MaLDAPtive: Obfuscation and De-Obfuscation

Daniel Bohannon, Sabajete Elezaj

DEF CON 32 Main Stage · Day 1 · Main Stage

Overview

In the realm of cybersecurity, Active Directory (AD) remains a critical component of enterprise infrastructure, making Lightweight Directory Access Protocol (LDAP) a prime target for both offensive and defensive operations. The talk "MaLDAPtive: Obfuscation and De-Obfuscation" by Daniel Bohannon and Sabajete Elezaj at DEF CON 32 delves into a particularly challenging aspect of this landscape: the sophisticated use of LDAP query obfuscation by attackers and the subsequent difficulties in detecting and de-obfuscating such techniques. The speakers, drawing from extensive experience in threat research, incident response, and detection engineering, highlight a significant gap in current defensive capabilities, specifically the lack of robust, production-ready telemetry for LDAP search filters.

Watch on YouTube

Visual summary for MaLDAPtive: Obfuscation and De-Obfuscation by Daniel Bohannon, Sabajete Elezaj
Visual summary for MaLDAPtive: Obfuscation and De-Obfuscation by Daniel Bohannon, Sabajete Elezaj

Key moments

  1. 0:00 Introduction to Maladaptive: LDAP Obfuscation & Detection
  2. 1:30 Talk agenda: history, LDAP components, obfuscation, solution
  3. 2:06 Brief history of LDAP and Active Directory's role
  4. 3:08 Offensive tools leveraging LDAP/AD for information gathering
  5. 3:57 Challenges in gathering production-ready LDAP search filter telemetry
  6. 4:33 Understanding client-side vs. server-side LDAP log differences
  7. 6:07 Anatomy of an LDAP search request: base, scope, filter, attributes

MaLDAPtive: Obfuscation and De-Obfuscation

Speakers: Daniel Bohannon, Principal Threat Researcher, Permiso Security; Sabajete Elezaj, Senior Cyber Security Engineer, Solaris

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=mKRS5Iyy7Qo

Overview

In the realm of cybersecurity, Active Directory (AD) remains a critical component of enterprise infrastructure, making Lightweight Directory Access Protocol (LDAP) a prime target for both offensive and defensive operations. The talk "MaLDAPtive: Obfuscation and De-Obfuscation" by Daniel Bohannon and Sabajete Elezaj at DEF CON 32 delves into a particularly challenging aspect of this landscape: the sophisticated use of LDAP query obfuscation by attackers and the subsequent difficulties in detecting and de-obfuscating such techniques. The speakers, drawing from extensive experience in threat research, incident response, and detection engineering, highlight a significant gap in current defensive capabilities, specifically the lack of robust, production-ready telemetry for LDAP search filters.

This presentation serves as a deep dive into the historical context and technical anatomy of LDAP search requests, setting the stage for an exploration of advanced obfuscation methods. Bohannon, known for his work on obfuscation, and Elezaj, with a strong background in cyber defense, aim to not only expose the array of techniques attackers can employ to hide their malicious LDAP queries but also to provide tangible solutions for defenders. Their research culminated in the release of a new tool, "Maladaptive," designed to assist in both the obfuscation and, crucially, the de-obfuscation and detection of these evasive queries. The talk underscores the necessity for defenders to gain comprehensive visibility into LDAP traffic to effectively counter modern adversary tactics.

The importance of this research cannot be overstated. As attackers increasingly leverage legitimate protocols and services like LDAP for reconnaissance, privilege escalation, and lateral movement within AD environments, their ability to conceal these actions through obfuscation poses a serious threat. By demystifying LDAP obfuscation and offering practical detection strategies and tools, Bohannon and Elezaj empower security professionals to strengthen their defenses against stealthy and persistent threats that exploit the very backbone of enterprise identity management.

