Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

FeedsContatoPrivacidade© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
windows-coerced-authentication-methods — A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols. | Kitploit
Ferramentas/GitHubGitHub/p0dalirius/windows-coerced-authentication-methods
Privilege EscalationExploitationPenetration TestingAuthenticationRed TeamingCurated Resources
GitHubp0dalirius/windows-coerced-authentication-methods

windows-coerced-authentication-methods

A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols.

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
Ver RepositórioSite
6017213há 15 diasRevisado pelo Kitploit
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.


This repository contains a list of many methods to coerce a windows machine to authenticate to an attacker-controlled machine.
GitHub repo size YouTube Channel Subscribers

All of these methods are callable by a standard user in the domain to force the machine account of the target Windows machine (usually a domain controller) to authenticate to an arbitrary target. The root cause of this "vulnerability/feature" in each of these methods is that Windows machines automatically authenticate to other machines when trying to access UNC paths (like \\192.168.2.1\SYSVOL\file.txt).

There are currently 30 working functions in 13 protocols.


Protocols & Methods

  • [MS-COMA]: Component Object Model Plus (COM+) Remote Administration Protocol

    • Remote call to ImportFromFile (opnum 3)/README.md)
  • [MS-DFSNM]: Distributed File System (DFS) Namespace Management Protocol

    • Remote call to NetrDfsAdd (opnum 1)/README.md)
    • Remote call to NetrDfsAddStdRoot (opnum 12)/README.md)
    • Remote call to NetrDfsRemoveStdRoot (opnum 13)/README.md)
    • Remote call to NetrDfsAddRootTarget (opnum 23)/README.md)
    • Remote call to NetrDfsRemoveRootTarget (opnum 24)/README.md)
  • [MS-DHCPM]: Microsoft Dynamic Host Configuration Protocol (DHCP) Server Management Protocol

    • Remote call to R_DhcpBackupDatabase (opnum 44)/README.md)
    • Remote call to R_DhcpRestoreDatabase (opnum 45)/README.md)
  • [MS-DNSP]: Domain Name Service (DNS) Server Management Protocol

    • Remote call to R_DnssrvOperation — LogFilePath (opnum 0)/README.md)
  • [MS-EFSR]: Encrypting File System Remote (EFSRPC) Protocol

    • Remote call to EfsRpcOpenFileRaw (opnum 0)/README.md)
    • Remote call to EfsRpcEncryptFileSrv (opnum 4)/README.md)
    • Remote call to EfsRpcDecryptFileSrv (opnum 5)/README.md)
    • Remote call to EfsRpcQueryUsersOnFile (opnum 6)/README.md)
    • Remote call to EfsRpcQueryRecoveryAgents (opnum 7)/README.md)
    • Remote call to EfsRpcFileKeyInfo (opnum 12)/README.md)
    • Remote call to EfsRpcDuplicateEncryptionInfoFile (opnum 13)/README.md)
    • Remote call to EfsRpcAddUsersToFileEx (opnum 15)/README.md)
    • Remote call to EfsRpcFileKeyInfoEx (opnum 16)/README.md)
    • Remote call to EfsRpcEncryptFileExSrv (opnum 21)/README.md)
Baixar ferramenta