{"repo":"The-Viper-One/Invoke-PassTheCert","free":true,"listed":false,"github":"https://github.com/The-Viper-One/Invoke-PassTheCert","clone":"git clone https://github.com/The-Viper-One/Invoke-PassTheCert.git","description":"Pure PowerShell port of PassTheCert tool to authenticate to an LDAP/S server with a certificate through Schannel","language":"PowerShell","stars":61,"topics":["certificate","ldap","penetration-testing","powershell"],"license":null,"category":"security-tools","readme_excerpt":"Invoke-PassTheCert Invoke-PassTheCert is a pure PowerShell port of PassTheCert. The purpose of this repository is to expand the landscape of PowerShell tooling available to Penetration testers and red teamers. The original work by AlmondOffsec can be found here: https://github.com/AlmondOffSec/PassTheCert along with the accompanying blog post: https://offsec.almond.consulting/authenticating-with-certificates-when-pkinit-is-not-supported.html Sometimes, Domain Controllers do not support PKINIT. This can be because their certificates do not have the Smart Card Logon EKU. However, several protocols, including LDAP, support Schannel, thus authentication through TLS. --- Note If the certificate is password protected you will need to provide the parameter. The parameter accepts either a path to a PFX file or a Base64 encoded certificate --- Basic Usage --- Command Reference Whoami Display the current identity authenticated via the certificate. --- Reset Password Reset a target user's password to a random value. --- Add SPN Adds an SPN (e.g., cifs/fake.domain.com ) to a user object. --- Remove SPN Removes SPN from target. --- Add to Group Adds a user or computer to a specified group. --- Remove from Group Removes a user or computer from a group. --- Toggle Account Status Enables or disables a user/computer account. --- Add Computer Adds a new computer account to the domain. A random password will be generated if is omitted. --- Remove Computer Removes a computer object from the doma","default_branch":null,"files":null,"tree":[],"storefront":"/r/The-Viper-One","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/The-Viper-One/Invoke-PassTheCert/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}