Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
LDAPmonitor — Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration! | Kitploit
Tools/GitHubGitHub/p0dalirius/ldapmonitor
Penetration Testing
GitHubp0dalirius/ldapmonitor

LDAPmonitor

Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration!

View RepositoryWebsite
944789 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration!
GitHub downloads GitHub release (latest by date) YouTube Channel Subscribers

With this tool you can quickly see if your attack worked and if it changed LDAP attributes of the target object.

Features

FeaturePython (.py)CSharp (.exe)Powershell (.ps1)
LDAPS support✔️✔️✔️
Random delay in seconds between queries✔️✔️✔️
Custom delay in seconds between queries✔️✔️✔️
Save output to logfile✔️✔️✔️
Colored or not colored output with --no-colors✔️❌❌
Custom page size for paged queries✔️✔️✔️
Authenticate with user and password✔️✔️✔️
Authenticate as current shell user❌✔️✔️
Authenticate with LM:NT hashes✔️❌❌
Authenticate with kerberos tickets✔️❌❌
Option to ignore user logon events✔️✔️✔️
Custom search base✔️✔️✔️
Iterate over all naming contexts✔️✔️✔️

Typical use cases

Here is a few use cases where this tool can be useful:

  • Detect account lockout in real time

  • Check if your privilege escalation worked (with ntlmrelay's --escalate-user option)

  • Detect when users are login in to know when to start a network poisoning.

Cross platform !

In Python (.py)

In CSharp (.exe)

In Powershell (.ps1)

Demonstration

https://user-images.githubusercontent.com/79218792/136900209-d2156d4c-d83d-4227-b51e-999ec99b2314.mp4

Limitations

LDAP paged queries returns pageSize results per page, and it takes approximately 1 second to query a page. Therefore your monitoring refresh rate is (number of LDAP objects // pageSize) seconds. On most domain controllers pageSize = 5000.

Contributing

Pull requests are welcome. Feel free to open an issue if you want to add other features.

Download Tool