SOAPHound is a tool observed in security testing and discussed in relation to behavior seen in the wild. The provided content describes a manual SOAPHound attack simulation dated 2024-02-13 by Michael Haag in the attack_range environment, with Sysmon telemetry collected for MITRE ATT&CK technique T1059.001 and a dataset named Sysmon_soaphound used for detection validation in Splunk. The content also attributes to SOAPHound a distinctive LDAP query filter, "(!soaphound=)". Huntress reported that this filter does not appear directly in Windows LDAP Event ID 1644 logs because LDAP optimization transforms it into "(! (FALSE))" before logging, which can cause SOAPHound-related LDAP activity to evade straightforward 1644-based detections. High-confidence indicators and detection-relevant artifacts mentioned in the content include the LDAP filter "(!soaphound=)", its optimized logged form "(! (FALSE))", and the simulation dataset path /datasets/attack_techniques/T1059.001/soaphound/sysmon_soaphound.log. The provided content does not specify a threat actor, malware family classification, infection vector, or targeted industry beyond its use in attack simulation and LDAP-query-related detection research.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Other capabilities include harvesting certificate templates and DNS nodes from the DC, providing deeper insight into potential attack surfaces... DNS nodes expose the internal naming structure of the domain, helping threat actors identify key systems, locate domain controllers, and map out paths for lateral movement or persistence.
LDAP is commonly used by criminals for lateral movement and critical assets enumeration in on-premises cyberattacks. | Threat actors often use LDAP for network enumeration during the discovery phase of an attack. Attackers query directories to extract sensitive information such as user accounts, group memberships and permissions, which they then use to escalate privileges and target critical assets.
Collector tools like SharpHound, SoapHound, and ShadowHound gather data on AD objects and relationships using a variety of protocols, including Lightweight Directory Access Protocol (LDAP), Server Message Block (SMB), and Active Directory Web Services (ADWS).
"Pattern Meaning Legitimate Use? ... SDflags:0x7 Full security descriptor request Very rare ... nTSecurityDescriptor in attributes ACL enumeration BloodHound pattern"
Detect AzureHound Command-Line Arguments ... Local Groups ... Detect SharpHound Usage ... Local Groups ... Group Discovery Via Net ... Local Groups
"Actual SOAPHound execution... Server controls: SDFlags:0x7" and "SDFlags:0x7 requests Owner (0x1) + Group (0x2) + DACL (0x4) = 0x7"
Detect AzureHound Command-Line Arguments ... Local Account ... Detect SharpHound Usage ... Local Account ... Windows SOAPHound Binary Execution ... Local Account
"The main thing differentiating the two protocols is with common LDAP diagnostic logging the host/device the collection appears to be coming from in the logs is always the DC the ADWS query is executed on due to the ADWS services interaction with the LDAP service on loopback..."
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Active Directory/LDAP enumeration tool whose query patterns may be optimized away before logging, complicating SIEM-based detection.
Referenced as a named tool or malware simulation in an attack-range dataset used to reproduce behavior seen in the wild. The content does not provide functional details beyond manual testing/simulation.
Tool that performs LDAP queries against Active Directory; the content highlights a specific LDAP query pattern/optimization behavior that can evade straightforward Event 1644 log-based detection and suggests a detection signature based on the transformed filter.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.