ldapsearch.exe

by OpenLDAP / Various
System Utilitymedium risk

Sources: 300M+ executions observed in the wild.

Summary

LDAP Search utility. Command-line tool for querying LDAP directories (Active Directory). Used for AD reconnaissance to enumerate users, groups, computers, OUs, and trust relationships.

ldapsearch.exe is the 1651st most commonly executed Windows program in EchoTrail's dataset, observed 528 times across enterprise environments. It typically runs from C:\... and it is most often launched by cmd.exe.

Get this in your tools

The same record for ldapsearch.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/ldapsearch.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

1651st
most commonly executed Windows program
528
observed endpoint executions

Behavior

Top Paths

  • C:\...100%

Top Hashes (SHA256)

  • db85064c9e22add333f3a4326b538a506d52f7de41043836a635e55ce5fe424698.11%
  • 8bf5f235b9491b459c1cf1ee3114bf5602b09b592200216bd81432d20b65906e1.89%

Process Ancestry

Top Parents

Security Analysis

What does ldapsearch.exe normally do?

Not a Windows built-in. Part of OpenLDAP tools or RSAT. Used by AD administrators for directory queries and troubleshooting.

When is ldapsearch.exe suspicious?

Querying sensitive AD attributes (userPassword, unicodePwd, msDS-ManagedPassword). Broad enumeration queries (objectClass=user with no filter). Execution by non-admin users. Running from unusual paths.

How do attackers abuse ldapsearch.exe?

AD RECONNAISSANCE: Attackers use ldapsearch to query Active Directory: - Enumerate all users, groups, and computers - Find privileged accounts and group memberships - Discover service accounts with SPNs (pre-Kerberoasting) - Identify trust relationships - Extract AD schema information

Detection guidance

MEDIUM-CONFIDENCE: - ldapsearch.exe execution on non-admin workstations - Broad LDAP queries (objectClass=*) - Queries targeting sensitive attributes - ldapsearch in combination with other AD recon tools DATA SOURCES: Process creation (Sysmon 1), LDAP query logging (if enabled)

False positive notes

AD administrators and IAM teams use ldapsearch for directory management. Scripts that integrate with AD for user provisioning. SCCM and other management tools may invoke LDAP queries.

MITRE ATT&CK techniques

References

Related Processes

Ask Rocky about ldapsearch.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for ldapsearch.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.