Spotting reconnaissance
in LDAP activity.
Developed detections to flag unusually high LDAP request volumes and workstation-originated activity associated with potential Active Directory reconnaissance and attack path mapping.
Read the approach
Volume-based detection. Identify unusually high LDAP request counts within short timeframes to flag potential automated enumeration against domain controllers.
Source and process context. Flag workstation-originated LDAP activity associated with PowerShell, Command Prompt, Python, BloodHound, and SharpHound for further investigation.
- 01 / OBSERVELDAP activity
Requests to domain controllers
- 02 / CORRELATEVolume + context
Short timeframes · workstation origin
Associated tools and processes - 03 / INVESTIGATEPotential reconnaissance
Flag activity for analyst review
PROJECT APPROACH / CONCEPTUAL WORKFLOW