Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
工具/GitHubGitHub/fuzzysecurity/standin
权限提升漏洞利用横向移动后渗透利用渗透测试DNS 分析
GitHubfuzzysecurity/standin

StandIn

StandIn 是一个小型的 .NET35/45 AD 后渗透工具包

查看仓库
864140264年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

StandIn

StandIn 是一个小型 AD 后渗透工具包。StandIn 的出现是因为最近在 xforcered,我们需要一个 .NET 原生解决方案来执行基于资源的约束委派。然而,StandIn 很快膨胀,包含了大量便利功能。

我希望继续开发 StandIn,以自学更多关于目录服务编程的知识,并有望扩展一个适合 AD 后渗透工具链的工具。

路线图

贡献指南

非常欢迎贡献。请确保拉取请求包含以下内容:功能描述、简要技术说明和示例输出。

如果你有希望添加到 StandIn 但还没有提交 PR 的功能?请创建一个工单并尽可能详细地描述该功能。

待办事项

以下项目目前计划在后续版本的 StandIn 中实现。

  • 域共享枚举。这可以分成两部分:(1) 基于用户主目录/脚本路径/配置文件路径查找并获取唯一列表,(2) 查询 fTDfs / msDFS-Linkv2 对象。
  • 查找并解析 GPO 以将用户映射到主机本地组。
  • GPO -> OU 及 OU -> GPO。
  • 可能重写策略函数。
  • 为某些函数添加可选的 JSON/XML 输出以帮助脚本编写。
  • 代码需要重构,更好地模块化函数并拆分到不同类中。

主题参考

  • An ACE up the sleeve(作者 @_wald0 和 @harmj0y)- 链接
  • Kerberoasting(作者 @xpn)- 链接
  • Roasting AS-REPs(作者 @harmj0y)- 链接
  • Kerberos Unconstrained Delegation(作者 @spotheplanet)- 链接
  • S4U2Pwnage(作者 @harmj0y)- 链接
  • Resource-based Constrained Delegation(作者 @spotheplanet)- 链接
  • Rubeus - 链接
  • Powerview - 链接
  • Powermad(作者 @kevin_robertson)- 链接
  • SharpGPOAbuse(作者 @den_n1s 和 @pkb1s)- 链接
  • adidnsdump(作者 @_dirkjan)- 链接
  • Certified Pre-Owned(作者 @harmj0y 和 @tifkin_)- 链接

索引

  • 帮助
  • LDAP 对象操作
    • 原始 LDAP
    • 获取对象
    • 获取对象访问权限
    • 授予对象访问权限
    • 设置对象密码
    • 向对象标志添加 ASREP
    • 从对象标志移除 ASREP
  • SID
  • ASREP
  • PASSWD_NOTREQD
  • SPN
    • SPN 收集
    • 设置 SPN
  • 非约束/约束/基于资源的约束委派
  • 域控制器
  • 信任
  • GPO 操作
    • 列出 GPO
    • GPO 添加本地管理员
    • GPO 添加用户权限
    • GPO 添加即时任务
    • GPO 增加用户/计算机版本
  • 策略
  • DNS
  • 组操作
    • 列出组成员身份
    • 添加/移除组用户
  • 计算机对象操作
    • 创建计算机对象
    • 禁用计算机对象
    • 删除计算机对象
    • 添加 msDS-AllowedToActOnBehalfOfOtherIdentity
    • 移除 msDS-AllowedToActOnBehalfOfOtherIdentity
  • Active Directory 证书服务 (ADCS)
    • 列出
    • 客户端身份验证
    • ENROLLEE_SUPPLIES_SUBJECT
    • PEND_ALL_REQUESTS
    • 更改所有者
    • 添加写入权限
    • 添加证书注册权限
  • 检测
  • 特别感谢

帮助```

__ ( / _// ~b33f __)/(//)(/(/) v1.4

----> Args? <----<

--help This help menu --object LDAP filter, e.g. samaccountname=HWest --ldap LDAP filter, can return result collection --filter Filter results, varies based on function --limit Limit results, varies based on function, defaults to 50 --computer Machine name, e.g. Celephais-01 --group samAccountName, e.g. "Necronomicon Admins" --ntaccount User name, e.g. "REDHOOK\UPickman" --sid Dependent on context --grant User name, e.g. "REDHOOK\KMason" --guid Rights GUID to add to object, e.g. 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 --domain Domain name, e.g. REDHOOK --user User name --pass Password --newpass New password to set for object --gpo List group policy objects --acl Show ACL's for returned GPO's --localadmin Add samAccountName to BUILTIN\Administrators for vulnerable GPO --setuserrights samAccountName for which to add token rights in a vulnerable GPO --tasktype Immediate task type (user/computer) --taskname Immediate task name --author Immediate task author --command Immediate task command --args Immediate task command args --target Optional, filter for DNS name or NTAccount --targetsid Optional, provider user SID --increase Increment either the user or computer GPO version number for the AD object --policy Reads some account/kerberos properties from the "Default Domain Policy" --dns Performs ADIDNS enumeration, supports wildcard filters --legacy Boolean, sets DNS seach root to legacy (CN=System) --forest Boolean, sets DNS seach root to forest (DC=ForestDnsZones) --passnotreq Boolean, list accounts that have PASSWD_NOTREQD set --type Rights type: GenericAll, GenericWrite, ResetPassword, WriteMembers, DCSync --spn Boolean, list kerberoastable accounts --setspn samAccountName for which to add/remove an SPN --principal Principal name to add to samAccountName (e.g. MSSQL/VermisMysteriis) --delegation Boolean, list accounts with unconstrained / constrained delegation --asrep Boolean, list ASREP roastable accounts --dc Boolean, list all domain controllers --trust Boolean, list all trust relationships --adcs List all CA's and all published templates --clientauth Boolean, modify ADCS template to add/remove "Client Authentication" --ess Boolean, modify ADCS template to add/remove "ENROLLEE_SUPPLIES_SUBJECT" --pend Boolean, modify ADCS template to add/remove "PEND_ALL_REQUESTS" --owner Boolean, modify ADCS template owner --write Boolean, modify ADCS template, add/remove WriteDacl/WriteOwner/WriteProperty permission for NtAccount --enroll Boolean, modify ADCS template, add/remove "Certificate-Enrollment" permission for NtAccount --add Boolean, context dependent group/spn/adcs --remove Boolean, context dependent msDS-AllowedToActOnBehalfOfOtherIdentity/group/adcs --make Boolean, make machine; ms-DS-MachineAccountQuota applies --disable Boolean, disable machine; should be the same user that created the machine --access Boolean, list access permissions for object --delete Boolean, delete machine from AD; requires elevated AD access

----> Usage? <----<

下载工具