logo

LDAP Enumeration: Unveiling the Double-Edged Sword of Active Directory

ID: dbcc97d8-ab99-58d9-b5f4-3c883bd250ed

STIX ID: report--dbcc97d8-ab99-58d9-b5f4-3c883bd250ed

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2024-12-17

Date Updated: 2026-04-28

Author: Stav Setty, Shachar Roitman and Tom Fakterman

...
...

This Unit 42 report examines how threat actors — including APT groups and ransomware affiliates — abuse LDAP/Active Directory for reconnaissance and enumeration, documents real-world usages of tools like AdFind, ADRecon, and SharpHound, highlights logging and detection challenges (high-volume benign LDAP noise), and provides practical detection strategies, notable LDAP attributes to monitor, and an XQL query for Cortex XDR to identify suspicious LDAP activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.