| | 1 | | using System.Collections.Generic; |
| | 2 | | using System.Linq; |
| | 3 | |
|
| | 4 | | namespace SharpHoundCommonLib.LDAPQueries { |
| | 5 | | /// <summary> |
| | 6 | | /// A class used to more easily build LDAP filters based on the common filters used by SharpHound |
| | 7 | | /// </summary> |
| | 8 | | public class LdapFilter { |
| 22 | 9 | | private readonly List<string> _filterParts = new(); |
| 22 | 10 | | private readonly List<string> _mandatory = new(); |
| | 11 | |
|
| | 12 | | /// <summary> |
| | 13 | | /// Pre-filters conditions passed into filters. Will fix filters that are missing parentheses naively |
| | 14 | | /// </summary> |
| | 15 | | /// <param name="conditions"></param> |
| | 16 | | /// <returns></returns> |
| 2 | 17 | | private static string[] CheckConditions(IEnumerable<string> conditions) { |
| 2 | 18 | | return conditions.Select(FixFilter).ToArray(); |
| 2 | 19 | | } |
| | 20 | |
|
| 2 | 21 | | private static string FixFilter(string filter) { |
| 3 | 22 | | if (!filter.StartsWith("(")) filter = $"({filter}"; |
| | 23 | |
|
| 3 | 24 | | if (!filter.EndsWith(")")) filter = $"{filter})"; |
| | 25 | |
|
| 2 | 26 | | return filter; |
| 2 | 27 | | } |
| | 28 | |
|
| | 29 | | /// <summary> |
| | 30 | | /// Takes a base filter and appends any number of LDAP conditionals in a LDAP "And" statement. |
| | 31 | | /// Returns the base filter if no extra conditions are specified |
| | 32 | | /// </summary> |
| | 33 | | /// <param name="baseFilter"></param> |
| | 34 | | /// <param name="conditions"></param> |
| | 35 | | /// <returns></returns> |
| 29 | 36 | | private static string BuildString(string baseFilter, params string[] conditions) { |
| 56 | 37 | | if (conditions.Length == 0) return baseFilter; |
| | 38 | |
|
| 2 | 39 | | return $"(&{baseFilter}{string.Join("", CheckConditions(conditions))})"; |
| 29 | 40 | | } |
| | 41 | |
|
| | 42 | | /// <summary> |
| | 43 | | /// Add a wildcard filter will match all object types |
| | 44 | | /// </summary> |
| | 45 | | /// <param name="conditions"></param> |
| | 46 | | /// <returns></returns> |
| 10 | 47 | | public LdapFilter AddAllObjects(params string[] conditions) { |
| 10 | 48 | | _filterParts.Add(BuildString("(objectclass=*)", conditions)); |
| | 49 | |
|
| 10 | 50 | | return this; |
| 10 | 51 | | } |
| | 52 | |
|
| | 53 | | /// <summary> |
| | 54 | | /// Add a filter that will match User objects |
| | 55 | | /// </summary> |
| | 56 | | /// <param name="conditions"></param> |
| | 57 | | /// <returns></returns> |
| 3 | 58 | | public LdapFilter AddUsers(params string[] conditions) { |
| 3 | 59 | | _filterParts.Add(BuildString("(samaccounttype=805306368)", conditions)); |
| | 60 | |
|
| 3 | 61 | | return this; |
| 3 | 62 | | } |
| | 63 | |
|
| | 64 | | /// <summary> |
| | 65 | | /// Add a filter that will match Group objects |
| | 66 | | /// </summary> |
| | 67 | | /// <param name="conditions"></param> |
| | 68 | | /// <returns></returns> |
| 3 | 69 | | public LdapFilter AddGroups(params string[] conditions) { |
| 3 | 70 | | _filterParts.Add(BuildString( |
| 3 | 71 | | "(|(samaccounttype=268435456)(samaccounttype=268435457)(samaccounttype=536870912)(samaccounttype=5368709 |
| 3 | 72 | | conditions)); |
| | 73 | |
|
| 3 | 74 | | return this; |
| 3 | 75 | | } |
| | 76 | |
|
| | 77 | | /// <summary> |
| | 78 | | /// Add a filter that will include any object with a primary group |
| | 79 | | /// </summary> |
| | 80 | | /// <param name="conditions"></param> |
| | 81 | | /// <returns></returns> |
| 0 | 82 | | public LdapFilter AddPrimaryGroups(params string[] conditions) { |
| 0 | 83 | | _filterParts.Add(BuildString("(primarygroupid=*)", conditions)); |
| | 84 | |
|
| 0 | 85 | | return this; |
| 0 | 86 | | } |
| | 87 | |
|
| | 88 | | /// <summary> |
| | 89 | | /// Add a filter that will include GPO objects |
