LDAPSearch Shadow Principals (PAM Trust)

Enumerate msDS-ShadowPrincipal objects to identify PAM trust shadow principals

Tool
ldapsearch
Category
Privilege Escalation / Trust Attacks
Platform
linux
Requires
Kerberos ticket
Protocols
LDAP, KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

ldapsearch -H ldap://<ip> -Y GSSAPI -b 'CN=Shadow Principal Configuration,CN=Services,CN=Configuration,<dc_dn>' '(objectClass=msDS-ShadowPrincipal)' msDS-ShadowPrincipalSid member name

Examples

ldapsearch -H ldap://192.168.101.1 -Y GSSAPI -b 'CN=Shadow Principal Configuration,CN=Services,CN=Configuration,DC=bastion,DC=local' '(objectClass=msDS-ShadowPrincipal)' msDS-ShadowPrincipalSid member name

Tags

ldapsearch ldap shadow-principal pam-trust trust enumeration