← All projects
PROFESSIONAL EXPERIENCE + INDEPENDENT LAB

Spotting reconnaissance
in LDAP activity.

Developed detections to flag unusually high LDAP request volumes and workstation-originated activity associated with potential Active Directory reconnaissance and attack path mapping.

LDAP analysisDetection developmentActive Directory
Read the approach

Volume-based detection. Identify unusually high LDAP request counts within short timeframes to flag potential automated enumeration against domain controllers.

Source and process context. Flag workstation-originated LDAP activity associated with PowerShell, Command Prompt, Python, BloodHound, and SharpHound for further investigation.

DETECTION LOGICLDAP
  1. 01 / OBSERVELDAP activity

    Requests to domain controllers

  2. 02 / CORRELATEVolume + context

    Short timeframes · workstation origin
    Associated tools and processes

  3. 03 / INVESTIGATEPotential reconnaissance

    Flag activity for analyst review

PROJECT APPROACH / CONCEPTUAL WORKFLOW

ORIGINAL PUBLIC LAB / PYTHON STANDARD LIBRARY

Try the detection approach

These scripts were written independently for this portfolio using public telemetry documentation and fictional events. They illustrate the approach described above; they are not the workplace rules, queries, or thresholds.

01 / Observed search bursts

Group normalized LDAP search records by source and domain controller, then flag a threshold crossing within a rolling time window. Duplicate records do not inflate the count.

python detect_query_bursts.py sample-searches.csv --threshold 5 --window-seconds 60

The bundled sample produces one alert: five observed searches from 192.0.2.25 within 60 seconds. A second client stays below the threshold. The threshold of five is for demonstration.

Download search-volume script ↓

02 / Process connection context

Review Sysmon Event 3 XML for selected process names connecting to LDAP or Global Catalog ports on an explicit list of domain-controller IPs.

python detect_sysmon_ldap.py sample-sysmon.xml --dc-ip 192.0.2.10

The sample flags one PowerShell connection. An inventory process and a destination outside the DC list do not match this heuristic. Every alert needs investigation.

Download process-context script ↓

Extract the ZIP, open a terminal in its folder, and run the examples with Python 3.10 or newer. No extra packages are required. Both scripts analyze local files and print JSON; neither queries the network nor changes logging settings.

TELEMETRY & LIMITATIONS

What the evidence supports

Searches and connections are different. Sysmon Event 3 provides process and network connection metadata. It does not count LDAP searches or expose encrypted query contents. Network connection logging must already be enabled in the lab.

Coverage matters. Directory Service Event 1644 uses diagnostic thresholds and does not capture every LDAP request. Normalize validated search records into the CSV schema before using the volume script.

Context matters. PowerShell can perform legitimate administration. Process names can be changed, and host roles need separate verification. These examples do not prove malicious intent, automatically identify workstations, or correlate individual queries with processes.

Validation scope. Synthetic tests cover thresholds, timestamps, duplicates, source separation, malformed input, and connection filtering. They do not establish real-world detection accuracy. See the README for blind spots and investigation steps.

Telemetry references: Microsoft Sysmon documentation and Microsoft Event 1644 guidance.