Uncovering Adversarial LDAP Tradecraft
ID: ef18715a-7c1a-5e7f-88e6-ca1265174544
STIX ID: report--ef18715a-7c1a-5e7f-88e6-ca1265174544
Feed Name: Binary Defense Blog
This joint TrustedSec and Binary Defense write-up examines adversarial LDAP tradecraft in Active Directory, contrasting normal versus suspicious query patterns (e.g., broad objectClass=* pulls, Kerberoasting, reconnaissance filters), and introduces LDAPMon to collect client-side LDAP telemetry via the Windows-LDAP-Client ETW provider alongside Sysmon. It provides practical detection guidance—baseline SYSTEM/Local Service/Network Service activity, correlate LDAP queries with process lineage and network connections (including C2 via execute-assembly/InlineExecute-Assembly), focus on outliers, and iteratively expand coverage—while warning about ETW tampering (patching EtwEventWrite) that can blind telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
