logo

The OID Problem: Writing LDAP Detections That Actually Work

ID: 07ddbf32-2d15-59ba-9d1a-5dd1415cf09f

STIX ID: report--07ddbf32-2d15-59ba-9d1a-5dd1415cf09f

Feed Name: Huntress Blog

Date Published: 2025-12-16

Date Updated: 2026-04-28

...
...

This post details a systematic detection-engineering approach for Active Directory LDAP reconnaissance: analyze attacker source (Impacket), emulate in a lab to generate real telemetry, inspect Event 1644 logs to discover Microsoft’s OID-to-bitwise transformation (e.g., 1.2.840.113556.1.4.803 -> &), and build/validate Sigma-style rules (with examples) that target the logged bitwise syntax and attribute combinations to reliably detect reconnaissance behaviors like user/computer enumeration, Kerberoasting prep, DCSync prep, and delegation discovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.