Handbook

LDAP Anon Bind

Updated 29 Sept 2026Services✎ Suggest a change
On this page

LDAP Anonymous Bind

Attack Flow

plain text
Anonymous LDAP query to DC → if permitted, full directory read access
→ Users, groups, computers, policy, trusts, SPNs

Test for Anonymous Bind

bash
ldapsearch -x -H ldap://<dc-ip> -b "DC=<domain>,DC=local"

nxc ldap <dc-ip> -u '' -p ''

Enumerate Users

bash
ldapsearch -x -H ldap://<dc-ip> -b "DC=<domain>,DC=local" "(objectClass=user)" sAMAccountName

# Enabled accounts only
ldapsearch -x -H ldap://<dc-ip> -b "DC=<domain>,DC=local" "(&(objectClass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))" sAMAccountName

# No pre-auth required — AS-REP roasting targets
ldapsearch -x -H ldap://<dc-ip> -b "DC=<domain>,DC=local" "(&(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=4194304))" sAMAccountName

Enumerate Groups

bash
ldapsearch -x -H ldap://<dc-ip> -b "DC=<domain>,DC=local" "(objectClass=group)" cn member

# Domain Admins specifically
ldapsearch -x -H ldap://<dc-ip> -b "DC=<domain>,DC=local" "(&(objectClass=group)(cn=Domain Admins))" member

Enumerate Computers

bash
ldapsearch -x -H ldap://<dc-ip> -b "DC=<domain>,DC=local" "(objectClass=computer)" sAMAccountName operatingSystem

Enumerate Service Accounts (Kerberoasting Targets)

bash
ldapsearch -x -H ldap://<dc-ip> -b "DC=<domain>,DC=local" "(&(objectClass=user)(servicePrincipalName=*))" sAMAccountName servicePrincipalName

Enumerate Password Policy

bash
ldapsearch -x -H ldap://<dc-ip> -b "DC=<domain>,DC=local" "(objectClass=domain)" minPwdLength lockoutThreshold lockoutDuration

Enumerate Domain Trusts

bash
ldapsearch -x -H ldap://<dc-ip> -b "CN=System,DC=<domain>,DC=local" "(objectClass=trustedDomain)" cn trustDirection

What Each Result Tells You

FindingImplication
Anonymous bind succeedsFull unauthenticated AD enumeration possible
Anonymous bind failsLDAP is locked down, move on
Users returnedFeed into spraying, AS-REP roasting, Kerbrute
Accounts with no pre-authImmediate AS-REP roasting targets
Accounts with SPNsKerberoasting targets once low-priv creds obtained
Lockout threshold returnedDetermines spray cadence
Domain trusts presentLateral movement scope to other domains