daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ldap-search.md (11744B)


      1 ---
      2 title: "LDAP Search"
      3 description: "Here's the updated cheat sheet using the specific credentials from the Support box:"
      4 category: active-directory
      5 subcategory: "Tooling & Recon"
      6 tags: ["active-directory"]
      7 tools: ["NetExec", "BloodHound", "ldapsearch"]
      8 difficulty: intermediate
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/LDAP Search.md"
     11 ---
     12 # LDAP Enumeration Cheat Sheet for HTB Support
     13 
     14 Here's the updated cheat sheet using the specific credentials from the Support box:
     15 
     16 **Credentials:**
     17 - Username: `ldap@support.htb`
     18 - Password: `nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz`
     19 - Domain: `support.htb`
     20 - Base DN: `DC=support,DC=htb`
     21 
     22 ## Basic ldapsearch Syntax (Modern)
     23 
     24 ### Initial Reconnaissance
     25 
     26 #### Get Naming Contexts (Anonymous)
     27 ```bash
     28 ldapsearch -x -H ldap://support.htb -b "" -s base namingContexts
     29 ```
     30 
     31 #### Test Authentication
     32 ```bash
     33 ldapsearch -x -H ldap://support.htb \
     34   -D 'ldap@support.htb' \
     35   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     36   -b "DC=support,DC=htb" \
     37   -s base
     38 ```
     39 
     40 #### Full Domain Dump
     41 ```bash
     42 ldapsearch -x -H ldap://support.htb \
     43   -D 'ldap@support.htb' \
     44   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     45   -b "DC=support,DC=htb" | less
     46 ```
     47 
     48 #### Clean Output (Recommended)
     49 ```bash
     50 ldapsearch -LLL -x -H ldap://support.htb \
     51   -D 'ldap@support.htb' \
     52   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     53   -b "DC=support,DC=htb"
     54 ```
     55 
     56 ## User Enumeration
     57 
     58 #### All Users
     59 ```bash
     60 ldapsearch -x -H ldap://support.htb \
     61   -D 'ldap@support.htb' \
     62   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     63   -b "DC=support,DC=htb" \
     64   "(objectClass=person)" cn mail
     65 ```
     66 
     67 #### All AD User Objects
     68 ```bash
     69 ldapsearch -x -H ldap://support.htb \
     70   -D 'ldap@support.htb' \
     71   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     72   -b "DC=support,DC=htb" \
     73   "(&(objectClass=user)(objectCategory=person))" \
     74   sAMAccountName mail displayName
     75 ```
     76 
     77 #### Users with Extended Attributes
     78 ```bash
     79 ldapsearch -x -H ldap://support.htb \
     80   -D 'ldap@support.htb' \
     81   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     82   -b "DC=support,DC=htb" \
     83   "(objectClass=user)" \
     84   sAMAccountName mail userAccountControl description info memberOf
     85 ```
     86 
     87 #### Search for Passwords in Description/Info Fields
     88 ```bash
     89 # Check description fields
     90 ldapsearch -x -H ldap://support.htb \
     91   -D 'ldap@support.htb' \
     92   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     93   -b "DC=support,DC=htb" \
     94   "(description=*)" description cn | grep -i "pass\|pwd"
     95 
     96 # Check info field (critical for this box!)
     97 ldapsearch -x -H ldap://support.htb \
     98   -D 'ldap@support.htb' \
     99   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    100   -b "DC=support,DC=htb" \
    101   "(info=*)" info cn sAMAccountName
    102 ```
    103 
    104 #### Find the Support User Specifically
    105 ```bash
    106 ldapsearch -x -H ldap://support.htb \
    107   -D 'ldap@support.htb' \
    108   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    109   -b "DC=support,DC=htb" \
    110   "(cn=support)" \
    111   cn info memberOf distinguishedName
    112 ```
    113 
    114 #### Active Users Only (Exclude Disabled)
    115 ```bash
    116 ldapsearch -x -H ldap://support.htb \
    117   -D 'ldap@support.htb' \
    118   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    119   -b "DC=support,DC=htb" \
    120   '(&(objectClass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))' \
    121   sAMAccountName cn
    122 ```
    123 
    124 #### Service Accounts (Kerberoastable)
    125 ```bash
    126 ldapsearch -x -H ldap://support.htb \
    127   -D 'ldap@support.htb' \
    128   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    129   -b "DC=support,DC=htb" \
    130   "(&(objectClass=user)(servicePrincipalName=*))" \
    131   sAMAccountName servicePrincipalName
    132 ```
    133 
    134 ## Group Enumeration
    135 
    136 #### All Groups
    137 ```bash
    138 ldapsearch -x -H ldap://support.htb \
    139   -D 'ldap@support.htb' \
    140   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    141   -b "DC=support,DC=htb" \
    142   "(objectClass=group)" cn description member
    143 ```
    144 
    145 #### Groups with "Admin" in Name
    146 ```bash
    147 ldapsearch -LLL -x -H ldap://support.htb \
    148   -D 'ldap@support.htb' \
    149   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    150   -b "DC=support,DC=htb" \
    151   "(&(objectClass=group)(name=*admin*))" name sAMAccountName member
    152 ```
    153 
    154 #### Shared Support Accounts Group
    155 ```bash
    156 ldapsearch -x -H ldap://support.htb \
    157   -D 'ldap@support.htb' \
    158   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    159   -b "DC=support,DC=htb" \
    160   "(cn=Shared Support Accounts)" member
    161 ```
    162 
    163 #### Remote Management Users Group
    164 ```bash
    165 ldapsearch -x -H ldap://support.htb \
    166   -D 'ldap@support.htb' \
    167   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    168   -b "DC=support,DC=htb" \
    169   "(cn=Remote Management Users)" member
    170 ```
    171 
    172 #### Domain Admins
    173 ```bash
    174 ldapsearch -x -H ldap://support.htb \
    175   -D 'ldap@support.htb' \
    176   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    177   -b "DC=support,DC=htb" \
    178   "(cn=Domain Admins)" member
    179 ```
    180 
    181 #### User's Group Memberships
    182 ```bash
    183 ldapsearch -x -H ldap://support.htb \
    184   -D 'ldap@support.htb' \
    185   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    186   -b "DC=support,DC=htb" \
    187   "(sAMAccountName=support)" memberOf
    188 ```
    189 
    190 ## Computer Enumeration
    191 
    192 #### All Computers
    193 ```bash
    194 ldapsearch -x -H ldap://support.htb \
    195   -D 'ldap@support.htb' \
    196   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    197   -b "DC=support,DC=htb" \
    198   "(objectClass=computer)" cn operatingSystem dNSHostName
    199 ```
    200 
    201 #### Domain Controllers Only
    202 ```bash
    203 ldapsearch -x -H ldap://support.htb \
    204   -D 'ldap@support.htb' \
    205   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    206   -b "DC=support,DC=htb" \
    207   "(userAccountControl:1.2.840.113556.1.4.803:=8192)" cn dNSHostName
    208 ```
    209 
    210 #### Computers with Unconstrained Delegation
    211 ```bash
    212 ldapsearch -x -H ldap://support.htb \
