Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
Active-Directory-Exploitation-Cheat-Sheet — Windows Active Directoryの一般的な列挙および攻撃方法を含むチートシート | Kitploit
ツール/GitHubGitHub/s1ckb0y1337/active-directory-exploitation-cheat-sheet
特権昇格偵察エクスプロイト横移動ポストエクスプロイトペネトレーションテスト学習と教育厳選リソース

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
GitHub
s1ckb0y1337/active-directory-exploitation-cheat-sheet

Active-Directory-Exploitation-Cheat-Sheet

Windows Active Directoryの一般的な列挙および攻撃方法を含むチートシート

リポジトリを見る
6.7k1.3k354ヶ月前Kitploit レビュー済み

Active Directory エクスプロイトチートシート

このチートシートには、Windows Active Directory の一般的な列挙と攻撃手法が含まれています。

ℹ️ このリポジトリは Nikos Katsiopis と Nikos Vourdas によって作成されました。

このチートシートは、PayloadAllTheThings リポジトリからインスピレーションを得ています。

Just Walking The Dog

概要

  • Active Directory エクスプロイトチートシート
    • 概要
    • ツール
    • ドメイン列挙
      • PowerView の使用
      • AD モジュールの使用
      • BloodHound の使用
        • リモート BloodHound
        • オンサイト BloodHound
      • Adalanche の使用
        • リモート Adalanche
      • 列挙オブジェクトのエクスポート
      • 便利な列挙ツール
    • ローカル権限昇格
      • 便利なローカル権限昇格ツール
    • 水平移動
      • PowerShell リモート処理
      • PS 資格情報によるリモートコード実行
      • PowerShell モジュールのインポートとリモートでの関数実行
      • リモートステートフルコマンドの実行
      • Mimikatz
      • リモートデスクトッププロトコル
      • URL ファイル攻撃
      • 便利なツール
    • ドメイン権限昇格
      • Kerberoast
      • ASREPRoast
      • パスワードスプレー攻撃
      • SPN の強制設定
      • シャドウコピーの悪用
      • Mimikatz を使用した保存済み資格情報の一覧表示と復号化
      • 制約なし委任
      • 制約付き委任
      • リソースベースの制約付き委任
      • DNSAdmins の悪用
      • Active Directory 統合 DNS の悪用
      • バックアップオペレーターグループの悪用
      • Exchange の悪用
      • プリンターバグの武器化
      • ACL の悪用
      • mitm6 による IPv6 の悪用
      • SID 履歴の悪用
      • SharePoint の悪用
      • Zerologon
      • PrintNightmare
      • Active Directory 証明書サービス
      • No PAC
    • ドメイン永続化
      • ゴールデンチケット攻撃
      • DCsync 攻撃
      • シルバーチケット攻撃
      • スケルトンキー攻撃
      • DSRM の悪用
      • カスタム SSP
    • フォレスト間攻撃
      • 信頼チケット
      • MSSQL サーバーの悪用
      • フォレスト信頼の破壊

ツール

  • Powersploit
  • PowerUpSQL
  • Powermad
  • Impacket
  • Mimikatz
  • Rubeus -> Compiled Version
  • BloodHound
  • AD Module
  • ASREPRoast
  • Adalanche

ドメイン列挙

PowerView の使用 ```powershell

Get-DomainPolicy

#Will show us the policy configurations of the Domain about system access or kerberos Get-DomainPolicy | Select-Object -ExpandProperty SystemAccess Get-DomainPolicy | Select-Object -ExpandProperty KerberosPolicy

- **ドメインコントローラの取得:**  ```powershell
Get-DomainController
Get-DomainController -Domain <DomainName>
  • ドメインユーザーの列挙: ```powershell #Save all Domain Users to a file Get-DomainUser | Out-File -FilePath .\DomainUsers.txt

    #Will return specific properties of a specific user Get-DomainUser -Identity [username] -Properties DisplayName, MemberOf | Format-List

    #Enumerate user logged on a machine Get-NetLoggedon -ComputerName

    #Enumerate Session Information for a machine Get-NetSession -ComputerName

    #Enumerate domain machines of the current/specified domain where specific users are logged into Find-DomainUserLocation -Domain | Select-Object UserName, SessionFromName

