
C#-Implementierung von SMBExec zur Remote-Befehlsausführung auf Windows-Zielen unter Verwendung von NTLM-Passwort-Hashes, die laterale Bewegung und Pass-the-Hash-Angriffe ermöglicht.
Eine native C#-Konvertierung von Kevin Robertsons Invoke-SMBExec PowerShell-Skript. (https://github.com/Kevin-Robertson/Invoke-TheHash/blob/master/Invoke-SMBExec.ps1)
Entwickelt für .NET 3.5
Sharp-SMBExec.exe hash:"hash" username:"username" domain:"domain.tld" target:"target.domain.tld" command:"command"
Diese Assembly ermöglicht es Ihnen, einen Befehl auf einem Zielcomputer unter Verwendung von SMB auszuführen, indem ein NTLM-Hash für den angegebenen Benutzer bereitgestellt wird.
Option Description
username* Username to use for authentication
hash* NTLM Password hash for authentication. This module will accept either LM:NTLM or NTLM format
domain Domain to use for authentication. This parameter is not needed with local accounts or when using @domain after the username
target Hostname or IP Address of the target.
command Command to execute on the target. If a command is not specified, the function will check to see if the username and hash provide local admin access on the target
ServiceName Default = 20 Character Random. The Name of the service to create and delete on the target.
-CheckAdmin Check admin access only, don't execute command
-Help (-h) Switch, Enabled debugging [Default='False']
-Debug Print Debugging Information along with output
-ForceSMB1 Force SMB1. The default behavior is to perform SMB Version negotiation and use SMB2 if it's supported by the target [Default='False']
-ComSpec Prepend %COMSPEC% /C to Command [Default='False']