LAPSToolkit functions written in PowerShell that leverage PowerView to audit and attack Active Directory environments that have deployed Microsoft’s Local Administrator Password Solution (LAPS).
It includes finding groups specifically delegated by sysadmins, finding users with “All Extended Rights” that can view passwords, and viewing all computers with LAPS enabled.
Please submit issues or comments for any problems or performance improvements. This project was created with code from an older version of PowerView.
Also Read : Androguard : Reverse Engineering, Malware & Goodware Analysis of Android Applications
Get-LAPSComputers:
Displays all computers with LAPS enabled, password expriation, and password if user has access
Searches through all OUs to see which AD groups can read the ms-Mcs-AdmPwd attribute
Parses through ExtendedRights for each AD computer with LAPS enabled and looks for which group has read access and if any user has “All Extended Rights”.
Sysadmins may not be aware the users with All Extended Rights can view passwords and may be less protected than the users in the delegated groups.
An example is the user which adds a computer to the domain automatically receives the “All Extended Rights” permission. Since this function will parse ACLs for each AD computer, this can take very long with a larger domain.
Credit: Sean Metcalf (@pyrotek3), Will Schroeder (@harmj0y), Karl Fosaaen (@kfosaaen), Matt Graeber (@mattifestation)
This cheat sheet covers the essential Kali Linux commands every pentester and ethical hacker uses…
When I first started learning malware analysis and reverse engineering, I thought the hardest part…
Both git fetch and git pull talk to a remote repository, but they do very different things to your…
Sometimes the change you need already exists, just on the wrong branch. A hotfix lands…
Email is still one of the most important communication channels inside modern applications. Password resets,…
Nginx is a high-performance web server and reverse proxy trusted by some of the largest…