Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
Log in
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
PowerShell-Red-Team — एक अभियान में रेड टीमर द्वारा उपयोग की जा सकने वाली PowerShell फ़ंक्शनों का संग्रह | Kitploit
उपकरण/GitHubGitHub/tobor88/powershell-red-team
विशेषाधिकार वृद्धिपासवर्ड हमलेपार्श्व आंदोलनजानकारी एकत्र करनापेनिट्रेशन टेस्टिंगरेड टीमिंग
GitHubtobor88/powershell-red-team

PowerShell-Red-Team

एक अभियान में रेड टीमर द्वारा उपयोग की जा सकने वाली PowerShell फ़ंक्शनों का संग्रह

रिपॉजिटरी देखें
55192602 साल पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

PowerShell-Red-Team-Enum

PowerShell फ़ंक्शनों का एक संग्रह जिसका उपयोग Red Teamer मशीन से डेटा एकत्र करने या लक्ष्य तक पहुँच प्राप्त करने के लिए कर सकता है। मैंने RedTeamEnum मॉड्यूल में शामिल कमांडों के लिए ps1 फ़ाइलें जोड़ी हैं। इससे आप आसानी से केवल एक कमांड ढूँढ सकते हैं और उपयोग कर सकते हैं, यदि आपको बस यही चाहिए। यदि आप पूरा मॉड्यूल चाहते हैं, तो अपने डिवाइस पर RedTeamEnum निर्देशिका और सामग्री डाउनलोड करने के बाद निम्नलिखित क्रियाएँ करें।

C:\PS> robocopy .\RedTeamEnum $env:USERPROFILE\Documents\WindowsPowerShell\Modules\RedTeamEnum *
# This will copy the module to a location that allows you to easily import it. If you are using OneDrive sync you may need to use $env:USERPROFILE\OneDrive\Documents\WindowsPowerShell\Modules\RedTeamEnum instead.

C:\PS> Import-Module -Name RedTeamEnum -Verbose
# This will import all the commands in the module.

C:\PS> Get-Command -Module RedTeamEnum
# This will list all the commands in the module.
  • Convert-Base64.ps1 एक फ़ंक्शन है जैसा कि नाम से पता चलता है, टेक्स्ट को Base64 प्रारूप में एन्कोडिंग और/या डिकोड करने के लिए है।
C:\PS> Convert-Base64 -Value "Convert me to base64!" -Encode

C:\PS> Convert-Base64 -Value "Q29udmVydCBtZSB0byBiYXNlNjQh" -Decode
  • Convert-StringToHash.ps1 एक फ़ंक्शन है जो स्ट्रिंग मान को हैश मान में बदलने के लिए है।
C:\PS> Convert-StringToHash -String "Convert me to base64!"
C:\PS> Convert-StringToHash -String "Password123" -Encoding UTF8 -Algorithm MD5
# Both of the above examples convert the string Password123 to an MD5 Hash value
  • Convert-SID.ps1 एक फ़ंक्शन है जो SID मानों को उपयोगकर्ता नामों में और उपयोगकर्ता नामों को SID मानों में बदलता है।
C:\PS> Convert-SID -Username tobor
# The above example converts tobor its SID value

C:\PS> Convert-SID -SID S-1-5-21-2860287465-2011404039-792856344-500
# The above value converts the SID value to its associated username
  • Test-BruteZipPassword एक फ़ंक्शन है जो 7zip का उपयोग करके पासवर्ड-सुरक्षित zip फ़ाइल को ब्रूट फोर्स करने के लिए पासवर्ड फ़ाइल का उपयोग करता है।
C:\PS> Test-BruteForceZipPassword -PassFile 'C:\Users\USER\Downloads\Applications\pass.txt' -Path 'C:\Users\USER\Downloads\Applications\KiTTY.7z' -ZipExe 'C:\Program Files\7-Zip\7z.exe'
# This example uses the passwords in the pass.txt file to crack the password protected KiTTY.7z file
  • Test-BruteForceCredentials एक फ़ंक्शन है जो किसी उपयोगकर्ता के पासवर्ड को ब्रूट फोर्स करने के लिए WinRM का उपयोग करता है।
C:\PS> Test-BruteForceCredentials -ComputerName DC01.domain.com -UseSSL -Username 'admin','administrator' -Passwd 'Password123!' -SleepMinutes 5
# This example will test the one password defined against both the admin and administrator users on the remote computer DC01.domain.com using WinRM over HTTPS with a time interval of 5 minutes between each attempt

C:\PS> Test-BruteForceCredentials -ComputerName File.domain.com -UserFile C:\Temp\users.txt -PassFile C:\Temp\rockyou.txt
# This example will test every password in rockyou.txt against every username in the users.txt file without any pause between tried attempts
  • Get-LdapInfo एक फ़ंक्शन है जिस पर मुझे सामान्य LDAP क्वेरी करने के लिए बहुत गर्व है। हालाँकि आउटपुट में केवल दो गुण दिखाई देंगे, ऑब्जेक्ट से जुड़े सभी गुणों को Select-Object -Property * पर पाइप करके या -Detailed स्विच पैरामीटर का उपयोग करके देखा जा सकता है।
C:\PS> Get-LdapInfo -Detailed -SPNNamedObjects -Domain domain.com -Credential (Get-Credential)
# The above returns all the properties of the returned objects in domain.com
#
C:\PS> Get-LdapInfo -DomainControllers | Select-Object -Property 'Name','ms-Mcs-AdmPwd'
# If this is run as admin it will return the LAPS password for the local admin account
#
C:\PS> Get-LdapInfo -ListUsers | Where-Object -Property SamAccountName -like "user.samname"
# NOTE: If you include the "-Detailed" switch and pipe the output to where-object it will not return any properties. If you wish to display all the properties of your result it will need to be carried out using the below format
#
C:\PS> Get-LdapInfo -AllServers | Where-Object -Property LogonCount -gt 1 | Select-Object -Property *

