Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
windows-coerced-authentication-methods — A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols. | Kitploit
Outils/GitHubGitHub/p0dalirius/windows-coerced-authentication-methods
Privilege EscalationExploitationPenetration TestingAuthenticationRed TeamingCurated Resources
GitHubp0dalirius/windows-coerced-authentication-methods

windows-coerced-authentication-methods

A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols.

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Voir le dépôtSite web
6017213il y a 14 joursVérifié par Kitploit
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.


This repository contains a list of many methods to coerce a windows machine to authenticate to an attacker-controlled machine.
GitHub repo size YouTube Channel Subscribers

All of these methods are callable by a standard user in the domain to force the machine account of the target Windows machine (usually a domain controller) to authenticate to an arbitrary target. The root cause of this "vulnerability/feature" in each of these methods is that Windows machines automatically authenticate to other machines when trying to access UNC paths (like \\192.168.2.1\SYSVOL\file.txt).

There are currently 30 working functions in 13 protocols.


Protocols & Methods

  • [MS-COMA]: Component Object Model Plus (COM+) Remote Administration Protocol

    • Remote call to ImportFromFile (opnum 3)/README.md)
  • [MS-DFSNM]: Distributed File System (DFS) Namespace Management Protocol

    • Remote call to NetrDfsAdd (opnum 1)/README.md)
    • Remote call to NetrDfsAddStdRoot (opnum 12)/README.md)
    • Remote call to NetrDfsRemoveStdRoot (opnum 13)/README.md)
    • Remote call to NetrDfsAddRootTarget (opnum 23)/README.md)
    • Remote call to NetrDfsRemoveRootTarget (opnum 24)/README.md)
  • [MS-DHCPM]: Microsoft Dynamic Host Configuration Protocol (DHCP) Server Management Protocol

    • Remote call to R_DhcpBackupDatabase (opnum 44)/README.md)
    • Remote call to R_DhcpRestoreDatabase (opnum 45)/README.md)
  • [MS-DNSP]: Domain Name Service (DNS) Server Management Protocol

    • Remote call to R_DnssrvOperation — LogFilePath (opnum 0)/README.md)
  • [MS-EFSR]: Encrypting File System Remote (EFSRPC) Protocol

    • Remote call to EfsRpcOpenFileRaw (opnum 0)/README.md)
    • Remote call to EfsRpcEncryptFileSrv (opnum 4)/README.md)
    • Remote call to EfsRpcDecryptFileSrv (opnum 5)/README.md)
    • Remote call to EfsRpcQueryUsersOnFile (opnum 6)/README.md)
    • Remote call to EfsRpcQueryRecoveryAgents (opnum 7)/README.md)
    • Remote call to EfsRpcFileKeyInfo (opnum 12)/README.md)
    • Remote call to EfsRpcDuplicateEncryptionInfoFile (opnum 13)/README.md)
    • Remote call to EfsRpcAddUsersToFileEx (opnum 15)/README.md)
    • Remote call to EfsRpcFileKeyInfoEx (opnum 16)/README.md)
    • Remote call to EfsRpcEncryptFileExSrv (opnum 21)/README.md)
Télécharger l’outil