Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
ldeep — In-depth ldap enumeration utility | Kitploit
Strumenti/GitHubGitHub/franc-pentest/ldeep
Authentication & AuthorizationReconnaissanceConfiguration AuditingInformation GatheringPenetration TestingIdentity & Access Management (IAM)DNS Analysis
GitHubfranc-pentest/ldeep

ldeep

In-depth ldap enumeration utility

Vedi Repository
598671 mese faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Stato del progetto

.. image:: https://github.com/franc-pentest/ldeep/actions/workflows/python-test.yml/badge.svg :target: https://github.com/franc-pentest/ldeep/actions/workflows/python-test.yml :alt: Build status .. image:: https://badgen.net/pypi/v/ldeep :target: https://pypi.org/project/ldeep/ :alt: PyPi version .. image:: https://img.shields.io/pypi/dm/ldeep.svg :alt: Download rate :target: https://pypi.org/project/ldeep/

============ Installazione

Per usare Kerberos, ldeep deve compilare estensioni native e potrebbero essere necessari alcuni header:

Debian::

sudo apt-get install -y libkrb5-dev krb5-config gcc python3-dev

ArchLinux::

sudo pacman -S krb5


Installare da pypi (ultima versione rilasciata)

::

python -m pip install ldeep


Installare da GitHub (stato attuale del ramo master)

::

python -m pip install git+https://github.com/franc-pentest/ldeep

=========== Sviluppo

Clona il progetto e installa il sistema di build backend pdm::

python -m pip install pdm git clone https://github.com/franc-pentest/ldeep && cd ldeep


Installare una versione isolata

Clona e installa le dipendenze::

pdm install

Esegui localmente::

pdm run ldeep


Installare il pacchetto nel tuo sistema

::

python -m pip install .


Generare le distribuzioni source e wheel

::

python -m build

===== ldeep

L'aiuto è autoesplicativo. Diamo un'occhiata::

$ ldeep -h usage: ldeep [-h] [--version] [-o OUTFILE] [--security_desc] {ldap,cache} ...

options: -h, --help show this help message and exit --version show program's version number and exit -o OUTFILE, --outfile OUTFILE Store the results in a file --security_desc Enable the retrieval of security descriptors in ldeep results

Mode: Available modes

root@kitploit:~
{ldap,cache}          Backend engine to retrieve data

ldeep può essere eseguito sia contro un server LDAP di Active Directory sia localmente su file salvati::

$ ldeep ldap -u Administrator -p 'password' -d winlab -s ldap://10.0.0.1 all backup/winlab [+] Retrieving auth_policies output [+] Retrieving auth_policies verbose output [+] Retrieving bitlockerkeys output [+] Retrieving bitlockerkeys verbose output [+] Retrieving computers output [+] Retrieving conf output [+] Retrieving delegations output [+] Retrieving delegations verbose output [+] Retrieving delegations verbose output [+] Retrieving delegations verbose output [+] Retrieving delegations verbose output [+] Retrieving dns_records output [+] Domain records: [+] Forest records: [+] Legacy records: [+] Retrieving dns_records verbose output [+] Retrieving domain_policy output [+] Retrieving domain_policy verbose output [+] Retrieving fsmo output [+] Retrieving fsmo verbose output [+] Retrieving fsp output [+] Retrieving fsp verbose output [+] Retrieving gmsa output [+] Retrieving gmsa verbose output [+] Retrieving gpo output [+] Retrieving gpo verbose output [+] Retrieving groups output [+] Retrieving groups verbose output [+] Retrieving machines output [+] Retrieving machines verbose output [+] Retrieving ou output [+] Retrieving ou verbose output [+] Retrieving pkis output [+] Retrieving pkis verbose output [+] Retrieving pso output [+] Retrieving sccm output [!] invalid attribute type mSSMSDefaultMP. Can't find SCCM management points [+] Retrieving sccm verbose output [!] invalid class in objectClass attribute: mssmsmanagementpoint. Can't find SCCM management points [+] Retrieving schema output [+] Retrieving server_info output [+] Retrieving server_info verbose output [+] Retrieving shadow_principals output [+] Retrieving shadow_principals verbose output [+] Retrieving silos output [+] Retrieving silos verbose output [+] Retrieving smsa output [+] Retrieving smsa verbose output [+] Retrieving subnets output [+] Retrieving subnets verbose output [+] Retrieving trusts output [+] Retrieving trusts verbose output [+] Retrieving users output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving zones output [+] Domain zones: [+] Forest zones: [+] Retrieving zones verbose output

$ ldeep cache -d backup -p winlab users Administrator [...]

