ### Search Scope Values
    344 
    345 | Scope | Description |
    346 |-------|-------------|
    347 | `base` | Search only the base DN itself |
    348 | `one` | Search immediate children of base DN only (one level) |
    349 | `sub` | Search base DN and all descendants (subtree — most common) |
    350 | `children` | Search all descendants but not the base DN itself |
    351 
    352 ### Common Attribute Shortcuts
    353 
    354 | Shortcut | Meaning |
    355 |----------|---------|
    356 | `*` | All regular (non-operational) attributes |
    357 | `+` | All operational attributes |
    358 | `1.1` | No attributes (DN only) |
    359 | `* +` | All attributes (regular + operational) |
    360 
    361 ### LDAP URI Format
    362 
    363 | Format | Description |
    364 |--------|-------------|
    365 | `ldap://host` | Standard LDAP on port 389 |
    366 | `ldap://host:port` | LDAP on custom port |
    367 | `ldaps://host` | LDAP over SSL/TLS on port 636 |
    368 | `ldaps://host:port` | LDAPS on custom port |
    369 | `ldapi://` | LDAP over Unix domain socket (local) |
    370 
    371 ### Common Exit Codes
    372 
    373 | Code | Meaning |
    374 |------|---------|
    375 | `0` | Success |
    376 | `1` | Operations error |
    377 | `2` | Protocol error |
    378 | `32` | No such object |
    379 | `49` | Invalid credentials |
    380 | `50` | Insufficient access rights |
    381 
    382 ---
    383 
    384 ## Pro Tips
    385 
    386 1. **Always use `-LLL`** for clean, parseable output
    387 2. **Use `-W`** instead of `-w` to avoid the password in shell history
    388 3. **The `info` field** in AD often contains sensitive data
    389 4. **Check group memberships** — `Remote Management Users` = WinRM access
    390 5. **Operational attributes** (`+`) reveal creation/modification metadata
    391 6. **Use `sub` scope** for comprehensive searches
    392 7. **Combine filters** with `&` (AND) and `|` (OR) for precise queries
    393 8. **Save output** to files for offline analysis with `> output.txt`