
StandIn 是一个小型 AD 后渗透工具包。StandIn 的出现是因为最近在 xforcered,我们需要一个 .NET 原生解决方案来执行基于资源的约束委派。然而,StandIn 很快膨胀,包含了大量便利功能。
我希望继续开发 StandIn,以自学更多关于目录服务编程的知识,并有望扩展一个适合 AD 后渗透工具链的工具。
非常欢迎贡献。请确保拉取请求包含以下内容:功能描述、简要技术说明和示例输出。
如果你有希望添加到 StandIn 但还没有提交 PR 的功能?请创建一个工单并尽可能详细地描述该功能。
以下项目目前计划在后续版本的 StandIn 中实现。
__ ( / _// ~b33f __)/(//)(/(/) v1.4
--
--> Args? <----<
--help This help menu --object LDAP filter, e.g. samaccountname=HWest --ldap LDAP filter, can return result collection --filter Filter results, varies based on function --limit Limit results, varies based on function, defaults to 50 --computer Machine name, e.g. Celephais-01 --group samAccountName, e.g. "Necronomicon Admins" --ntaccount User name, e.g. "REDHOOK\UPickman" --sid Dependent on context --grant User name, e.g. "REDHOOK\KMason" --guid Rights GUID to add to object, e.g. 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 --domain Domain name, e.g. REDHOOK --user User name --pass Password --newpass New password to set for object --gpo List group policy objects --acl Show ACL's for returned GPO's --localadmin Add samAccountName to BUILTIN\Administrators for vulnerable GPO --setuserrights samAccountName for which to add token rights in a vulnerable GPO --tasktype Immediate task type (user/computer) --taskname Immediate task name --author Immediate task author --command Immediate task command --args Immediate task command args --target Optional, filter for DNS name or NTAccount --targetsid Optional, provider user SID --increase Increment either the user or computer GPO version number for the AD object --policy Reads some account/kerberos properties from the "Default Domain Policy" --dns Performs ADIDNS enumeration, supports wildcard filters --legacy Boolean, sets DNS seach root to legacy (CN=System) --forest Boolean, sets DNS seach root to forest (DC=ForestDnsZones) --passnotreq Boolean, list accounts that have PASSWD_NOTREQD set --type Rights type: GenericAll, GenericWrite, ResetPassword, WriteMembers, DCSync --spn Boolean, list kerberoastable accounts --setspn samAccountName for which to add/remove an SPN --principal Principal name to add to samAccountName (e.g. MSSQL/VermisMysteriis) --delegation Boolean, list accounts with unconstrained / constrained delegation --asrep Boolean, list ASREP roastable accounts --dc Boolean, list all domain controllers --trust Boolean, list all trust relationships --adcs List all CA's and all published templates --clientauth Boolean, modify ADCS template to add/remove "Client Authentication" --ess Boolean, modify ADCS template to add/remove "ENROLLEE_SUPPLIES_SUBJECT" --pend Boolean, modify ADCS template to add/remove "PEND_ALL_REQUESTS" --owner Boolean, modify ADCS template owner --write Boolean, modify ADCS template, add/remove WriteDacl/WriteOwner/WriteProperty permission for NtAccount --enroll Boolean, modify ADCS template, add/remove "Certificate-Enrollment" permission for NtAccount --add Boolean, context dependent group/spn/adcs --remove Boolean, context dependent msDS-AllowedToActOnBehalfOfOtherIdentity/group/adcs --make Boolean, make machine; ms-DS-MachineAccountQuota applies --disable Boolean, disable machine; should be the same user that created the machine --access Boolean, list access permissions for object --delete Boolean, delete machine from AD; requires elevated AD access
--
--> Usage? <----<