Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
ツール/GitHubGitHub/wh0amitz/sharpadws
特権昇格偵察永続化メカニズムエクスプロイト横移動ポストエクスプロイトペネトレーションテスト認証レッドチーミング
GitHubwh0amitz/sharpadws

SharpADWS

Active Directory の偵察および Red Team 向けの Active Directory Web サービス (ADWS) 経由のエクスプロイト。

60259152年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
リポジトリを見る

SharpADWS

中文文档

Active Directory Web Services(ADWS)を介したRed Team向けのActive Directory偵察および攻撃ツール。

概要

SharpADWSは、Active Directory Web Services(ADWS)プロトコルを介してActive Directoryデータを収集・変更する、Red Team向けのActive Directory偵察および攻撃ツールです。

通常、Active Directoryの列挙や操作はLDAPプロトコルを通じて行われます。SharpADWSは、LDAPサーバーと直接通信せずにActive Directoryデータを抽出または変更できます。ADWSでは、LDAPクエリは一連のSOAPメッセージにラップされ、NET TCPバインディング暗号化チャネルを使用してADWSサーバーに送信されます。ADWSサーバーはLDAPクエリをローカルで展開し、同じドメインコントローラー上で動作するLDAPサーバーに転送します。

Active Directory Web Services(ADWS)はActive Directory Domain Services(ADDS)のインストール時に自動的に有効化されるため、SharpADWSはすべてのドメイン環境で汎用的に使用できます。

利点

ADWSをLDAPのポストエクスプロイテーションに使用する主な利点の1つは、比較的知られていないこと、そしてLDAPトラフィックがネットワーク上に送信されないため、一般的な監視ツールで検出されにくいことです。ADWSはLDAPとはまったく異なるサービスとして動作し、TCPポート9389で利用可能で、インターフェースとしてSOAPプロトコルを使用します。

ADWSを調査する中で、SOAP Webサービスであるため、LDAPクエリの実際の実行はドメインコントローラー上でローカルに行われることに気づきました。これにより、有益な興味深い副作用がいくつか発生します。例えば、ドメインコントローラー上のLDAPクエリを分析する際に、クエリが127.0.0.1のログから発信されていることに気づくかもしれませんが、多くの場合、これは無視されます。

これの副次的な利点として、このアクティビティはLDAPSearchアクションタイプのDeviceEventsには表示されないため、テレメトリデータがほとんど利用できなくなります。

プロトコルの実装

SharpADWSは、MS-ADDM、MS-WSTIM、およびMS-WSDSプロトコルを実装しています。このプロジェクトのソースコードを使用すると、Active Directory Web Services上で以下の操作を簡単に実装できます:

  • Enumerate:指定された検索クエリフィルターに対応するコンテキストを作成します。
  • Pull:特定の列挙のコンテキスト内で結果オブジェクトを取得します。
  • Renew:指定された列挙コンテキストの有効期限を更新します。
  • GetStatus:指定された列挙コンテキストの有効期限を取得します。
  • Release:指定された列挙コンテキストを解放します。
  • Delete:既存のオブジェクトを削除します。
  • Get:オブジェクトから1つ以上のプロパティを取得します。
  • Put:オブジェクト上の1つ以上のプロパティの内容を変更します。
    • Add:指定されたプロパティ値の値を、指定されたプロパティの値セットに追加します。ターゲットオブジェクトにプロパティが存在しない場合は作成します。
    • Replace:指定されたプロパティの値セットを、操作で指定された値で置き換えます。ターゲットオブジェクトにプロパティが存在しない場合は作成します。操作で値が指定されていない場合、現在指定されている属性のすべての値が削除されます。
    • Delete:指定された属性から指定された属性値を削除します。値が指定されていない場合、すべての値が削除されます。指定されたプロパティがターゲットオブジェクトに存在しない場合、PUT要求は失敗します。
  • Create:新しいオブジェクトを作成します。

使用方法

コマンドライン引数 -h を使用すると、以下の使用法情報が表示されます:```cmd C:\Users\Marcus>SharpADWS.exe -h

SharpADWS 1.0.0-beta - Copyright (c) 2024 WHOAMI (whoamianony.top)