| | 90 | | /// </summary> |
| | 91 | | /// <param name="conditions"></param> |
| | 92 | | /// <returns></returns> |
| 0 | 93 | | public LdapFilter AddGPOs(params string[] conditions) { |
| 0 | 94 | | _filterParts.Add(BuildString("(&(objectcategory=groupPolicyContainer)(flags=*))", conditions)); |
| | 95 | |
|
| 0 | 96 | | return this; |
| 0 | 97 | | } |
| | 98 | |
|
| | 99 | | /// <summary> |
| | 100 | | /// Add a filter that will include OU objects |
| | 101 | | /// </summary> |
| | 102 | | /// <param name="conditions"></param> |
| | 103 | | /// <returns></returns> |
| 1 | 104 | | public LdapFilter AddOUs(params string[] conditions) { |
| 1 | 105 | | _filterParts.Add(BuildString("(objectcategory=organizationalUnit)", conditions)); |
| | 106 | |
|
| 1 | 107 | | return this; |
| 1 | 108 | | } |
| | 109 | |
|
| | 110 | | /// <summary> |
| | 111 | | /// Add a filter that will include Domain objects |
| | 112 | | /// </summary> |
| | 113 | | /// <param name="conditions"></param> |
| | 114 | | /// <returns></returns> |
| 0 | 115 | | public LdapFilter AddDomains(params string[] conditions) { |
| 0 | 116 | | _filterParts.Add(BuildString("(objectclass=domain)", conditions)); |
| | 117 | |
|
| 0 | 118 | | return this; |
| 0 | 119 | | } |
| | 120 | |
|
| | 121 | | /// <summary> |
| | 122 | | /// Add a filter that will include Container objects |
| | 123 | | /// </summary> |
| | 124 | | /// <param name="conditions"></param> |
| | 125 | | /// <returns></returns> |
| 1 | 126 | | public LdapFilter AddContainers(params string[] conditions) { |
| 1 | 127 | | _filterParts.Add(BuildString("(&(!(objectClass=groupPolicyContainer))(objectClass=container))", conditions)) |
| | 128 | |
|
| 1 | 129 | | return this; |
| 1 | 130 | | } |
| | 131 | |
|
| | 132 | | /// <summary> |
| | 133 | | /// Add a filter that will include Configuration objects |
| | 134 | | /// </summary> |
| | 135 | | /// <param name="conditions"></param> |
| | 136 | | /// <returns></returns> |
| 0 | 137 | | public LdapFilter AddConfiguration(params string[] conditions) { |
| 0 | 138 | | _filterParts.Add(BuildString("(objectClass=configuration)", conditions)); |
| | 139 | |
|
| 0 | 140 | | return this; |
| 0 | 141 | | } |
| | 142 | |
|
| | 143 | | /// <summary> |
| | 144 | | /// Add a filter that will include Computer objects |
| | 145 | | /// |
| | 146 | | /// Note that gMSAs and sMSAs have this samaccounttype as well |
| | 147 | | /// </summary> |
| | 148 | | /// <param name="conditions"></param> |
| | 149 | | /// <returns></returns> |
| 2 | 150 | | public LdapFilter AddComputers(params string[] conditions) { |
| 2 | 151 | | _filterParts.Add(BuildString("(samaccounttype=805306369)", conditions)); |
| 2 | 152 | | return this; |
| 2 | 153 | | } |
| | 154 | |
|
| | 155 | | /// <summary> |
| | 156 | | /// Add a filter that will include PKI Certificate templates |
| | 157 | | /// </summary> |
| | 158 | | /// <param name="conditions"></param> |
| | 159 | | /// <returns></returns> |
| 1 | 160 | | public LdapFilter AddCertificateTemplates(params string[] conditions) { |
| 1 | 161 | | _filterParts.Add(BuildString("(objectclass=pKICertificateTemplate)", conditions)); |
| 1 | 162 | | return this; |
| 1 | 163 | | } |
| | 164 | |
|
| | 165 | | /// <summary> |
| | 166 | | /// Add a filter that will include Certificate Authorities |
| | 167 | | /// </summary> |
| | 168 | | /// <param name="conditions"></param> |
| | 169 | | /// <returns></returns> |
| 1 | 170 | | public LdapFilter AddCertificateAuthorities(params string[] conditions) { |
| 1 | 171 | | _filterParts.Add(BuildString("(objectClass=certificationAuthority)", |
| 1 | 172 | | conditions)); |
| 1 | 173 | | return this; |
| 1 | 174 | | } |
| | 175 | |
|
| | 176 | | /// <summary> |
| | 177 | | /// Add a filter that will include Enterprise Certificate Authorities |
