返回介绍

10.9. 横向移动

发布于 2024-02-07 20:47:54 字数 4674 浏览 0 评论 0 收藏 0

10.9. 横向移动

10.9.1. 域

  • impacket is a collection of Python classes for working with network protocols
  • adidnsdump Active Directory Integrated DNS dump tool
  • BloodHound Six Degrees of Domain Admin
  • PlumHound Bloodhound for Blue and Purple Teams
  • windapsearch Python script to enumerate users, groups and computers from a Windows domain through LDAP queries
  • ldapdomaindump Active Directory information dumper via LDAP
  • Kerberoast a series of tools for attacking MS Kerberos implementations
  • ADRecon Active Directory Recon
  • Creds Some usefull Scripts and Executables for Pentest & Forensics
  • Lithnet Password Protection for Active Directory Active Directory password filter featuring breached password checking and custom complexity rules
  • ASREPRoast Project that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled.

10.9.2. LDAP

10.9.3. 微软系产品利用

  • LyncSniper A tool for penetration testing Skype for Business and Lync deployments
  • MSOLSpray A password spraying tool for Microsoft Online accounts (Azure/O365)
  • MailSniper MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms

10.9.4. Azure AD

  • ROADtools Azure AD exploration framework
  • Stormspotter Azure Red Team tool for graphing Azure and Azure Active Directory objects

10.9.5. Exchange

10.9.6. PowerShell

10.9.7. 内网信息收集

  • nbtscan NetBIOS scanning tool
  • SharpShares Quick and dirty binary to list network share information from all machines in the current domain and if they're readable
  • WinShareEnum Windows Share Enumerator
  • HackBrowserData 全平台的浏览器数据导出工具

10.9.8. Kerberos

  • Rubeus
  • kerbrute A tool to perform Kerberos pre-auth bruteforcing
  • kerberoast A series of tools for attacking MS Kerberos implementations

10.9.9. 自动化审计

10.9.10. 绕过

  • SysWhispers AV/EDR evasion via direct system calls
  • SysWhispers2 AV/EDR evasion via direct system calls
  • Dumpert LSASS memory dumper using direct system calls and API unhooking

10.9.11. 内网扫描

  • InScan 边界打点后的自动化渗透工具
  • fscan 一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。
列表为空,暂无数据
    我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
    原文