
adPEAS v2.3.2
Powershell 도구로 Active Directory 열거를 자동화합니다.
adPEAS v2 — Active Directory 권한 상승 Awesome 스크립트
포괄적인 Active Directory 보안 평가 — 의존성 제로, 단일 파일, 즉시 사용 가능.
adPEAS란 무엇인가?
adPEAS는 Active Directory 환경에서 잘못된 구성, 취약점, 권한 상승 경로를 식별하는 PowerShell 기반 보안 평가 도구입니다. RSAT도, ActiveDirectory 모듈도, 서드파티 의존성도 필요 없이 모든 Windows 시스템에서 작동하는 안정적이고 자체 완결적인 도구가 필요한 침투 테스터, 보안 감사자, 레드 팀을 위해 설계되었습니다.
adPEAS v2는 adPEAS v1의 완전한 재작성 버전입니다. 기존의 DirectoryEntry/DirectorySearcher 접근 방식을 통합된 System.DirectoryServices.Protocols.LdapConnection 아키텍처로 대체하고, 네이티브 Kerberos 인증, 고급 보고, 공격적 작업을 모두 순수 PowerShell로 추가했습니다.
v2의 새로운 기능
- 네이티브 Kerberos 스택 — AS-REQ/AS-REP, TGS-REQ/TGS-REP, Pass-the-Ticket, PKINIT, 모두 순수 PowerShell로 구현
- 다양한 인증 방식 — Password, NT-Hash (OPtH), AES 키 (PtK), 인증서 (PKINIT & Pass-the-Cert/Schannel), Windows 통합 인증
- 9개 카테고리에 걸친 40개 이상의 보안 검사 및 심각도 점수 산정
- 대화형 HTML 보고서 — 검색, 필터링, 위험 점수, 툴팁 지원
- JSON 내보내기 — 오프라인 보고서 변환, 증분 스캔, 스캔 비교용
- BloodHound CE 수집기 — 공격 경로 분석을 위한 내장 데이터 수집
- 공격적 작업 — Kerberoasting, AS-REP Roasting, Golden/Silver/Diamond Tickets, RBCD 악용, Shadow Credentials 등
- 세션 기반 워크플로 — 한 번 연결하고 여러 검사를 대화형으로 실행
- 탭 자동 완성 — 대화형 탐색을 위한 AD 객체 이름 자동 완성
adPEAS가 처음이신가요? 빠른 시작 가이드를 확인하거나 blog.sekurity.de의 블로그 시리즈를 읽고 아키텍처, 인증, 내부 구조를 자세히 알아보세요.
한눈에 보는 기능
| 카테고리 | 주요 기능 |
|---|---|
| 인증 | 자격 증명, PKINIT, Pass-the-Cert, NT-Hash, AES 키, Windows 인증, 자동 폴백을 갖춘 Kerberos 우선 |
| 보안 검사 | 도메인 구성, Kerberoast, ASREPRoast, ACL, DCSync, 위임, AD CS 권한 상승 경로, GPO 악용, LAPS, BitLocker 복구 키, 구형 시스템 |
| 보고 | 콘솔 (색상 구분), 일반 텍스트, 대화형 HTML, JSON 내보내기 |
| 공격적 작업 | Kerberoasting, AS-REP Roasting, Golden/Silver/Diamond Tickets, RBCD, Shadow Credentials, Pass-the-Ticket |
| BloodHound | 내장 BloodHound CE 수집기 (ZIP 내보내기) |
| OPSEC 모드 | 능동적 테스트 (Kerberoast, ASREPRoast, BloodHound) 건너뛰기 |
| 배포 | 단일 .ps1 파일, RSAT 불필요, 외부 모듈 불필요, 오프라인 및 에어갭 환경에서 작동 |
요구 사항
- OS: Windows 10/11, Windows Server 2016/2019/2022/2025
- PowerShell: 5.1+ (Windows PowerShell)
- .NET Framework: 4.5+ (Windows에 포함)
- 네트워크: LDAP (389), LDAPS (636), Kerberos (88), SMB (445)
ActiveDirectory 모듈, RSAT 또는 외부 PowerShell 모듈이 필요하지 않습니다.
다운로드
릴리스 버전
| 파일 | 크기 | 사용 사례 |
|---|---|---|
adPEAS.ps1 | ~4.5 MB | 개발, 디버깅, 코드 리뷰 |
adPEAS_min.ps1 | ~3-4 MB | 더 작은 설치 공간으로 일반 사용 |
adPEAS_ultra.ps1 | ~3 MB | 최소 크기, 주석 없음 |
adPEAS_obf.ps1 | <1 MB | 최소 크기, 전송용 난독화 |
네 가지 버전 모두 기능적으로 동일합니다. 배포 시나리오에 따라 선택하세요.
