Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
ADReaper — 一个用Go编写的用于Windows Active Directory渗透测试的快速枚举工具。 | Kitploit
工具/GitHubGitHub/m0n1x90/adreaper
侦察信息收集渗透测试身份验证
GitHubm0n1x90/adreaper

ADReaper

一个用Go编写的用于Windows Active Directory渗透测试的快速枚举工具。

查看仓库
286363年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

ADReaper

ADReaper 是一个用 Golang 编写的工具,能够在几秒钟内通过 LDAP 查询枚举 Active Directory 环境。

安装

你可以从 最新发布 下载适用于 Windows/Linux 的预编译可执行二进制文件。

从源码安装

要从源码构建,克隆仓库并使用 GO 构建:

root@kitploit:~
$ git clone https://github.com/AidenPearce369/ADReaper
$ cd ADReaper/
$ go build

使用方法

ADReaper 通过多种命令执行枚举,这些命令根据各自用途执行 LDAP 查询。

root@kitploit:~
PS C:\Users\redteamer\Desktop\shared> .\ADReaper.exe

      -command string

            要运行的命令
                  dc              - 列出域控制器
                  domain-trust    - 列出域信任关系
                  users           - 列出所有用户
                  computers       - 列出所有计算机
                  groups          - 列出所有组及其成员
                  spn             - 列出服务主体名称对象
                  never-loggedon  - 列出从未登录过的用户
                  gpo             - 列出组策略对象
                  ou              - 列出组织单位
                  ms-sql          - 列出 MS-SQL 服务器
                  asreproast      - 列出可 AS-REP 烘焙的账户
                  unconstrained   - 列出启用了无约束委派的账户
                  admin-priv      - 列出具有管理员权限的 AD 对象

      -dc string

            输入域控制器

      -filter string

            用于用户/组/计算机的筛选器

            list - 仅列出所有对象
            full-data - 列出所有对象及其属性
            membership - 列出对象中的所有成员

            (默认值 "list")
      -name string

            传递用户/组/计算机的对象名称

      -password string

            输入密码

      -user string

            输入用户名

查询域的 域控制器 属性:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command dc

查询域的 信任属性:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command domain-trust

列出域中的所有 用户:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command users

列出域中所有带属性的 用户:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command users -filter full-data

列出域中 特定用户 的属性:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command users -name <用户>

列出特定用户的组成员资格:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command users -name <用户> -filter membership

列出域中所有可用的 计算机:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command computers

列出域中所有带属性的 计算机:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command computers -filter full-data

列出域中 特定计算机 的属性:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command computers -name <计算机名>

列出域中所有可用的 组:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command groups

列出域中所有带属性的 组:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command groups -filter full-data

列出域中 特定组 的属性:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command groups -name <组名>

列出域中 特定组 的成员:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command groups -name <组名> -filter membership

列出域中 从未登录过 的用户:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command never-loggedon

列出域中的 GPO:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command gpo

列出域中的 OU:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command ou

列出具有更高权限的 AD 对象:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command admin-priv

列出域中的 MS-SQL 服务器:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command ms-sql

列出域中所有 MS-SQL 服务器 的属性:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command ms-sql -filter full-data

列出域中特定 MS-SQL 服务器 的所有属性:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command ms-sql -name <计算机名>

列出域中可用的 SPN:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command spn

列出域中 特定 SPN 的所有属性:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command spn -name <spn 的 sam>

列出启用了 无约束委派 的 AD 对象:

root@kitploit:~
.\ADReaper.exe -dc <dc.domain> -user <用户名> -password <密码> -command unconstrained

待办事项

期待贡献者参与构建下一个版本

计划的功能包括:

  • 自定义 LDAP 查询
  • 使用现有命令过滤 LDAP 属性
  • LAPS 枚举
  • Kerberoasting SPN
  • AS-REP Roasting SPN
  • 本地管理员访问权限嗅探
  • ACL 枚举
  • 导出 BloodHound 的 JSON 数据

如果有兴趣,请联系我 :)

下载工具