Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
SharpADWS — 레드팀을 위한 Active Directory Web Services (ADWS)를 통한 Active Directory 정찰 및 공격 | Kitploit
도구/GitHubGitHub/wh0amitz/sharpadws
Privilege EscalationReconnaissancePersistence MechanismsExploitationLateral MovementPost-ExploitationPenetration TestingAuthenticationRed Teaming
GitHubwh0amitz/sharpadws

SharpADWS

레드팀을 위한 Active Directory Web Services (ADWS)를 통한 Active Directory 정찰 및 공격

60259152년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
저장소 보기

SharpADWS

中文文档

레드팀을 위한 Active Directory Web Services(ADWS) 기반 Active Directory 정찰 및 공격 도구

개요

SharpADWS는 Active Directory Web Services(ADWS) 프로토콜을 통해 Active Directory 데이터를 수집하고 수정하는 레드팀용 Active Directory 정찰 및 공격 도구입니다.

일반적으로 Active Directory 열거 또는 조작은 LDAP 프로토콜을 통해 이루어집니다. SharpADWS는 LDAP 서버와 직접 통신하지 않고 Active Directory 데이터를 추출하거나 수정할 수 있습니다. ADWS에서 LDAP 쿼리는 일련의 SOAP 메시지로 래핑된 후 NET TCP 바인딩 암호화 채널을 사용하여 ADWS 서버로 전송됩니다. 그런 다음 ADWS 서버는 로컬에서 LDAP 쿼리를 언패킹하여 동일한 도메인 컨트롤러에서 실행 중인 LDAP 서버로 전달합니다.

Active Directory Web Services(ADWS)는 Active Directory Domain Services(ADDS)가 설치될 때 자동으로 활성화되므로 SharpADWS는 모든 도메인 환경에서 보편적으로 사용할 수 있습니다.

장점

ADWS를 LDAP 사후 공격에 사용할 때의 주요 이점 중 하나는 상대적으로 덜 알려져 있으며, LDAP 트래픽이 네트워크를 통해 전송되지 않기 때문에 일반적인 모니터링 도구로 쉽게 탐지되지 않는다는 점입니다. ADWS는 LDAP과 완전히 다른 서비스를 실행하며, TCP 포트 9389에서 사용 가능하고 SOAP 프로토콜을 인터페이스로 사용합니다.

ADWS를 연구하면서 실제 LDAP 쿼리 실행이 도메인 컨트롤러에서 로컬로 이루어지기 때문에 흥미로운 부작용이 발생한다는 점을 발견했습니다. 예를 들어, 도메인 컨트롤러에서 LDAP 쿼리를 분석할 때 쿼리가 127.0.0.1 로그에서 발생한 것으로 나타나며, 이는 많은 경우 무시됩니다.

또 다른 이점은 이러한 활동이 DeviceEvents의 LDAPSearch 작업 유형에 나타나지 않으므로 원격 측정 데이터가 거의 없다는 것입니다.

프로토콜 구현

SharpADWS는 MS-ADDM, MS-WSTIM 및 MS-WSDS 프로토콜을 구현합니다. 이 프로젝트의 소스 코드를 사용하여 Active Directory Web Services에서 다음과 같은 작업을 쉽게 수행할 수 있습니다:

  • Enumerate: 지정된 검색 쿼리 필터에 매핑되는 컨텍스트를 생성합니다.
  • Pull: 특정 열거 컨텍스트의 결과 개체를 검색합니다.
  • Renew: 지정된 열거 컨텍스트의 만료 시간을 업데이트합니다.
  • GetStatus: 지정된 열거 컨텍스트의 만료 시간을 가져옵니다.
  • Release: 지정된 열거 컨텍스트를 해제합니다.
  • Delete: 기존 개체를 삭제합니다.
  • Get: 개체에서 하나 이상의 속성을 검색합니다.
  • Put: 개체의 하나 이상의 속성 내용을 수정합니다.
    • Add: 지정된 속성 값 집합에 지정된 속성 값을 추가하거나 대상 개체에 속성이 아직 없으면 속성을 생성합니다.
    • Replace: 지정된 속성의 값 집합을 작업에 지정된 값으로 바꾸거나 대상 개체에 속성이 아직 없으면 속성을 생성합니다. 작업에 값이 지정되지 않은 경우 현재 지정된 속성의 모든 값이 삭제됩니다.
    • Delete: 지정된 속성에서 지정된 특성 값을 제거합니다. 값이 지정되지 않은 경우 모든 값이 삭제됩니다. 대상 개체에 지정된 속성이 없으면 PUT 요청이 실패합니다.
  • Create: 새 개체를 생성합니다.