  • ドメインコンピュータの列挙: ```powershell Get-DomainComputer -Properties OperatingSystem, Name, DnsHostName | Sort-Object -Property DnsHostName

    #Enumerate Live machines Get-DomainComputer -Ping -Properties OperatingSystem, Name, DnsHostName | Sort-Object -Property DnsHostName

  • グループとグループメンバーの列挙: ```powershell #Save all Domain Groups to a file: Get-DomainGroup | Out-File -FilePath .\DomainGroup.txt

    #Return members of Specific Group (eg. Domain Admins & Enterprise Admins) Get-DomainGroup -Identity '' | Select-Object -ExpandProperty Member Get-DomainGroupMember -Identity '' | Select-Object MemberDistinguishedName

    #Enumerate the local groups on the local (or remote) machine. Requires local admin rights on the remote machine Get-NetLocalGroup | Select-Object GroupName

    #Enumerates members of a specific local group on the local (or remote) machine. Also requires local admin rights on the remote machine Get-NetLocalGroupMember -GroupName Administrators | Select-Object MemberName, IsGroup, IsDomain

    #Return all GPOs in a domain that modify local group memberships through Restricted Groups or Group Policy Preferences Get-DomainGPOLocalGroup | Select-Object GPODisplayName, GroupName

  • 共有の列挙: ```powershell #Enumerate Domain Shares Find-DomainShare

    #Enumerate Domain Shares the current user has access Find-DomainShare -CheckShareAccess

    #Enumerate "Interesting" Files on accessible shares Find-InterestingDomainShareFile -Include passwords

  • グループポリシーの列挙: ```powershell Get-DomainGPO -Properties DisplayName | Sort-Object -Property DisplayName

    #Enumerate all GPOs to a specific computer Get-DomainGPO -ComputerIdentity -Properties DisplayName | Sort-Object -Property DisplayName

    #Get users that are part of a Machine's local Admin group Get-DomainGPOComputerLocalGroupMapping -ComputerName

  • OUを列挙: ```powershell Get-DomainOU -Properties Name | Sort-Object -Property Name

  • ACLの列挙: ```powershell

    Returns the ACLs associated with the specified account

    Get-DomainObjectAcl -Identity -ResolveGUIDs

    #Search for interesting ACEs Find-InterestingDomainAcl -ResolveGUIDs

    #Check the ACLs associated with a specified path (e.g smb share) Get-PathAcl -Path "\Path\Of\A\Share"

  • ドメイン信頼の列挙: ```powershell Get-DomainTrust Get-DomainTrust -Domain

    #Enumerate all trusts for the current domain and then enumerates all trusts for each domain it finds Get-DomainTrustMapping

  • フォレスト信頼の列挙: ```powershell Get-ForestDomain Get-ForestDomain -Forest

    #Map the Trust of the Forest Get-ForestTrust Get-ForestTrust -Forest

  • ユーザーハンティング: ```powershell #Finds all machines on the current domain where the current user has local admin access Find-LocalAdminAccess -Verbose

    #Find local admins on all machines of the domain Find-DomainLocalGroupMember -Verbose

    #Find computers were a Domain Admin OR a specified user has a session Find-DomainUserLocation | Select-Object UserName, SessionFromName

    #Confirming admin access Test-AdminAccess

❗ ユーザーハンティングによるドメイン管理者への権限昇格:
マシンに対してローカル管理者権限を持っている -> そのマシンにドメイン管理者のセッションがある -> トークンを奪い、なりすます -> Profit!

AD モジュールの使用

  • 現在のドメインを取得: Get-ADDomain
  • 他のドメインを列挙: Get-ADDomain -Identity <Domain>
  • ドメイン SID を取得: Get-DomainSID
  • ドメインコントローラを取得: ```powershell Get-ADDomainController Get-ADDomainController -Identity
  • ドメインユーザーの列挙: ```powershell Get-ADUser -Filter * -Identity -Properties *
ツールをダウンロード