
Windows Active Directory 침투 테스트를 위한 Go로 작성된 빠른 열거 도구
ADReaper는 Golang으로 작성된 도구로, LDAP 쿼리를 사용하여 몇 초 내에 Active Directory 환경을 열거합니다.
Windows/Linux용 사전 컴파일된 실행 바이너리는 최신 릴리스에서 다운로드할 수 있습니다.
소스에서 빌드하려면 저장소를 클론하고 GO로 빌드하세요.
$ git clone https://github.com/AidenPearce369/ADReaper
$ cd ADReaper/
$ go build
ADReaper는 다양한 명령으로 열거를 수행하며, 각 명령은 해당하는 LDAP 쿼리를 수행합니다.
PS C:\Users\redteamer\Desktop\shared> .\ADReaper.exe
-command string
Command to run
dc - to list domain controllers
domain-trust - to list domain trust
users - to list all users
computers - to list all computers
groups - to list all groups with members
spn - to list service principal objects
never-loggedon - to list users never logged on
gpo - to list group policy objects
ou - to list organizational units
ms-sql - to list MS-SQL servers
asreproast - to list AS-REP roastable accounts
unconstrained - to list Unconstrained Delegated accounts
admin-priv - to list AD objects with admin privilege
-dc string
Enter the DC
-filter string
Filters to use for users/groups/computers
list - lists all objects only
full-data - list all objects with properties
membership - lists all members from an object
(default "list")
-name string
Pass object name of user/group/computer
-password string
Enter the Password
-user string
Enter the Username
도메인의 Domain Controller 속성을 조회하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command dc
도메인의 Trust Attributes를 조회하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command domain-trust
도메인의 모든 Users를 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command users
도메인의 모든 Users를 속성과 함께 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command users -filter full-data
도메인의 Specific Users 속성을 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command users -name <user>
특정 사용자의 멤버십을 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command users -name <user> -filter membership
도메인의 모든 Computers를 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command computers
도메인의 모든 Computers를 속성과 함께 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command computers -filter full-data
도메인의 Specific Computer 속성을 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command computers -name <computer name>
도메인의 모든 Groups를 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command groups
도메인의 모든 Groups를 속성과 함께 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command groups -filter full-data
도메인의 Specific Group 속성을 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command groups -name <group name>
도메인의 Specific Group 멤버를 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command groups -name <group name> -filter membership
도메인에서 Never Logged On 사용자를 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command never-loggedon
도메인의 GPOs를 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command gpo
도메인의 OUs를 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command ou
상위 권한이 있는 AD 개체를 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command admin-priv
도메인의 MS-SQL Servers를 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command ms-sql
도메인의 MS-SQL Servers 모든 속성을 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command ms-sql -filter full-data
도메인의 특정 MS-SQL Server 모든 속성을 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command ms-sql -name <computer name>
도메인에서 사용 가능한 SPNs를 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command spn
도메인의 Specific SPN 모든 속성을 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command spn -name <sam of spn>
Unconstrained Delegation이 활성화된 AD 개체를 나열하려면,
.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command unconstrained
다음 버전을 구축할 기여자를 기다리고 있습니다.
계획된 기능,
관심 있으시면 저에게 연락 주세요 :)