
AD Enum هي أداة اختبار اختراق تسمح باكتشاف الأخطاء في التهيئة عبر بروتوكول LDAP واستغلال بعض هذه الثغرات باستخدام Kerberos.
ADEnum.pyADEnum.py هي أداة اختبار اختراق تسمح بإيجاد التهيئات الخاطئة من خلال بروتوكول LDAP واستغلال بعض نقاط الضعف تلك باستخدام Kerberos.
█████╗ ██████╗ ███████╗███╗ ██╗██╗ ██╗███╗ ███╗
██╔══██╗██╔══██╗ ██╔════╝████╗ ██║██║ ██║████╗ ████║
███████║██║ ██║ █████╗ ██╔██╗ ██║██║ ██║██╔████╔██║
██╔══██║██║ ██║ ██╔══╝ ██║╚██╗██║██║ ██║██║╚██╔╝██║
██║ ██║██████╔╝ ███████╗██║ ╚████║╚██████╔╝██║ ╚═╝ ██║
╚═╝ ╚═╝╚═════╝ ╚══════╝╚═╝ ╚═══╝ ╚═════╝ ╚═╝ ╚═╝
usage: ADenum.py -d [domain] -u [username] -p [password]
Pentest tool that detect misconfig in AD with LDAP
options:
-h, --help show this help message and exit
-d [domain] The name of domain (e.g. "test.local")
-u [username] The user name
-p [password] The user password
-ip [ipAddress] The IP address of the server (e.g. "1.1.1.1")
-j Enable hash cracking (john)
-jp [path] John binary path
-w [wordList] The path of the wordlist to be used john (Default: /usr/share/seclists/Passwords/Leaked-
Databases/rockyou.txt
-v, --version Show program's version number and exit
-s Use LDAP with SSL
-c, --NPUsersCheck Check with GetNPUsers.py for ASREP Roastable
Impacket (https://github.com/SecureAuthCorp/impacket)
Python 3
إذا كنت تستخدم ديبيان أو أوبونتو:
$ sudo apt-get install libsasl2-dev python-dev libldap2-dev libssl-dev
إذا كنت تستخدم كالي:
$ sudo apt-get install libsasl2-dev python2-dev libldap2-dev libssl-dev
pip3:
$ pip3 install -r requirements.txt
يكتشف ATA حدثين مشبوهين لكنه لا يطلق تنبيهًا:
كما هو موضح في هذه اللقطة الشاشة:

الوثائق:
Impacket:
This project is made for educational and ethical testing purposes only. Usage of this software for attacking targets without prior mutual consent is illegal.
It is the end user's responsibility to obey all applicable local, state and federal laws.
Developers assume no liability and are not responsible for any misuse or damage caused by this program.