Skip to content
KitploitKITPLOIT
ИнструментыЭксплойтыБлог
Log in
Отправить
ИнструментыЭксплойтыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

ЛентыКонтактыКонфиденциальность© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
Atlas — Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C# | Kitploit
Инструменты/GitHubGitHub/portbuster1337/atlas
ReconnaissanceExploitationLateral MovementPost-ExploitationNetwork SecurityPenetration TestingRed Teaming
GitHubportbuster1337/atlas

Atlas

Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#

Репозиторий
8378019 дней назадПроверено Kitploit

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться
Контент недоступен на запрошенном языке. Показываем английскую версию.

Atlas

Atlas is a cross-platform (Windows/Linux) network execution and security assessment toolkit built on top of TrustedSec's Titanis protocol library. It is inspired by the workflow of NetExec/CrackMapExec: target lists, credential sets, modular enumeration, and compact [HH:mm:ss] [+] host - message console output.

This tool is intended for authorized security testing. Only use against systems you have explicit permission to test.

Features

ProtocolCapabilities
smbAuth check (NTLM/Kerberos/anonymous), shares, users, groups, disks, sessions via SRVS/SAMR; SAM/LSA via Remote Registry; file ops over SMB2/3; --pass-pol/--rid-brute/--gen-relay-list/--generate-krb5-file/--generate-hosts-file/--generate-tgt; snapshots/streams/open-files/NICs; group members, LSA SID/name lookup, registry query, services, logged-on users, task list/kill, EFS coercion; execution via wmiexec / smbexec / mmcexec (MMC DCOM)
kerberosUser enumeration, pre-auth/AS-REP detection, Kerberoasting, Key List attack, ticket forging (golden/silver), TGT request, password change, S4U2Self/Proxy (-S4UserName)
wmiAuth via DCOM/WMI, Win32_Process.Create (-x/-X) or --wmi-query (WQL), namespace listing, StdRegProv registry, DCOM method invoke, EPM endpoint listing
ldapAuth via SASL/simple bind, queries + flags (--users/--trusted-for-delegation/--pass-pol/--get-sid etc.), --kerberoasting, write ops (-AddUser/-AddComputer/-Delete/-Modify/-SetPassword), modules, --bloodhound (-c) to BloodHound CE JSON+zip
dcsyncReplicate via [MS-DRSR] (DRSGetNCChanges): single objects, full --ntds NC sync, topology (-DcInfo/-ListDomains/-ListSites/-ListRoles/-ListPartitions/-ListGcs/-Neighbors/-CrackName)

Flag style follows NetExec where possible (--shares, --users, --pass-pol, --rid-brute, --local-groups, -d domain, -H hash, --kdcHost, -M/-o/-L modules). Single-dash Titanis spellings (-Shares, -ud, -NtlmHash) keep working. Note: -x/-X can't coexist (case-insensitive), so PowerShell exec is -ps; -d is the domain everywhere including kerberos (realm falls back to it).

Modules (74: 48 smb + 26 ldap; atlas <proto> -L lists them)

ModuleProtocolDescription
spidersmbRecursive share crawler (depth, maxfiles, match)
shareaccesssmbPer-share READ/WRITE access check
localadminssmbLocal Administrators via SAMR
gpp_passwordsmbDecrypts cpassword from Groups.xml etc.
gpp_autologinsmbRegistry.xml autologon credentials
gpp_privilegessmbGptTmpl.inf privilege assignments
uac / wdigest / runasppl / install_elevatedsmbRegistry checks via winreg
spoolersmbPrint Spooler status via SCM
keepass / rclone / winscp / mremoteng / vnc etc.smbFile hunters on shares
ntlmv1 / reg-winlogon / hyperv-hostsmbLmCompatibilityLevel, Winlogon autologon, Hyper-V host
remote-uac / rdp / shadowrdpsmbRead/write remote UAC, RDP, RDP shadowing (ACTION=...)
reg-querysmbQuery/set/delete registry values (PATH=..., KEY=..., VALUE=..., TYPE=..., DELETE=True)
enum_cvesmbPatch-level CVE check from build + UBR
enum_avsmbAV/EDR via LSA service names + IPC$ pipes
enum_dns / get_netconnections / bitlockersmbVia WMI (root\MicrosoftDNS, NIC configs, BitLocker)
putty / notepad / recent_files / recyclebin / snippedsmbPuTTY sessions + .ppk, Notepad tab-state, Recent LNKs, recycle bin, screenshots
lockscreendoorssmbBackdoored accessibility binaries via FileDescription
drop-sc / drop-library-ms / scuffy / slinkysmbCoercion lure drops + CLEANUP=True
webdav / smbghost / onelogon / sccm-recon6smbWebClient check, SMBGhost probe, VulnerableChannelAllowList, SCCM recon
wccsmbWindows security posture checklist (UAC/LSA/RDP/Defender/LAPS/NetBIOS/...)
change-passwordsmbSelf-service password change via SAMR (USER=..., OLDPASS=..., NEWPASS=...)
maqldapms-DS-MachineAccountQuota
pre2kldapPre-Windows 2000 computers (UAC 4128)
lapsldapLAPS passwords
adcsldapAD CS enrollment services
subnetsldapSites/Subnets from Configuration NC
daclread / badsuccessor / certipy-find etc.ldapLDAP enumeration via Titanis
get-unixUserPassword / dns-nonsecureldapUnix passwords, nonsecure DNS zones
modify-group / add-computerldapGroup membership, computer lifecycle (NAME=..., DELETE=True, ...)

