Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
LDAPRecon-AI — AI搭載分析付きActive Directory LDAPセキュリティ監査人 - Ayi NEDJIMI著 https://ayinedjimi-consultants.fr | Kitploit
ツール/GitLabGitLab/ayinedjimi-consultants/ldaprecon-ai
脆弱性スキャナー構成監査ペネトレーションテスト機械学習AIセキュリティ
GitLabayinedjimi-consultants/ldaprecon-ai

LDAPRecon-AI

AI搭載分析付きActive Directory LDAPセキュリティ監査人 - Ayi NEDJIMI著 https://ayinedjimi-consultants.fr

リポジトリを見る
ウェブサイト
217ヶ月前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

LDAPRecon-AI

Python License: MIT Security Audit Active Directory MITRE ATT&CK CIS Benchmark ANSSI

Active Directory LDAP セキュリティ監査ツール(AI分析機能搭載)

AD環境のセキュリティ体制を列挙・評価・スコアリング

English | Francais

  _     ____    _    ____  ____                          _    ___
 | |   |  _ \  / \  |  _ \|  _ \ ___  ___ ___  _ __    / \  |_ _|
 | |   | | | |/ _ \ | |_) | |_) / _ \/ __/ _ \| '_ \  / _ \  | |
 | |___| |_| / ___ \|  __/|  _ <  __/ (_| (_) | | | |/ ___ \ | |
 |_____|____/_/   \_\_|   |_| \_\___|\___\___/|_| |_/_/   \_\___|

免責事項 / AVERTISSEMENT

このツールは許可されたセキュリティ監査のみを目的としています。コンピュータシステムへの不正アクセスは違法です。セキュリティ評価を実施する前に、必ず適切な書面による許可を取得してください。

Cet outil est destine uniquement aux audits de securite autorises. L'acces non autorise aux systemes informatiques est illegal. Obtenez toujours une autorisation ecrite avant de realiser un audit de securite.


English

概要

LDAPRecon-AI は、Active Directory の LDAP セキュリティを包括的に監査するツールです。ユーザー、グループ、コンピュータ、委任、GPO、信頼関係を列挙し、AD ドメインのセキュリティ体制を評価します。Pingcastle スタイルのスコア(0~100) を提供し、詳細な発見結果は CIS Benchmark、ANSSI AD 推奨事項、MITRE ATT&CK のテクニックにマッピングされます。

機能

  • ユーザー監査: Kerberoastable アカウント、AS-REP roastable、期限切れパスワード、無効なアカウント、AdminSDHolder の孤立アカウント
  • グループ分析: 特権グループのメンバーシップ、ネストされたメンバーシップの解決、大規模グループの検出
  • コンピュータインベントリ: 旧 OS の検出、非アクティブなコンピュータ、LAPS 展開状況
  • 委任検出: 無制限委任、制限付き委任、RBCD、プロトコル遷移(T2A4D)
  • 信頼評価: SID フィルタリング、選択的認証、推移的信頼のリスク
  • パスワードポリシー: CIS 準拠チェック、ロックアウトポリシー、細粒度パスワードポリシー
  • セキュリティスコアリング: グローバルスコア 0~100、カテゴリ別内訳
  • AI 分析: OpenAI を利用したオプションのエグゼクティブサマリーと修復計画
  • マルチフォーマットレポート: HTML(インタラクティブ)、JSON、Markdown、CSV

アーキテクチャ

LDAPRecon-AI/
  src/ldaprecon_ai/
    __init__.py        # パッケージ初期化
    cli.py             # Rich CLI(サブコマンド)
    enumerator.py      # コア LDAP 列挙エンジン
    filters.py         # セキュリティ特化型 LDAP フィルタライブラリ
    models.py          # Pydantic データモデル
    reporter.py        # マルチフォーマットレポート生成
    scorer.py          # セキュリティ体制スコアリングエンジン
  tests/
    conftest.py        # 共有テストフィクスチャ
    test_enumerator.py # Enumerator の単体テスト
    test_filters.py    # Filter の単体テスト
    test_scorer.py     # Scorer の単体テスト

