Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration!

License

NotificationsYou must be signed in to change notification settings

p0dalirius/LDAPmonitor

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

58 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration!
GitHub downloadsGitHub release (latest by date)YouTube Channel Subscribers

With this tool you can quickly see if your attack worked and if it changed LDAP attributes of the target object.

Features

FeaturePython (.py)CSharp (.exe)Powershell (.ps1)
LDAPS support✔️✔️✔️
Random delay in seconds between queries✔️✔️✔️
Custom delay in seconds between queries✔️✔️✔️
Save output to logfile✔️✔️✔️
Colored or not colored output with--no-colors✔️
Custom page size for paged queries✔️✔️✔️
Authenticate with user and password✔️✔️✔️
Authenticate as current shell user✔️✔️
Authenticate with LM:NT hashes✔️
Authenticate with kerberos tickets✔️
Option to ignore user logon events✔️✔️✔️
Custom search base✔️✔️✔️
Iterate over all naming contexts✔️✔️✔️

Typical use cases

Here is a few use cases where this tool can be useful:

  • Detect account lockout in real time

  • Check if your privilege escalation worked (with ntlmrelay's--escalate-user option)

  • Detect when users are login in to know when to start a network poisoning.

Cross platform !

Demonstration

ldapmonitor_demo.mp4

Limitations

LDAP paged queries returnspageSize results per page, and it takes approximately 1 second to query a page. Therefore your monitoring refresh rate is(number of LDAP objects // pageSize) seconds. On most domain controllerspageSize = 5000.

Contributing

Pull requests are welcome. Feel free to open an issue if you want to add other features.

About

Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration!

Topics

Resources

License

Stars

Watchers

Forks

Sponsor this project

  •  

Contributors6


[8]ページ先頭

©2009-2025 Movatter.jp