
AD Enumは、LDAPプロトコルを通じて設定ミスを発見し、Kerberosを使用してそれらの弱点の一部を悪用することを可能にするペンテスティングツールです。
ADEnum.pyADEnum.py は、LDAPプロトコルを介して設定ミスを発見し、Kerberosを利用してそれらの脆弱性を悪用するためのペネトレーションテストツールです。
█████╗ ██████╗ ███████╗███╗ ██╗██╗ ██╗███╗ ███╗
██╔══██╗██╔══██╗ ██╔════╝████╗ ██║██║ ██║████╗ ████║
███████║██║ ██║ █████╗ ██╔██╗ ██║██║ ██║██╔████╔██║
██╔══██║██║ ██║ ██╔══╝ ██║╚██╗██║██║ ██║██║╚██╔╝██║
██║ ██║██████╔╝ ███████╗██║ ╚████║╚██████╔╝██║ ╚═╝ ██║
╚═╝ ╚═╝╚═════╝ ╚══════╝╚═╝ ╚═══╝ ╚═════╝ ╚═╝ ╚═╝
usage: ADenum.py -d [domain] -u [username] -p [password]
Pentest tool that detect misconfig in AD with LDAP
options:
-h, --help show this help message and exit
-d [domain] The name of domain (e.g. "test.local")
-u [username] The user name
-p [password] The user password
-ip [ipAddress] The IP address of the server (e.g. "1.1.1.1")
-j Enable hash cracking (john)
-jp [path] John binary path
-w [wordList] The path of the wordlist to be used john (Default: /usr/share/seclists/Passwords/Leaked-
Databases/rockyou.txt
-v, --version Show program's version number and exit
-s Use LDAP with SSL
-c, --NPUsersCheck Check with GetNPUsers.py for ASREP Roastable
Impacket (https://github.com/SecureAuthCorp/impacket)
Python 3
Debian または Ubuntu を使用している場合:
$ sudo apt-get install libsasl2-dev python-dev libldap2-dev libssl-dev
Kali を使用している場合:
$ sudo apt-get install libsasl2-dev python2-dev libldap2-dev libssl-dev
pip3:
$ pip3 install -r requirements.txt
ATA は2つの不審なイベントを検出しますが、アラートはトリガーしません:
次のスクリーンショットに示すように:

ドキュメント:
Impacket:
This project is made for educational and ethical testing purposes only. Usage of this software for attacking targets without prior mutual consent is illegal.
It is the end user's responsibility to obey all applicable local, state and federal laws.
Developers assume no liability and are not responsible for any misuse or damage caused by this program.