finds.dev← search

// the find

sp4r1ng/PhantomLDAP

★ 1 · C · NOASSERTION · updated Jun 2026

Advanced OpSec-Safe Active Directory Enumeration BOF Suite

PhantomLDAP is a set of eight Cobalt Strike BOFs in C for enumerating Active Directory from a Beacon: SPNs for Kerberoasting, AS-REP targets, admin accounts, computers, trusts, GPOs, DACL analysis, and raw LDAP queries. It is aimed at authorized red team and pentest work, and at defenders who want to see what this kind of enumeration looks like in logs and network traffic.

- The ACL module parses the self-relative SECURITY_DESCRIPTOR directly into its DACL and ACE chain, then classifies extended rights by GUID (DS-Replication-Get-Changes-All for DCSync, ForceChangePassword, WriteDACL). Most tools push this step to offline processing, so doing it in-process is the most useful part of the repo.

- Paging uses RFC 2696 simple paged results with 500-object blocks, and each page is freed before the next request. That is the right default for a loader running inside another process, since it avoids one large result set.

- The repo ships a Makefile, per-module .o outputs, a CI workflow, unit tests for the hash and PEB-walk code, and Sigma rules and Event ID notes in docs/detection. Offensive repos rarely include the detection side, and it is useful for anyone writing rules against this tooling.

- The stealth claims in the README (no IAT entries, no CLR, low ETW footprint) appear only as assertions in a comparison table. CI cross-compiles and runs nm on the symbols; nothing in the repo tests behavior against a real domain controller, so the OpSec story is untested.

- The 'zero-import' check greps only for __imp_ldap, which cannot show the module has no other imports, and the sample output in the README is illustrative rather than captured from a lab run.

- This is a 1.0.0 release from a single maintainer with one star and no outside contributors, and it targets Cobalt Strike 4.x only. The dynamic PEB-walk and DJB2 resolution are established techniques, so the value is in packaging them across eight modules, and that packaging has not been exercised by anyone else yet.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →