Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
TaskHound — 원격 시스템에서 권한 있는 예약 작업(Scheduled Tasks)을 열거하는 도구 | Kitploit
도구/GitHubGitHub/1r0bit/taskhound
Privilege EscalationReconnaissanceLateral MovementInformation GatheringPost-ExploitationPenetration TestingRed Teaming
GitHub1r0bit/taskhound

TaskHound

원격 시스템에서 권한 있는 예약 작업(Scheduled Tasks)을 열거하는 도구

저장소 보기
31225251개월 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

TaskHound Logo

Windows 권한 있는 예약 작업 검색 도구 — 재미와 이익을 위한 도구입니다.

Latest Release BloodHound OpenGraph Python 3.11+
Ask DeepWiki Twitter Blog


TaskHound는 권한 있는 계정과 저장된 자격 증명으로 실행되는 Windows 예약 작업을 탐색합니다. SMB를 통해 작업을 열거하고, XML을 파싱하며, BloodHound 연동을 통해 고가치 공격 기회를 식별합니다.

배경 이야기/로어 및 자세한 설명은 관련 블로그 게시물을 참조하세요 - Part 1 및 Part 2.

주요 기능

기능설명
Tier 0 및 고가치 탐지도메인 관리자, 엔터프라이즈 관리자 및 기타 권한 있는 계정으로 실행되는 작업을 자동으로 식별
BloodHound 연동라이브 BHCE/Legacy 인스턴스에 연결하거나 내보낸 데이터를 가져와 고가치 사용자 탐지
OpenGraph 지원예약 작업을 BloodHound CE의 공격 경로 노드로 시각화
LAPS 연동호스트별 인증을 위해 LAPS 비밀번호(Windows LAPS 및 Legacy) 자동 검색 및 사용
DPAPI 자격 증명 추출저장된 작업 자격 증명이 포함된 DPAPI Blob 수집 및 복호화
멀티스레드 스캔대규모 환경을 위한 속도 제한 기능이 있는 병렬 대상 처리
LDAP 기반 Tier-0 탐지BloodHound 없이 그룹 구성원을 통해 권한 있는 계정 탐지
자격 증명 검증RPC를 통해 저장된 작업 비밀번호가 여전히 유효한지 확인
오프라인 분석마운트된 디스크 이미지 또는 이전에 수집된 XML 처리
다중 출력 형식심각도 점수가 포함된 일반 텍스트, JSON, CSV 및 HTML 보안 보고서
SID 해석BloodHound → Cache → LSARPC → LDAP → GC를 통한 다중 계층 해석
캐싱SID 조회 및 LAPS 자격 증명을 위한 SQLite 기반 영구 캐시

빠른 시작```bash

Install

git clone https://github.com/1r0BIT/TaskHound.git cd TaskHound python3 -m venv .venv && source .venv/bin/activate pip install -r requirements.txt && pip install .

Basic usage - single target

taskhound -u homer.simpson -p 'Doh!123' -d thesimpsons.local -t moe.thesimpsons.local

Multiple targets with threading

taskhound -u homer.simpson -p 'Doh!123' -d thesimpsons.local --targets-file hosts.txt --threads 10

Auto-discover all domain computers

taskhound -u homer.simpson -p 'Doh!123' -d thesimpsons.local --dc-ip 10.0.0.1 --auto-targets --threads 20

With LAPS - auto-retrieves per-host local admin passwords

taskhound -u homer.simpson -p 'Doh!123' -d thesimpsons.local --targets-file hosts.txt --laps --threads 10

Offline analysis of mounted disk image

taskhound --offline-disk /mnt/disk

> **인증 지원**: TaskHound는 비밀번호, NTLM 해시, Kerberos(ccache 포함), AES 키 인증을 포함한 대부분의 주요 인증 메커니즘을 지원합니다.

