AD-Port

Active Directory ์ฃผ์š” ํฌํŠธ, ์ทจ์•ฝ์  ๋ฐ ๋„๊ตฌ


ํฌํŠธ
ํ”„๋กœํ† ์ฝœ / ์„œ๋น„์Šค
์ฃผ์š” ์ทจ์•ฝ์ 
๊ด€๋ จ ๋„๊ตฌ

53

DNS

- DNS ์บ์‹œ ์ค‘๋… (Cache Poisoning)

- DNS ์ฆํญ ๊ณต๊ฒฉ (Amplification)

nslookup, dig, dnsenum, Fierce, dnsrecon, dnstracer

88

Kerberos ์ธ์ฆ

- AS-REP Roasting

- ํ‹ฐ์ผ“ ์œ„์กฐ (Golden/Silver Ticket)

- Pass-the-Ticket

impacket, Rubeus, Kerbrute, Hashcat, GetUserSPNs, mitm6

135

MS-RPC

- DCOM ์ทจ์•ฝ์ 

- MS-RPC ๊ถŒํ•œ ์ƒ์Šน

rpcclient, Metasploit, Nmap, PowerSploit, NetExec, Evil-WinRM

137โ€“139

NetBIOS

- SMB ๋ฆด๋ ˆ์ด

- NTLM ๋ฆด๋ ˆ์ด

- NetBIOS ์Šคํ‘ธํ•‘

smbclient, Responder, impacket, Nmap, NetExec

389

LDAP (๋น„์•”ํ˜ธํ™”)

- LDAP ์ธ์ ์…˜

- ์ž๊ฒฉ ์ฆ๋ช… ์ˆ˜์ง‘

- ์ต๋ช… ๋ฐ”์ธ๋”ฉ

ldapsearch, Nmap, ldapdomaindump, NetExec, BloodHound, ADExplorer

445

SMB

- EternalBlue

- SMB ๋ฆด๋ ˆ์ด

- SMB ์„œ๋ช… ๋น„ํ™œ์„ฑํ™”

- Pass-the-Hash

smbclient, impacket, Nmap, NetExec, Metasploit, smbmap

464

Kerberos (ํŒจ์Šค์›Œ๋“œ ๋ณ€๊ฒฝ)

- Kerberoasting

- ํŒจ์Šค์›Œ๋“œ ์Šคํ”„๋ ˆ์ด ๊ณต๊ฒฉ

impacket, Rubeus, Kerbrute, Hashcat, KrbRelayUp

593

HTTP RPC

- ์ธ์ฆ ์šฐํšŒ

- MS-RPC ์ธ์ ์…˜

rpcclient, Metasploit, Nmap, PowerSploit, Evil-WinRM, NetExec

636

LDAPS (์•”ํ˜ธํ™”๋œ LDAP)

- LDAP ์ธ์ ์…˜

- ์ธ์ฆ์„œ ์Šคํ‘ธํ•‘

ldapsearch, Nmap, NetExec, BloodHound, ADExplorer

3268โ€“3269

๊ธ€๋กœ๋ฒŒ ์นดํƒˆ๋กœ๊ทธ (GC)

- LDAP ์ธ์ ์…˜

- ๋ฐ์ดํ„ฐ ๋…ธ์ถœ

ldapsearch, Nmap, NetExec, BloodHound, ADExplorer

3389

RDP (์›๊ฒฉ ๋ฐ์Šคํฌํ†ฑ)

- BlueKeep

- ์•ฝํ•œ ์•”ํ˜ธํ™”

- RDP ํ•˜์ด์žฌํ‚น

- ์ธ์ฆ์„œ ์ „๋‹ฌ

ncrack, xfreerdp, Metasploit, NetExec, rdpscan

5985โ€“5986

WinRM (PowerShell ์›๊ฒฉ ๊ด€๋ฆฌ)

- ์ž๊ฒฉ ์ฆ๋ช… ํƒˆ์ทจ

- Pass-the-Hash

- ๋ฌด์ œํ•œ ์œ„์ž„

Evil-WinRM, Impacket, NetExec, Metasploit, PowerView

Last updated