Background

▶ Watch: Introduction to Maladaptive: LDAP Obfuscation & Detection (0:00)

To comprehend the intricacies of LDAP obfuscation, it's essential to first establish a foundational understanding of Active Directory and the LDAP protocol. The speakers initiated their discussion with a historical overview, tracing the origins of directory services back to the Directory Access Protocol (DAP) in the 1980s. LDAP, the "Lightweight Directory Access Protocol," emerged as a more streamlined version, with its first three iterations appearing between 1993 and 1997. A pivotal moment for enterprise IT was the year 2000, when Microsoft released Active Directory, ensuring its compliance with LDAP standards. This made Active Directory the most popular and widely used directory service application globally, hence its central role in the speakers' research.

An LDAP ecosystem fundamentally consists of server-side and client-side components. Active Directory functions as the server, responding to LDAP queries or search filters issued by clients. LDAP itself is the protocol facilitating this exchange of information. On the offensive side, Active Directory and LDAP have long been a fertile ground for attackers seeking to gain information, enumerate users, groups, and permissions, or identify attack paths. The last decade has seen a proliferation of open-source tooling dedicated to this purpose, including well-known frameworks like PowerView from SpecterOps, and the "hound" family of tools such as Bloodhound, Sharphound, and Soaphound. These tools enable rapid reconnaissance and mapping of AD environments, providing attackers with clear pathways to sensitive assets, often culminating in Domain Admin (DA) privileges.

Defenders, in turn, leverage some of these same tools, like Bloodhound and PingCastle, to identify and remediate attack paths. However, a significant challenge highlighted by the speakers is the persistent lack of robust, production-ready telemetry gathering for LDAP search filters. This gap in visibility presents a major frustration for security teams. In their lab environment, the researchers utilized Silk ETW by Ruben Boonen to capture client-side LDAP visibility. Recognizing this broader telemetry deficiency, the Maladaptive project includes a dedicated telemetry module to help organizations configure and gather client-side data. While server-side logging options exist, such as debug modes, they are generally not recommended for production environments due to performance overhead or log verbosity. For comprehensive visibility in production, the speakers noted that Microsoft Windows Defender offers some capabilities, and Crowdstrike also provides some coverage, but obtaining raw, auditable data for validation remains a challenge.

Crucially, the speakers emphasized the substantial differences between client-side and server-side logs regarding LDAP queries. Client-side logs, especially when queries are issued via mechanisms like the AD accelerator in PowerShell which routes requests through wldap32.dll, often provide a "What You See Is What You Get" (Whizzywig) view. This means any obfuscation applied to the query will appear exactly as-is in the ETW stream for the LDAP provider, making client-side logs invaluable for understanding attacker techniques but also a playground for evasion. However, the speakers noted that attackers can bypass client-side logging entirely, citing tools like Soaphound from Falcon Force, which makes direct SOAP requests to domain controllers, circumventing local client-side telemetry. Conversely, server-side logs perform significant normalization of LDAP queries. While this normalization typically strips away much of the obfuscation, the speakers hinted that "some interesting tricks" can still persist, suggesting avenues for advanced evasion even at the server level.

The talk then delved into the anatomy of an LDAP search request as defined by RFC 4511. The four main components are:

  • Base Object: Specifies the starting point within the Active Directory structure for the search.
  • Scope: Defines how deep the search should run from the base object (e.g., base, one-level, subtree).
  • Filter: The logical expression that dictates what to look for within the directory structure. This is the primary target for obfuscation.
  • Attribute Selection: Determines which properties or attributes of the matching objects should be returned.

Understanding these components is critical, as obfuscation techniques can target various parts of the filter string, making detection a complex task. The foundation laid by this background section clearly articulates the problem space: a widely used protocol, extensively targeted by adversaries, suffering from inadequate defensive visibility, and ripe for sophisticated obfuscation.

Key Findings

▶ Watch: Brief history of LDAP and Active Directory's role (2:06)

The primary key finding emphasized by Daniel Bohannon and Sabajete Elezaj, though the specific obfuscation techniques were not detailed in the provided transcript segment, is the critical disparity in how LDAP query obfuscation manifests in client-side versus server-side logs, and the resulting implications for detection. They highlighted that client-side logs, particularly those captured via ETW streams when using standard Windows LDAP APIs like wldap32.dll, often present LDAP search filters in their raw, obfuscated form (a "Whizzywig" view). This is a double-edged sword: it offers defenders a direct look at attacker techniques, but it also means that basic string-matching detections against known malicious patterns are easily bypassed by obfuscation.

