{"id":4238,"date":"2021-11-09T04:07:47","date_gmt":"2021-11-09T04:07:47","guid":{"rendered":"https:\/\/www.jameseduard.com\/?p=4238"},"modified":"2021-11-09T04:07:47","modified_gmt":"2021-11-09T04:07:47","slug":"ldap-monitor-monitor-creation-deletion-and-changes-to-ldap-objects","status":"publish","type":"post","link":"https:\/\/www.jameseduard.com\/?p=4238","title":{"rendered":"LDAP Monitor = Monitor creation, deletion and changes to LDAP objects"},"content":{"rendered":"<p>[vc_row][vc_column][vc_column_text]<\/p>\n<h1 dir=\"auto\">LDAP Monitor<\/h1>\n<p dir=\"auto\">Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration!<\/p>\n<p dir=\"auto\">With this tool you can quickly see if your attack worked and if it changed LDAP attributes of the target object.<\/p>\n<p dir=\"auto\"><a href=\"https:\/\/github.com\/p0dalirius\/LDAPmonitor\/blob\/master\/python\/imgs\/example.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img decoding=\"async\" src=\"https:\/\/github.com\/p0dalirius\/LDAPmonitor\/raw\/master\/python\/imgs\/example.png\" alt=\"\" \/><\/a><\/p>\n<h2 dir=\"auto\"><a id=\"user-content-features\" class=\"anchor\" href=\"https:\/\/github.com\/p0dalirius\/LDAPmonitor#features\" aria-hidden=\"true\"><\/a>Features<\/h2>\n<table>\n<thead>\n<tr>\n<th>Feature<\/th>\n<th><a href=\"https:\/\/github.com\/p0dalirius\/LDAPmonitor\/blob\/master\/python\">Python (.py)<\/a><\/th>\n<th><a href=\"https:\/\/github.com\/p0dalirius\/LDAPmonitor\/blob\/master\/csharp\">CSharp (.exe)<\/a><\/th>\n<th><a href=\"https:\/\/github.com\/p0dalirius\/LDAPmonitor\/blob\/master\/powershell\">Powershell (.ps1)<\/a><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>LDAPS support<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<\/tr>\n<tr>\n<td>Random delay in seconds between queries<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<\/tr>\n<tr>\n<td>Custom delay in seconds between queries<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<\/tr>\n<tr>\n<td>Save output to logfile<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<\/tr>\n<tr>\n<td>Colored or not colored output with\u00a0<code>--no-colors<\/code><\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x274c;<\/td>\n<td>&#x274c;<\/td>\n<\/tr>\n<tr>\n<td>Custom page size for paged queries<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<\/tr>\n<tr>\n<td>Authenticate with user and password<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<\/tr>\n<tr>\n<td>Authenticate as current shell user<\/td>\n<td>&#x274c;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<\/tr>\n<tr>\n<td>Authenticate with LM:NT hashes<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x274c;<\/td>\n<td>&#x274c;<\/td>\n<\/tr>\n<tr>\n<td>Authenticate with kerberos tickets<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x274c;<\/td>\n<td>&#x274c;<\/td>\n<\/tr>\n<tr>\n<td>Option to ignore user logon events<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<td>&#x2714;&#xfe0f;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 dir=\"auto\">Demonstration<\/h2>\n<div style=\"width: 640px;\" class=\"wp-video\"><video class=\"wp-video-shortcode\" id=\"video-4238-1\" width=\"640\" height=\"360\" preload=\"metadata\" controls=\"controls\"><source type=\"video\/mp4\" src=\"https:\/\/user-images.githubusercontent.com\/79218792\/136900209-d2156d4c-d83d-4227-b51e-999ec99b2314.mp4?_=1\" \/><a href=\"https:\/\/user-images.githubusercontent.com\/79218792\/136900209-d2156d4c-d83d-4227-b51e-999ec99b2314.mp4\">https:\/\/user-images.githubusercontent.com\/79218792\/136900209-d2156d4c-d83d-4227-b51e-999ec99b2314.mp4<\/a><\/video><\/div>\n<p>&nbsp;<\/p>\n<p><b><a class=\"kiploit-download\" title=\"Download LDAPmonitor\" href=\"https:\/\/github.com\/p0dalirius\/LDAPmonitor\" target=\"_blank\" rel=\"nofollow noopener\">Download LDAPmonitor<\/a><\/b>[\/vc_column_text][\/vc_column][\/vc_row]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[vc_row][vc_column][vc_column_text] LDAP Monitor Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration! With this tool you can quickly see if your attack worked and if it changed LDAP attributes of the target object. Features Feature Python (.py) CSharp (.exe) Powershell (.ps1) LDAPS support &#x2714;&#xfe0f; &#x2714;&#xfe0f; &#x2714;&#xfe0f; Random delay in<\/p>\n","protected":false},"author":1,"featured_media":4239,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9,154,541,620,726],"tags":[823,275,34],"class_list":["post-4238","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-network-security","category-pentesting-tools","category-python","category-security","category-security-assessment-tool","tag-ldap","tag-pentest","tag-security"],"_links":{"self":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/posts\/4238","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4238"}],"version-history":[{"count":0,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/posts\/4238\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}