{"id":13845341,"url":"https://github.com/PShlyundin/ldap_shell","last_synced_at":"2025-07-12T02:30:40.192Z","repository":{"id":44869524,"uuid":"393331763","full_name":"PShlyundin/ldap_shell","owner":"PShlyundin","description":"AD ACL abuse ","archived":false,"fork":false,"pushed_at":"2024-07-14T16:33:10.000Z","size":242,"stargazers_count":257,"open_issues_count":0,"forks_count":38,"subscribers_count":5,"default_branch":"main","last_synced_at":"2024-11-06T22:38:14.045Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/PShlyundin.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-08-06T09:48:47.000Z","updated_at":"2024-11-03T20:01:46.000Z","dependencies_parsed_at":"2023-01-21T04:18:33.936Z","dependency_job_id":"690fb4a6-de9f-4f52-b202-6d31435f3747","html_url":"https://github.com/PShlyundin/ldap_shell","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/PShlyundin%2Fldap_shell","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/PShlyundin%2Fldap_shell/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/PShlyundin%2Fldap_shell/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/PShlyundin%2Fldap_shell/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/PShlyundin","download_url":"https://codeload.github.com/PShlyundin/ldap_shell/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225784421,"owners_count":17523643,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:03:20.989Z","updated_at":"2025-07-12T02:30:40.153Z","avatar_url":"https://github.com/PShlyundin.png","language":"Python","funding_links":[],"categories":["Python"],"sub_categories":[],"readme":"# LDAP shell\nThis project is a fork of ldap_shell from Impacket. It provides an interactive shell for Active Directory enumeration and manipulation via LDAP/LDAPS protocols, making it useful for both system administrators and security professionals.\n\n\n## Installation\nThese tools are only compatible with Python 3.5+. Clone the repository from GitHub, install the dependencies and you should be good to go.\nInstallation with pip:\n```bash\ngit clone https://github.com/PShlyundin/ldap_shell.git\ncd ldap_shell\npython3 -m pip install .\n```\n\nInstallation with uv:\n```bash\nuv venv\nuv pip install .\n```\n\n## Usage\n### Connection options\n```bash\n# Basic authentication with password\nldap_shell domain.local/user:password\n\n# Specify domain controller IP address\nldap_shell domain.local/user:password -dc-ip 192.168.1.2\n\n# Authentication using NTLM hashes\nldap_shell domain.local/user -hashes aad3b435b51404eeaad3b435b51404ee:aad3b435b51404eeaad3b435b51404e1\n\n# Kerberos authentication using TGT\nexport KRB5CCNAME=/home/user/ticket.ccache\nldap_shell -k -no-pass domain.local/user\n```\n### Functionality\n```\nGet Info\n    dump [output_dir] - Dumps the domain\n    get_group_users group - Get all users in a group\n    get_laps_gmsa [target] - Retrieves LAPS and GMSA passwords associated with a given account (sAMAccountName) or for all. Supported LAPS 2.0\n    get_maq [user] - Get Machine Account Quota and allowed users\n    get_user_groups user - Retrieves all groups recursively this user is a member of\n    search ldap_filter [attributes] - Search AD objects\n\nAbuse ACL\n    add_user_to_group user group - Add a user to a group\n    change_password user [password] - Attempt to change a given user's password. Requires LDAPS.\n    clear_rbcd target [grantee] - Clear RBCD permissions for a target computer\n    dacl_modify target grantee action mask - Modify DACL entries for target object\n    del_dcsync target - Remove DCSync rights from user/computer by deleting ACEs in domain DACL\n    del_user_from_group user group - Delete a user from a group\n    get_ntlm target - Get NTLM hash using Shadow Credentials attack (requires write access to msDS-KeyCredentialLink)\n    set_dcsync target - If you have write access to the domain object, assign the DS-Replication right to the selected user\n    set_dontreqpreauth target flag - Targeted AsRepRoast attack. Set or unset DONT_REQUIRE_PREAUTH flag for a target user.\n    set_genericall target [grantee] - Set GenericAll permissions for a target object\n    set_owner target [grantee] - Set new owner for target object\n    set_rbcd target grantee - Configure RBCD permissions for a target computer\n    set_spn target action [spn] - List, add or delete SPN for a target object\n\nMisc\n    add_computer computer_name [password] [target_dn] - Add a new computer account to the domain\n    add_group group_name [target_dn] - Add new group to Active Directory\n    add_user username [password] [target_dn] - Add a new user account to the domain\n    del_computer computer_name - Delete a computer account from the domain\n    del_group group_name - Delete group from Active Directory\n    del_user username - Delete a user account from the domain\n    disable_account username - Disable a user account in the domain\n    enable_account username - Enable a user account in the domain\n    start_tls  - Start TLS connection with LDAP server\n    switch_user username [password] - Switch current user to another\n\nOther\n    help [command] - Show help\nexit - exit from shell\n```\n\n## License\nApache License 2.0\n\n## Authors\n* [Riocool](https://t.me/riocool)\n* My [Telegram channel](https://t.me/RedTeambro)\n\n## Credits\n* [Impacket](https://github.com/SecureAuthCorp/impacket)\n* [saber-nyan](https://saber-nyan.com)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FPShlyundin%2Fldap_shell","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FPShlyundin%2Fldap_shell","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FPShlyundin%2Fldap_shell/lists"}