Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
SharpWnfSuite — Utilità C# per il servizio di notifiche di Windows | Kitploit
Strumenti/GitHubGitHub/daem0nc0re/sharpwnfsuite
RicognizioneAnalisi delle VulnerabilitàExploitRaccolta InformazioniPost-ExploitUtilità e Framework
GitHubdaem0nc0re/sharpwnfsuite

SharpWnfSuite

Utilità C# per il servizio di notifiche di Windows

Vedi Repository
15828191 anno faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

SharpWnfSuite

Questo è il repository per gli strumenti di Windows Notification Facility (WNF). Attualmente, è stata caricata una versione in C# degli strumenti presenti in wnfun sviluppati da Alex Ionescu (@aionescu) e Gabrielle Viala (@pwissenlit). Quando sviluppero ulteriori strumenti per Windows Notification Facility, verranno caricati qui.

Indice

  • SharpWnfSuite
    • Uso
      • SharpWnfDump
      • SharpWnfNameDumper
      • SharpWnfClient
      • SharpWnfServer
      • SharpWnfScan
      • SharpWnfInject
    • KernelPrimitive
    • WnfCallbackPayload
    • Riferimenti
    • Riconoscimenti

Uso

SharpWnfDump

Torna all'inizio

Progetto

Questo strumento esegue il dump o manipola le informazioni sui WNF State Name. Equivalente a wnfdump.exe e WnfDump.py. Ho apportato alcuni aggiornamenti rispetto allo strumento originale (Exception Handling, Well-Known State Name e nuovo membro WNF_DATA_SCOPE).

Per recuperare le informazioni su tutti i WNF State Name Well-Known, Permanent e Persistent presenti sul tuo host, esegui con il flag -d (--dump):``` PS C:\Dev> .\SharpWnfDump.exe -d

| WNF State Name [WellKnown Lifetime] | S | L | P | AC | N | CurSize | MaxSize | Changes |

| WNF_WEBA_CTAP_DEVICE_STATE | S | W | N | RW | I | 0 | 12 | 0 | | WNF_WEBA_CTAP_DEVICE_CHANGE_NOTIFY | S | W | N | RW | I | 0 | 4 | 0 | | WNF_PNPA_DEVNODES_CHANGED | S | W | N | RO | U | 0 | 0 | 11 |

--snip--

Per mostrare solo i nomi di stato utilizzati nel sistema, imposta il flag `-u` (`--used`).
Questo flag può essere applicato alle opzioni `-d` e `-b`:```
PS C:\Dev> .\SharpWnfDump.exe -d -u

| WNF State Name [WellKnown Lifetime]                             | S | L | P | AC | N | CurSize | MaxSize | Changes |
----------------------------------------------------------------------------------------------------------------------
| WNF_PNPA_DEVNODES_CHANGED                                       | S | W | N | RO | U |       0 |       0 |     140 |
| WNF_AUDC_RENDER                                                 | S | W | N | RO | U |    4096 |    4096 |       7 |
| WNF_AUDC_CAPTURE                                                | S | W | N | RO | U |    4096 |    4096 |       1 |
| WNF_AUDC_SPATIAL_STATUS                                         | S | W | N | RO | U |    4096 |    4096 |       3 |

--snip--

Se desideri recuperare le informazioni del Security Descripter, imposta il flag -s (--sid):``` PS C:\Dev> .\SharpWnfDump.exe -d -s

| WNF State Name [WellKnown Lifetime] | S | L | P | AC | N | CurSize | MaxSize | Changes |

| WNF_WEBA_CTAP_DEVICE_STATE | S | W | N | RW | I | 0 | 12 | 0 |

    D:(A;;CCDC;;;SY)(A;;CCDC;;;BA)(A;;CCDC;;;S-1-5-80-242729624-280608522-2219052887-3187409060-2225943459)(A;;CC;;;AU)(A;;CC;;;AC)

| WNF_WEBA_CTAP_DEVICE_CHANGE_NOTIFY | S | W | N | RW | I | 0 | 4 | 0 |

    D:(A;;CCDC;;;SY)(A;;CCDC;;;BA)(A;;CCDC;;;S-1-5-80-242729624-280608522-2219052887-3187409060-2225943459)(A;;CC;;;AU)(A;;CC;;;AC)

| WNF_PNPA_DEVNODES_CHANGED | S | W | N | RO | U | 0 | 0 | 11 |

    D:(A;;CC;;;BU)(A;;CCDC;;;SY)

