Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
windows-coerced-authentication-methods — A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols. | Kitploit
Strumenti/GitHubGitHub/p0dalirius/windows-coerced-authentication-methods
Privilege EscalationExploitationPenetration TestingAuthenticationRed TeamingCurated Resources
GitHubp0dalirius/windows-coerced-authentication-methods

windows-coerced-authentication-methods

A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols.

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
Vedi RepositorySito web
601721314 giorni faRevisionato da Kitploit
Contenuto non disponibile nella lingua richiesta. Visualizzazione della versione inglese.


This repository contains a list of many methods to coerce a windows machine to authenticate to an attacker-controlled machine.
GitHub repo size YouTube Channel Subscribers

All of these methods are callable by a standard user in the domain to force the machine account of the target Windows machine (usually a domain controller) to authenticate to an arbitrary target. The root cause of this "vulnerability/feature" in each of these methods is that Windows machines automatically authenticate to other machines when trying to access UNC paths (like \\192.168.2.1\SYSVOL\file.txt).

There are currently 30 working functions in 13 protocols.


Protocols & Methods

  • [MS-COMA]: Component Object Model Plus (COM+) Remote Administration Protocol

    • Remote call to ImportFromFile (opnum 3)/README.md)
  • [MS-DFSNM]: Distributed File System (DFS) Namespace Management Protocol

    • Remote call to NetrDfsAdd (opnum 1)/README.md)
    • Remote call to NetrDfsAddStdRoot (opnum 12)/README.md)
    • Remote call to NetrDfsRemoveStdRoot (opnum 13)/README.md)
    • Remote call to NetrDfsAddRootTarget (opnum 23)/README.md)
    • Remote call to NetrDfsRemoveRootTarget (opnum 24)/README.md)
  • [MS-DHCPM]: Microsoft Dynamic Host Configuration Protocol (DHCP) Server Management Protocol

    • Remote call to R_DhcpBackupDatabase (opnum 44)/README.md)
    • Remote call to R_DhcpRestoreDatabase (opnum 45)/README.md)
  • [MS-DNSP]: Domain Name Service (DNS) Server Management Protocol

    • Remote call to R_DnssrvOperation — LogFilePath (opnum 0)/README.md)
  • [MS-EFSR]: Encrypting File System Remote (EFSRPC) Protocol

    • Remote call to EfsRpcOpenFileRaw (opnum 0)/README.md)
    • Remote call to EfsRpcEncryptFileSrv (opnum 4)/README.md)
    • Remote call to EfsRpcDecryptFileSrv (opnum 5)/README.md)
    • Remote call to EfsRpcQueryUsersOnFile (opnum 6)/README.md)
    • Remote call to EfsRpcQueryRecoveryAgents (opnum 7)/README.md)
    • Remote call to EfsRpcFileKeyInfo (opnum 12)/README.md)
    • Remote call to EfsRpcDuplicateEncryptionInfoFile (opnum 13)/README.md)
    • Remote call to EfsRpcAddUsersToFileEx (opnum 15)/README.md)
    • Remote call to EfsRpcFileKeyInfoEx (opnum 16)/README.md)
    • Remote call to EfsRpcEncryptFileExSrv (opnum 21)/README.md)
Scarica lo strumento