Skip to content

Add 60+ advanced penetration tools across 6 new categories - #71

Open
netanelcyber wants to merge 11 commits into
mainfrom
claude/project-thread-djm1k0
Open

netanelcyber wants to merge 11 commits into
mainfrom
claude/project-thread-djm1k0

Conversation

@netanelcyber

Copy link
Copy Markdown
Owner

Requested by NETANEL · project thread

Summary

Before: The dashboard supported 14 service categories and ~80 tools covering basic AD reconnaissance, Kerberos, ADCS (ESC1/3/9), SMB, LDAP, DNS, and Email.

After: The dashboard now supports 20 service categories and 140+ tools, adding full coverage for lateral movement, credential access, domain privilege escalation, extended ADCS, post-exploitation persistence, DNS attacks, Exchange/OWA, and WSUS/GPO abuse.

New tool categories added

Category Tools Examples
Lateral Movement 9 PTH-SMB, PTH-WinRM, PTT, overpass-the-hash, WMI/DCOM/schtask/psexec/SSH exec
Credential Access 9 LSASS dump, SAM dump, DPAPI secrets, NTDS.dit extract, DCSync, browser/WiFi creds
Privilege Escalation 8 Zerologon (CVE-2020-1472), PrintNightmare (CVE-2021-34527), noPac, RBCD, Certifried, Shadow Credentials
ADCS Extended 11 ESC4-ESC14, PKINIT abuse, certificate theft
Post-Exploitation 8 AdminSDHolder, custom SSP, directory replication, WMI/registry/schtask persistence
DNS Attacks 3 Zone transfer, subdomain enumeration, wildcard detection
Exchange/OWA 3 Version detection, OWA password spray, Exchange PrivExc
WSUS/GPO 2 WSUS abuse (WSUSpendu), GPO payload deployment

Implementation

  • AdPentest.aspx: 53 new entries in ServiceCategories dictionary; UI text updated to reflect 20 categories / 140+ tools
  • adpentest/core.py: 60+ new entries in AD_TOOLS; build_ad_command handlers for all (impacket/certipy/CME where available, Python-based safe checks as fallback); 30+ Python check functions using port probes, anonymous LDAP queries, and HTTP fingerprinting; detection-only tools added to CAREFUL_ACTIVE_TOOLS

How

Each new tool follows the existing pattern: registered in AD_TOOLS, mapped to a category in ServiceCategories, and given a build_ad_command entry that either calls an external binary (impacket, certipy, crackmapexec) or runs a Python-based check function. The check functions are safe reconnaissance only — port probes, anonymous LDAP binds, HTTP header fingerprinting — no exploitation payloads.

https://claude.ai/code/session_01YUw9b6KFCFqBLMgzxj9fLw


Generated by Claude Code

tenten48tenten and others added 11 commits September 16, 2026 17:18
feat: Jinja2-based interactive HTML pentest report generator (Closes #22)
Brings over AdPentest.aspx from the earlier session branch
(claude/eager-cray-4gl5be) with correct Page directive and assembly
references: EntityFramework, System.Data.SQLite, System.Data.SQLite.EF6,
Newtonsoft.Json, and System.ComponentModel.DataAnnotations.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
- Include target in CVE dedup key so multi-host findings are not collapsed
- Validate CVE match entries are JObject before indexing
- Allow PopulateReport on truncated output (JSON may still be valid)
- Observe cancellation token to stop scan on app pool recycle
- Add fallbacks for target/mode fields to accept older report formats
- Fix confidence caption from "all low" to "low- to medium-confidence"

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
- Validate Host header (localhost/127.0.0.1/[::1]) to block DNS-rebinding
  attacks against the IsLocal-only page
- Guard exit-code status assignment with !cancelled so "cancelled" status
  is not overwritten by "completed"/"failed"/"output-truncated"
- Check activeSearch is JObject before indexing into it

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
- DrainAsync now reads up to 4 MiB (MaxParseChars) for report parsing
  while still capping the DB-stored display at 512 KiB, so large JSON
  reports are parsed correctly even when display output is truncated
- run_id is now optional in PopulateReport so sample/imported JSON
  without a run_id can be imported successfully
- When QueueBackgroundWorkItem fails, update the DB row from "queued"
  to "error" so it does not mislead operators

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
The row variable was declared inside try, making row.Id unreachable
in the catch block. Moved rowId declaration before try and added a
guard (rowId > 0) so the error-status update only runs after a
successful DB insert.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
- output-truncated status only replaces "completed", preserving
  "failed" and "timeout" statuses when output is also truncated
- Target field in PopulateReport is now optional; falls back to
  row.RequestedTarget so CLI error reports without a target field
  are accepted
- Port list caption in Hebrew and English now matches the actual
  ports scanned by active_service_search in core.py

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
…mode

- stream-timeout no longer overwrites cancelled/timeout status
- PopulateReport runs whenever stdout completed, even during
  stream-timeout (stderr-only timeout no longer blocks parsing)
- Mode falls back to row.Mode for targetless error reports

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
Add ASP.NET Web Forms dashboard with verified page directives
Dashboard (AdPentest.aspx):
- Lateral Movement: PTH, PTT, overpass-the-hash, WMI/DCOM/schtask/psexec/SSH
- Credential Access: LSASS/SAM/DPAPI/NTDS dump, DCSync, browser/WiFi creds
- Privilege Escalation: Zerologon, PrintNightmare, noPac, RBCD, Certifried
- ADCS Extended: ESC4-ESC14, PKINIT abuse, certificate theft
- Post-Exploitation: AdminSDHolder, custom SSP, WMI/registry/schtask persistence
- DNS Attacks: zone transfer, subdomain enum, wildcard detection
- Exchange/OWA: version detect, password spray, PrivExc
- WSUS/GPO: WSUS abuse, GPO payload deployment

Backend (adpentest/core.py):
- 60+ new entries in AD_TOOLS set
- build_ad_command handlers for all new tools (impacket/certipy/CME where available, Python checks as fallback)
- 30+ safe Python check functions (port probes, anonymous LDAP queries, HTTP fingerprinting)
- Detection-focused tools added to CAREFUL_ACTIVE_TOOLS for safe scanning
- Category count updated from 14 to 20, tool count from 80+ to 140+

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YUw9b6KFCFqBLMgzxj9fLw
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@netanelcyber netanelcyber self-assigned this Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants