bloodyAD set restore

Restore a tombstoned object from the AD recycle bin. Useful for resurrecting accounts you accidentally deleted during an engagement, or for recovering objects a defender purged mid-test.

Tool
bloodyAD
Category
Post-Exploitation / AD Object Manipulation
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

bloodyAD --host <dc-ip> -d '<domain>' -u '<user>' -p '<password>' set restore '<deleted-dn>'

Examples

bloodyAD --host 10.10.10.10 -d corp.local -u admin -p 'Password123!' set restore 'CN=svc_app\0ADEL:abcd...,CN=Deleted Objects,DC=corp,DC=local'

Tags

bloodyad recycle-bin restore