ldapdomaindump
Active Directory information dumper via LDAP
Decision gist · record as of 2026-08-14
Yes, if you are performing internal penetration testing or AD security assessments and need to extract and format LDAP data for analysis. The low install friction and permissive license make it straightforward to add to a pentest toolkit. Caveat: maintenance is aging (last release 497 days ago), so verify compatibility with your target AD environment and LDAP server version before relying on it in production assessments.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.6 or greater.
- Target LDAP server must be accessible and you must have valid credentials (or anonymous access) to query it.
- Low friction install with just two runtime dependencies (dnspython and ldap3).
License · maintenance · safety
MIT (permissive) — MIT license is permissive; you can use, modify, and distribute this package freely with minimal restrictions.
last release 2025-04-04 (497 days) · last repo commit 2025-04-06 · 1,423 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 661,510 downloads/mo, #5,450 on PyPI
Alternatives
Verify before relying
pip install ldapdomaindump
ldapdomaindump -u DOMAIN\\username -p password -o ./output hostname_or_ip- Whether the tool works with modern Active Directory deployments and current LDAP server versions.
- Performance characteristics and memory usage on very large domains (beyond the --minimal flag guidance).
- Compatibility with recent versions of BloodHound or other downstream tools that consume its output.
What it is and what it does
ldapdomaindump is a command-line tool that queries an Active Directory domain via LDAP and extracts structured information about users, groups, computers, policies, and domain trusts. It's designed for the reconnaissance phase of internal penetration tests, where an authenticated user or machine account can retrieve data that would otherwise be scattered across LDAP in an unreadable format.
The tool outputs multiple files in parallel: HTML for human review, JSON and CSV/TSV for machine parsing, and greppable tab-delimited text. It supports both NTLM and SIMPLE authentication, can work with NTLM hashes, and integrates with relaying tools like impacket's ntlmrelayx. It includes utility scripts to convert output to BloodHound-compatible CSV or enum4linux-style pretty-printed format. Runtime dependencies are dnspython and ldap3.
Use it for
- Enumerate all users, groups, and computers in an AD domain during an internal pentest reconnaissance phase.
- Extract domain policy information (password requirements, lockout policies) for security assessment.
- Generate structured reports of domain trusts and their properties for trust relationship analysis.
- Feed domain data into BloodHound (via ldd2bloodhound utility) or other AD visualization tools.
- Integrate with NTLM relay attacks by accepting an existing authenticated LDAP connection from impacket.
- Minimize memory usage on large networks by using the --minimal flag to dump only essential attributes.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are performing internal penetration testing or AD security assessments and need to extract and format LDAP data for analysis.
The low install friction and permissive license make it straightforward to add to a pentest toolkit. Caveat: maintenance is aging (last release 497 days ago), so verify compatibility with your target AD environment and LDAP server version before relying on it in production assessments.
Install
ldapdomaindump on PyPI
Before you install
Low friction install with just two runtime dependencies (dnspython and ldap3). Maintenance is aging—last release was 497 days ago—but the repository remains active with recent commits and no archived status.
Requires Python 3.6 or greater. Target LDAP server must be accessible and you must have valid credentials (or anonymous access) to query it.
License in practice
MIT license is permissive; you can use, modify, and distribute this package freely with minimal restrictions.
Quickstart
pip install ldapdomaindump
ldapdomaindump -u DOMAIN\\username -p password -o ./output hostname_or_ip
Verify before relying
- Whether the tool works with modern Active Directory deployments and current LDAP server versions.
- Performance characteristics and memory usage on very large domains (beyond the --minimal flag guidance).
- Compatibility with recent versions of BloodHound or other downstream tools that consume its output.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.6 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesdnspythonldap3 |
| Maintenance | Aging 497 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 661,510 / month, #5,450 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
Evidence: ldapdomaindump-0.10.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “active directory ldap dumper”
- ldapdomaindumpCollects and exports Active Directory information via LDAP in…
- python-active-directoryAn Active Directory client library for Python on UNIX/Linux systems…
- ldap3ldap3 is a pure Python LDAP V3 client library that implements RFC…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also bloodhound · msldap · ldap3 · python-active-directory · django-auth-ldap · python-ldap · dsinternals · urlextract · python3-ldap · ldaptor