    213   -D 'ldap@support.htb' \
    214   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    215   -b "DC=support,DC=htb" \
    216   "(userAccountControl:1.2.840.113556.1.4.803:=524288)" cn
    217 ```
    218 
    219 ## Organizational Units
    220 
    221 ```bash
    222 ldapsearch -x -LLL -H ldap://support.htb \
    223   -D 'ldap@support.htb' \
    224   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    225   -b "DC=support,DC=htb" \
    226   -s sub \
    227   "(|(objectClass=organizationalUnit)(objectClass=group))"
    228 ```
    229 
    230 ## Operational Attributes
    231 
    232 ```bash
    233 # Get all operational attributes
    234 ldapsearch -x -H ldap://support.htb \
    235   -D 'ldap@support.htb' \
    236   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    237   -b "DC=support,DC=htb" \
    238   "(objectClass=*)" '+'
    239 
    240 # Specific operational attributes
    241 ldapsearch -x -H ldap://support.htb \
    242   -D 'ldap@support.htb' \
    243   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    244   -b "DC=support,DC=htb" \
    245   "(objectClass=*)" \
    246   creatorsName createTimestamp modifiersName modifyTimestamp
    247 ```
    248 
    249 ## Modern Tools
    250 
    251 ### ldapdomaindump
    252 ```bash
    253 # Comprehensive domain dump
    254 ldapdomaindump -u 'support.htb\ldap' \
    255   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    256   support.htb \
    257   -o ldap_output
    258 
    259 # Output creates:
    260 # - domain_users.json/html
    261 # - domain_groups.json/html
    262 # - domain_computers.json/html
    263 # - domain_trusts.json/html
    264 # - domain_policy.json/html
    265 ```
    266 
    267 ### BloodHound Python
    268 ```bash
    269 bloodhound-python -c All \
    270   -u ldap \
    271   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    272   -d support.htb \
    273   -ns 10.10.11.174
    274 ```
    275 
    276 ### CrackMapExec / NetExec
    277 ```bash
    278 # Verify credentials
    279 crackmapexec smb support.htb \
    280   -u ldap \
    281   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz'
    282 
    283 # LDAP enumeration
    284 netexec ldap support.htb \
    285   -u ldap \
    286   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    287   --users --groups --computers
    288 ```
    289 
    290 ## Secure Alternative (Password Prompt)
    291 
    292 Instead of putting the password in the command, use `-W` for a prompt:
    293 
    294 ```bash
    295 ldapsearch -x -H ldap://support.htb \
    296   -D 'ldap@support.htb' \
    297   -W \
    298   -b "DC=support,DC=htb"
    299 ```
    300 
    301 ## LDAPS (Secure LDAP)
    302 
    303 ```bash
    304 ldapsearch -x -H ldaps://support.htb:636 \
    305   -D 'ldap@support.htb' \
    306   -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    307   -b "DC=support,DC=htb"
    308 ```
    309 
    310 ## Key Takeaways
    311 
    312 1. **Always use `-H ldap://`** instead of deprecated `-h` hostname
    313 2. **Add `-x`** for simple authentication in modern versions
    314 3. **Use `-LLL`** for cleaner output
    315 4. **The `info` field** contained the password for the support user in this box
    316 5. **Check group memberships** - support user was in "Remote Management Users"
    317 
    318 ***
    319 
    320 ## Command-Line Flags Reference Table
    321 
    322 | Flag | Long Form | Description | Example |
    323 |------|-----------|-------------|---------|
    324 | `-H` | `--uri` | LDAP URI to connect to (replaces deprecated `-h`) | `-H ldap://support.htb` |
    325 | `-h` | `--host` | **DEPRECATED** Hostname (use `-H` instead) | ~~`-h support.htb`~~ |
    326 | `-p` | `--port` | Port number (default: 389 for LDAP, 636 for LDAPS) | `-p 389` |
    327 | `-D` | `--binddn` | Bind Distinguished Name for authentication | `-D 'ldap@support.htb'` |