インストール

git clone https://github.com/ayinedjimi/LDAPRecon-AI.git
cd LDAPRecon-AI
pip install -e ".[dev]"

使用方法

完全監査

ldaprecon-ai -s dc01.corp.example.com -d corp.example.com \
  -u "CORP\\auditor" -p "P@ssw0rd" audit -o ./reports

ユーザー列挙(危険アカウントのみ)

ldaprecon-ai -s dc01 -d corp.example.com -u [email protected] \
  -p "P@ssw0rd" users --risk-only --min-score 25

Kerberos 委任検出

ldaprecon-ai -s dc01 -d corp.example.com -u "CORP\\auditor" \
  -p "P@ssw0rd" delegation

セキュリティスコア

ldaprecon-ai -s dc01 -d corp.example.com -u "CORP\\auditor" \
  -p "P@ssw0rd" score --json

AI 分析付き

ldaprecon-ai -s dc01 -d corp.example.com -u "CORP\\auditor" \
  -p "P@ssw0rd" --openai-key sk-... audit -o ./reports

実施されるセキュリティチェック

チェックカテゴリリスクレベルMITRECISANSSI
Kerberoastable アカウントKerberos高T1558.0031.1.4AD-R29
AS-REP roastableKerberos高T1558.004-AD-R29
無制限委任委任重大T1550.0032.3.10.7AD-R26
パスワードが期限切れにならないパスワード中T11101.1.5AD-R36
パスワードが不要パスワード重大T10781.1.3AD-R36
DES のみの暗号化Kerberos重大T15582.3.6.1AD-R30
旧 OSコンピュータ高T121018.10.43.1-
SID フィルタリング無効信頼重大T1134.005-AD-R15
弱いパスワードポリシーパスワード中T1110.0011.1.1AD-R36
AdminSDHolder の孤立特権中T1078.002-AD-R14

テストの実行

pytest tests/ -v --tb=short

Francais

Presentation

LDAPRecon-AI est un outil complet d'audit de securite LDAP pour Active Directory. Il enumere les utilisateurs, groupes, ordinateurs, delegations, GPOs et relations d'approbation pour evaluer la posture de securite d'un domaine AD. Il fournit un score type Pingcastle (0-100) avec des resultats mappes sur CIS Benchmark, Recommandations ANSSI AD et MITRE ATT&CK.

Fonctionnalites

  • Audit Utilisateurs : Comptes Kerberoastable, AS-REP roastable, mots de passe obsoletes, comptes desactives, orphelins AdminSDHolder
  • Analyse Groupes : Appartenance aux groupes privilegies, resolution imbriquee, detection grands groupes
  • Inventaire Ordinateurs : Detection OS obsoletes, ordinateurs inactifs, deploiement LAPS
  • Decouverte Delegation : Non contrainte, contrainte, RBCD, transition de protocole
  • Evaluation Approbations : Filtrage SID, authentification selective, risques transitifs
  • Politique Mots de Passe : Conformite CIS, politique de verrouillage, politiques granulaires
  • Scoring Securite : Score global 0-100 avec detail par categorie
  • Analyse IA : Resume executif optionnel via OpenAI avec plan de remediation
  • Rapports Multi-Format : HTML (interactif), JSON, Markdown, CSV

Utilisation

# Audit complet
ldaprecon-ai -s dc01.corp.example.com -d corp.example.com \
  -u "CORP\\auditeur" -p "MotDePasse" audit -o ./rapports

# Utilisateurs a risque uniquement
ldaprecon-ai -s dc01 -d corp.example.com -u [email protected] \
  -p "MotDePasse" users --risk-only

# Score de securite en JSON
ldaprecon-ai -s dc01 -d corp.example.com -u "CORP\\auditeur" \
  -p "MotDePasse" score --json

Tests

pytest tests/ -v --tb=short

Author / Auteur

Ayi NEDJIMI

  • Website: ayinedjimi-consultants.fr
  • HuggingFace: AYI-NEDJIMI

License

MIT License - See LICENSE for details.

ツールをダウンロード