属性 ms-mcs-AdmPwd 存储了 LAPS 明文密码。
此可执行文件旨在通过 execute-assembly 在 Cobalt Strike 会话中执行。
它将从 Active Directory 中检索 LAPS 密码。
需要(任一):
ExtendedRight 或 Generic All Rights 的账户 _____ __ __ ___ ____ _____
/ ___// /_ ____ __________ / / / | / __ \/ ___/
\__ \/ __ \/ __ `/ ___/ __ \/ / / /| | / /_/ /\__ \
___/ / / / / /_/ / / / /_/ / /___/ ___ |/ ____/___/ /
/____/_/ /_/\__,_/_/ / .___/_____/_/ |_/_/ /____/
/_/
必需
/host:<1.1.1.1> LDAP 目标主机,通常是域控制器
可选
/user:<username> 账户用户名
/pass:<password> 账户密码
/out:<file> 将凭据输出到文件
/ssl 启用 SSL (LDAPS://)
用法: SharpLAPS.exe /user:DOMAIN\User /pass:MyP@ssw0rd123! /host:192.168.1.1