Conversely, the speakers pointed out that server-side logs perform significant normalization of LDAP queries. This normalization process typically resolves various obfuscation layers, presenting a "cleaned" version of the filter to the directory service. While this sounds beneficial for detection, it's not a complete panacea. The researchers' work suggests that "some interesting tricks" can still persist even after server-side normalization, implying that not all obfuscation is effectively neutralized at this stage. This finding underscores the need for a multi-layered detection strategy that considers both the client's perspective (for sophisticated obfuscation) and the server's perspective (for residual evasion).

Another crucial finding, which underpins the entire research, is the pervasive lack of production-ready telemetry for LDAP search filters. This visibility gap is a significant impediment for defenders. Without reliable data sources, detecting malicious LDAP activity, whether obfuscated or not, becomes exceedingly difficult. The speakers' frustration on this point directly led to their development of the Maladaptive tool, which includes a telemetry module designed to provide this much-needed client-side visibility. This highlights that a fundamental step towards effective defense against LDAP-based attacks, especially obfuscated ones, is to first ensure comprehensive data collection.

In summary, the key findings revolve around:

  1. Client-side logs reveal raw obfuscation: Excellent for understanding attacker methods but challenging for simple detection rules.
  2. Server-side logs normalize queries, but not perfectly: This simplifies some detection but leaves room for advanced, persistent obfuscation.
  3. Critical telemetry gap: A fundamental lack of readily available, production-grade LDAP search filter logs prevents effective defense.
  4. The necessity of a de-obfuscation solution: Implied by the talk's title and the speakers' goals, a dedicated tool is required to transform obfuscated queries into a detectable format.

These findings collectively paint a picture of a complex defensive landscape where traditional detection methods are insufficient, and specialized tools and improved telemetry are essential to counter modern adversary techniques.

Technical Deep Dive

▶ Watch: Offensive tools leveraging LDAP/AD for information gathering (3:08)

While the provided transcript segment concludes before the detailed technical deep dive into obfuscation techniques, Daniel Bohannon and Sabajete Elezaj explicitly stated their intention to "dive crazy deep into all the obfuscation." Based on the talk title "MaLDAPtive: Obfuscation and De-Obfuscation," and Bohannon's noted "obsession" with taking "things that look normal and making them look just absolutely crazy," this section would undoubtedly cover a wide array of sophisticated methods employed by attackers to conceal their malicious LDAP search filters.

The core of LDAP obfuscation lies in exploiting the parsing rules and error handling mechanisms of LDAP servers, specifically Microsoft's Active Directory. Attackers aim to craft queries that appear benign or nonsensical to human analysts and basic detection rules, while still being correctly interpreted and executed by the directory service. This involves manipulating the filter component of an LDAP search request, as defined in RFC 4511.

Common categories of LDAP obfuscation techniques that would likely be explored in such a deep dive include:

  1. Character Escaping: LDAP filters use special characters (e.g., (, ), =, , &, |, !, <>, >=, <=, ~=) for their syntax. The RFC specifies how these characters, if intended as literal values, must be escaped using a backslash followed by their two-digit hexadecimal ASCII representation (e.g., \2A for ). Attackers can over-escape characters, escape non-special characters, or use alternative encodings to break simple string matching. For example, a filter like (objectClass=user) could be obfuscated as (objectClass=u\73er) or (objectClass=\75ser).
  2. Unicode and UTF-8 Encoding Abuse: LDAP supports Unicode. Attackers might use various Unicode representations of characters, including full-width characters or combining diacritics, that normalize to standard ASCII characters when processed by the server but appear distinct in raw logs. This could involve encoding parts of attribute names or values.
  3. Wildcard Usage: The wildcard is legitimately used in LDAP filters for substring matching (e.g., (cn=admin)). Obfuscation can involve strategic placement of wildcards, or using them in conjunction with escaped characters to break up keywords. For instance, (sAMAccountName=admin*) might become (sAMAccountName=a*d*m*i*n*) or (sAMAccountName=\61dmin*).
  4. Attribute and Value Manipulation:
  • Attribute Name Obfuscation: While attribute names are generally more rigid, attackers might explore case variations (though AD is typically case-insensitive for attribute names), or insert null bytes or non-printable characters that are ignored by the parser but disrupt string matching.
  • Value Obfuscation: The values being searched for (e.g., admin, domain admins) are prime targets. This could involve encoding, character substitution, or breaking values with wildcards.
  1. Filter Structure Obfuscation:
  • Nested Filters: Complex nesting of AND (&), OR (|), and NOT (!) operators can create convoluted filters that are difficult to parse mentally or with simple regex, even if the underlying logic is straightforward.
  • Redundant or Always-True/Always-False Clauses: Adding (|(objectClass=)) or (&(!(objectClass=))) clauses that don't affect the search results but add noise and complexity to the filter string.
  • Whitespace and Comments: While LDAP filters generally don't support comments in the same way programming languages do, creative use of ignored characters or malformed syntax that is gracefully handled by the server could serve a similar purpose.
  1. Schema Extensions and Custom Attributes: Leveraging less common or custom attributes, or even malformed attribute names that the server might still process, to hide intent.

The speakers' mention of the difference between client-side "Whizzywig" logging and server-side "normalization" is key here. Client-side logs, particularly from ETW streams via wldap32.dll, would show the full, raw obfuscated query. This is where techniques like excessive escaping or Unicode abuse would be most evident. The challenge for defenders is to de-obfuscate these strings back to their canonical form for detection. Server-side normalization aims to do this automatically, but the researchers' insight that "some interesting tricks" persist suggests that certain advanced obfuscation methods might not be fully normalized, potentially due to parser quirks, non-standard compliance, or specific AD behaviors.

The "Maladaptive" tool, therefore, would likely incorporate a sophisticated de-obfuscation engine capable of reversing these techniques. This engine would need to understand the nuances of LDAP filter syntax, character escaping, and potentially various encoding schemes to accurately reconstruct the original, intended query. This is crucial for enabling defenders to apply consistent detection rules, regardless of the obfuscation layer. The technical deep dive would not only illustrate these obfuscation methods but also detail the logic and algorithms within Maladaptive that enable its de-obfuscation capabilities, providing a practical framework for analyzing and neutralizing these evasive tactics.

Demo / Proof of Concept

▶ Watch: Understanding client-side vs. server-side LDAP log differences (4:33)

The speakers, Daniel Bohannon and Sabajete Elezaj, explicitly stated their intention to conduct "a demo and a tool release at the end" of their presentation. The tool they developed and released is named Maladaptive. While the specifics of the demo were not included in the provided transcript segment, it can be inferred that the demonstration would showcase the capabilities of Maladaptive in both generating obfuscated LDAP queries and, more importantly, in de-obfuscating and detecting them.

A typical demonstration for such a tool would likely involve the following:

  1. Obfuscation Generation: The speakers would demonstrate Maladaptive's ability to take a standard, easily detectable LDAP search filter (e.g., (sAMAccountName=krbtgt)) and transform it into multiple highly obfuscated variants. This would involve applying the various techniques discussed in the technical deep dive, such as character escaping, wildcard insertion, Unicode manipulation, and filter structure obfuscation. The goal here would be to illustrate how easily a simple query can be made to look "absolutely crazy" in raw form.
  2. Client-Side Telemetry Capture: The demonstration would then likely involve executing these obfuscated queries from a client machine within an Active Directory environment. Using their custom telemetry module (also part of Maladaptive) or Silk ETW, they would show how these obfuscated queries appear in client-side logs. This would visually confirm the "Whizzywig" nature of client-side logging, where the complex, unreadable strings are faithfully recorded.
  3. Server-Side Log Comparison: Following the client-side capture, the demo would likely compare these raw client logs with corresponding server-side logs from the Domain Controller. This would highlight the normalization process on the server, showing how many obfuscation layers are stripped away. Crucially, it would also aim to demonstrate any "interesting tricks" that persist even after server-side normalization, proving that not all evasion is neutralized automatically.
  4. De-Obfuscation with Maladaptive: The core of the demo would then be to feed the captured, obfuscated client-side log entries into Maladaptive's de-obfuscation engine. The tool would then parse these complex strings and output their canonical, de-obfuscated forms. This would vividly illustrate how Maladaptive can reveal the true intent of an attacker's query, making it amenable to standard detection rules.
  5. Detection Engineering Workflow: Finally, the demo might touch upon how defenders can integrate Maladaptive into their detection workflows. This could involve demonstrating how the de-obfuscated queries can then be matched against known malicious patterns or indicators of compromise, thereby enabling the detection of previously stealthy attacks. The telemetry module would be shown as the mechanism to gather the necessary raw data for this process.

