What is it about?
Threat actors use LDAP to map target environments before striking, but detecting this activity is difficult due to a lack of labeled data. We show that correlating LDAP queries with nearby endpoint detections can generate weak labels at scale, enabling ML classification. We also offer a statistical hypothesis-testing framework for mining malicious LDAP signatures, providing an immediately deployable solution while ML infrastructure catches up.
Featured Image
Photo by Parker Coffman on Unsplash
Why is it important?
This is among the first applications of machine learning to LDAP reconnaissance, a common but understudied attack technique. We show that endpoint detections can serve as a weak signal to train models where labeled data doesn't exist, and that ML outputs can be distilled into statistically validated rules deployable in production systems that aren't ML-ready. This pattern offers a practical template for other security domains facing similar labeling and infrastructure constraints.
Perspectives
This was a multi-team effort, involving many security experts and data scientists, to understand threat actor behavior and build a weak supervision pipeline to reflect this. I hope this encourages other security teams to explore weak supervision to fill the label gaps that exist today and will only grow as cyber threats continue to explode. I believe this work also embodies the spirit of cybersecurity: move faster than the adversary. We put our customers first, choosing not to wait for infrastructure to catch up and instead delivering immediate protection through the signature mining framework. It was especially rewarding to see the high field precision firsthand and hear directly about real breaches stopped because of this detection.
Shaefer Drew
Read the Original
This page is a summary of: ML-Powered LDAP Reconnaissance Detection using Weak Supervision, August 2026, ACM (Association for Computing Machinery),
DOI: 10.1145/3770855.3818449.
You can read the full text:
Resources
Contributors
The following have contributed to this page







