Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Awesome-RedTeam-Cheatsheet — 不断扩展的红队速查表。 | Kitploit
工具/GitHubGitHub/ristbs/awesome-redteam-cheatsheet
权限提升持久化机制横向移动渗透测试学习与教育红队精选资源
GitHubristbs/awesome-redteam-cheatsheet

Awesome-RedTeam-Cheatsheet

不断扩展的红队速查表。

查看仓库
1.3k167213年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

image


红队技术

  • 初始访问技术(即将推出)
  • 代码执行技术(即将推出)
  • 横向移动技术(即将推出)
  • 规避技术(即将推出)
  • 持久化技术(即将推出)
  • 权限提升技术(即将推出)
  • 凭据转储技术(即将推出)
  • Pivoting 技术(即将推出)

Windows 协议与术语

  • Windows 协议与术语指南(即将推出)

其他

  • OPSEC 指南
  • 恶意软件开发
  • 攻击 AD Azure Cloud(即将推出)

支持

你可以在这里支持我 🐱 :

Active Directory 速查表

这份 AD 攻击速查表由 RistBS 制作,灵感来源于 Active-Directory-Exploitation-Cheat-Sheet 仓库。

概要

  • RistBS 的 AD 利用速查表
    • 概要
    • 工具
    • PowerShell 组件
      • PowerShell 技巧
      • PSWA 滥用
    • 枚举
      • GPO 枚举
      • ACL 与 ACE 枚举
      • RID 循环
    • 权限提升
      • 令牌模拟
      • Kerberoasting
      • ASREPRoasting
      • DNSAdmin
    • 横向移动
      • WMIExec
    • 凭据转储
      • LSASS 转储
      • NTDS 转储
      • DPAPI 滥用
      • LSA 转储
      • SAM 转储
      • 远程直接转储注册表
      • 读取 GMSA 密码
    • 哈希破解
    • AD 密码暴力破解
      • 自定义用户名和密码字典
    • Pivoting
      • SMB 管道
      • SharpSocks
      • 通过 DVC 的 RDP 隧道
    • 持久化
      • SIDHistory 注入
      • AdminSDHolder 与 SDProp
    • ACLs 与 ACEs 滥用
      • GenericAll
    • 增强安全性绕过
      • 反恶意软件扫描接口
      • ConstrainLanguageMode
      • 刚好足够的 Administration
      • 执行策略
      • 用于凭据转储的 RunAsPPL
      • ETW 禁用
    • MS Exchange
      • OWA、EWS 和 EAS 密码喷射
      • GAL 和 OAB 提取
      • PrivExchange
      • ProxyLogon
      • CVE-2020-0688
    • MSSQL 服务器
      • UNC 路径注入
      • MC-SQLR 毒化
      • DML、DDL 和登录触发器
    • 森林持久化
      • DCShadow
    • 跨森林攻击
      • 信任票据
      • 使用 KRBTGT 哈希
    • Azure Active Directory (AAD)
      • AZ 用户枚举
      • PowerZure
      • Golden SAML
      • PRT 操纵
      • MSOL 服务账户
    • 其他
      • 域级别属性
        • MachineAccountQuota (MAQ) 利用
        • Bad-Pwd-Count
      • 滥用 IPv6 在 AD 中
        • 恶意 DHCP
        • IOXIDResolver 接口枚举
      • 参考资料

工具

PowerShell 工具:

  • [⭐] Nishang -> https://github.com/samratashok/nishang

Nishang 包含多个适用于 Windows 渗透测试的 PowerShell 环境下的有用脚本。

  • [⭐] PowerView -> https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1

PowerView 是 PowerSploit 中的一个脚本,可用于枚举 AD 架构以实现潜在的横向移动。

枚举工具:

  • [⭐] Bloodhound -> https://github.com/BloodHoundAD/BloodHound
  • [⭐] crackmapexec -> https://github.com/byt3bl33d3r/CrackMapExe

AD 利用工具包:

  • [⭐] Impacket -> https://github.com/SecureAuthCorp/impacket
  • [⭐] kekeo -> https://github.com/gentilkiwi/kekeo

转储工具:

  • [⭐] mimikatz -> https://github.com/gentilkiwi/mimikatz
  • [⭐] rubeus -> https://github.com/GhostPack/Rubeus

监听器工具:

  • [⭐] responder -> https://github.com/SpiderLabs/Responder

PowerShell 组件

PowerShell 技巧

PS-Session :```powershell #METHOD 1 $c = New-PSSession -ComputerName 10.10.13.100 -Authentication Negociate -Credential $user Enter-PSSession -Credential $c -ComputerName 10.10.13.100

METHOD 2

$pass = ConvertTo-SecureString 'Ab!Q@aker1' -asplaintext -force $cred = New-Object System.Management.Automation.PSCredential('$user, $pass') Enter-PSSession -Credential $c -ComputerName 10.10.13.100

### PSWA 滥用

允许任何拥有凭证的人连接到任何机器和任何配置

**[ ! ] 此操作需要凭证。**```powershell
Add-PswaAuthorizationRule -UsernName * -ComputerName * -ConfigurationName *

枚举

查找具有SPN的用户

使用 PowerView :```powershell Get-NetUser –SPN

> 使用 [AD Module](https://docs.microsoft.com/en-us/powershell/module/activedirectory/?view=windowsserver2022-ps) :```powershell
Get-ADUser -Filter {ServicePrincipalName -ne "$null"} -Properties ServicePrincipalName

信任枚举

MapTrust :```powershell Invoke-MapDomainTrust

**当前域的域信任 :**

> 使用 [PowerView](https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1) :```powershell
Get-NetDomainTrust #Find potential external trust
Get-NetDomainTrust –Domain $domain

使用 AD Module :```powershell Get-ADTrust Get-ADTrust –Identity $domain

### 森林枚举

**关于当前森林的详细信息:**```powershell
Get-NetForest
Get-NetForest –Forest $forest
Get-ADForest
Get-ADForest –Identity $domain

GPO枚举

GPO列表```powershell Get-NetGPO Get-NetGPO -ComputerName $computer Get-GPO -All Get-GPResultantSetOfPolicy -ReportType Html -Path C:\Users\Administrator\report.html

### ACL与ACE枚举
下载工具