--snip--

Se vuoi recuperare i dati del buffer, imposta il flag `-v` (`--value`) o `-r` (`--read`).
Questi flag possono essere usati con il flag `-s`:```
PS C:\Dev> .\SharpWnfDump.exe -d -v

| WNF State Name [WellKnown Lifetime]                             | S | L | P | AC | N | CurSize | MaxSize | Changes |
----------------------------------------------------------------------------------------------------------------------
| WNF_WEBA_CTAP_DEVICE_STATE                                      | S | W | N | RW | I |       0 |      12 |       0 |
| WNF_WEBA_CTAP_DEVICE_CHANGE_NOTIFY                              | S | W | N | RW | I |       0 |       4 |       0 |

--snip--

| WNF_AUDC_RENDER                                                 | S | W | N | RO | U |    4096 |    4096 |       1 |

                   00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F

        00000000 | 01 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 | ........ ........
        00000010 | 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 | ........ ........
        00000020 | 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 | ........ ........

--snip--

Per recuperare informazioni su tutti i Temporary WNF State Names sul tuo host, esegui con il flag -b (--brut):``` PS C:\Dev> .\SharpWnfDump.exe -b

| WNF State Name [System Scope] | S | L | P | AC | N | CurSize | MaxSize | Changes |

| 0x41C64E6DA3AC3845 | S | T | N | RW | A | 8 | ? | 1 | | 0x41C64E6DA3AC4845 | S | T | N | RW | A | 8 | ? | 1 | | 0x41C64E6DA3AC6845 | S | T | N | RW | A | 8 | ? | 1 |

--snip--

Il flag `-b` (`--brut`) può essere usato con il flag `-v` (`--value`) o `-r` (`--read`), ma non può essere usato con il flag `-s` (`--sid`).

Il significato di ciascuna colonna nella tabella ottenuta dai risultati dell'opzione `--dump` o `--brut` è il seguente:

| Column Name | Description |
| :--- | :--- |
| `WNF State Name` | Qui vengono visualizzati i WNF State Name |
| `S` | Ambito dei dati per il WNF State Name. I significati delle lettere visualizzate sono i seguenti:<br><br>+ `S` : Ambito di sistema<br>+ `s` : Ambito di sessione<br>+ `U` : Ambito utente<br>+ `P` : Ambito di processo<br>+ `M` : Ambito macchina<br>+ `p` : Ambito macchina fisica |
| `L` | Durata (lifetime) per il WNF State Name. I significati delle lettere visualizzate sono i seguenti:<br><br>+ `W` : Ben noto<br>+ `P` : Permanente<br>+ `V` : Persistente (volatile)<br>+ `T` : Temporaneo |
| `P` | Indica se il WNF State Name è permanente:<br><br>+ `Y` : Sì<br>+ `N` : No |
| `AC` | Controllo di accesso per il WNF State Name:<br><br>+ `RW` : Leggibile e scrivibile<br>+ `RO` : Sola lettura<br>+ `WO` : Solo scrittura<br>+ `NA` : Non leggibile né scrivibile |
| `N` | Indica l'esistenza di sottoscrittori:<br><br>+ `A` : Il sottoscrittore esiste<br>+ `I` : Nessun sottoscrittore esiste<br>+ `U` : Sconosciuto |
| `CurSize` | Il numero indica la dimensione corrente del buffer utilizzato per il WNF State Name. |
| `MaxSize` | Il numero indica la dimensione massima del buffer utilizzabile per il WNF State Name. |
| `Changes` | Il numero indica quante volte è stato aggiornato. |

Se si desidera recuperare informazioni su uno specifico WNF State Name, eseguire `SharpWnfDump.exe` con l'opzione `-i` (`--info`) come segue:```
PS C:\Dev> .\SharpWnfDump.exe -i WNF_SHEL_APPRESOLVER_SCAN
Scarica lo strumento