Active Directory LDAP セキュリティ監査ツール(AI分析機能搭載)
AD環境のセキュリティ体制を列挙・評価・スコアリング
_ ____ _ ____ ____ _ ___
| | | _ \ / \ | _ \| _ \ ___ ___ ___ _ __ / \ |_ _|
| | | | | |/ _ \ | |_) | |_) / _ \/ __/ _ \| '_ \ / _ \ | |
| |___| |_| / ___ \| __/| _ < __/ (_| (_) | | | |/ ___ \ | |
|_____|____/_/ \_\_| |_| \_\___|\___\___/|_| |_/_/ \_\___|
免責事項 / AVERTISSEMENT
このツールは許可されたセキュリティ監査のみを目的としています。コンピュータシステムへの不正アクセスは違法です。セキュリティ評価を実施する前に、必ず適切な書面による許可を取得してください。
Cet outil est destine uniquement aux audits de securite autorises. L'acces non autorise aux systemes informatiques est illegal. Obtenez toujours une autorisation ecrite avant de realiser un audit de securite.
LDAPRecon-AI は、Active Directory の LDAP セキュリティを包括的に監査するツールです。ユーザー、グループ、コンピュータ、委任、GPO、信頼関係を列挙し、AD ドメインのセキュリティ体制を評価します。Pingcastle スタイルのスコア(0~100) を提供し、詳細な発見結果は CIS Benchmark、ANSSI AD 推奨事項、MITRE ATT&CK のテクニックにマッピングされます。
LDAPRecon-AI/
src/ldaprecon_ai/
__init__.py # パッケージ初期化
cli.py # Rich CLI(サブコマンド)
enumerator.py # コア LDAP 列挙エンジン
filters.py # セキュリティ特化型 LDAP フィルタライブラリ
models.py # Pydantic データモデル
reporter.py # マルチフォーマットレポート生成
scorer.py # セキュリティ体制スコアリングエンジン
tests/
conftest.py # 共有テストフィクスチャ
test_enumerator.py # Enumerator の単体テスト
test_filters.py # Filter の単体テスト
test_scorer.py # Scorer の単体テスト
git clone https://github.com/ayinedjimi/LDAPRecon-AI.git
cd LDAPRecon-AI
pip install -e ".[dev]"
ldaprecon-ai -s dc01.corp.example.com -d corp.example.com \
-u "CORP\\auditor" -p "P@ssw0rd" audit -o ./reports
ldaprecon-ai -s dc01 -d corp.example.com -u [email protected] \
-p "P@ssw0rd" users --risk-only --min-score 25
ldaprecon-ai -s dc01 -d corp.example.com -u "CORP\\auditor" \
-p "P@ssw0rd" delegation
ldaprecon-ai -s dc01 -d corp.example.com -u "CORP\\auditor" \
-p "P@ssw0rd" score --json
ldaprecon-ai -s dc01 -d corp.example.com -u "CORP\\auditor" \
-p "P@ssw0rd" --openai-key sk-... audit -o ./reports
| チェック | カテゴリ | リスクレベル | MITRE | CIS | ANSSI |
|---|---|---|---|---|---|
| Kerberoastable アカウント | Kerberos | 高 | T1558.003 | 1.1.4 | AD-R29 |
| AS-REP roastable | Kerberos | 高 | T1558.004 | - | AD-R29 |
| 無制限委任 | 委任 | 重大 | T1550.003 | 2.3.10.7 | AD-R26 |
| パスワードが期限切れにならない | パスワード | 中 | T1110 | 1.1.5 | AD-R36 |
| パスワードが不要 | パスワード | 重大 | T1078 | 1.1.3 | AD-R36 |
| DES のみの暗号化 | Kerberos | 重大 | T1558 | 2.3.6.1 | AD-R30 |
| 旧 OS | コンピュータ | 高 | T1210 | 18.10.43.1 | - |
| SID フィルタリング無効 | 信頼 | 重大 | T1134.005 | - | AD-R15 |
| 弱いパスワードポリシー | パスワード | 中 | T1110.001 | 1.1.1 | AD-R36 |
| AdminSDHolder の孤立 | 特権 | 中 | T1078.002 | - | AD-R14 |
pytest tests/ -v --tb=short
LDAPRecon-AI est un outil complet d'audit de securite LDAP pour Active Directory. Il enumere les utilisateurs, groupes, ordinateurs, delegations, GPOs et relations d'approbation pour evaluer la posture de securite d'un domaine AD. Il fournit un score type Pingcastle (0-100) avec des resultats mappes sur CIS Benchmark, Recommandations ANSSI AD et MITRE ATT&CK.
# Audit complet
ldaprecon-ai -s dc01.corp.example.com -d corp.example.com \
-u "CORP\\auditeur" -p "MotDePasse" audit -o ./rapports
# Utilisateurs a risque uniquement
ldaprecon-ai -s dc01 -d corp.example.com -u [email protected] \
-p "MotDePasse" users --risk-only
# Score de securite en JSON
ldaprecon-ai -s dc01 -d corp.example.com -u "CORP\\auditeur" \
-p "MotDePasse" score --json
pytest tests/ -v --tb=short
Ayi NEDJIMI
MIT License - See LICENSE for details.