The release of Maladaptive as an open-source tool would provide defenders with a practical utility to replicate the research, test their own environments, and integrate its capabilities into their security operations. The demo would serve as a powerful proof of concept, validating the research findings and demonstrating the immediate utility of the developed solution in countering advanced LDAP obfuscation.

Defensive Implications

▶ Watch: Anatomy of an LDAP search request: base, scope, filter, attributes (6:07)

The research presented in "MaLDAPtive" has profound defensive implications, fundamentally altering how security teams should approach the detection and prevention of Active Directory attacks leveraging LDAP. The core message for defenders is clear: traditional, signature-based detection mechanisms that rely on simple string matching against expected LDAP query patterns are inherently vulnerable to the sophisticated obfuscation techniques discussed.

Here are the key defensive implications:

  1. Prioritize LDAP Telemetry: The most immediate and critical implication is the absolute necessity for comprehensive, production-ready telemetry for LDAP search filters. The speakers explicitly highlighted the current deficiency in this area. Defenders must actively seek or implement solutions to capture client-side LDAP queries, ideally at the point of origin before server-side normalization. The Maladaptive telemetry module aims to address this gap, providing a means to collect data from ETW streams associated with the LDAP provider and wldap32.dll. Without this raw data, detecting obfuscated queries is a near-impossible task.
  2. Embrace De-Obfuscation: Given that attackers can render malicious LDAP filters unrecognizable through obfuscation, defenders cannot rely solely on raw log analysis. It is imperative to integrate de-obfuscation capabilities into security pipelines. Tools like Maladaptive, with their ability to parse and normalize obfuscated LDAP filters back to their canonical form, become indispensable. This allows security analysts to apply consistent detection logic and rules against the true intent of a query, rather than its obfuscated presentation.
  3. Shift to Behavioral and Contextual Detections: While de-obfuscation helps, a robust defense also requires moving beyond purely signature-based detections. Defenders should develop behavioral analytics around LDAP activity. This includes monitoring for:
  • Unusual query patterns: Even if de-obfuscated, queries that are highly complex, contain many wildcards, or request an unusual number of attributes could be suspicious.
  • High volume of queries from unusual sources: An attacker performing reconnaissance will often issue a large number of queries.
  • Queries for sensitive attributes/objects: Repeated queries for "krbtgt," "Domain Admins" group members, or password-related attributes warrant high scrutiny.
  • Queries originating from non-standard processes or hosts: Legitimate LDAP queries usually come from specific applications or system processes. Anomalous origins could indicate compromise.
  1. Understand Client vs. Server Log Differences: Defenders must be acutely aware of the distinctions between client-side and server-side LDAP logs.
  • Client-side logs offer the "Whizzywig" view, showing raw obfuscation. This is where advanced de-obfuscation tools are most effective. However, these logs can be bypassed by direct SOAP requests or other non-standard LDAP client implementations (e.g., Soaphound).
  • Server-side logs provide a normalized view, which can catch some threats but may miss advanced, persistent obfuscation. They are also crucial for understanding what the directory service actually processed. A combined approach, correlating data from both sources where possible, offers the most comprehensive picture.
  1. Test and Validate Defenses: The release of Maladaptive as an obfuscation tool also empowers red teams and internal security teams to test their existing detection capabilities. By generating obfuscated queries and attempting to bypass current monitoring, organizations can identify weaknesses in their telemetry, de-obfuscation, and detection rules. This adversarial simulation is vital for continuous improvement of security posture.
  2. Educate Security Teams: Analysts need to be trained on the nuances of LDAP, its common attack patterns, and the various obfuscation techniques. Understanding the underlying protocol, as detailed in RFC 4511, is fundamental to developing effective detection strategies and writing robust rules.