Queste due modalità hanno opzioni differenti:


LDAP

::

root@kitploit:~
$ ldeep ldap -h
usage: ldeep - 1.0.80 ldap [-h] -d DOMAIN -s LDAPSERVER [-b BASE] [-t {ntlm,simple}] [--throttle THROTTLE] [--page_size PAGE_SIZE] [-n] [-u USERNAME] [-p PASSWORD] [-H NTLM] [-k] [--pfx-file PFX_FILE]
                           [--pfx-pass PFX_PASS] [--cert-pem CERT_PEM] [--key-pem KEY_PEM] [-a]
                           {auth_policies,bitlockerkeys,computers,conf,delegations,domain_policy,fsmo,gmsa,gpo,groups,machines,ou,pkis,pso,sccm,shadow_principals,silos,smsa,subnets,templates,trusts,users,zones,from_guid,from_sid,laps,memberships,membersof,object,sddl,silo,zone,all,enum_users,search,whoami,add_to_group,change_uac,create_computer,create_user,modify_password,remove_from_group,unlock}
                           ...

LDAP mode

options:
  -h, --help            show this help message and exit
  -d DOMAIN, --domain DOMAIN
                        The domain as NetBIOS or FQDN
  -s LDAPSERVER, --ldapserver LDAPSERVER
                        The LDAP path (ex : ldap://corp.contoso.com:389)
  -b BASE, --base BASE  LDAP base for query (by default, this value is pulled from remote Ldap)
  -t {ntlm,simple}, --type {ntlm,simple}
                        Authentication type: ntlm (default) or simple. Simple bind will always be in cleartext with ldap (not ldaps)
  --throttle THROTTLE   Add a throttle between queries to sneak under detection thresholds (in seconds between queries: argument to the sleep function)
  --page_size PAGE_SIZE
                        Configure the page size used by the engine to query the LDAP server (default: 1000)
  -n, --no-encryption   Encrypt the communication or not (default: encrypted, except with simple bind and ldap)

NTLM authentication:
  -u USERNAME, --username USERNAME
                        The username
  -p PASSWORD, --password PASSWORD
                        The password used for the authentication
  -H NTLM, --ntlm NTLM  NTLM hashes, format is LMHASH:NTHASH

Kerberos authentication:
  -k, --kerberos        For Kerberos authentication, ticket file should be pointed by $KRB5NAME env variable

Certificate authentication:
  --pfx-file PFX_FILE   PFX file
  --pfx-pass PFX_PASS   PFX password
  --cert-pem CERT_PEM   User certificate
  --key-pem KEY_PEM     User private key

Anonymous authentication:
  -a, --anonymous       Perform anonymous binds

commands:
  available commands

  {auth_policies,bitlockerkeys,computers,conf,delegations,dns_records,domain_policy,fsmo,fsp,gmsa,gpo,groups,machines,ou,pkis,pso,sccm,schema,server_info,shadow_principals,silos,smsa,subnets,trusts,users,zones,from_guid,from_sid,laps,memberships,membersof,object,sddl,silo,zone,all,enum_users,search,whoami,add_to_group,change_uac,create_computer,create_user,modify_password,remove_from_group,unlock}
    auth_policies       List the authentication policies configured in the Active Directory.
    bitlockerkeys       Extract the bitlocker recovery keys.
    computers           List the computer hostnames and resolve them if --resolve is specify.
    conf                Dump the configuration partition of the Active Directory.
    delegations         List accounts configured for any kind of delegation.
    dns_records         List the DNS records configured in the Active Directory.
    domain_policy       Return the domain policy.
    fsmo                List FSMO roles.
    fsp                 List the Foreign Security Principals.
    gmsa                List the gmsa accounts and retrieve secrets(NT + kerberos keys) if possible.
    gpo                 Return the list of Group policy objects.
    groups              List the groups.
    machines            List the machine accounts.
    ou                  Return the list of organizational units with linked GPO.
    pkis                List pkis.
    pso                 List the Password Settings Objects.
    sccm                List servers related to SCCM infrastructure (Primary/Secondary Sites and Distribution Points).
    schema              Dump the schema partition of the Active Directory.
    server_info         List server info.
    shadow_principals   List the shadow principals and the groups associated with.
    silos               List the silos configured in the Active Directory.
    smsa                List the smsa accounts and the machines they are associated with.
    subnets             List sites and associated subnets.
    trusts              List the domain's trust relationships.
    users               List users according to a filter.
    zones               List the DNS zones configured in the Active Directory.
    from_guid           Return the object associated with the given `guid`.
    from_sid            Return the object associated with the given `sid`.
    laps                Return the LAPS passwords. If a target is specified, only retrieve the LAPS password for this one.
    memberships         List the groups to which `object` belongs.
    membersof           List the members of `group`.
    object              Return the records containing `object` in a CN.
    sddl                Returns the SDDL of an object given it's CN.
    silo                Get information about a specific `silo`.
    zone                Return the records of a DNS zone.
    all                 Collect and store computers, domain_policy, zones, gpo, groups, ou, users, trusts, pso information
    enum_users          Anonymously enumerate enabled users with LDAP pings.
    search              Query the LDAP with `filter` and retrieve ALL or `attributes` if specified.
    whoami              Return user identity.
    add_to_group        Add `user` to `group`.
    change_uac          Change user account control
    create_computer     Create a computer account
    create_user         Create a user account
    modify_password     Change `user`'s password.
    remove_from_fsp     Remove `SID` from FSP.
    remove_from_group   Remove `user` from `group`.
    unlock              Unlock `user`.

