LDAP Enumeration: Unveiling the Double-Edged Sword of Active Directory
ID: dbcc97d8-ab99-58d9-b5f4-3c883bd250ed
STIX ID: report--dbcc97d8-ab99-58d9-b5f4-3c883bd250ed
Feed Name: Palo Alto Networks Unit 42
Date Published: 2024-12-17
Date Updated: 2026-04-28
Author: Stav Setty, Shachar Roitman and Tom Fakterman
This Unit 42 report examines how threat actors — including APT groups and ransomware affiliates — abuse LDAP/Active Directory for reconnaissance and enumeration, documents real-world usages of tools like AdFind, ADRecon, and SharpHound, highlights logging and detection challenges (high-volume benign LDAP noise), and provides practical detection strategies, notable LDAP attributes to monitor, and an XQL query for Cortex XDR to identify suspicious LDAP activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
