Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
PetitPotam | Kitploit
工具/GitHubGitHub/corelight/petitpotam
防御工具网络安全身份验证入侵检测异常检测
GitHubcorelight/petitpotam

PetitPotam

查看仓库
114年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

PetitPotam NTLM 中继攻击检测

一个用于检测通过 Petit Potam 漏洞利用触发 NTLM 中继攻击尝试的 Zeek 软件包。 该软件包将检测看似成功和失败的漏洞利用尝试。它通过检查 EFS DCERPC 函数调用的返回代码来区分这两者。

注意:该软件包仅检测通过未加密 SMB 传输的漏洞利用尝试。通过加密 SMB 进行的 DCERPC 调用将不会被检测到。在这些情况下,有时可以通过检查 ntlm.log 输出来 寻找正在进行的成功 NTLM 中继攻击的迹象。

安装

安装此软件包最简单的方式是通过 zkg:

zkg install corelight/petitpotam

使用

使用 ./testing/Traces/UnPatchedDCOpenFileRaw.pcapng,您可以按以下步骤操作:

root@kitploit:~
% zeek -Cr ./testing/Traces/UnPatchedDCOpenFileRaw.pcapng ./scripts/main.zeek

% cat ./notice.log
#separator \x09
#set_separator	,
#empty_field	(empty)
#unset_field	-
#path	notice
#open	2021-09-08-09-40-22
#fields	ts	uid	id.orig_h	id.orig_p	id.resp_h	id.resp_p	fuid	file_mime_type	file_desc	proto	note	msg	sub	src	dst	p	n	peer_descr	actions	email_dest	suppress_for	remote_location.country_code	remote_location.region	remote_location.city	remote_location.latitude	remote_location.longitude
#types	time	string	addr	port	addr	port	string	string	string	enum	enum	string	string	addr	addr	port	count	string	set[enum]	set[string]	interval	string	string	string	double	double
1630594391.099325	CyNNkV2Rl7jrlWadG7	192.168.0.15	33524	192.168.0.85	445	-	-	-	tcp	PetitPotam::PetitPotam	Successful PetitPotam NTLM relay attack: efsrpc2 EfsRpcOpenFileRaw()	-	192.168.0.15	192.168.0.85	445	-	-	Notice::ACTION_LOG	(empty)	3600.000000	-	-	-	-	-
#close	2021-09-08-09-40-22

% cat ./dce_rpc.log
#separator \x09
#set_separator	,
#empty_field	(empty)
#unset_field	-
#path	dce_rpc
#open	2021-09-08-09-40-22
#fields	ts	uid	id.orig_h	id.orig_p	id.resp_h	id.resp_p	rtt	named_pipe	endpoint	operation
#types	time	string	addr	port	addr	port	interval	string	string	string
1630594365.186353	Cdyntb1vGsZnt6aus7	192.168.0.85	57206	192.168.0.80	49677	0.001003	49677	drsuapi	DRSUnbind
1630594365.187814	Cdyntb1vGsZnt6aus7	192.168.0.85	57206	192.168.0.80	49677	0.000819	49677	drsuapi	DRSUnbind
1630594390.076173	CyNNkV2Rl7jrlWadG7	192.168.0.15	33524	192.168.0.85	445	1.023152	\\pipe\\lsass	efsrpc2	EfsRpcOpenFileRaw
1630594416.810307	CDjrA835p6W6vhm4sg	192.168.0.85	57210	192.168.0.80	49677	0.001444	49677	drsuapi	DRSGetNCChanges
#close	2021-09-08-09-40-22

其他参考

  • https://github.com/topotam/PetitPotam
  • https://www.bleepingcomputer.com/news/microsoft/new-petitpotam-attack-allows-take-over-of-windows-domains/
  • https://www.bleepingcomputer.com/news/security/microsoft-shares-mitigations-for-new-petitpotam-ntlm-relay-attack/
  • https://msrc.microsoft.com/update-guide/vulnerability/ADV210003
  • https://support.microsoft.com/en-us/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429

许可证

版权所有 (c) 2021, Corelight, Inc. 保留所有权利。

允许以源代码和二进制形式重新分发和使用,无论是否经过修改,前提是满足以下条件:

(1) 源代码的再分发必须保留上述版权声明、此条件列表和以下免责声明。

(2) 二进制形式的再分发必须在随分发提供的文档和/或其他材料中复制上述版权声明、此条件列表和以下免责声明。

(3) 未经事先明确的书面许可,不得使用 Broala, Inc. 的名称或其贡献者的名称来认可或推广由本软件衍生的产品。

本软件由版权持有者和贡献者“按现状”提供,不附带任何明示或暗示的保证,包括但不限于对适销性和特定用途适用性的暗示保证。在任何情况下,版权所有者或贡献者均不对任何直接、间接、偶然、特殊、示范性或后果性损害(包括但不限于采购替代商品或服务;使用、数据或利润的损失;或业务中断)承担责任,无论该损害是如何引起的,也不论是基于何种责任理论(无论是合同、严格责任还是侵权行为(包括疏忽或其他方式)),即使已被告知发生此类损害的可能性。

下载工具