Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
smbmap — SMB共有列挙ツール。ドメイン間のドライブ、権限、および内容をリスト表示します。ファイルのアップロード/ダウンロード/削除、リモートコマンド実行、パス・ザ・ハッシュ、Kerberos、および再帰的なコンテンツ検索をサポートしており、ペネトレーションテストに使用されます。 | Kitploit
ツール/GitHubGitHub/shawndevans/smbmap
偵察脆弱性分析情報収集ネットワークセキュリティペネトレーションテスト
GitHubshawndevans/smbmap

smbmap

SMB共有列挙ツール。ドメイン間のドライブ、権限、および内容をリスト表示します。ファイルのアップロード/ダウンロード/削除、リモートコマンド実行、パス・ザ・ハッシュ、Kerberos、および再帰的なコンテンツ検索をサポートしており、ペネトレーションテストに使用されます。

リポジトリを見る
2.1k367298ヶ月前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

SMBMap

SMBMapを使用すると、ドメイン全体にわたるSamba共有ドライブを列挙できます。共有ドライブの一覧表示、ドライブの権限、共有内容、アップロード/ダウンロード機能、ファイル名の自動ダウンロードパターンマッチング、さらにはリモートコマンドの実行が可能です。このツールはペネトレーションテストを念頭に置いて設計されており、大規模ネットワーク上の潜在的な機密データの検索を簡素化することを目的としています。

一部の機能は十分にテストされていないため、バグが見つかり次第、変更が行われます。私は実際にエンゲージメント中にのみバグを見つけて修正するため、進捗はやや遅いです。フィードバックやバグ報告をいただければ幸いです。

Note SMBMapはPython3にアップデートされました!

Installation```bash

$ sudo pip3 install smbmap $ smbmap smbmap usage: smbmap [-h] (-H HOST | --host-file FILE) [-u USERNAME] [-p PASSWORD | --prompt] [-s SHARE] [-d DOMAIN] [-P PORT] [-v] [--admin] [--no-banner] [--no-color] [--no-update] [-x COMMAND] [--mode CMDMODE] [-L | -r [PATH]] [-A PATTERN | -g FILE | --csv FILE] [--dir-only] [--no-write-check] [-q] [--depth DEPTH] [--exclude SHARE [SHARE ...]] [-F PATTERN] [--search-path PATH] [--search-timeout TIMEOUT] [--download PATH] [--upload SRC DST] [--delete PATH TO FILE] [--skip] ...

## Features:
- Pass-the-Hash サポート
- ファイルのアップロード/ダウンロード/削除
- 権限の列挙 (書き込み可能な共有、Metasploit との連携)
- リモートコマンド実行
- 分散ファイルコンテンツ検索 (ベータ版!)
- ファイル名マッチング (自動ダウンロード機能付き)
- ホストファイルパーサーは IP、ホスト名、CIDR をサポート
- SMB 署名検出
- サーバーバージョン出力
- Kerberos サポート! (超ベータ版)

## ヘルプ```
usage: smbmap.py [-h] (-H HOST | --host-file FILE) [-u USERNAME] [-p PASSWORD | --prompt] [-k] [--no-pass] [--dc-ip IP or Host] [-s SHARE] [-d DOMAIN] [-P PORT] [-v] [--signing] [--admin] [--no-banner] [--no-color] [--no-update]
                 [--timeout SCAN_TIMEOUT] [-x COMMAND] [--mode CMDMODE] [-L | -r [PATH]] [-g FILE | --csv FILE] [--dir-only] [--no-write-check] [-q] [--depth DEPTH] [--exclude SHARE [SHARE ...]] [-A PATTERN] [-F PATTERN]
                 [--search-path PATH] [--search-timeout TIMEOUT] [--download PATH] [--upload SRC DST] [--delete PATH TO FILE] [--skip]

    ________  ___      ___  _______   ___      ___       __         _______
   /"       )|"  \    /"  ||   _  "\ |"  \    /"  |     /""\       |   __ "\
  (:   \___/  \   \  //   |(. |_)  :) \   \  //   |    /    \      (. |__) :)
   \___  \    /\  \/.    ||:     \/   /\   \/.    |   /' /\  \     |:  ____/
    __/  \   |: \.        |(|  _  \  |: \.        |  //  __'  \    (|  /
   /" \   :) |.  \    /:  ||: |_)  :)|.  \    /:  | /   /  \   \  /|__/ \
  (_______/  |___|\__/|___|(_______/ |___|\__/|___|(___/    \___)(_______)
-----------------------------------------------------------------------------
SMBMap - Samba Share Enumerator v1.10.7 | Shawn Evans - [email protected]
                     https://github.com/ShawnDEvans/smbmap

