Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
ADReaper — Windows Active Directory 침투 테스트를 위한 Go로 작성된 빠른 열거 도구 | Kitploit
도구/GitHubGitHub/m0n1x90/adreaper
ReconnaissanceInformation GatheringPenetration TestingAuthentication
GitHubm0n1x90/adreaper

ADReaper

Windows Active Directory 침투 테스트를 위한 Go로 작성된 빠른 열거 도구

저장소 보기
28636113년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

ADReaper

ADReaper는 Golang으로 작성된 도구로, LDAP 쿼리를 사용하여 몇 초 내에 Active Directory 환경을 열거합니다.

설치

Windows/Linux용 사전 컴파일된 실행 바이너리는 최신 릴리스에서 다운로드할 수 있습니다.

소스에서 설치

소스에서 빌드하려면 저장소를 클론하고 GO로 빌드하세요.

$ git clone https://github.com/AidenPearce369/ADReaper
$ cd ADReaper/
$ go build

사용법

ADReaper는 다양한 명령으로 열거를 수행하며, 각 명령은 해당하는 LDAP 쿼리를 수행합니다.

PS C:\Users\redteamer\Desktop\shared> .\ADReaper.exe

      -command string

            Command to run
                  dc              - to list domain controllers
                  domain-trust    - to list domain trust
                  users           - to list all users
                  computers       - to list all computers
                  groups          - to list all groups with members
                  spn             - to list service principal objects
                  never-loggedon  - to list users never logged on
                  gpo             - to list group policy objects
                  ou              - to list organizational units
                  ms-sql          - to list MS-SQL servers
                  asreproast      - to list AS-REP roastable accounts
                  unconstrained   - to list Unconstrained Delegated accounts
                  admin-priv      - to list AD objects with admin privilege

      -dc string

            Enter the DC

      -filter string

            Filters to use for users/groups/computers

            list - lists all objects only
            full-data - list all objects with properties
            membership - lists all members from an object

            (default "list")
      -name string

            Pass object name of user/group/computer

      -password string

            Enter the Password

      -user string

            Enter the Username

도메인의 Domain Controller 속성을 조회하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command dc

도메인의 Trust Attributes를 조회하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command domain-trust

도메인의 모든 Users를 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command users

도메인의 모든 Users를 속성과 함께 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command users -filter full-data

도메인의 Specific Users 속성을 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command users -name <user>

특정 사용자의 멤버십을 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command users -name <user> -filter membership

도메인의 모든 Computers를 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command computers

도메인의 모든 Computers를 속성과 함께 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command computers -filter full-data

도메인의 Specific Computer 속성을 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command computers -name <computer name>

도메인의 모든 Groups를 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command groups

도메인의 모든 Groups를 속성과 함께 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command groups -filter full-data

도메인의 Specific Group 속성을 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command groups -name <group name>

도메인의 Specific Group 멤버를 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command groups -name <group name> -filter membership

도메인에서 Never Logged On 사용자를 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command never-loggedon

도메인의 GPOs를 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command gpo

도메인의 OUs를 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command ou

상위 권한이 있는 AD 개체를 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command admin-priv

도메인의 MS-SQL Servers를 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command ms-sql

도메인의 MS-SQL Servers 모든 속성을 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command ms-sql -filter full-data

도메인의 특정 MS-SQL Server 모든 속성을 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command ms-sql -name <computer name> 

도메인에서 사용 가능한 SPNs를 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command spn

도메인의 Specific SPN 모든 속성을 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command spn -name <sam of spn>

Unconstrained Delegation이 활성화된 AD 개체를 나열하려면,

.\ADReaper.exe -dc <dc.domain> -user <username> -password <password> -command unconstrained 

할 일

다음 버전을 구축할 기여자를 기다리고 있습니다.

계획된 기능,

  • 사용자 정의 LDAP 쿼리
  • 기존 명령으로 LDAP 속성 필터링
  • LAPS 열거
  • Kerberoasting SPNs
  • AS-REP Roasting SPNs
  • 로컬 관리자 액세스 헌팅
  • ACL 열거
  • BloodHound용 JSON 데이터 내보내기

관심 있으시면 저에게 연락 주세요 :)

도구 다운로드