// the find
sp4r1ng/PhantomLDAP
Advanced OpSec-Safe Active Directory Enumeration BOF Suite
PhantomLDAP is a set of eight Cobalt Strike BOFs in C for enumerating Active Directory from a Beacon: SPNs for Kerberoasting, AS-REP targets, admin accounts, computers, trusts, GPOs, DACL analysis, and raw LDAP queries. It is aimed at authorized red team and pentest work, and at defenders who want to see what this kind of enumeration looks like in logs and network traffic.
- The ACL module parses the self-relative SECURITY_DESCRIPTOR directly into its DACL and ACE chain, then classifies extended rights by GUID (DS-Replication-Get-Changes-All for DCSync, ForceChangePassword, WriteDACL). Most tools push this step to offline processing, so doing it in-process is the most useful part of the repo.
- Paging uses RFC 2696 simple paged results with 500-object blocks, and each page is freed before the next request. That is the right default for a loader running inside another process, since it avoids one large result set.
- The repo ships a Makefile, per-module .o outputs, a CI workflow, unit tests for the hash and PEB-walk code, and Sigma rules and Event ID notes in docs/detection. Offensive repos rarely include the detection side, and it is useful for anyone writing rules against this tooling.
- The stealth claims in the README (no IAT entries, no CLR, low ETW footprint) appear only as assertions in a comparison table. CI cross-compiles and runs nm on the symbols; nothing in the repo tests behavior against a real domain controller, so the OpSec story is untested.
- The 'zero-import' check greps only for __imp_ldap, which cannot show the module has no other imports, and the sample output in the README is illustrative rather than captured from a lab run.
- This is a 1.0.0 release from a single maintainer with one star and no outside contributors, and it targets Cobalt Strike 4.x only. The dynamic PEB-walk and DJB2 resolution are established techniques, so the value is in packaging them across eight modules, and that packaging has not been exercised by anyone else yet.