Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
TaskHound — 用于枚举远程系统上特权计划任务的工具 | Kitploit
工具/GitHubGitHub/1r0bit/taskhound
权限提升侦察横向移动信息收集后渗透利用渗透测试红队
GitHub1r0bit/taskhound

TaskHound

用于枚举远程系统上特权计划任务的工具

查看仓库
31225251个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

TaskHound 徽标

Windows 特权计划任务发现工具,兼具趣味与实用性。

最新版本 BloodHound OpenGraph Python 3.11+
询问 DeepWiki 推特 博客


TaskHound 用于搜寻 Windows 上以特权账户和存储凭据运行的计划任务。它通过 SMB 枚举任务、解析 XML,并通过与 BloodHound 的集成识别高价值的攻击机会。

有关背景故事/传说和详细解释,参见相关的博客文章——第1部分 和 第2部分。

主要功能

功能描述
第0层与高价值检测自动识别以域管理员、企业管理员及其他特权账户运行的任务
BloodHound 集成连接实时 BHCE/传统实例,或导入导出数据以检测高价值用户
OpenGraph 支持将计划任务可视化为 BloodHound CE 中的攻击路径节点
LAPS 集成自动检索并使用 LAPS 密码(包括 Windows LAPS 和传统版本)以进行每台主机认证
DPAPI 凭据提取收集并解密包含存储任务凭据的 DPAPI 数据块
多线程扫描支持并行目标处理,并针对大型环境进行速率限制
基于 LDAP 的第0层检测通过组成员关系检测特权账户,无需 BloodHound
凭据验证通过 RPC 验证存储的任务密码是否仍然有效
离线分析处理挂载的磁盘映像或先前收集的 XML 文件
多种输出格式纯文本、JSON、CSV 及带有严重性评分的 HTML 安全报告
SID 解析通过 BloodHound → 缓存 → LSARPC → LDAP → GC 的多层解析
缓存基于 SQLite 的持久缓存,用于 SID 查找和 LAPS 凭据

快速开始```bash

Install

git clone https://github.com/1r0BIT/TaskHound.git cd TaskHound python3 -m venv .venv && source .venv/bin/activate pip install -r requirements.txt && pip install .

Basic usage - single target

taskhound -u homer.simpson -p 'Doh!123' -d thesimpsons.local -t moe.thesimpsons.local

Multiple targets with threading

taskhound -u homer.simpson -p 'Doh!123' -d thesimpsons.local --targets-file hosts.txt --threads 10

Auto-discover all domain computers

taskhound -u homer.simpson -p 'Doh!123' -d thesimpsons.local --dc-ip 10.0.0.1 --auto-targets --threads 20

With LAPS - auto-retrieves per-host local admin passwords

taskhound -u homer.simpson -p 'Doh!123' -d thesimpsons.local --targets-file hosts.txt --laps --threads 10

Offline analysis of mounted disk image

taskhound --offline-disk /mnt/disk

> **认证支持**:TaskHound 支持大多数主流认证机制,包括密码、NTLM 哈希、Kerberos(也包括 ccache 缓存)以及 AES 密钥认证。

## 配置文件

TaskHound 支持使用 TOML 配置文件来持久化设置。在工作目录或 `~/.config/taskhound/` 下创建 `taskhound.toml`:```toml
[authentication]
username = "svc_taskhound"
domain = "THESIMPSONS.LOCAL"

[target]
dc_ip = "10.0.0.1"
threads = 10
timeout = 30

[bloodhound]
live = true
connector = "http://127.0.0.1:8080"
api_key = "${BH_API_KEY}"      # Use env vars for secrets
api_key_id = "${BH_API_KEY_ID}"
type = "bhce"

[bloodhound.opengraph]
enabled = true
output_dir = "./opengraph"

[laps]
enabled = true

[cache]
enabled = true
ttl = 86400  # 24 hours

优先级:CLI参数 > 环境变量 > 本地配置 > 用户配置 > 默认值

AdaptixC2集成

TaskHound的BOF已包含在 Adaptix扩展套件 的 SAR-BOF/taskhound/ 目录下。

演示输出```

TTTTT AAA SSS K K H H OOO U U N N DDDD T A A S K K H H O O U U NN N D D T AAAAA SSS KKK HHHHH O O U U N N N D D T A A S K K H H O O U U N NN D D T A A SSSS K K H H OOO UUU N N DDDD

                 by 0xr0BIT

[+] Connecting to BloodHound CE at http://127.0.0.1:8080 [+] BloodHound connection successful (API v2) [+] High Value target data loaded (42 users) [+] OpenGraph generation enabled (auto-upload active) [] Processing target: moe.thesimpsons.local [+] moe.thesimpsons.local: Connected via SMB [+] moe.thesimpsons.local: Local Admin Access confirmed [] moe.thesimpsons.local: Enumerating scheduled tasks (skipping \Microsoft) [+] moe.thesimpsons.local: Found 12 tasks (3 privileged, 2 with stored credentials)

┌──────────────────────────────────────────────────────────────────────────────┐ │ [TIER-0] moe.thesimpsons.local - \DuffBrewery\BackupJob │ ├──────────────────────────────────────────────────────────────────────────────┤ │ Enabled │ True │ │ RunAs │ THESIMPSONS\Administrator │ │ What │ C:\Scripts\backup_beer_recipes.ps1 │ │ Author │ THESIMPSONS\burns.monty │ │ Date │ 2025-06-15T02:30:00 │ │ Trigger │ Calendar (starts 2025-06-15 02:30, daily) │ │ Reason │ Tier 0 - Domain Admins membership │ │ Cred Validation │ CONFIRMED_VALID │ │ Pwd Analysis │ Password unchanged AND ran within schedule - confirmed │ └──────────────────────────────────────────────────────────────────────────────┘

┌──────────────────────────────────────────────────────────────────────────────┐ │ [PRIV] moe.thesimpsons.local - \KrustyBurger\InventorySync │ ├──────────────────────────────────────────────────────────────────────────────┤ │ Enabled │ True │ │ RunAs │ THESIMPSONS\svc_krusty │ │ What │ C:\KrustyApps\sync.exe --silent │ │ Author │ THESIMPSONS\carlson.carl │ │ Date │ 2025-03-10T08:00:00 │ │ Trigger │ Calendar (starts 2025-03-10 08:00, every 4 hours) │ │ Reason │ High Value match found in BloodHound │ │ Cred Validation │ DEFINITELY_STALE │ │ Pwd Analysis │ Password changed AFTER last run - credentials are stale │ └──────────────────────────────────────────────────────────────────────────────┘

╭─────────────────────────── SCAN COMPLETE ────────────────────────────────────╮ │ [+] Succeeded: 1 │ │ [-] Failed: 0 │ │ Total time: 2.34s │ │ Avg per target: 2340ms │ ╰──────────────────────────────────────────────────────────────────────────────╯

╭─────────────────────────── TASK SUMMARY ─────────────────────────────────────╮ │ Hostname Tier-0 Privileged Normal │ │ moe.thesimpsons.local 1 2 9 │ ╰──────────────────────────────────────────────────────────────────────────────╯

下载工具