    328 | `-w` | `--bindpw` | Bind password (plaintext - visible in process list) | `-w 'password'` |
    329 | `-W` | `--bindpw-prompt` | Prompt for bind password (more secure) | `-W` |
    330 | `-y` | `--bindpw-file` | Read password from file | `-y /path/to/passfile` |
    331 | `-b` | `--basedn` | Base Distinguished Name for search | `-b "DC=support,DC=htb"` |
    332 | `-s` | `--scope` | Search scope: `base`, `one`, `sub`, `children` | `-s sub` |
    333 | `-x` | `--simple` | Use simple authentication instead of SASL | `-x` |
    334 | `-Z` | `--starttls` | Issue StartTLS extended operation | `-Z` |
    335 | `-L` | N/A | LDIFv1 format (one `-L`) | `-L` |
    336 | `-LL` | N/A | Disable comments in output (two `-L`) | `-LL` |
    337 | `-LLL` | N/A | Disable comments and version (three `-L`, cleanest) | `-LLL` |
    338 | `-v` | `--verbose` | Verbose output | `-v` |
    339 | `-d` | `--debug` | Debug level (0-9, higher = more verbose) | `-d 1` |
    340 | `-A` | N/A | Retrieve attribute names only (no values) | `-A` |
    341 | `-l` | `--timelimit` | Time limit for search in seconds | `-l 30` |
    342 | `-z` | `--sizelimit` | Size limit for number of entries returned | `-z 100` |
    343 | `-S` | N/A | Sort results by specified attribute | `-S cn` |
    344 | `-E` | `--extensions` | LDAP extensions (e.g., paging) | `-E pr=1000/noprompt` |
    345 | `-o` | N/A | Set general options | `-o ldif-wrap=no` |
    346 | `-n` | N/A | Show what would be done (dry run) | `-n` |
    347 | `-u` | N/A | Include User Friendly names in output | `-u` |
    348 | `-t` | N/A | Write binary values to temp files | `-t` |
    349 | `-T` | N/A | Directory for temp files (use with `-t`) | `-T /tmp` |
    350 | `-F` | N/A | URL prefix for temp files | `-F file:///tmp/` |
    351 | `-M` | N/A | Enable Manage DSA IT control | `-M` |
    352 | `-C` | N/A | Chase referrals | `-C` |
    353 | `-c` | N/A | Continuous operation mode (ignore errors) | `-c` |
    354 
    355 ### Search Scope Values
    356 
    357 | Scope | Description |
    358 |-------|-------------|
    359 | `base` | Search only the base DN itself |
    360 | `one` | Search immediate children of base DN only (one level) |
    361 | `sub` | Search base DN and all descendants (subtree - most common) |
    362 | `children` | Search all descendants but not the base DN itself |
    363 
    364 ### Common Attribute Shortcuts
    365 
    366 | Shortcut | Meaning |
    367 |----------|---------|
    368 | `*` | All regular (non-operational) attributes |
    369 | `+` | All operational attributes |
    370 | `1.1` | No attributes (DN only) |
    371 | `*` `+` | All attributes (regular + operational) |
    372 
    373 ### LDAP URI Format
    374 
    375 | Format | Description |
    376 |--------|-------------|
    377 | `ldap://host` | Standard LDAP on port 389 |
    378 | `ldap://host:port` | LDAP on custom port |
    379 | `ldaps://host` | LDAP over SSL/TLS on port 636 |
    380 | `ldaps://host:port` | LDAPS on custom port |
    381 | `ldapi://` | LDAP over Unix domain socket (local) |
    382 
    383 ### Common Exit Codes
    384 
    385 | Code | Meaning |
    386 |------|---------|
    387 | `0` | Success |
    388 | `1` | Operations error |
    389 | `2` | Protocol error |
    390 | `32` | No such object |
    391 | `49` | Invalid credentials |
    392 | `50` | Insufficient access rights |
    393 
    394 ***
    395 
    396 ## Pro Tips
    397 
    398 1. **Always use `-LLL`** for clean, parseable output
    399 2. **Use `-W`** instead of `-w` to avoid password in shell history
    400 3. **The `info` field** in AD often contains sensitive data
    401 4. **Check group memberships** - Remote Management Users = WinRM access
    402 5. **Operational attributes** (`+`) reveal creation/modification metadata
    403 6. **Use `sub` scope** for comprehensive searches
    404 7. **Combine filters** with `&` (AND) and `|` (OR) for precise queries
    405 8. **Save output** to files for offline analysis with `> output.txt`