What it does. Hardens LDAP directory services against credential harvesting, LDAP Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill configuring-ldap-security-hardening, or copy the skill folder into ~/.claude/skills/configuring-ldap-security-hardening/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/configuring-ldap-security-hardening/SKILL.md
SKILL.md (verbatim)
name: configuring-ldap-security-hardening
description: Hardens LDAP directory services against credential harvesting, LDAP
injection, anonymous binding, and channel-binding bypass by enforcing LDAPS, channel
binding, and LDAP signing. Use when securing an LDAP or Active Directory environment
against these attack classes or auditing directory service configurations for
these vulnerabilities.
domain: cybersecurity
subdomain: identity-access-management
tags:
- iam
- identity
- access-control
- ldap
- directory-services
- hardening
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.AA-01
- PR.AA-02
- PR.AA-05
- PR.AA-06
mitre_attack:
- T1087.002
- T1110.003
- T1557.001
- T1040
- T1078.002
mitre_f3:
version: '1.1'
tactics:
- initial-access
- positioning
techniques:
- id: T1110.003
name: 'Brute Force: Password Spraying'
tactic: initial-access
source: attack
- id: T1110
name: Brute Force
tactic: initial-access
source: attack
- id: F1006
name: Account Takeover
tactic: initial-access
source: f3
- id: T1557
name: Adversary-in-the-Middle
tactic: positioning
source: attack
Configuring LDAP Security Hardening
Overview
Harden LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous binding, and channel binding bypass. Covers LDAPS enforcement, channel binding, LDAP signing, access control lists, and monitoring for LDAP-based attacks.
When to Use
- When deploying or configuring configuring ldap security hardening capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation
Prerequisites
- Familiarity with identity access management concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities
Objectives
- Implement comprehensive configuring ldap security hardening capability
- Establish automated discovery and monitoring processes
- Integrate with enterprise IAM and security tools
- Generate compliance-ready documentation and reports
- Align with NIST 800-53 access control requirements
Security Controls
| Control |
NIST 800-53 |
Description |
| Account Management |
AC-2 |
Lifecycle management |
| Access Enforcement |
AC-3 |
Policy-based access control |
| Least Privilege |
AC-6 |
Minimum necessary permissions |
| Audit Logging |
AU-3 |
Authentication and access events |
| Identification |
IA-2 |
User and service identification |
Verification
Other files in this skill
references/api-reference.md (verbatim)
LDAP Security Hardening — API Reference
Libraries
| Library |
Install |
Purpose |
| ldap3 |
pip install ldap3 |
LDAP protocol client for security auditing |
Key ldap3 Methods
| Method |
Description |
Server(ip, port, use_ssl, tls, get_info=ALL) |
Create LDAP server with TLS config |
Connection(server, user, password, authentication=NTLM) |
Authenticated bind |
Connection(server, auto_bind=True) |
Anonymous bind test |
conn.search(base, filter, attributes) |
Search directory objects |
LDAP Security Settings (GPO)
| Setting |
Registry Path |
Recommended Value |
| LDAP Signing |
HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters\LDAPServerIntegrity |
2 (Require) |
| Channel Binding |
HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters\LdapEnforceChannelBinding |
2 (Always) |
| Simple Bind |
GPO: Network security: LDAP client signing requirements |
Require signing |
Security Checks
| Check |
Risk |
Severity |
| Anonymous bind allowed |
User/group enumeration |
CRITICAL |
| LDAPS not available |
Cleartext credential transmission |
HIGH |
| LDAP signing not enforced |
NTLM relay via LDAP |
HIGH |
| Channel binding disabled |
Credential relay attacks |
MEDIUM |
External References
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.