pentesting-freeipa - FreeIPA domain enumeration and security assessment.
Enumerates FreeIPA domains via LDAP and Kerberos, analyzes HBAC and sudo rules, extracts hashes, and identifies delegation takeover paths.
Tags
Updated: 2026-09-22Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Fingerprint FreeIPA environment
- Perform anonymous LDAP enumeration
- Enumerate authenticated LDAP objects
- Analyze HBAC and sudo rules
- Extract Kerberos CCACHE tickets
- Extract hashes from directory database
- Generate attack graphs with IPAHound
- Perform PKINIT delegation takeovers
Inputs
- FreeIPA domain configuration files
- Kerberos ticket files or keytabs
- User credentials or CCACHE tickets
- Target IPA server hostname
Outputs
- Directory enumeration data
- Extracted password hashes
- IPAHound attack graph data
- FreeIPA finding report
Requirements
- Linux environment
- Domain-joined host or network access
- Tools: ldapsearch, kinit, ipa
- Root privileges for hash extraction