CACHE

::

root@kitploit:~
$ ldeep cache -h
usage: ldeep cache [-h] [-d DIR] -p PREFIX
                   {auth_policies,bitlockerkeys,computers,conf,delegations,domain_policy,fsmo,gmsa,gpo,groups,machines,ou,pkis,pso,sccm,shadow_principals,silos,smsa,subnets,trusts,users,zones,from_guid,from_sid,laps,memberships,membersof,object,sddl,silo,zone}
                   ...

Cache mode

options:
  -h, --help            show this help message and exit
  -d DIR, --dir DIR     Use saved JSON files in specified directory as cache
  -p PREFIX, --prefix PREFIX
                        Prefix of ldeep saved files

commands:
  available commands

  {auth_policies,bitlockerkeys,computers,conf,delegations,dns_records,domain_policy,fsmo,fsp,gmsa,gpo,groups,machines,ou,pkis,pso,sccm,schema,server_info,shadow_principals,silos,smsa,subnets,trusts,users,zones,from_guid,from_sid,laps,memberships,membersof,object,sddl,silo,zone}
    auth_policies       List the authentication policies configured in the Active Directory.
    bitlockerkeys       Extract the bitlocker recovery keys.
    computers           List the computer hostnames and resolve them if --resolve is specify.
    conf                Dump the configuration partition of the Active Directory.
    delegations         List accounts configured for any kind of delegation.
    dns_records         List the DNS records configured in the Active Directory.
    domain_policy       Return the domain policy.
    fsmo                List FSMO roles.
    fsp                 List the Foreign Security Principals.
    gmsa                List the gmsa accounts and retrieve secrets(NT + kerberos keys) if possible.
    gpo                 Return the list of Group policy objects.
    groups              List the groups.
    machines            List the machine accounts.
    ou                  Return the list of organizational units with linked GPO.
    pkis                List pkis.
    pso                 List the Password Settings Objects.
    sccm                List servers related to SCCM infrastructure (Primary/Secondary Sites and Distribution Points).
    schema              Dump the schema partition of the Active Directory.
    server_info         List server info.
    shadow_principals   List the shadow principals and the groups associated with.
    silos               List the silos configured in the Active Directory.
    smsa                List the smsa accounts and the machines they are associated with.
    subnets             List sites and associated subnets.
    trusts              List the domain's trust relationships.
    users               List users according to a filter.
    zones               List the DNS zones configured in the Active Directory.
    from_guid           Return the object associated with the given `guid`.
    from_sid            Return the object associated with the given `sid`.
    laps                Return the LAPS passwords. If a target is specified, only retrieve the LAPS password for this one.
    memberships         List the groups to which `object` belongs.
    membersof           List the members of `group`.
    object              Return the records containing `object` in a CN.
    sddl                Returns the SDDL of an object given it's CN.
    silo                Get information about a specific `silo`.
    zone                Return the records of a DNS zone.

