Skip to content

Add Deleted Objects Collection #194

@sttlr

Description

@sttlr

As it turns out, SharpHound does not collect CN=Deleted Objects.

Manually, it can be viewed using ldapsearch:

ldapsearch -H ldap://<DC_IP> \
  -x -D "[email protected]" -w '<PASSWORD>' \
  -b "CN=Deleted Objects,DC=domain,DC=local" \
  -E 1.2.840.113556.1.4.417 \
  "(sAMAccountName=*)" '*'

NOTE: LDAP_SERVER_SHOW_DELETED OID - 1.2.840.113556.1.4.417 is required.

Ref: https://learn.microsoft.com/en-gb/previous-versions/windows/desktop/ldap/ldap-server-show-deleted-oid

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions