Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
adPEAS — 用于自动化Active Directory枚举的Powershell工具。 | Kitploit
工具/GitHubGitHub/61106960/adpeas
权限提升侦察漏洞扫描器漏洞利用信息收集后渗透利用渗透测试身份验证红队
GitHub61106960/adpeas

adPEAS

用于自动化Active Directory枚举的Powershell工具。

1.4k1561043天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
# adPEAS v2 — Active Directory 权限提升神器脚本

<p align="center">
  <img src="https://assets.kitploit.com/production/public/readmes/4985/094efb3e3ea9d020e014d57d49df2544da13c1a85d28db14f491e55817bcc68f.jpg" alt="adPEAS Logo" width="800">
</p>

<p align="center">
  <strong>全面的 Active Directory 安全评估 — 零依赖、单文件、开箱即用。</strong>
</p>

---

## 什么是 adPEAS?

adPEAS 是一款基于 PowerShell 的安全评估工具,用于识别 Active Directory 环境中的错误配置、漏洞和权限提升路径。它专为渗透测试人员、安全审计人员和红队设计,提供可靠、自包含的工具,可在任何 Windows 系统上运行 — 无需 RSAT、无需 ActiveDirectory 模块、无需第三方依赖。

**adPEAS v2** 是 adPEAS v1 的完全重写版本。它用统一的 `System.DirectoryServices.Protocols.LdapConnection` 架构取代了旧版的 `DirectoryEntry`/`DirectorySearcher` 方法,并新增了原生 Kerberos 认证、高级报告和攻击性操作 — 全部使用纯 PowerShell 实现。

### v2 新特性

- **原生 Kerberos 协议栈** — AS-REQ/AS-REP、TGS-REQ/TGS-REP、Pass-the-Ticket、PKINIT,全部使用纯 PowerShell 实现
- **多种认证方式** — 密码、NT-Hash(OPtH)、AES 密钥(PtK)、证书(PKINIT 和 Pass-the-Cert/Schannel)、Windows 集成认证
- **40+ 项安全检查**,涵盖 9 个类别,带严重性评分
- **交互式 HTML 报告**,支持搜索、过滤、风险评分和工具提示
- **JSON 导出**,用于离线报告转换、增量扫描和扫描对比
- **BloodHound CE 收集器** — 内置数据收集,用于攻击路径分析
- **攻击性操作** — Kerberoasting、AS-REP Roasting、Golden/Silver/Diamond Tickets、RBCD 滥用、Shadow Credentials 等
- **基于会话的工作流** — 连接一次,交互式运行多项检查
- **Tab 补全** — 自动补全 AD 对象名称,便于交互式探索

> **初次使用 adPEAS?** 请查看[快速入门指南](https://github.com/61106960/adpeas/blob/main/docs/02-Quick-Start.md),或阅读 [blog.sekurity.de 上的博客系列](https://blog.sekurity.de/blog/adpeas-v2-introduction),深入了解架构、认证和内部机制。

---

## 功能一览

| 类别 | 亮点 |
|----------|-----------|
| **认证** | 凭据、PKINIT、Pass-the-Cert、NT-Hash、AES 密钥、Windows 认证、Kerberos 优先并自动回退 |
| **安全检查** | 域配置、Kerberoast、ASREPRoast、ACL、DCSync、委派、AD CS 提权路径、GPO 滥用、LAPS、BitLocker 恢复密钥、过时系统 |
| **报告** | 控制台(彩色编码)、纯文本、交互式 HTML、JSON 导出 |
| **攻击性操作** | Kerberoasting、AS-REP Roasting、Golden/Silver/Diamond Tickets、RBCD、Shadow Credentials、Pass-the-Ticket |
| **BloodHound** | 内置 BloodHound CE 收集器(ZIP 导出) |
| **OPSEC 模式** | 跳过主动测试(Kerberoast、ASREPRoast、BloodHound) |
| **部署** | 单个 `.ps1` 文件,无需 RSAT,无外部模块,可离线及气隙环境运行 |

---

## 系统要求

- **操作系统**:Windows 10/11、Windows Server 2016/2019/2022/2025
- **PowerShell**:5.1+(Windows PowerShell)
- **.NET Framework**:4.5+(Windows 内置)
- **网络**:LDAP (389)、LDAPS (636)、Kerberos (88)、SMB (445)

无需 ActiveDirectory 模块、RSAT 或外部 PowerShell 模块。

---

## 下载

### 发布版本

| 文件 | 大小 | 使用场景 |
|------|------|----------|
| `adPEAS.ps1` | ~4.5 MB | 开发、调试、代码审查 |
| `adPEAS_min.ps1` | ~3-4 MB | 常规使用,占用更小 |
| `adPEAS_ultra.ps1` | ~3 MB | 最小体积,无注释 |
| `adPEAS_obf.ps1` | <1 MB | 最小体积,混淆处理便于传输 |

四个版本功能完全相同。请根据您的部署场景选择。

```powershell
# Clone the repository
git clone https://github.com/61106960/adPEAS.git
cd adPEAS
```

### 从源码构建

`main` 分支始终包含所有四个变体的最新构建,每次修复和功能更新都会重新构建,因此上述原始 URL 提供的是最新代码。这些构建带有开发版本字符串(`2.5.1+20260917-1759`)。每个已标记的 [GitHub Release](https://github.com/61106960/adPEAS/releases) 都附有四个稳定构建作为可下载资源,带有干净的版本字符串(`2.5.1`)— 如果您需要已知、可引用的版本,请使用这些。要自行从源码构建:

```powershell
git clone https://github.com/61106960/adPEAS.git
cd adPEAS
.\Build-Release.ps1
```

这将在仓库根目录生成所有四个变体(`adPEAS.ps1`、`adPEAS_min.ps1`、`adPEAS_ultra.ps1`、`adPEAS_obf.ps1`)。需要 Windows PowerShell 5.1,无额外依赖。

---

## 快速开始

```powershell
# Option 1: Import as module (recommended)
Import-Module .\adPEAS.ps1

# Option 2: Dot-sourcing
. .\adPEAS.ps1

# Option 3: Read and execute in memory
Get-Content -Raw .\adPEAS.ps1 | Invoke-Expression

# Option 4: Load directly from GitHub into memory (no file on disk)
Invoke-Expression (Invoke-WebRequest -Uri "https://raw.githubusercontent.com/61106960/adPEAS/main/adPEAS_obf.ps1" -UseBasicParsing).Content
```

### 单行命令(兼容 v1)

```powershell
# Domain-joined machine (current user)
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth

# With credentials
Invoke-adPEAS -Domain "contoso.com" -Username "john.doe" -Password "P@ssw0rd!"

# OPSEC mode (skip Kerberoast, ASREPRoast, BloodHound)
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -OPSEC
```

### 基于会话(v2 风格)

```powershell
# Connect once
Connect-adPEAS -Domain "contoso.com" -UseWindowsAuth

# Run full scan
Invoke-adPEAS

# Or run individual checks
Get-KerberoastableAccounts
Get-ADCSVulnerabilities
Get-DangerousACLs

# Disconnect when done
Disconnect-adPEAS
```

### 认证方式

```powershell
# Credentials
Connect-adPEAS -Domain "contoso.com" -Credential (Get-Credential)

# Overpass-the-Hash (NT-Hash)
Connect-adPEAS -Domain "contoso.com" -Username "admin" -NTHash "32ED87BDB5FDC5E9CBA88547376818D4"

# Pass-the-Key (AES256)
Connect-adPEAS -Domain "contoso.com" -Username "admin" -AES256Key "4a3b2c1d5e6f..."

# PKINIT (Certificate)
Connect-adPEAS -Domain "contoso.com" -Certificate "user.pfx"

# Pass-the-Cert / Schannel (LDAPS, no Kerberos)
Connect-adPEAS -Domain "contoso.com" -Certificate "user.pfx" -PassTheCert

# LDAPS
Connect-adPEAS -Domain "contoso.com" -UseWindowsAuth -UseLDAPS
```

### 输出与报告

```powershell
# All formats (default) — creates .txt, .html, and .json
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -Outputfile .\report

# HTML only
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -Outputfile .\report -Format HTML

# Offline report conversion from JSON
Convert-adPEASReport -InputJson ".\report.json" -OutputPath ".\new_report"

# Compare two scans (diff report)
Compare-adPEASReport -Baseline ".\scan_q1.json" -Current ".\scan_q2.json" -OutputPath ".\diff"
```

---

## 安全检查模块

| 模块 | 描述 |
|--------|-------------|
| `Domain` | 域配置、信任关系、密码策略、LDAP 签名、SMB 签名 |
| `Creds` | Kerberoast、ASREPRoast、LAPS 和 BitLocker 恢复密钥访问、SYSVOL 中的凭据泄露 |
| `Rights` | ACL、DCSync、密码重置权限、危险的 OU 权限 |
| `Delegation` | 非约束委派、约束委派、基于资源的约束委派 |
| `ADCS` | 证书模板和 CA:ESC1-ESC5、ESC8、ESC9、ESC13、ESC14、ESC15(ESC10 通过 GPO 检查)。需要 CA 主机管理员权限的提权路径不在范围内 — 参见[安全检查](https://github.com/61106960/adpeas/blob/main/docs/04-Security-Checks.md) |
| `Accounts` | 特权账户、受保护用户、服务账户、SID 历史 |
| `GPO` | GPO 权限、本地组成员身份、计划任务、脚本、危险注册表设置(WDigest、AlwaysInstallElevated、OneLogon/Zerologon 等)以及通过 GPO 部署的 Point and Print 打印机驱动策略(PrintNightmare) |
| `Computer` | LAPS、过时系统、基础设施服务器 |
| `Application` | Exchange、SCCM、SCOM 基础设施 |
| `Bloodhound` | BloodHound CE 数据收集 |

运行特定模块:

```powershell
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -Module Domain,Creds,ADCS
```

或运行除少数之外的所有模块,无需列出其余模块:

```powershell
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -ExcludeModule Bloodhound,Computer
```

---

## 文档

完整文档位于 [docs/](https://github.com/61106960/adpeas/blob/main/docs) 目录:

| 文档                                                | 主题                             |
| ------------------------------------------------------- | --------------------------------- |
| [安装](https://github.com/61106960/adpeas/blob/main/docs/01-Installation.md)                 | 下载、设置、执行策略 |
| [快速开始](https://github.com/61106960/adpeas/blob/main/docs/02-Quick-Start.md)                   | 5 分钟快速上手          |
| [认证](https://github.com/61106960/adpeas/blob/main/docs/03-Authentication-Methods.md)     | 所有认证选项        |
| [安全检查](https://github.com/61106960/adpeas/blob/main/docs/04-Security-Checks.md)           | 完整检查参考          |
| [BloodHound 收集器](https://github.com/61106960/adpeas/blob/main/docs/05-BloodHound-Collector.md) | BloodHound CE 导出              |
| [核心函数](https://github.com/61106960/adpeas/blob/main/docs/06-Core-Functions.md)             | LDAP 查询函数              |
| [Set- 和 New- 模块](https://github.com/61106960/adpeas/blob/main/docs/07-Set-Modules.md)            | AD 修改函数         |
| [辅助函数](https://github.com/61106960/adpeas/blob/main/docs/08-Helper-Functions.md)         | 实用函数                 |
| [架构](https://github.com/61106960/adpeas/blob/main/docs/09-Architecture.md)                 | 技术架构            |
| [风险评分](https://github.com/61106960/adpeas/blob/main/docs/10-Risk-Scoring-System.md)          | 严重性和风险评分          |
| [故障排除](https://github.com/61106960/adpeas/blob/main/docs/11-Troubleshooting.md)           | 常见问题及解决方案       |
| [FAQ](https://github.com/61106960/adpeas/blob/main/docs/12-FAQ.md)                                   | 常见问题解答        |

### 博客系列

关于 adPEAS v2 内部机制的详细博客系列发布在 [blog.sekurity.de](https://blog.sekurity.de/blog/adpeas-v2-introduction)。

---

## 许可证

adPEAS 是**源码可获取**的。对您自己组织进行内部安全评估是免费的。商业使用(咨询、MSP、付费项目)需要商业许可证。

完整条款请参见 [LICENSE](https://github.com/61106960/adpeas/blob/main/license/LICENSE.md),商业协议请参见 [COMMERCIAL_AGREEMENT](https://github.com/61106960/adpeas/blob/main/license/COMMERCIAL_AGREEMENT.md),许可选项请参见 [PRICING](https://github.com/61106960/adpeas/blob/main/license/PRICING.md)。

- **许可咨询:** [email protected]
- **技术支持:** [email protected]

---

## 法律声明

adPEAS 仅供**授权的安全测试**使用。测试前请务必获得书面授权。切勿对您不拥有或未获许可测试的系统使用。作者不对本工具的滥用负责。请遵守所有适用的法律和法规。

---

## 作者

**Alexander Sturz** — [SEKurity GmbH](https://sekurity.de)

- GitHub: [@61106960](https://github.com/61106960)
- 博客: [blog.sekurity.de](https://blog.sekurity.de)
下载工具