In essence, "MaLDAPtive" calls for a proactive and intelligent approach to defending Active Directory. It mandates improved visibility, the adoption of specialized de-obfuscation tools, and a shift towards more sophisticated behavioral analytics to counter the evolving landscape of LDAP-based attacks.

Key Takeaways

  • LDAP Query Obfuscation is a Significant Threat: Attackers are increasingly using sophisticated techniques to obfuscate LDAP search filters, making malicious reconnaissance and lateral movement within Active Directory environments difficult to detect.
  • Critical Telemetry Gap Exists for LDAP Filters: There is a widespread lack of production-ready, client-side telemetry for LDAP search filters, hindering defenders' ability to gain necessary visibility into potentially malicious activity.
  • Client-Side vs. Server-Side Logs Differ Greatly: Client-side logs often show raw, obfuscated queries ("Whizzywig"), while server-side logs perform normalization. However, some advanced obfuscation can persist even after server-side processing, necessitating a multi-faceted logging strategy.
  • De-Obfuscation Tools are Essential for Detection: Relying on simple string matching against raw logs is insufficient. Defenders need specialized tools like "Maladaptive" to de-obfuscate complex LDAP queries back to their canonical form for effective detection.
  • Proactive Defense Requires Enhanced Visibility and Behavioral Analytics: To counter advanced LDAP threats, organizations must prioritize robust client-side LDAP telemetry, integrate de-obfuscation into their security pipelines, and develop behavioral detection rules that go beyond basic signatures.
  • The Maladaptive Tool Addresses Key Defensive Challenges: The release of Maladaptive, including its telemetry and de-obfuscation modules, provides defenders with practical capabilities to both understand and counter sophisticated LDAP obfuscation techniques.

About the Speaker(s)

Daniel Bohannon (DBO) is a Principal Threat Researcher at Permiso Security, a startup specializing in cloud and identity security. With over a decade of experience, DBO has focused extensively on endpoint security, incident response, and threat research during his tenures at Mandiant and Microsoft. He is particularly passionate about obfuscation, finding satisfaction in transforming normal-looking constructs into "absolutely crazy" forms and then developing detection methods for them as a defender. Beyond his technical pursuits, he enjoys coffee, books, and the conversations they inspire.

Sabajete Elezaj (Sabi) is a Senior Cyber Security Engineer at Solaris, based in Berlin, Germany, originally hailing from Albania. Her professional passion lies in cyber defense, where she actively engages in incident response, detection engineering, and threat hunting when time permits. Sabajete also brings experience from consulting and government roles. Outside of her cybersecurity work, she enjoys mountains (even featuring a goat in her bio), movies, and a great espresso.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Bohannon and Elezaj deliver a much-needed deep dive into LDAP query obfuscation, a critical blind spot for defenders. Their research meticulously dissects how attackers hide in plain sight within Active Directory, highlighting the stark differences between client-side and server-side logging. The release of their 'Maladaptive' tool, with its focus on both obfuscation and crucial de-obfuscation, provides a tangible and immediate solution to a pervasive telemetry gap, making this a highly actionable and impactful technical contribution to modern defense strategies.

Heather Calloway (CISO) — MUST SEE

The talk "MaLDAPtive" by Bohannon and Elezaj delivers a critical assessment of the pervasive lack of LDAP query telemetry in enterprise environments and its exploitation by sophisticated adversaries. By dissecting the anatomy of LDAP obfuscation and releasing a practical de-obfuscation tool, the speakers not only expose a significant blind spot in Active Directory security but also provide a clear, actionable path for security leaders and operators to enhance visibility and strengthen defenses against stealthy, protocol-level attacks. This work is essential for any organization reliant on Active Directory and impacts core institutional accountability.

→ Top-rated talks at DEF CON 32 Main Stage

All talks from DEF CON 32 Main Stage