-h Display this help screen

Connection options: -d Specify domain for enumeration -u Username to use for ADWS Connection -p Password to use for ADWS Connection

Supported methods: Cache Dump all objectSids to cache file for Acl methods Acl Enumerate and analyze DACLs for specified objects, specifically Users, Computers, Groups, Domains, DomainControllers and GPOs DCSync Enumerate all DCSync-capable accounts and can set DCSync backdoors DontReqPreAuth Enumerates all accounts that do not require kerberos preauthentication, and can enable this option for accounts Kerberoastable Enumerates all Kerberoastable accounts, and can write SPNs for accounts AddComputer Add a machine account within the scope of ms-DS-MachineAccountQuota for RBCD attack RBCD Read, write and remove msDS-AllowedToActOnBehalfOfOtherIdentity attributes for Resource-Based Constrained Delegation attack Certify Enumerate all ADCS data like Certify.exe, and can write template attributes Whisker List, add and remove msDS-KeyCredentialLink attribute like Whisker.exe for ShadowCredentials attack FindDelegation Enumerate all delegation relationships for the target domain

Acl options: -dn RFC 2253 DN to base search from -scope Set your Scope, support Base (Default), Onelevel, Subtree -trustee The sAMAccountName of a security principal to check for its effective permissions -right Filter DACL for a specific AD rights -rid Specify a rid value and filter out DACL that security principal's rid is greater than it -user Enumerate DACL for all user objects -computer Enumerate DACL for all computer objects -group Enumerate DACL for all group objects -domain Enumerate DACL for all domain objects -domaincontroller Enumerate DACL for all domain controller objects -gpo Enumerate DACL for all gpo objects

DCSync options: -action [{list, write}] Action to operate on DCSync method list List all accounts with DCSync permissions write Escalate accounts with DCSync permissions -target Specify the sAMAccountName of the account

DontReqPreAuth options: -action [{list, write}] Action to operate on DontReqPreAuth method list List all accounts that do not require kerberos preauthentication write Enable do not require kerberos preauthentication for an account -target Specify the sAMAccountName of the account

Kerberoastable options: -action [{list, write}] Action to operate on Kerberoastable method list List all kerberoastable accounts write Write SPNs for an account to kerberoast -target Specify the sAMAccountName of the account

AddComputer options: -computer-name Name of computer to add, without '$' suffix -computer-pass Password to set for the computer

RBCD options: -action [{read,write,remove}] Action to operate on RBCD method read Read the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of the account write Write the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of the account remove Remove the msDS-AllowedToActOnBehalfOfOtherIdentity attribute value of the account added by the write action

Certify options: -action [{find, modify}] Action to operate on Certify method find Find all CA and certificate templates modify Modify certificate templates -enrolleeSuppliesSubject Enumerate certificate templates with CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag for find action, and can enable CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag for modify action -clientAuth Enumerate certificate templates with client authentication pKIExtendedKeyUsage for find action, and can enable Client Authentication for modify action

Whisker options: -action [{list, add, remove}] Action to operate on ShadowCredentials method list List all the values of the msDS-KeyCredentialLink attribute for an account add Add a new value to the msDS-KeyCredentialLink attribute for an account remove Remove a value from the msDS-KeyCredentialLink attribute for an account -device-id Specify the DeviceID to remove -target Specify the sAMAccountName of the account

FindDelegation options: No options, just run!

### Cache

SharpADWS が ACL を列挙する際、未知の trustee オブジェクトごとに追加の ADWS リクエストを実行しないようにするため、cacheメソッドを使用して事前にすべてのアカウントオブジェクトの完全なキャッシュを作成し、ファイルに保存する必要があります。これにより、大量の(不必要な)フローを回避します。キャッシュには、現在のドメイン内の各アカウントオブジェクト名とその objectSid のマッピングが含まれています。```cmd
C:\Users\Marcus>SharpADWS.exe Cache

[*] Cache file has been generated: object.cache

Acl

ツールをダウンロード