Skip to content

LDAP (389)

The LDAP module emulates an LDAP server, allowing you to create honeypots that mimic directory services, and log interactions.

Configuration

json
"ldap": [
  {
    "port": 389,
    "server": "server-01",
    "domain": "microsoft",
    "tld": "intra",
    "level": "WinThreshold"
  }
]

Options

OptionTypeDescriptionDefault
portintegerTCP port number for the LDAP service389
serverstringServer name to present"server-01"
domainstringDomain name for the LDAP server"microsoft"
tldstringTop-level domain"intra"
levelstringWindows authentication level"WinThreshold"

The level parameter sets the domain functional level, which determines the available Active Directory Domain Services (AD DS) features. It corresponds to the domain functional levels defined in Windows Server, as documented in the Set-ADDomainMode PowerShell cmdlet.

Valid values for level are:

  • Windows2000Domain - Windows Server 2000 native level
  • Windows2003InterimDomain - Windows Server 2003 interim level
  • Windows2003Domain - Windows Server 2003 native level
  • Windows2008Domain - Windows Server 2008 level
  • Windows2008R2Domain - Windows Server 2008 R2 level
  • Windows2012Domain - Windows Server 2012 level
  • Windows2012R2Domain - Windows Server 2012 R2 level
  • WinThreshold - Windows Server 2016 level (default)