Daniel Bohannon & Sabajete Elezaj: MaLDAPtive — LDAP Obfuscation and De-Obfuscation
A DEF CON 32 talk on how attackers can hide malicious LDAP queries targeting Active Directory.
The researchers demonstrate dozens of obfuscation techniques that can bypass simple signature-based detection systems. They introduce MaLDAPtive — a framework for obfuscating, de-obfuscating, and analyzing LDAP queries.
The talk shows how attacks on Active Directory can be concealed within complex LDAP queries and how defenders can better detect these techniques.
The researchers demonstrate dozens of obfuscation techniques that can bypass simple signature-based detection systems. They introduce MaLDAPtive — a framework for obfuscating, de-obfuscating, and analyzing LDAP queries.
The talk shows how attacks on Active Directory can be concealed within complex LDAP queries and how defenders can better detect these techniques.