  • Get-NetworkShareInfo एक cmdlet है जिसका उपयोग किसी रिमोट या स्थानीय मशीन पर उपलब्ध नेटवर्क शेयरों के बारे में जानकारी प्राप्त करने और/या ब्रूट फोर्स डिस्कवर करने के लिए किया जाता है।
C:\PS> Get-NetworkShareInfo -ShareName C$
# The above example returns information on the share C$ on the local machine
#RESULTS
Name         : C$
InstallDate  :
Description  : Default share
Path         : C:\
ComputerName : TOBORDESKTOP
Status       : OK

C:\PS> Get-NetworkShareInfo -ShareName NETLOGON,SYSVOL,C$ -ComputerName DC01.domain.com, DC02.domain.com, 10.10.10.1
# The above example disocvers and returns information on NETLOGON, SYSVOL, and C$ on the 3 remote devices DC01, DC02, and 10.10.10.1
  • Test-PrivEsc एक फ़ंक्शन है जिसका उपयोग यह पता लगाने के लिए किया जा सकता है कि क्या WSUS अपडेट HTTP पर PrivEsc के लिए संवेदनशील हैं, सामान्य स्थानों पर क्लियर टेक्स्ट क्रेडेंशियल संग्रहीत हैं, AlwaysInstallElevated PrivEsc के लिए संवेदनशील है, अनकोटेड सर्विस पथ मौजूद हैं, और सेवाओं के लिए संभावित कमजोर लिखने की अनुमतियों की गणना।
 C:\PS> Test-PrivEsc
  • Get-InitialEnum विंडोज ऑपरेटिंग सिस्टम की बुनियादी बातों की गणना करने के लिए एक फ़ंक्शन है ताकि संभावित कमजोरियों को बेहतर ढंग से प्रदर्शित करने में मदद मिल सके।
 C:\PS> Get-InitialEnum
  • Start-SimpleHTTPServer फ़ाइलें डाउनलोड करने के लिए HTTP सर्वर होस्ट करने के लिए उपयोग किया जाने वाला फ़ंक्शन है। यह पायथन के SimpleHTTPServer मॉड्यूल के समान होने का इरादा है। वेब सर्वर के माध्यम से निर्देशिकाएँ पार करने योग्य नहीं हैं। जो फ़ाइलें डाउनलोड के लिए होस्ट की जाएंगी, वे उसी वर्तमान निर्देशिका से होंगी जिसमें आप यह कमांड जारी करते समय हैं।
C:\PS> Start-SimpleHTTPServer
Open HTTP Server on port 8000

#OR
C:\PS> Start-SimpleHTTPServer -Port 80
# Open HTTP Server on port 80
  • Invoke-PortScan.ps1 एक फ़ंक्शन है जो लक्ष्य पर सभी संभावित TCP पोर्ट को स्कैन करने के लिए है। मैं भविष्य में UDP के साथ-साथ पोर्ट रेंज को परिभाषित करने की क्षमता भी शामिल करके इसे बेहतर बनाऊंगा। यह वास्तव में उपयोग करने लायक भी नहीं है क्योंकि यह बहुत धीमा है। थ्रेडिंग मेरा कमजोर क्षेत्र है और मैं इस पर काम करने की योजना बना रहा हूँ।
 C:\PS> Invoke-PortScan -IpAddress 192.168.0.1
  • Invoke-PingSweep एक फ़ंक्शन है जिसका उपयोग सबनेट रेंज की पिंग स्वीप करने के लिए किया जाता है।
C:\PS> Invoke-PingSweep -Subnet 192.168.1.0 -Start 192 -End 224 -Source Singular
# NOTE: The source parameter only works if IP Source Routing value is "Yes"

C:\PS> Invoke-PingSweep -Subnet 10.0.0.0 -Start 1 -End 20 -Count 2
# Default value for count is 1

C:\PS> Invoke-PingSweep -Subnet 172.16.0.0 -Start 64 -End 128 -Count 3 -Source Multiple
  • Invoke-UseCreds एक फ़ंक्शन है जिसे मैंने पेन टेस्ट के दौरान प्राप्त क्रेडेंशियल्स का उपयोग करने की प्रक्रिया को सरल बनाने के लिए बनाया है। मैं -Password के बजाय -Passwd का उपयोग करता हूँ क्योंकि जब उस पैरामीटर को परिभाषित किया जाता है तो इसे एक सुरक्षित स्ट्रिंग के रूप में कॉन्फ़िगर किया जाना चाहिए, जो कि इस फ़ंक्शन के साथ उस फ़ील्ड में मान दर्ज करने पर मामला नहीं है। आपके द्वारा वह मान सेट करने के बाद यह एक सुरक्षित स्ट्रिंग में परिवर्तित हो जाता है।
# The below command will use the entered credentials to open the msf.exe executable as the user tobor
C:\PS> Invoke-UseCreds -Username 'OsbornePro\tobor' -Passwd 'P@ssw0rd1' -Path .\msf.exe -Verbose

यह cmdlet आपकी स्थानीय मशीन पर स्थित फ़ाइलों को निष्पादित करने और उन्हें रिमोट मशीन पर निष्पादित करने के लिए भी उपयोग किया जा सकता है।

# The below command will use the entered credentials to open the exploit.ps1 executable as the user tobor on DC01 and DC02 using WinRM
C:\PS> Invoke-UseCreds -Username 'OsbornePro\tobor' -Passwd 'P@ssw0rd1' -Path .\exploit.ps1 -ComputerName "DC01.domain.com","DC02.domain.com"
टूल डाउनलोड करें