============== Esempi di utilizzo

Elencare gli utenti senza verbosità::

root@kitploit:~
$ ldeep ldap -u Administrator -p 'password' -d winlab.local -s ldap://10.0.0.1 users
userspn2
userspn1
gobobo
test
krbtgt
DefaultAccount
Guest
Administrator

Elencare gli utenti con crittografia password reversibile abilitata e con verbosità::

root@kitploit:~
$ ldeep ldap -u Administrator -p 'password' -d winlab.local -s ldap://10.0.0.1 users reversible -v
[
  {
    "accountExpires": "9999-12-31T23:59:59.999999",
    "badPasswordTime": "1601-01-01T00:00:00+00:00",
    "badPwdCount": 0,
    "cn": "User SPN1",
    "codePage": 0,
    "countryCode": 0,
    "dSCorePropagationData": [
      "1601-01-01T00:00:00+00:00"
    ],
    "displayName": "User SPN1",
    "distinguishedName": "CN=User SPN1,CN=Users,DC=winlab,DC=local",
    "dn": "CN=User SPN1,CN=Users,DC=winlab,DC=local",
    "givenName": "User",
    "instanceType": 4,
    "lastLogoff": "1601-01-01T00:00:00+00:00",
    "lastLogon": "1601-01-01T00:00:00+00:00",
    "logonCount": 0,
    "msDS-SupportedEncryptionTypes": 0,
    "name": "User SPN1",
    "objectCategory": "CN=Person,CN=Schema,CN=Configuration,DC=winlab,DC=local",
    "objectClass": [
      "top",
      "person",
      "organizationalPerson",
      "user"
    ],
    "objectGUID": "{593cb08f-3cc5-431a-b3d7-9fbad4511b1e}",
    "objectSid": "S-1-5-21-3640577749-2924176383-3866485758-1112",
    "primaryGroupID": 513,
    "pwdLastSet": "2018-10-13T12:19:30.099674+00:00",
    "sAMAccountName": "userspn1",
    "sAMAccountType": "SAM_GROUP_OBJECT | SAM_NON_SECURITY_GROUP_OBJECT | SAM_ALIAS_OBJECT | SAM_NON_SECURITY_ALIAS_OBJECT | SAM_USER_OBJECT | SAM_NORMAL_USER_ACCOUNT | SAM_MACHINE_ACCOUNT | SAM_TRUST_ACCOUNT | SAM_ACCOUNT_TYPE_MAX",
    "servicePrincipalName": [
      "HOST/blah"
    ],
    "sn": "SPN1",
    "uSNChanged": 115207,
    "uSNCreated": 24598,
    "userAccountControl": "ENCRYPTED_TEXT_PWD_ALLOWED | NORMAL_ACCOUNT | DONT_REQ_PREAUTH",
    "userPrincipalName": "[email protected]",
    "whenChanged": "2018-10-22T18:04:43+00:00",
    "whenCreated": "2018-10-13T12:19:30+00:00"
  }
]

Elencare le GPO::

root@kitploit:~
$ ldeep -u Administrator -p 'password' -d winlab.local -s ldap://10.0.0.1 gpo
{6AC1786C-016F-11D2-945F-00C04fB984F9}: Default Domain Controllers Policy
{31B2F340-016D-11D2-945F-00C04FB984F9}: Default Domain Policy

Ottenere tutto::

root@kitploit:~
$ ldeep ldap -u Administrator -p 'password' -d winlab.local -s ldap://10.0.0.1 all /tmp/winlab.local_dump
[+] Retrieving computers output
[+] Retrieving domain_policy output
[+] Retrieving gpo output
[+] Retrieving groups output
[+] Retrieving groups verbose output
[+] Retrieving ou output
[+] Retrieving pso output
[+] Retrieving trusts output
[+] Retrieving users output
[+] Retrieving users verbose output
[+] Retrieving zones output
[+] Retrieving zones verbose output

Utilizzando quest'ultima opzione da riga di comando, l'output viene salvato in modo persistente sia in modalità verbose che non verbose::

root@kitploit:~
$ ls winlab.local_dump_*
winlab.local_dump_computers.lst      winlab.local_dump_groups.json  winlab.local_dump_pso.lst     winlab.local_dump_users.lst
winlab.local_dump_domain_policy.lst  winlab.local_dump_groups.lst   winlab.local_dump_trusts.lst  winlab.local_dump_zones.json
winlab.local_dump_gpo.lst            winlab.local_dump_ou.lst       winlab.local_dump_users.json  winlab.local_dump_zones.lst

La modalità cache può essere utilizzata per interrogare altre informazioni.


Uso con la configurazione Kerberos

Per Kerberos, dovrai anche configurare il file /etc/krb5.conf.::

[realms] CORP.LOCAL = { kdc = DC01.CORP.LOCAL }

======== Prossimamente

  • Enumerazione ADCS
  • Albero del progetto
  • Altre idee?

================ Progetti correlati

  • https://github.com/fortra/impacket
  • https://github.com/ropnop/windapsearch
  • https://github.com/shellster/LDAPPER
Scarica lo strumento