Directory Services Scanner
Type: identity-ad
Category: Identity
Access Mode: LDAP
Produces: certificate, public-key, private-key
The Active Directory / ADCS scanner connects to domain controllers via LDAP to discover certificates, certificate templates, SSH keys, and other cryptographic material stored in AD.
What It Discovers
Section titled “What It Discovers”- ADCS-issued certificates across all domains in a forest
- Certificate templates and their security settings
- Domain controller certificates
- User and computer certificates published to AD
- SSH public keys stored in AD attributes
- NGC (Next Generation Credentials) keys
- Trust certificates between forests/domains
- KDS root keys (Group Managed Service Account key material)
- DPAPI backup keys
- Kerberos KRBTGT keys
Configuration
Section titled “Configuration”forests: - name: corp.example.com auth_type: simple username: CN=cbom-scanner,OU=ServiceAccounts,DC=corp,DC=example,DC=com password: scanner-password use_ssl: true domains: - server: dc1.corp.example.com base_dn: DC=corp,DC=example,DC=com port: 636 - server: dc2.child.corp.example.com base_dn: DC=child,DC=corp,DC=example,DC=com port: 636Kerberos Authentication
Section titled “Kerberos Authentication”forests: - name: corp.example.com auth_type: kerberos username: cbom-scanner@CORP.EXAMPLE.COM keytab: /opt/cbom/scanner.keytab use_ssl: true domains: - server: dc1.corp.example.com base_dn: DC=corp,DC=example,DC=comConfig Fields
Section titled “Config Fields”| Field | Type | Required | Default | Description |
|---|---|---|---|---|
forests | object list | Yes | — | AD forests to scan |
forests[].name | string | Yes | — | Forest FQDN |
forests[].auth_type | string | Yes | — | simple (LDAP bind) or kerberos |
forests[].username | string | Yes | — | Bind DN or Kerberos principal |
forests[].password | string | No | — | Password (not needed for keytab) |
forests[].keytab | string | No | — | Path to Kerberos keytab file |
forests[].use_ssl | boolean | No | true | Use LDAPS (port 636) |
forests[].domains | object list | Yes | — | Domains within this forest |
forests[].domains[].server | string | Yes | — | Domain Controller hostname/IP |
forests[].domains[].base_dn | string | Yes | — | LDAP base DN |
forests[].domains[].port | integer | No | 636 | LDAP port |
Permissions Required
Section titled “Permissions Required”The scanner account needs read access to:
- Configuration partition (
CN=Configuration,DC=...) - Domain partitions (user/computer objects with certificate attributes)
- ADCS containers (
CN=Public Key Services,CN=Services,CN=Configuration) - Certificate templates
- NTAuth store
A domain user with “Read” permissions on the relevant OUs is sufficient. No write access or domain admin privileges required.
Multi-Forest Scanning
Section titled “Multi-Forest Scanning”forests: - name: corp.example.com auth_type: simple username: scanner@corp.example.com password: pass1 domains: - server: dc1.corp.example.com base_dn: DC=corp,DC=example,DC=com
- name: partner.example.com auth_type: kerberos username: scanner@PARTNER.EXAMPLE.COM keytab: /opt/cbom/partner.keytab domains: - server: dc1.partner.example.com base_dn: DC=partner,DC=example,DC=com- LDAPS required — Always use
use_ssl: truein production to protect credentials in transit - Service account — Create a dedicated service account with minimal read permissions
- Large forests — Each domain is scanned independently; one unreachable DC won’t stop the rest
- Kerberos — Preferred for environments where LDAP simple bind is restricted by policy
Related
Section titled “Related”- Windows Certificate Store — Scan local cert stores on Windows
- Network Scanners — Scan DC LDAPS endpoints