返回更新列表
新发布Aug 26, 2026

adPEAS v2.3.2

用于自动化Active Directory枚举的Powershell工具。

分享

adPEAS v2 — Active Directory 权限提升神器脚本

adPEAS Logo

全面的 Active Directory 安全评估 — 零依赖、单文件、开箱即用。


什么是 adPEAS?

adPEAS 是一款基于 PowerShell 的安全评估工具,用于识别 Active Directory 环境中的错误配置、漏洞和权限提升路径。它专为渗透测试人员、安全审计人员和红队设计,提供可靠、自包含的工具,可在任何 Windows 系统上运行 — 无需 RSAT、无需 ActiveDirectory 模块、无需第三方依赖。

adPEAS v2 是 adPEAS v1 的完全重写版本。它用统一的 System.DirectoryServices.Protocols.LdapConnection 架构取代了旧版的 DirectoryEntry/DirectorySearcher 方法,并新增了原生 Kerberos 认证、高级报告和攻击性操作 — 全部使用纯 PowerShell 实现。

v2 新特性

  • 原生 Kerberos 协议栈 — AS-REQ/AS-REP、TGS-REQ/TGS-REP、Pass-the-Ticket、PKINIT,全部使用纯 PowerShell 实现
  • 多种认证方式 — 密码、NT-Hash(OPtH)、AES 密钥(PtK)、证书(PKINIT 和 Pass-the-Cert/Schannel)、Windows 集成认证
  • 40+ 项安全检查,涵盖 9 个类别,带严重性评分
  • 交互式 HTML 报告,支持搜索、过滤、风险评分和工具提示
  • JSON 导出,用于离线报告转换、增量扫描和扫描对比
  • BloodHound CE 收集器 — 内置数据收集,用于攻击路径分析
  • 攻击性操作 — Kerberoasting、AS-REP Roasting、Golden/Silver/Diamond Tickets、RBCD 滥用、Shadow Credentials 等
  • 基于会话的工作流 — 连接一次,交互式运行多项检查
  • Tab 补全 — 自动补全 AD 对象名称,便于交互式探索

初次使用 adPEAS? 请查看快速入门指南,或阅读 blog.sekurity.de 上的博客系列,深入了解架构、认证和内部机制。


功能一览

类别亮点
认证凭据、PKINIT、Pass-the-Cert、NT-Hash、AES 密钥、Windows 认证、Kerberos 优先并自动回退
安全检查域配置、Kerberoast、ASREPRoast、ACL、DCSync、委派、AD CS 提权路径、GPO 滥用、LAPS、BitLocker 恢复密钥、过时系统
报告控制台(彩色编码)、纯文本、交互式 HTML、JSON 导出
攻击性操作Kerberoasting、AS-REP Roasting、Golden/Silver/Diamond Tickets、RBCD、Shadow Credentials、Pass-the-Ticket
BloodHound内置 BloodHound CE 收集器(ZIP 导出)
OPSEC 模式跳过主动测试(Kerberoast、ASREPRoast、BloodHound)
部署单个 .ps1 文件,无需 RSAT,无外部模块,可离线及气隙环境运行

系统要求

  • 操作系统:Windows 10/11、Windows Server 2016/2019/2022/2025
  • PowerShell:5.1+(Windows PowerShell)
  • .NET Framework:4.5+(Windows 内置)
  • 网络:LDAP (389)、LDAPS (636)、Kerberos (88)、SMB (445)

无需 ActiveDirectory 模块、RSAT 或外部 PowerShell 模块。


下载

发布版本

文件大小使用场景
adPEAS.ps1~4.5 MB开发、调试、代码审查
adPEAS_min.ps1~3-4 MB常规使用,占用更小
adPEAS_ultra.ps1~3 MB最小体积,无注释
adPEAS_obf.ps1<1 MB最小体积,混淆处理便于传输

四个版本功能完全相同。请根据您的部署场景选择。

# Clone the repository
git clone https://github.com/61106960/adPEAS.git
cd adPEAS

从源码构建

main 分支始终包含所有四个变体的最新构建,每次修复和功能更新都会重新构建,因此上述原始 URL 提供的是最新代码。这些构建带有开发版本字符串(2.5.1+20260917-1759)。每个已标记的 GitHub Release 都附有四个稳定构建作为可下载资源,带有干净的版本字符串(2.5.1)— 如果您需要已知、可引用的版本,请使用这些。要自行从源码构建:

git clone https://github.com/61106960/adPEAS.git
cd adPEAS
.\Build-Release.ps1

这将在仓库根目录生成所有四个变体(adPEAS.ps1、adPEAS_min.ps1、adPEAS_ultra.ps1、adPEAS_obf.ps1)。需要 Windows PowerShell 5.1,无额外依赖。


快速开始

# Option 1: Import as module (recommended)
Import-Module .\adPEAS.ps1

# Option 2: Dot-sourcing
. .\adPEAS.ps1

# Option 3: Read and execute in memory
Get-Content -Raw .\adPEAS.ps1 | Invoke-Expression

# Option 4: Load directly from GitHub into memory (no file on disk)
Invoke-Expression (Invoke-WebRequest -Uri "https://raw.githubusercontent.com/61106960/adPEAS/main/adPEAS_obf.ps1" -UseBasicParsing).Content

单行命令(兼容 v1)

# Domain-joined machine (current user)
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth

# With credentials
Invoke-adPEAS -Domain "contoso.com" -Username "john.doe" -Password "P@ssw0rd!"

# OPSEC mode (skip Kerberoast, ASREPRoast, BloodHound)
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -OPSEC

基于会话(v2 风格)

# Connect once
Connect-adPEAS -Domain "contoso.com" -UseWindowsAuth

# Run full scan
Invoke-adPEAS

# Or run individual checks
Get-KerberoastableAccounts
Get-ADCSVulnerabilities
Get-DangerousACLs

# Disconnect when done
Disconnect-adPEAS

认证方式

# Credentials
Connect-adPEAS -Domain "contoso.com" -Credential (Get-Credential)

# Overpass-the-Hash (NT-Hash)
Connect-adPEAS -Domain "contoso.com" -Username "admin" -NTHash "32ED87BDB5FDC5E9CBA88547376818D4"

# Pass-the-Key (AES256)
Connect-adPEAS -Domain "contoso.com" -Username "admin" -AES256Key "4a3b2c1d5e6f..."

# PKINIT (Certificate)
Connect-adPEAS -Domain "contoso.com" -Certificate "user.pfx"

# Pass-the-Cert / Schannel (LDAPS, no Kerberos)
Connect-adPEAS -Domain "contoso.com" -Certificate "user.pfx" -PassTheCert

# LDAPS
Connect-adPEAS -Domain "contoso.com" -UseWindowsAuth -UseLDAPS

输出与报告

# All formats (default) — creates .txt, .html, and .json
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -Outputfile .\report

# HTML only
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -Outputfile .\report -Format HTML

# Offline report conversion from JSON
Convert-adPEASReport -InputJson ".\report.json" -OutputPath ".\new_report"

# Compare two scans (diff report)
Compare-adPEASReport -Baseline ".\scan_q1.json" -Current ".\scan_q2.json" -OutputPath ".\diff"

安全检查模块

模块描述
Domain域配置、信任关系、密码策略、LDAP 签名、SMB 签名
CredsKerberoast、ASREPRoast、LAPS 和 BitLocker 恢复密钥访问、SYSVOL 中的凭据泄露
RightsACL、DCSync、密码重置权限、危险的 OU 权限
Delegation非约束委派、约束委派、基于资源的约束委派
ADCS证书模板和 CA:ESC1-ESC5、ESC8、ESC9、ESC13、ESC14、ESC15(ESC10 通过 GPO 检查)。需要 CA 主机管理员权限的提权路径不在范围内 — 参见安全检查
Accounts特权账户、受保护用户、服务账户、SID 历史
GPOGPO 权限、本地组成员身份、计划任务、脚本、危险注册表设置(WDigest、AlwaysInstallElevated、OneLogon/Zerologon 等)以及通过 GPO 部署的 Point and Print 打印机驱动策略(PrintNightmare)
ComputerLAPS、过时系统、基础设施服务器
ApplicationExchange、SCCM、SCOM 基础设施
BloodhoundBloodHound CE 数据收集

运行特定模块:

Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -Module Domain,Creds,ADCS

或运行除少数之外的所有模块,无需列出其余模块:

Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -ExcludeModule Bloodhound,Computer

文档

完整文档位于 docs/ 目录:

文档主题
安装下载、设置、执行策略
快速开始5 分钟快速上手
认证所有认证选项
安全检查完整检查参考
BloodHound 收集器BloodHound CE 导出
核心函数LDAP 查询函数
Set- 和 New- 模块AD 修改函数
辅助函数实用函数
架构技术架构
风险评分严重性和风险评分
故障排除常见问题及解决方案
FAQ常见问题解答

博客系列

分类