如何通过LDAP查询获取Active Directory中15分钟内创建的Windows安全组?
Got it, let's figure out how to find Windows security groups created in Active Directory in the last 15 minutes using an LDAP query. I've worked through similar scenarios before, so here's a step-by-step breakdown that should get you what you need:
Step 1: Know the Critical AD Attributes
First, we need to target two key things: security groups specifically, and groups created in the last 15 minutes. Here's what you need to know about the attributes involved:
objectCategory=group: Ensures we only query group objects (not users, computers, etc.)groupType: A bitmask where the0x80000000flag marks a group as a security group (distribution groups don't have this bit set)whenCreated: Stores the UTC timestamp when the group was created, in ISO 8601 format (YYYYMMDDHHMMSS.0Z)
Step 2: Calculate the 15-Minute-Old Timestamp
LDAP requires a specific UTC timestamp format for date filters. You can calculate this manually, but it's easier to automate. For example, in PowerShell:
# Generate the timestamp for 15 minutes ago in LDAP-compatible UTC format $15MinutesAgo = [DateTime]::UtcNow.AddMinutes(-15).ToString("yyyyMMddHHmmss.0Z")
This gives you a string like 20240520141500.0Z (adjusted to your current UTC time minus 15 minutes).
Step 3: Build the LDAP Filter
Combine the attribute checks into a single filter. We use a bitwise comparison for groupType to ensure we only get security groups:
(& (objectCategory=group) (groupType:1.2.840.113556.1.4.803:=0x80000000) (whenCreated>=<YOUR_TIMESTAMP>))
Replace <YOUR_TIMESTAMP> with the value you generated in Step 2. The 1.2.840.113556.1.4.803 OID tells LDAP to check if the 0x80000000 bit is set in the groupType attribute.
Step 4: Run the Query
If you're using PowerShell (with the RSAT Active Directory module installed), here's a complete script to execute the query and return the results with creation times:
# Calculate the timestamp $15MinutesAgo = [DateTime]::UtcNow.AddMinutes(-15).ToString("yyyyMMddHHmmss.0Z") # Build the filter $ldapFilter = "(& (objectCategory=group) (groupType:1.2.840.113556.1.4.803:=0x80000000) (whenCreated>=$15MinutesAgo))" # Retrieve the groups and display their name and creation time Get-ADGroup -LDAPFilter $ldapFilter -Properties whenCreated | Select-Object Name, whenCreated
For other tools like ldp.exe or third-party LDAP browsers, just paste the full filter (with your timestamp) into the search filter field and run the query against your AD domain.
Key Notes
- Always use UTC time for
whenCreatedto avoid timezone discrepancies (AD stores this attribute in UTC by default) - The bitwise filter for
groupTypeis crucial—don't just usegroupType=0x80000000, because security groups often have additional bits set (like global/domain-local group flags) - If you need to run this on a schedule, wrap the PowerShell script in a task to automatically calculate the timestamp each time
内容的提问来源于stack exchange,提问作者Shay Young