# Clone the repository
git clone https://github.com/61106960/adPEAS.git
cd adPEAS
소스에서 빌드
main 브랜치는 항상 네 가지 변형 모두의 최신 빌드를 포함하고 있으며, 모든 수정 및 기능과 함께 재빌드되므로 위의 raw URL은 최신 코드를 제공합니다. 해당 빌드에는 개발 버전 문자열(2.5.1+20260917-1759)이 포함됩니다. 태그가 지정된 모든 GitHub Release에는 네 가지 안정 빌드가 다운로드 가능한 에셋으로 첨부되어 있으며, 깔끔한 버전 문자열(2.5.1)을 가집니다 — 알려진 인용 가능한 버전이 필요하면 해당 빌드를 사용하세요. 직접 소스에서 빌드하려면:
git clone https://github.com/61106960/adPEAS.git
cd adPEAS
.\Build-Release.ps1
이 명령은 저장소 루트에 네 가지 변형(adPEAS.ps1, adPEAS_min.ps1, adPEAS_ultra.ps1, adPEAS_obf.ps1)을 모두 생성합니다. Windows PowerShell 5.1이 필요하며 추가 의존성은 없습니다.
빠른 시작
# Option 1: Import as module (recommended)
Import-Module .\adPEAS.ps1
# Option 2: Dot-sourcing
. .\adPEAS.ps1
# Option 3: Read and execute in memory
Get-Content -Raw .\adPEAS.ps1 | Invoke-Expression
# Option 4: Load directly from GitHub into memory (no file on disk)
Invoke-Expression (Invoke-WebRequest -Uri "https://raw.githubusercontent.com/61106960/adPEAS/main/adPEAS_obf.ps1" -UseBasicParsing).Content
원라이너 (v1 호환)
# Domain-joined machine (current user)
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth
# With credentials
Invoke-adPEAS -Domain "contoso.com" -Username "john.doe" -Password "P@ssw0rd!"
# OPSEC mode (skip Kerberoast, ASREPRoast, BloodHound)
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -OPSEC
세션 기반 (v2 스타일)
# Connect once
Connect-adPEAS -Domain "contoso.com" -UseWindowsAuth
# Run full scan
Invoke-adPEAS
# Or run individual checks
Get-KerberoastableAccounts
Get-ADCSVulnerabilities
Get-DangerousACLs
# Disconnect when done
Disconnect-adPEAS
인증 방식
# Credentials
Connect-adPEAS -Domain "contoso.com" -Credential (Get-Credential)
# Overpass-the-Hash (NT-Hash)
Connect-adPEAS -Domain "contoso.com" -Username "admin" -NTHash "32ED87BDB5FDC5E9CBA88547376818D4"
# Pass-the-Key (AES256)
Connect-adPEAS -Domain "contoso.com" -Username "admin" -AES256Key "4a3b2c1d5e6f..."
# PKINIT (Certificate)
Connect-adPEAS -Domain "contoso.com" -Certificate "user.pfx"
# Pass-the-Cert / Schannel (LDAPS, no Kerberos)
Connect-adPEAS -Domain "contoso.com" -Certificate "user.pfx" -PassTheCert
# LDAPS
Connect-adPEAS -Domain "contoso.com" -UseWindowsAuth -UseLDAPS
출력 및 보고
# All formats (default) — creates .txt, .html, and .json
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -Outputfile .\report
# HTML only
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -Outputfile .\report -Format HTML
# Offline report conversion from JSON
Convert-adPEASReport -InputJson ".\report.json" -OutputPath ".\new_report"
# Compare two scans (diff report)
Compare-adPEASReport -Baseline ".\scan_q1.json" -Current ".\scan_q2.json" -OutputPath ".\diff"
보안 검사 모듈
| 모듈 | 설명 |
|---|---|
Domain | 도메인 구성, 트러스트, 암호 정책, LDAP 서명, SMB 서명 |
Creds | Kerberoast, ASREPRoast, LAPS 및 BitLocker 복구 키 접근, SYSVOL 내 자격 증명 노출 |
Rights | ACL, DCSync, 암호 재설정 권한, 위험한 OU 권한 |
Delegation | 비제약, 제약, 리소스 기반 제약 위임 |
ADCS | 인증서 템플릿 및 CA: ESC1-ESC5, ESC8, ESC9, ESC13, ESC14, ESC15 (ESC10은 GPO 검사를 통해). CA 호스트에 대한 관리자 접근이 필요한 권한 상승 경로는 범위 밖입니다 - 보안 검사 참조 |
Accounts | 권한 있는 계정, 보호된 사용자, 서비스 계정, SID 기록 |
GPO | GPO 권한, 로컬 그룹 멤버십, 예약된 작업, 스크립트, 위험한 레지스트리 설정 (WDigest, AlwaysInstallElevated, OneLogon/Zerologon, …) 및 GPO를 통해 배포된 Point and Print 프린터 드라이버 정책 (PrintNightmare) |
Computer | LAPS, 구형 시스템, 인프라 서버 |
Application | Exchange, SCCM, SCOM 인프라 |
Bloodhound | BloodHound CE 데이터 수집 |
특정 모듈 실행:
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -Module Domain,Creds,ADCS
또는 나머지를 나열하지 않고 몇 개를 제외한 모든 것을 실행:
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -ExcludeModule Bloodhound,Computer
문서
전체 문서는 docs/ 디렉터리에서 확인할 수 있습니다: