Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
도구/GitHubGitHub/awakecoding/wireshark-rdp
Packet Sniffing & AnalysisNetwork ForensicsNetwork SecurityAuthenticationLearning & EducationCurated Resources
GitHubawakecoding/wireshark-rdp

wireshark-rdp

Wireshark RDP 리소스

저장소 보기
2222951년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

샘플 RDP Wireshark 캡처 파일

다양한 시나리오를 보여주는 RDP 복호화 캡처 파일 모음입니다.

NLA를 사용하는 RDP, Kerberos 암호 인증 #1

rdp-nla-kerberos-auth1.pcapng

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: Kerberos를 사용한 RDP NLA

NLA를 사용하는 RDP, Kerberos 암호 인증 #2

rdp-nla-kerberos-auth2.pcapng

  • 사용자 이름: IT-HELP\Administrator
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: Kerberos를 사용한 RDP NLA

NLA를 사용하는 RDP, 서버에서 거부된 NTLM #1

rdp-nla-ntlm-rejected1.pcapng

  • 사용자 이름: IT-HELP\Administrator
  • 서버: 10.10.0.10
  • 인증: NTLM을 사용한 RDP NLA

클라이언트는 FQDN 대신 IP 주소를 사용하여 연결했으며, 그 결과 인바운드 NTLM을 거부하도록 구성된 서버에서 NTLM 다운그레이드가 발생했습니다.

NLA를 사용하는 RDP, 서버에서 거부된 NTLM #2

rdp-nla-ntlm-rejected2.pcapng

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: Kerberos를 사용한 RDP NLA(암호) 후 NTLM 다운그레이드

클라이언트는 서버의 FQDN을 사용하여 연결하고 Kerberos 암호 기반 인증을 시도했습니다. 그러나 잘못된 암호를 입력한 후 RDP 클라이언트가 NTLM으로 다운그레이드되었으며, 사용자가 Active Directory의 Protected Users 그룹 구성원이므로 서버에서 NTLM 인증을 거부했습니다.

NLA를 사용하는 RDP, Kerberos 스마트카드 인증 #1

rdp-nla-smartcard-auth1.pcapng

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: Kerberos를 사용한 RDP NLA(스마트카드)

NLA를 사용하는 RDP, Kerberos 스마트카드 인증 #2

rdp-nla-smartcard-auth2.pcapng

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: Kerberos를 사용한 RDP NLA(스마트카드)

NLA를 사용하지 않는 RDP, 스마트카드 인증 #1

rdp-no-nla-smartcard-auth1.pcapng

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: NLA를 사용하지 않는 RDP(스마트카드)

NLA를 사용하지 않는 RDP, 서버에서 수락됨 #1

rdp-no-nla-accepted1.pcapng

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: NLA를 사용하지 않는 RDP(암호)

NLA를 사용하지 않는 RDP, 서버에서 거부됨 #1

rdp-no-nla-rejected1.pcapng

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: NLA를 사용하지 않는 RDP(암호)

TLS를 사용하지 않는 RDP, 서버에서 수락됨 #1

rdp-no-tls-accepted1.pcapng

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: NLA 및 TLS를 사용하지 않는 RDP(암호)

RDP Restricted Admin Mode, 서버에서 수락됨 #1

rdp-restricted-admin-accepted1.pcapng

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: NLA + Restricted Admin Mode를 사용하는 RDP

RDP Restricted Admin Mode, 서버에서 거부됨 #1

rdp-restricted-admin-rejected1.pcapng

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: NLA + Restricted Admin Mode를 사용하는 RDP

RDP Remote Credential Guard, 서버에서 수락됨 #1

rdp-credential-guard-accepted1.pcapng

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: NLA + Remote Credential Guard를 사용하는 RDP

RDP Remote Credential Guard, 서버에서 거부됨 #1

rdp-credential-guard-rejected1.pcapng

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: NLA + Remote Credential Guard를 사용하는 RDP

다른 자격 증명을 사용하는 RD Gateway, Kerberos 암호 인증

rdp-rdg-diff-creds-kerberos-password.pcapng

RD Gateway:

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-GW.ad.it-help.ninja
  • 인증: Kerberos, 암호 기반

RDP 서버:

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: Kerberos, 암호 기반

다른 자격 증명을 사용하는 RD Gateway, Kerberos 스마트카드 인증

rdp-rdg-diff-creds-kerberos-smartcard.pcapng

RD Gateway:

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-GW.ad.it-help.ninja
  • 인증: Kerberos, 스마트카드 기반

RDP 서버:

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: Kerberos, 스마트카드 기반

KDC 프록시가 없는 RD Gateway, NTLM 다운그레이드 실패

rdp-rdg-no-kdc-proxy-ntlm-downgrade-failure.pcapng

RD Gateway:

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-GW.ad.it-help.ninja
  • 인증: Kerberos, 암호 기반

KDC 프록시가 없는 RD Gateway, NTLM 다운그레이드 성공

rdp-rdg-no-kdc-proxy-ntlm-downgrade-success.pcapng

RD Gateway:

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-GW.ad.it-help.ninja
  • 인증: Kerberos, 암호 기반

KDC 프록시를 사용하는 RD Gateway, 동일 자격 증명, Kerberos 암호 인증

rdp-rdg-same-creds-kerberos-password-success1.pcapng

RD Gateway:

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-GW.ad.it-help.ninja
  • 인증: Kerberos, 암호 기반

RDP 서버:

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: Kerberos, 암호 기반

KDC 직접 연결을 사용하는 RD Gateway, 동일 자격 증명, Kerberos 암호 인증

rdp-rdg-same-creds-kerberos-password-success2.pcapng

RD Gateway:

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-GW.ad.it-help.ninja
  • 인증: Kerberos, 암호 기반

RDP 서버:

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: Kerberos, 암호 기반

KDC 프록시를 사용하는 RD Gateway, 동일 자격 증명, Kerberos 스마트카드 인증

rdp-rdg-same-creds-kerberos-smartcard-success1.pcapng

RD Gateway:

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-GW.ad.it-help.ninja
  • 인증: Kerberos, 스마트카드 기반

RDP 서버:

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: Kerberos, 스마트카드 기반

KDC 직접 연결을 사용하는 RD Gateway, 동일 자격 증명, Kerberos 스마트카드 인증

rdp-rdg-same-creds-kerberos-smartcard-success2.pcapng

RD Gateway:

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-GW.ad.it-help.ninja
  • 인증: Kerberos, 스마트카드 기반

RDP 서버:

  • 사용자 이름: [email protected]
  • 서버: IT-HELP-TEST.ad.it-help.ninja
  • 인증: Kerberos, 스마트카드 기반

다양한 형식의 RDP 클립보드 리디렉션

rdp-clipboard-various-formats1.pcapng

다양한 형식(텍스트, 이미지, 서식 있는 텍스트, 파일 복사 등)의 클립보드 리디렉션을 보여주는 샘플 캡처입니다.

RDP vmconnect, 로컬, 기본 세션 모드

rdp-vmconnect-local-basic-session-mode1.pcapng

암시적 자격 증명을 사용하여 기본 세션 모드에서 Hyper-V에 연결하는 로컬 RDP vmconnect 연결이며, 게스트는 Alpine Linux VM입니다.

RDP vmconnect, 로컬, 향상된 세션 모드

rdp-vmconnect-local-enhanced-session-mode1.pcapng

암시적 자격 증명을 사용하여 향상된 세션 모드에서 Hyper-V에 연결하는 로컬 RDP vmconnect 연결이며, 게스트는 Windows Server VM입니다.

RDP vmconnect, 원격, 기본 세션 모드

rdp-vmconnect-remote-basic-session-mode1.pcapng

명시적 자격 증명을 사용하여 기본 세션 모드에서 Hyper-V에 연결하는 원격 RDP vmconnect 연결이며, 게스트는 Alpine Linux VM입니다.

RDP vmconnect, 원격, 향상된 세션 모드

rdp-vmconnect-remote-enhanced-session-mode1.pcapng

명시적 자격 증명을 사용하여 향상된 세션 모드에서 Hyper-V에 연결하는 원격 RDP vmconnect 연결이며, 게스트는 Windows Server VM입니다.

도구 다운로드