options:
  -h, --help            show this help message and exit

Main arguments:
  -H HOST               IP or FQDN
  --host-file FILE      File containing a list of hosts
  -u USERNAME, --username USERNAME
                        Username, if omitted null session assumed
  -p PASSWORD, --password PASSWORD
                        Password or NTLM hash, format is LMHASH:NTHASH
  --prompt              Prompt for a password
  -s SHARE              Specify a share (default C$), ex 'C$'
  -d DOMAIN             Domain name (default WORKGROUP)
  -P PORT               SMB port (default 445)
  -v, --version         Return the OS version of the remote host
  --signing             Check if host has SMB signing disabled, enabled, or required
  --admin               Just report if the user is an admin
  --no-banner           Removes the banner from the top of the output
  --no-color            Removes the color from output
  --no-update           Removes the "Working on it" message
  --timeout SCAN_TIMEOUT
                        Set port scan socket timeout. Default is .5 seconds

Kerberos settings:
  -k, --kerberos        Use Kerberos authentication
  --no-pass             Use CCache file (export KRB5CCNAME='~/current.ccache')
  --dc-ip IP or Host    IP or FQDN of DC

Command Execution:
  Options for executing commands on the specified host

  -x COMMAND            Execute a command ex. 'ipconfig /all'
  --mode CMDMODE        Set the execution method, wmi or psexec, default wmi

Shard drive Search:
  Options for searching/enumerating the share of the specified host(s)

  -L                    List all drives on the specified host, requires ADMIN rights.
  -r [PATH]             Recursively list dirs and files (no share\path lists the root of ALL shares), ex. 'email/backup'
  -g FILE               Output to a file in a grep friendly format, used with -r (otherwise it outputs nothing), ex -g grep_out.txt
  --csv FILE            Output to a CSV file, ex --csv shares.csv
  --dir-only            List only directories, ommit files.
  --no-write-check      Skip check to see if drive grants WRITE access.
  -q                    Quiet verbose output. Only shows shares you have READ or WRITE on, and suppresses file listing when performing a search (-A).
  --depth DEPTH         Traverse a directory tree to a specific depth. Default is 1 (root node).
  --exclude SHARE [SHARE ...]
                        Exclude share(s) from searching and listing, ex. --exclude ADMIN$ C$'
  -A PATTERN            Define a file name pattern (regex) that auto downloads a file on a match (requires -r), not case sensitive, ex '(web|global).(asax|config)'

File Content Search:
  Options for searching the content of files (must run as root), kind of experimental

  -F PATTERN            File content search, -F '[Pp]assword' (requires admin access to execute commands, and PowerShell on victim host)
  --search-path PATH    Specify drive/path to search (used with -F, default C:\Users), ex 'D:\HR\'
  --search-timeout TIMEOUT
                        Specifcy a timeout (in seconds) before the file search job gets killed. Default is 300 seconds.

Filesystem interaction:
  Options for interacting with the specified host's filesystem

  --download PATH       Download a file from the remote system, ex.'C$\temp\passwords.txt'
  --upload SRC DST      Upload a file to the remote system ex. '/tmp/payload.exe C$\temp\payload.exe'
  --delete PATH TO FILE
                        Delete a remote file, ex. 'C$\temp\msf.exe'
  --skip                Skip delete file confirmation prompt

Examples:

$ python smbmap.py -u jsmith -p password1 -d workgroup -H 192.168.0.1
$ python smbmap.py -u jsmith -p 'aad3b435b51404eeaad3b435b51404ee:da76f2c4c96028b7a6111aef4a50a94d' -H 172.16.0.20
$ python smbmap.py -u 'apadmin' -p 'asdf1234!' -d ACME -Hh 10.1.3.30 -x 'net group "Domain Admins" /domain'

デフォルトの出力:```

$ ./smbmap.py -H 192.168.86.214 -u Administrator -p asdf1234

________  ___      ___  _______   ___      ___       __         _______

/" )|" \ /" || _ "\ |" \ /" | /""\ | __ "
(: _/ \ \ // |(. |_) :) \ \ // | / \ (. |) :) ___ \ /\ /. ||: / /\ /. | /' /\ \ |: / __/ \ |: . |(| _ \ |: . | // __' \ (| / /" \ :) |. \ /: ||: |) :)|. \ /: | / / \ \ /|/
(
/ ||_/||(/ ||_/||(/ _)(_______)

 SMBMap - Samba Share Enumerator | Shawn Evans - [email protected]
                 https://github.com/ShawnDEvans/smbmap
ツールをダウンロード