## 구성 파일

TaskHound는 영구 설정을 위한 TOML 구성 파일을 지원합니다. 작업 디렉터리 또는 `~/.config/taskhound/`에 `taskhound.toml`을 생성하세요:```toml
[authentication]
username = "svc_taskhound"
domain = "THESIMPSONS.LOCAL"

[target]
dc_ip = "10.0.0.1"
threads = 10
timeout = 30

[bloodhound]
live = true
connector = "http://127.0.0.1:8080"
api_key = "${BH_API_KEY}"      # Use env vars for secrets
api_key_id = "${BH_API_KEY_ID}"
type = "bhce"

[bloodhound.opengraph]
enabled = true
output_dir = "./opengraph"

[laps]
enabled = true

[cache]
enabled = true
ttl = 86400  # 24 hours

우선순위: CLI 인자 > 환경 변수 > 로컬 구성 > 사용자 구성 > 기본값

AdaptixC2 통합

TaskHound의 BOF는 Adaptix Extension-Kit의 SAR-BOF/taskhound/ 아래에 포함되어 있습니다.

데모 출력```

TTTTT AAA SSS K K H H OOO U U N N DDDD T A A S K K H H O O U U NN N D D T AAAAA SSS KKK HHHHH O O U U N N N D D T A A S K K H H O O U U N NN D D T A A SSSS K K H H OOO UUU N N DDDD

                 by 0xr0BIT

[+] Connecting to BloodHound CE at http://127.0.0.1:8080 [+] BloodHound connection successful (API v2) [+] High Value target data loaded (42 users) [+] OpenGraph generation enabled (auto-upload active) [] Processing target: moe.thesimpsons.local [+] moe.thesimpsons.local: Connected via SMB [+] moe.thesimpsons.local: Local Admin Access confirmed [] moe.thesimpsons.local: Enumerating scheduled tasks (skipping \Microsoft) [+] moe.thesimpsons.local: Found 12 tasks (3 privileged, 2 with stored credentials)

┌──────────────────────────────────────────────────────────────────────────────┐ │ [TIER-0] moe.thesimpsons.local - \DuffBrewery\BackupJob │ ├──────────────────────────────────────────────────────────────────────────────┤ │ Enabled │ True │ │ RunAs │ THESIMPSONS\Administrator │ │ What │ C:\Scripts\backup_beer_recipes.ps1 │ │ Author │ THESIMPSONS\burns.monty │ │ Date │ 2025-06-15T02:30:00 │ │ Trigger │ Calendar (starts 2025-06-15 02:30, daily) │ │ Reason │ Tier 0 - Domain Admins membership │ │ Cred Validation │ CONFIRMED_VALID │ │ Pwd Analysis │ Password unchanged AND ran within schedule - confirmed │ └──────────────────────────────────────────────────────────────────────────────┘

┌──────────────────────────────────────────────────────────────────────────────┐ │ [PRIV] moe.thesimpsons.local - \KrustyBurger\InventorySync │ ├──────────────────────────────────────────────────────────────────────────────┤ │ Enabled │ True │ │ RunAs │ THESIMPSONS\svc_krusty │ │ What │ C:\KrustyApps\sync.exe --silent │ │ Author │ THESIMPSONS\carlson.carl │ │ Date │ 2025-03-10T08:00:00 │ │ Trigger │ Calendar (starts 2025-03-10 08:00, every 4 hours) │ │ Reason │ High Value match found in BloodHound │ │ Cred Validation │ DEFINITELY_STALE │ │ Pwd Analysis │ Password changed AFTER last run - credentials are stale │ └──────────────────────────────────────────────────────────────────────────────┘

╭─────────────────────────── SCAN COMPLETE ────────────────────────────────────╮ │ [+] Succeeded: 1 │ │ [-] Failed: 0 │ │ Total time: 2.34s │ │ Avg per target: 2340ms │ ╰──────────────────────────────────────────────────────────────────────────────╯

╭─────────────────────────── TASK SUMMARY ─────────────────────────────────────╮ │ Hostname Tier-0 Privileged Normal │ │ moe.thesimpsons.local 1 2 9 │ ╰──────────────────────────────────────────────────────────────────────────────╯

도구 다운로드