Skip to content

Add native C# tool implementations for AD pentest dashboard - #73

Open
netanelcyber wants to merge 2 commits into
claude/fix-await-in-catch-fvwu3wfrom
claude/project-thread-dst7nu
Open

netanelcyber wants to merge 2 commits into
claude/fix-await-in-catch-fvwu3wfrom
claude/project-thread-dst7nu

Conversation

@netanelcyber

Copy link
Copy Markdown
Owner

Summary

  • Ports core AD pentest tools from Python (core.py) to native C# in ServerCode/18_NativeTools.cs (1161 lines), eliminating the Python subprocess dependency for key scanning operations
  • Adds LDAP-based scanners: RootDSE queries, SPN enumeration (Kerberoasting targets), AS-REP roastable account detection, unconstrained/constrained delegation detection, ADCS ESC1/ESC3 vulnerability scanning
  • Adds network tools: parallel TCP port scanner with service fingerprinting (32 workers), SMB signing detection and null-session probing via raw SMB1 negotiate packets
  • Adds email protocol testers: SMTP banner grab/VRFY/RCPT TO enumeration, POP3 and IMAP capability detection
  • Wires up a "Native Scan" button in AdPentest.aspx that runs all tools against the target, stores results as a JSON report, and displays a summary grid
  • All scans are lab-scoped to AllowedTargets (netanel-pt.local)

How

Uses System.DirectoryServices.Protocols for LDAP operations (anonymous bind, subtree search with AD-specific filters like userAccountControl bit flags and msDS-AllowedToDelegateTo). Port scanning uses System.Net.Sockets.TcpClient with Parallel.ForEach. Email protocols use raw TCP with StreamReader/StreamWriter for SMTP/POP3/IMAP command sequences. SMB probing sends a minimal SMB1 COM_NEGOTIATE packet and parses the SecurityMode byte from the response.


🤖 Generated with Claude Code

https://claude.ai/code/session_01UzUdU1kWmiCo1iCANQvAqm


Generated by Claude Code

Port AD pentest tools to C# for direct execution without Python dependency:
- LDAP: RootDSE queries, SPN enumeration, AS-REP roastable detection,
  unconstrained/constrained delegation, ADCS ESC1/ESC3 scanning
- Network: parallel TCP port scanner with service fingerprinting
- Email: SMTP (banner/VRFY/RCPT), POP3 (capabilities), IMAP (capabilities)
- SMB: signing detection and null-session probing via raw SMB1 negotiate
- Combined bNativeScan_Click handler runs all tools, stores JSON report

Uses System.DirectoryServices.Protocols (LDAP), System.Net.Sockets (TCP),
raw protocol handlers (SMTP/POP3/IMAP/SMB). Lab-scoped to AllowedTargets.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UzUdU1kWmiCo1iCANQvAqm
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

- Add System.DirectoryServices.Protocols assembly reference to page directives
- Add System.Net.Sockets and System.Collections.Concurrent namespace imports
- Rename GetAttr to LdapGetAttr to avoid potential naming conflicts

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UzUdU1kWmiCo1iCANQvAqm
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants