Autonomous Hunter

700 cleartext LDAP binds. 6 accounts exposed.

700
cleartext binds/day, exposing 6 accounts
700
Cleartext binds per day, port 389, not LDAPS 636
6
Accounts exposed, including virtualization, backup, site recovery
11
Domain controllers, all receiving plaintext credentials
None
Alert generated, no signature exists for cleartext LDAP volume

The problem

700 times a day, six service account passwords crossed the wire in plaintext.

A management server was authenticating to all 11 domain controllers via cleartext LDAP, transmitting 6 service account passwords unencrypted around 700 times a day.

Credential exposure

Six high-privilege service accounts transmitted passwords in plaintext roughly 700 times daily. A single packet capture on the network segment compromises the entire infrastructure stack.

Lateral movement risk

These service accounts have broad access across Active Directory. Captured credentials enable lateral movement, privilege escalation, and persistent access, with no additional exploitation required.

Recommended action

A single packet capture on the network segment would have compromised the entire infrastructure stack. The fix: migrate all LDAP binds to LDAPS, or enable LDAP channel binding and signing on all domain controllers.

Contact us for a 30-day POV
on your own directory traffic.

Book a Demo
Or reach us directly at hello@alphalevelsec.com  ·  alphalevel.ai