Shared across all protocols:

  • Target specification: single host/IP, CIDR, ranges (a.b.c.d-e), comma lists, @file
  • Full authentication matrix inherited from Titanis: passwords, NT hashes, AES keys, keytabs, .kirbi/.ccache tickets, PKINIT certificates, S4U, SPN overrides, SOCKS5
  • Multi-host fan-out with configurable concurrency and per-host timeout
  • NetExec-style console output

Requirements

  • .NET SDK 9.0+ (some vendored Titanis projects use C# 13)
  • Network reachability to targets (445/TCP for SMB, 88/TCP for Kerberos, 389/TCP for LDAP, 135/TCP + dynamic RPC ports for WMI/DCSync)

Build

The repository vendors the Titanis source under external/Titanis and builds it as part of the solution.

git clone https://github.com/<your-account>/atlas.git
cd atlas
dotnet build Atlas.sln -p:NoWarn=CS1998

The resulting binary is a framework-dependent .NET application:

dotnet src/Atlas.Cli/bin/Debug/net8.0/atlas.dll --help

Usage

atlas <protocol> <targets> [authentication] [actions] [options]

Target specification accepts any mix of: HOST, 10.0.0.5, 192.168.1.0/24, 10.0.0.1-64, comma-separated lists, or @targets.txt.

SMB

# Credential check only
atlas smb 10.0.0.5 -u administrator -p 'Password1!'

# Enumeration
atlas smb 10.0.0.0/24 -u admin -p 'Password1!' -Shares -Users -Groups -Disks -Sessions

# SAM / LSA dumping (requires local admin)
atlas smb 10.0.0.5 -u admin -p 'Password1!' -Sam -Lsa

# File operations
atlas smb 10.0.0.5 -u admin -p pass -LsPath 'C$\Users'
atlas smb 10.0.0.5 -u admin -p pass -GetFile 'C$\Windows\win.ini'
atlas smb 10.0.0.5 -u admin -p pass -PutSource ./payload.bin -PutDest 'C$\Temp\payload.bin'

# Modules and flags
atlas smb 10.0.0.0/24 -u admin -p pass -M spider -mo 'depth=3,maxfiles=50,match=.conf'
atlas smb 10.0.0.0/24 -u admin -p pass -M shareaccess -M gpp_password
atlas smb 10.0.0.5 -u admin -p pass -M localadmins -M uac

# Flags (NetExec-like)
atlas smb 10.0.0.5 -u admin -p pass --pass-pol --rid-brute 2000
atlas smb 10.0.0.5 --Anonymous --gen-relay-list relay.txt --generate-krb5-file krb5.conf

# Password spray
atlas smb 10.0.0.0/24 -UserList users.txt -PassList 'Password1!,Summer2024!'

Kerberos

# User enumeration (no credentials required)
atlas kerberos dc01.corp.local -d CORP.LOCAL -UserList users.txt

# Kerberoasting (requires any domain credential)
atlas kerberos dc01.corp.local -d CORP.LOCAL -Roast -u lowpriv -p 'Password1!'
atlas kerberos dc01.corp.local -d CORP.LOCAL -Roast -u lowpriv -p pass -SpnList 'MSSQLSvc/sql01.corp.local:1433'

# Key List attack against an RODC
atlas kerberos rodc01.corp.local -d CORP.LOCAL -rodcNo 20000 -rodcKey <aes256-hex> -UserList 'jdoe:1104'

WMI

atlas wmi dc01.corp.local -d CORP.LOCAL -u admin -p pass           # auth check
atlas wmi dc01.corp.local -d CORP.LOCAL -u admin -p pass -x whoami # exec

LDAP

Скачать инструмент