Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
KnockKnock — 在 Microsoft Teams 和 OneDrive 中枚举有效用户,并输出简洁结果。 | Kitploit
工具/GitHubGitHub/optiv/knockknock
OSINT (开源情报)侦察信息收集渗透测试云安全身份验证Archived
GitHuboptiv/knockknock

KnockKnock

在 Microsoft Teams 和 OneDrive 中枚举有效用户,并输出简洁结果。

查看仓库
626221年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

此仓库已归档

要查看 KnockKnock 的最新版本或提交问题,请参考 https://github.com/waffl3ss/KnockKnock。


KnockKnock - v0.9.9

请务必实际阅读 README。

设计用于通过查询 OneDrive 和/或 Microsoft Teams 来验证潜在用户名,这些是被动方法。
它可以输出/创建通过 Microsoft Teams 枚举识别出的旧版 Skype 用户列表。
它还可以从 Teams 获取详细信息,例如可用性、设备类型和外出留言。
最后,它还能生成一份整洁的列表供将来使用,所有操作均通过单一工具完成。


用法

$ python3 .\KnockKnock.py -h

  _  __                 _    _  __                 _
 | |/ /_ __   ___   ___| | _| |/ /_ __   ___   ___| | __
 | ' /| '_ \ / _ \ / __| |/ / ' /| '_ \ / _ \ / __| |/ /
 | . \| | | | (_) | (__|   <| . \| | | | (_) | (__|   <
 |_|\_\_| |_|\___/ \___|_|\_\_|\_\_| |_|\___/ \___|_|\_\
   v0.9.9                                   @waffl3ss


usage: KnockKnock.py [-h] [-teams] [-onedrive] [-l] -i INPUTLIST [-o OUTPUTFILE] -d TARGETDOMAIN [-t TEAMSTOKEN] [-threads MAXTHREADS] [-v]

options:
  -h, --help           show this help message and exit
  -teams               Run the Teams User Enumeration Module
  -onedrive            Run the One Drive Enumeration Module
  -l                   Write legacy skype users to a seperate file
  -s                   Write Teams Status for users to a seperate file
  -i INPUTLIST         Input file with newline-seperated users to check
  -o OUTPUTFILE        Write output to file
  -d TARGETDOMAIN      Domain to target
  -t TEAMSTOKEN        Teams Token (file containing token or a string)
  -threads MAXTHREADS  Number of threads to use in the Teams User Enumeration (default = 10)
  -v                   Show verbose errors

示例

./KnockKnock.py -teams -i UsersList.txt -d Example.com -o OutFile.txt -t BearerToken.txt
./KnockKnock.py -onedrive -i UsersList.txt -d Example.com -o OutFile.txt
./KnockKnock.py -onedrive -teams -i UsersList.txt -d Example.com -t BearerToken.txt -l

选项

  • 您可以选择一种或两种模式,只要为所选模块提供了相应的选项即可。
  • 两个模块都需要域标志(-d)和用户输入列表(-i)。
  • 该工具不要求提供输出文件作为选项;如果未提供,则仅打印到屏幕。
  • 详细模式会显示大量额外信息,包括无效用户。
  • Teams 选项需要一个 Bearer 令牌。脚本会自动解析令牌以获取认证所需信息。
  • LEGACY (-l) 选项显示仍具有 SkypeID 设置的用户,并将其写入单独的文件。
  • STATUS (-s) 选项显示用户的 Teams 可用性、设备和外出留言,然后将其写入单独的文件。

如何获取你的 Bearer 令牌

要获取你的 Bearer 令牌,你需要在浏览器中安装 Cookie 管理器插件,并通过浏览器登录你自己的 Microsoft Teams。
接下来,查看与当前网页(teams.microsoft.com)相关的 Cookies。
你要找的 Cookie 对应于域 .teams.microsoft.com,名称为 'authtoken'。
你可以复制整个令牌,因为脚本会为你提取所需的部分。


参考

@nyxgeek - onedrive_user_enum
@immunIT - TeamsUserEnum

下载工具