GithubHelp home page GithubHelp logo

caudit's Introduction

描述

十大集权设施基线扫描工具

  • AD、K8s、VCenter、Excange、JumpServer、齐治堡垒机、天钥堡垒机、Zabbix、阿里云、腾讯云、华为云
  • 内置AD基线扫描脚本数量80+、漏洞利用脚本数量40+
  • 内置Exchange基线扫描脚本20条,漏洞利用脚本10条
  • 内置VCenter基线扫描脚本15条,漏洞利用脚本18条
  • 内置K8s漏洞利用脚本8条、JumpServer漏洞利用脚本1条、齐治堡垒机漏洞利用脚本1条
  • 内置阿里云漏洞利用脚本8条、腾讯云漏洞利用脚本6条、华为云漏洞利用脚本2条
  • 支持结果保存为HTML文件

Example

显示全局参数和可用模块

./CAudit.py -h

1.png

显示每个模块参数(以AD为例)

./CAudit.py AD -h

2.png

列出每个模块所有可用插件(以AD为例)

./CAudit.py AD --list

3.png

列出每个模块扫描/漏洞利用类型插件(以AD为例)

./CAudit.py AD scan --list
./CAudit.py AD exploit --list

4.png

使用全部扫描插件(以AD为例)

CAudit.py --save ad_scan.html AD scan -u USER -p PASS -d DC.DOMAIN.COM --dc-ip 1.1.1.1 --all

5.png

使用指定的扫描插件

./CAudit.py AD scan --plugin i_maq -d DC.DOMAIN.COM --dc-ip 1.1.1.1 --username USER --password PASS

6.png

使用 Docker

使用前先拉最新镜像

docker pull amulab/center

运行

docker run --rm -it amulab/center

为了方便使用可以先设置别名

alias center='docker run --rm -it amulab/center'

再使用center命令运行

caudit's People

Contributors

bge-faith avatar blyth0he avatar poundofantonio avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar

caudit's Issues

安装后无法正常运行

root@containerd-host:/opt/test# ./CAudit.py AD -h
./CAudit.py: 行 1: import: 未找到命令
./CAudit.py: 行 2: import: 未找到命令
./CAudit.py: 行 3: import: 未找到命令
./CAudit.py: 行 4: from: 未找到命令
./CAudit.py: 行 5: from: 未找到命令
./CAudit.py: 行 7: from: 未找到命令
./CAudit.py: 行 9: import: 未找到命令
./CAudit.py: 行 10: from: 未找到命令
./CAudit.py: 行 11: from: 未找到命令
./CAudit.py: 行 12: from: 未找到命令
./CAudit.py: 行 13: from: 未找到命令
./CAudit.py: 行 16: 未预期的记号 "(" 附近有语法错误
./CAudit.py: 行 16: def load_module_param(mod_name, exploit_plugin_name, all_module_plugins):' root@containerd-host:/opt/test# ./CAudit.py AD --list ./CAudit.py: 行 1: import: 未找到命令 ./CAudit.py: 行 2: import: 未找到命令 ./CAudit.py: 行 3: import: 未找到命令 ./CAudit.py: 行 4: from: 未找到命令 ./CAudit.py: 行 5: from: 未找到命令 ./CAudit.py: 行 7: from: 未找到命令 ./CAudit.py: 行 9: import: 未找到命令 ./CAudit.py: 行 10: from: 未找到命令 ./CAudit.py: 行 11: from: 未找到命令 ./CAudit.py: 行 12: from: 未找到命令 ./CAudit.py: 行 13: from: 未找到命令 ./CAudit.py: 行 16: 未预期的记号 "(" 附近有语法错误 ./CAudit.py: 行 16: def load_module_param(mod_name, exploit_plugin_name, all_module_plugins):'
root@containerd-host:/opt/test#
root@containerd-host:/opt/test#
root@containerd-host:/opt/test#
root@containerd-host:/opt/test# ./CAudit.py -h
./CAudit.py: 行 1: import: 未找到命令
./CAudit.py: 行 2: import: 未找到命令
./CAudit.py: 行 3: import: 未找到命令
./CAudit.py: 行 4: from: 未找到命令
./CAudit.py: 行 5: from: 未找到命令
./CAudit.py: 行 7: from: 未找到命令
./CAudit.py: 行 9: import: 未找到命令
./CAudit.py: 行 10: from: 未找到命令
./CAudit.py: 行 11: from: 未找到命令
./CAudit.py: 行 12: from: 未找到命令
./CAudit.py: 行 13: from: 未找到命令
./CAudit.py: 行 16: 未预期的记号 "(" 附近有语法错误
./CAudit.py: 行 16: `def load_module_param(mod_name, exploit_plugin_name, all_module_plugins):'
root@containerd-host:/opt/test# ls
CAudit.py doc Dockerfile modules plugins README.md requirements.txt temp utils version

对AD域控服务器进行远程扫描,报错KeyError: 'instance_list'

执行命令
python CAudit.py --save ad_8.5_scan.html AD scan -u xxxx -p xxx -d test1.test.com --dc-ip 192.168.8.5 --all
出现如下错误:
[] run plugin: Plugin_AD_Scan_PrinterBug
[
] run plugin: Plugin_AD_Scan_Support_SMBv1
[] run plugin: Plugin_AD_Scan_ZeroLogon
[
] [192.168.8.5] is not vuln
[-] SMB SessionError: STATUS_ACCESS_DENIED({Access Denied} A process has requested access to an object but has not been granted those access rights.)
[-] SMB SessionError: STATUS_ACCESS_DENIED({Access Denied} A process has requested access to an object but has not been granted those access rights.)
0000 76 FF FF FF BD D9 7B 63 A0 98 39 F7 C8 CF 7D FA v.....{c..9...}.
0010 95 BD E0 C6 ....
Traceback (most recent call last):
File "d:\CAudit\CAudit.py", line 179, in
output.show_results(scripts_result, user_args.scan_type)
File "d:\CAudit\utils\logger.py", line 216, in show_results
if status == "Success" and len(v["results"]["data"]["instance_list"]) > 0:
~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^
KeyError: 'instance_list'

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.