LAPSToolkit : Tool to Audit & Attack LAPS Environments

LAPSToolkit functions written in PowerShell that leverage PowerView to audit and attack Active Directory environments that have deployed Microsoft’s Local Administrator Password Solution (LAPS).

It includes finding groups specifically delegated by sysadmins, finding users with “All Extended Rights” that can view passwords, and viewing all computers with LAPS enabled.

Please submit issues or comments for any problems or performance improvements. This project was created with code from an older version of PowerView.

Also Read : Androguard : Reverse Engineering, Malware & Goodware Analysis of Android Applications

Get-LAPSComputers:

Displays all computers with LAPS enabled, password expriation, and password if user has access

Find-LAPSDelegatedGroups:

Searches through all OUs to see which AD groups can read the ms-Mcs-AdmPwd attribute

Find-AdmPwdExtendedRights

Parses through ExtendedRights for each AD computer with LAPS enabled and looks for which group has read access and if any user has “All Extended Rights”.

Sysadmins may not be aware the users with All Extended Rights can view passwords and may be less protected than the users in the delegated groups.

An example is the user which adds a computer to the domain automatically receives the “All Extended Rights” permission. Since this function will parse ACLs for each AD computer, this can take very long with a larger domain.

Credit: Sean Metcalf (@pyrotek3), Will Schroeder (@harmj0y), Karl Fosaaen (@kfosaaen), Matt Graeber (@mattifestation)

R K

Recent Posts

Admin Panel Dorks : A Complete List of Google Dorks

Introduction Google Dorking is a technique where advanced search operators are used to uncover information…

3 days ago

Best Linux Distros in 2026

Linux is renowned for its versatility, open-source nature, and security. Whether you're a beginner, developer,…

3 days ago

Top 10 Cyber Insurance Companies in 2026

Cyber insurance helps businesses and individuals mitigate financial losses from data breaches, ransomware, extortion, legal…

3 days ago

Ransomware Incident Response

Ransomware is one of the most dangerous and destructive forms of cybercrime today. With cybercriminals…

4 days ago

Best Social Media Search Engines and Tools for 2026

Social media is a key part of our daily lives, with millions of users sharing…

4 days ago

How to Remove Your Personal Information from Data Broker Websites (2026 Guide)

What Are Data Brokers? Data brokers are companies that collect, aggregate, and sell personal information,…

4 days ago