| | 178 | | /// </summary> |
| | 179 | | /// <param name="conditions"></param> |
| | 180 | | /// <returns></returns> |
| 1 | 181 | | public LdapFilter AddEnterpriseCertificationAuthorities(params string[] conditions) { |
| 1 | 182 | | _filterParts.Add(BuildString("(objectCategory=pKIEnrollmentService)", conditions)); |
| 1 | 183 | | return this; |
| 1 | 184 | | } |
| | 185 | |
|
| | 186 | | /// <summary> |
| | 187 | | /// Add a filter that will include Issuance Policies |
| | 188 | | /// </summary> |
| | 189 | | /// <param name="conditions"></param> |
| | 190 | | /// <returns></returns> |
| 0 | 191 | | public LdapFilter AddIssuancePolicies(params string[] conditions) { |
| 0 | 192 | | _filterParts.Add(BuildString("(objectClass=msPKI-Enterprise-Oid)", conditions)); |
| 0 | 193 | | return this; |
| 0 | 194 | | } |
| | 195 | |
|
| | 196 | | /// <summary> |
| | 197 | | /// Add a filter that will include schema items |
| | 198 | | /// </summary> |
| | 199 | | /// <param name="conditions"></param> |
| | 200 | | /// <returns></returns> |
| 0 | 201 | | public LdapFilter AddSchemaID(params string[] conditions) { |
| 0 | 202 | | _filterParts.Add(BuildString("(schemaidguid=*)", conditions)); |
| 0 | 203 | | return this; |
| 0 | 204 | | } |
| | 205 | |
|
| | 206 | | /// <summary> |
| | 207 | | /// Add a filter that will include Computer objects but exclude gMSA and sMSA objects |
| | 208 | | /// </summary> |
| | 209 | | /// <param name="conditions"></param> |
| | 210 | | /// <returns></returns> |
| 6 | 211 | | public LdapFilter AddComputersNoMSAs(params string[] conditions) { |
| 6 | 212 | | _filterParts.Add(BuildString( |
| 6 | 213 | | "(&(samaccounttype=805306369)(!(objectclass=msDS-GroupManagedServiceAccount))(!(objectclass=msDS-Managed |
| 6 | 214 | | conditions)); |
| 6 | 215 | | return this; |
| 6 | 216 | | } |
| | 217 | |
|
| | 218 | | /// <summary> |
| | 219 | | /// Adds a generic user specified filter |
| | 220 | | /// </summary> |
| | 221 | | /// <param name="filter">LDAP Filter to add to query</param> |
| | 222 | | /// <param name="enforce">If true, filter will be AND otherwise OR</param> |
| | 223 | | /// <returns></returns> |
| 0 | 224 | | public LdapFilter AddFilter(string filter, bool enforce) { |
| 0 | 225 | | if (enforce) |
| 0 | 226 | | _mandatory.Add(FixFilter(filter)); |
| | 227 | | else |
| 0 | 228 | | _filterParts.Add(FixFilter(filter)); |
| | 229 | |
|
| 0 | 230 | | return this; |
| 0 | 231 | | } |
| | 232 | |
|
| | 233 | | /// <summary> |
| | 234 | | /// Combines all the specified parts of the LDAP filter and merges them into a single string |
| | 235 | | /// </summary> |
| | 236 | | /// <returns></returns> |
| 18 | 237 | | public string GetFilter() { |
| 18 | 238 | | var filterPartList = _filterParts.ToArray().Distinct(); |
| 18 | 239 | | var mandatoryList = _mandatory.ToArray().Distinct(); |
| | 240 | |
|
| 18 | 241 | | var filterPartsExceptMandatory = filterPartList.Except(mandatoryList).ToList(); |
| | 242 | |
|
| 18 | 243 | | var filterPartsDistinct = string.Join("", filterPartsExceptMandatory); |
| 18 | 244 | | var mandatoryDistinct = string.Join("", mandatoryList); |
| | 245 | |
|
| 18 | 246 | | if (filterPartsExceptMandatory.Count == 1) |
| 17 | 247 | | filterPartsDistinct = filterPartsExceptMandatory[0]; |
| 1 | 248 | | else if (filterPartsExceptMandatory.Count > 1) |
| 1 | 249 | | filterPartsDistinct = $"(|{filterPartsDistinct})"; |
| | 250 | |
|
| 18 | 251 | | filterPartsDistinct = _mandatory.Count > 0 |
| 18 | 252 | | ? $"(&{filterPartsDistinct}{mandatoryDistinct})" |
| 18 | 253 | | : filterPartsDistinct; |
| | 254 | |
|
| 18 | 255 | | return filterPartsDistinct; |
| 18 | 256 | | } |
| | 257 | |
|
| 1 | 258 | | public IEnumerable<string> GetFilterList() { |
| 1 | 259 | | return _filterParts.Distinct(); |
| 1 | 260 | | } |
| | 261 | | } |
| | 262 | | } |