{"repo":"lefayjey/linWinPwn","free":true,"listed":false,"github":"https://github.com/lefayjey/linWinPwn","clone":"git clone https://github.com/lefayjey/linWinPwn.git","description":"linWinPwn is a bash script that streamlines the use of a number of Active Directory tools","language":"Shell","stars":2198,"topics":["penetration-testing","pentesting","active-directory","hacking","impacket","bloodhound","kerberoast","enumeration","exploitation","pentest-tool"],"license":"MIT","category":"security-tools","readme_excerpt":"linWinPwn - Swiss-Army knife for Active Directory Pentesting using Linux Description linWinPwn is a bash script that wraps a number of Active Directory tools for enumeration (LDAP, RPC, ADCS, MSSQL, Kerberos, SCCM), vulnerability checks (noPac, ZeroLogon, MS17-010, MS14-068), object modifications (password change, add user to group, RBCD, Shadow Credentials) and password dumping (secretsdump, lsassy, nanodump, DonPAPI). The script streamlines the use of a large number of tools: impacket, bloodhound, netexec, enum4linux-ng, ldapdomaindump, lsassy, smbmap, kerbrute, certipy, silenthound, bloodyAD, DonPAPI and many others. Setup Git clone the repository and install requirements using the install.sh script Alternatively, use the pre-built Docker image from Docker Hub Or build from source Usage Mode The linWinPwn script can be executed in interactive mode (default), or in automated mode (enumeration only). 1. Interactive Mode (Default) - Open interactive menu to run checks separately 2. Automated Mode - Using the --auto parameter, run enumeration tools (no exploitation, modifications or password dumping) When using the automated mode, different checks are performed based on the authentication method. - Unauthenticated (no credentials provided) - Anonymous enumeration using netexec, enum4linux-ng, ldapdomaindump, ldeep - RID bruteforce using netexec - kerbrute user spray - Pre2k authentication check on collected list of computers - ASREPRoast using collected list of users (and crac","default_branch":null,"files":null,"tree":[],"storefront":"/r/lefayjey","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/lefayjey/linWinPwn/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}