사용법

명령줄 인수 -h를 사용하여 다음 사용법 정보를 표시할 수 있습니다:```cmd C:\Users\Marcus>SharpADWS.exe -h

SharpADWS 1.0.0-beta - Copyright (c) 2024 WHOAMI (whoamianony.top)

-h Display this help screen

Connection options: -d Specify domain for enumeration -u Username to use for ADWS Connection -p Password to use for ADWS Connection

Supported methods: Cache Dump all objectSids to cache file for Acl methods Acl Enumerate and analyze DACLs for specified objects, specifically Users, Computers, Groups, Domains, DomainControllers and GPOs DCSync Enumerate all DCSync-capable accounts and can set DCSync backdoors DontReqPreAuth Enumerates all accounts that do not require kerberos preauthentication, and can enable this option for accounts Kerberoastable Enumerates all Kerberoastable accounts, and can write SPNs for accounts AddComputer Add a machine account within the scope of ms-DS-MachineAccountQuota for RBCD attack RBCD Read, write and remove msDS-AllowedToActOnBehalfOfOtherIdentity attributes for Resource-Based Constrained Delegation attack Certify Enumerate all ADCS data like Certify.exe, and can write template attributes Whisker List, add and remove msDS-KeyCredentialLink attribute like Whisker.exe for ShadowCredentials attack FindDelegation Enumerate all delegation relationships for the target domain

Acl options: -dn RFC 2253 DN to base search from -scope Set your Scope, support Base (Default), Onelevel, Subtree -trustee The sAMAccountName of a security principal to check for its effective permissions -right Filter DACL for a specific AD rights -rid Specify a rid value and filter out DACL that security principal's rid is greater than it -user Enumerate DACL for all user objects -computer Enumerate DACL for all computer objects -group Enumerate DACL for all group objects -domain Enumerate DACL for all domain objects -domaincontroller Enumerate DACL for all domain controller objects -gpo Enumerate DACL for all gpo objects

DCSync options: -action [{list, write}] Action to operate on DCSync method list List all accounts with DCSync permissions write Escalate accounts with DCSync permissions -target Specify the sAMAccountName of the account

DontReqPreAuth options: -action [{list, write}] Action to operate on DontReqPreAuth method list List all accounts that do not require kerberos preauthentication write Enable do not require kerberos preauthentication for an account -target Specify the sAMAccountName of the account

Kerberoastable options: -action [{list, write}] Action to operate on Kerberoastable method list List all kerberoastable accounts write Write SPNs for an account to kerberoast -target Specify the sAMAccountName of the account

AddComputer options: -computer-name Name of computer to add, without '$' suffix -computer-pass Password to set for the computer

RBCD options: -action [{read,write,remove}] Action to operate on RBCD method read Read the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of the account write Write the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of the account remove Remove the msDS-AllowedToActOnBehalfOfOtherIdentity attribute value of the account added by the write action

Certify options: -action [{find, modify}] Action to operate on Certify method find Find all CA and certificate templates modify Modify certificate templates -enrolleeSuppliesSubject Enumerate certificate templates with CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag for find action, and can enable CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag for modify action -clientAuth Enumerate certificate templates with client authentication pKIExtendedKeyUsage for find action, and can enable Client Authentication for modify action

Whisker options: -action [{list, add, remove}] Action to operate on ShadowCredentials method list List all the values of the msDS-KeyCredentialLink attribute for an account add Add a new value to the msDS-KeyCredentialLink attribute for an account remove Remove a value from the msDS-KeyCredentialLink attribute for an account -device-id Specify the DeviceID to remove -target Specify the sAMAccountName of the account

FindDelegation options: No options, just run!

### Cache

SharpADWS가 ACL을 열거할 때, 각 알 수 없는 trustee 객체에 대해 추가적인 ADWS 요청을 수행하지 않기 위해, 캐시 메서드를 통해 미리 모든 계정 객체의 완전한 캐시를 생성하여 파일에 저장함으로써 다수의 (불필요한) 흐름을 방지해야 합니다. 캐시는 현재 도메인 내 각 계정 객체 이름과 해당 objectSid의 매핑을 포함합니다.```cmd
C:\Users\Marcus>SharpADWS.exe Cache

[*] Cache file has been generated: object.cache

Acl

Acl 메서드는 -dn을 지정하여 객체의 DACL을 열거할 수 있으며, -trustee, -right 및 -rid 매개변수를 통해 열거된 DACL의 필터링을 지원합니다. 예를 들어, 모든 도메인 컨트롤러 객체를 열거하고 trustee가 Marcus인 DACL을 필터링하려면 다음과 같습니다.```cmd C:\Users\Marcus>SharpADWS.exe acl -dn "OU=Domain Controllers,DC=corp,DC=local" -scope Subtree -trustee Marcus

도구 다운로드