
Una herramienta ligera para extraer rápidamente información valiosa del entorno de Active Directory tanto para ataque como para defensa.
ADCollector es una herramienta ligera que enumera el entorno de Active Directory para identificar posibles vectores de ataque. Te dará una comprensión básica de la configuración/despliegue del entorno como punto de partida.
ADCollector no es una alternativa al potente PowerView, solo automatiza la enumeración para identificar rápidamente información jugosa sin pensar demasiado en la etapa inicial de Reconocimiento. Las funciones implementadas en ADCollector son ideales para la enumeración en un entorno empresarial grande con muchos usuarios/equipos, sin generar mucho tráfico y tomando una gran cantidad de tiempo. Solo se enfoca en extraer atributos/propiedades/ACLs útiles de los objetivos más valiosos en lugar de enumerar todos los atributos disponibles de todos los objetos de usuario/equipo en el dominio. Definitivamente necesitarás PowerView para hacer una enumeración más detallada más adelante. Puedes usar ADSI en lugar de PowerView para enumerar el dominio siempre que sepas lo que quieres enumerar, consulta https://dev-2null.github.io/Easy-Domain-Enumeration-with-ADSI/.
El objetivo de desarrollar esta herramienta es ayudarme a aprender más sobre la seguridad de Active Directory desde una perspectiva diferente, así como descubrir qué hay detrás de las funciones de PowerView.
Utiliza el espacio de nombres S.DS para recuperar información del dominio/forest desde el controlador de dominio (servidor LDAP). También utiliza el espacio de nombres S.DS.P para búsquedas LDAP.
Esta herramienta aún está en construcción. Las características que se implementarán se pueden ver en mi página del proyecto
Asegúrate de tener acceso a SYSVOL si lo ejecutas desde un host no unido al dominio. Es posible que necesites ejecutar el siguiente comando si se aplica una política UNC endurecida:
reg add HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NetworkProvider\HardenedPaths /v "\\*\SYSVOL" /d "RequireMutualAuthentication=0" /t REG_SZ
PS C:\> .\ADCollector.exe --help
_ ____ ____ _ _ _
/ \ | _ \ / ___|___ | | | ___ ___ _| |_ ___ _ __
/ _ \ | | | | | / _ \| | |/ _ \/ __|_ __/ _ \| '__|
/ ___ \| |_| | |__| (_) | | | __/ (__ | || (_) | |
/_/ \_\____/ \____\___/|_|_|\___|\___| |__/\___/|_|
v3.0.1 by dev2null
--Domain Domain to enumerate
--LDAPS (Default: false) LDAP over SSL/TLS
--DisableSigning (Default: false) Disable Kerberos Encryption (with -LDAPS flag)
--UserName Alternative UserName
--Password Alternative Credential
--DC Alternative Domain Controller (Hostname/IP) to connect to
--OU Perform the Search under a specific Organizational Unit
--LDAPONLY Only Enumearte Objects in LDAP
--ACLScan Perform ACL scan for an Identity
--ADCS (Default: false) Only Perform AD Certificate Service Check
--TEMPLATES (Default: false) Only Enumerate All Certificate Templates with their DACL
--SCHEMA (Default: false) Count Schema Attributes in the default naming context
--ADIDNS (Default: false) Only Collect ADIDNS Records
--NGAGP Only enumerate Nested Group Membership and Applied Group Policies on the target object
--DACL Enumerate DACL on the target object (with DistinguishedName)
--SessionEnum (Default: false) Enumerate session information on the target host
--UserEnum (Default: false) Enumerate user information on the target host
--LocalGMEnum (Default: false) Enumerate local group members on the target host
--Host (Default: Localhost) Hostname for Session/User/Groupmember Enumeration
--Group (Default: Administrators) Local Group Name for Local GroupMember Enumeration
--Debug (Default: false) Debug Mode
--help Display this help screen.
Example: .\ADCollector.exe
.\ADCollector.exe --LDAPs --DisableSigning
.\ADCollector.exe --OU IT
.\ADCollector.exe --OU OU=IT,DC=domain,DC=local
.\ADCollector.exe --ADCS
.\ADCollector.exe --TEMPLATES
.\ADCollector.exe --LDAPOnly
.\ADCollector.exe --SCHEMA
.\ADCollector.exe --ADIDNS
.\ADCollector.exe --NGAGP samaccountname
.\ADCollector.exe --DACL DC=domain,DC=net
.\ADCollector.exe --ACLScan user --OU OU=IT,DC=domain,DC=local
.\ADCollector.exe --SessionEnum --Host targetHost
.\ADCollector.exe --UserEnum --Host targetHost
.\ADCollector.exe --LocalGMEnum --Host targetHost --Group 'Remote Desktop Users'
.\ADCollector.exe --Domain domain.local --Username user --Password pass
.\ADCollector.exe --Domain domain.local --DC 10.10.10.1