Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
windows-coerced-authentication-methods — A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols. | Kitploit
工具/GitHubGitHub/p0dalirius/windows-coerced-authentication-methods
Privilege EscalationExploitationPenetration TestingAuthenticationRed TeamingCurated Resources
GitHubp0dalirius/windows-coerced-authentication-methods

windows-coerced-authentication-methods

A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols.

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库网站
601721315天前Kitploit 审核通过
内容在请求的语言中不可用。显示英文版本。


This repository contains a list of many methods to coerce a windows machine to authenticate to an attacker-controlled machine.
GitHub repo size YouTube Channel Subscribers

All of these methods are callable by a standard user in the domain to force the machine account of the target Windows machine (usually a domain controller) to authenticate to an arbitrary target. The root cause of this "vulnerability/feature" in each of these methods is that Windows machines automatically authenticate to other machines when trying to access UNC paths (like \\192.168.2.1\SYSVOL\file.txt).

There are currently 30 working functions in 13 protocols.


Protocols & Methods

  • [MS-COMA]: Component Object Model Plus (COM+) Remote Administration Protocol

    • Remote call to ImportFromFile (opnum 3)/README.md)
  • [MS-DFSNM]: Distributed File System (DFS) Namespace Management Protocol

    • Remote call to NetrDfsAdd (opnum 1)/README.md)
    • Remote call to NetrDfsAddStdRoot (opnum 12)/README.md)
    • Remote call to NetrDfsRemoveStdRoot (opnum 13)/README.md)
    • Remote call to NetrDfsAddRootTarget (opnum 23)/README.md)
    • Remote call to NetrDfsRemoveRootTarget (opnum 24)/README.md)
  • [MS-DHCPM]: Microsoft Dynamic Host Configuration Protocol (DHCP) Server Management Protocol

    • Remote call to R_DhcpBackupDatabase (opnum 44)/README.md)
    • Remote call to R_DhcpRestoreDatabase (opnum 45)/README.md)
  • [MS-DNSP]: Domain Name Service (DNS) Server Management Protocol

    • Remote call to R_DnssrvOperation — LogFilePath (opnum 0)/README.md)
  • [MS-EFSR]: Encrypting File System Remote (EFSRPC) Protocol

    • Remote call to EfsRpcOpenFileRaw (opnum 0)/README.md)
    • Remote call to EfsRpcEncryptFileSrv (opnum 4)/README.md)
    • Remote call to EfsRpcDecryptFileSrv (opnum 5)/README.md)
    • Remote call to EfsRpcQueryUsersOnFile (opnum 6)/README.md)
    • Remote call to EfsRpcQueryRecoveryAgents (opnum 7)/README.md)
    • Remote call to EfsRpcFileKeyInfo (opnum 12)/README.md)
    • Remote call to EfsRpcDuplicateEncryptionInfoFile (opnum 13)/README.md)
    • Remote call to EfsRpcAddUsersToFileEx (opnum 15)/README.md)
    • Remote call to EfsRpcFileKeyInfoEx (opnum 16)/README.md)
    • Remote call to EfsRpcEncryptFileExSrv (opnum 21)/README.md)
下载工具