Directory

A directory service stores and serves the identities, credentials, and authorization data an organization runs on. Compromising it is rarely about a single bug; it is about abusing the service's own features, protocols, and object permissions to move from a low-privileged foothold to control of the identity store, and with it the entire estate that trusts it.

This area splits by the directory product, because the attack surface is product-specific:

  • Active Directory, the Windows directory and its authentication ecosystem (Kerberos, NTLM, LDAP, AD CS). This is the dominant target in enterprise networks and the larger of the two subtrees.
  • LDAP, the generic directory protocol as it appears on non-Windows directories (OpenLDAP, 389 Directory Server, and others) and as the LDAP layer that AD itself exposes.

Scope and seams#

Directory attacks sit at the service layer: you are attacking the directory as a running service and data store, not an application's query handling. Application-layer LDAP injection (user input concatenated into an LDAP filter in web code) is a different class and lives under web code injection; this area cross-references it rather than repeating it.

Several named attacks that pass through a domain actually target separate products, so they live in their own server areas and are cross-referenced from Active Directory: the Netlogon protocol, the Print Spooler service, Exchange, and configuration-management platforms such as SCCM.

Sections#

  • Active Directory: enumeration, authentication and credential abuse, DACL abuse, Group Policy, trusts, and persistence.
  • LDAP: anonymous and authenticated enumeration, credentials exposed in attributes, and signing and channel-binding weaknesses.

References#

  • The Hacker Recipes: Active Directory
  • PortSwigger / OWASP WSTG: Identity and authentication testing

Cookie Consent

We use cookies to enhance your experience. Learn more