AD-Port
Active Directory ์ฃผ์ ํฌํธ, ์ทจ์ฝ์ ๋ฐ ๋๊ตฌ
53
DNS
- DNS ์บ์ ์ค๋ (Cache Poisoning)
- DNS ์ฆํญ ๊ณต๊ฒฉ (Amplification)
nslookup, dig, dnsenum, Fierce, dnsrecon, dnstracer
88
Kerberos ์ธ์ฆ
- AS-REP Roasting
- ํฐ์ผ ์์กฐ (Golden/Silver Ticket)
- Pass-the-Ticket
impacket, Rubeus, Kerbrute, Hashcat, GetUserSPNs, mitm6
135
MS-RPC
- DCOM ์ทจ์ฝ์
- MS-RPC ๊ถํ ์์น
rpcclient, Metasploit, Nmap, PowerSploit, NetExec, Evil-WinRM
137โ139
NetBIOS
- SMB ๋ฆด๋ ์ด
- NTLM ๋ฆด๋ ์ด
- NetBIOS ์คํธํ
smbclient, Responder, impacket, Nmap, NetExec
389
LDAP (๋น์ํธํ)
- LDAP ์ธ์ ์
- ์๊ฒฉ ์ฆ๋ช ์์ง
- ์ต๋ช ๋ฐ์ธ๋ฉ
ldapsearch, Nmap, ldapdomaindump, NetExec, BloodHound, ADExplorer
445
SMB
- EternalBlue
- SMB ๋ฆด๋ ์ด
- SMB ์๋ช ๋นํ์ฑํ
- Pass-the-Hash
smbclient, impacket, Nmap, NetExec, Metasploit, smbmap
464
Kerberos (ํจ์ค์๋ ๋ณ๊ฒฝ)
- Kerberoasting
- ํจ์ค์๋ ์คํ๋ ์ด ๊ณต๊ฒฉ
impacket, Rubeus, Kerbrute, Hashcat, KrbRelayUp
593
HTTP RPC
- ์ธ์ฆ ์ฐํ
- MS-RPC ์ธ์ ์
rpcclient, Metasploit, Nmap, PowerSploit, Evil-WinRM, NetExec
636
LDAPS (์ํธํ๋ LDAP)
- LDAP ์ธ์ ์
- ์ธ์ฆ์ ์คํธํ
ldapsearch, Nmap, NetExec, BloodHound, ADExplorer
3268โ3269
๊ธ๋ก๋ฒ ์นดํ๋ก๊ทธ (GC)
- LDAP ์ธ์ ์
- ๋ฐ์ดํฐ ๋ ธ์ถ
ldapsearch, Nmap, NetExec, BloodHound, ADExplorer
3389
RDP (์๊ฒฉ ๋ฐ์คํฌํฑ)
- BlueKeep
- ์ฝํ ์ํธํ
- RDP ํ์ด์ฌํน
- ์ธ์ฆ์ ์ ๋ฌ
ncrack, xfreerdp, Metasploit, NetExec, rdpscan
5985โ5986
WinRM (PowerShell ์๊ฒฉ ๊ด๋ฆฌ)
- ์๊ฒฉ ์ฆ๋ช ํ์ทจ
- Pass-the-Hash
- ๋ฌด์ ํ ์์
Evil-WinRM, Impacket, NetExec, Metasploit, PowerView
Last updated