Repository navigation
Expand file tree
/
Copy pathGet-ComputerNames.py
More file actions
executable file
·72 lines (60 loc) · 2.75 KB
/
Copy pathGet-ComputerNames.py
File metadata and controls
executable file
·72 lines (60 loc) · 2.75 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
#!/usr/bin/env python3
import subprocess
import re
import argparse
def run_rpcclient(domain, k, username, password, dc, command):
"""Run rpcclient with the given arguments and return stdout."""
base_cmd = ["rpcclient"]
if k:
base_cmd.append("-k")
else:
creds = f"{username}%{password}"
base_cmd += ["-U", creds]
base_cmd += ["-c", command, dc]
result = subprocess.run(
base_cmd,
capture_output=True, text=True, check=False
)
if result.returncode != 0:
print(f"[!] rpcclient error: {result.stderr.strip()}")
return result.stdout
def get_domain_sid(domain, k, username, password, dc):
output = run_rpcclient(domain, k, username, password, dc, f"lookupdomain {domain}")
match = re.search(r"Domain SID:\s*(S-[0-9\-]+)", output)
if match:
return match.group(1)
else:
print("[!] Failed to get Domain SID.")
exit(1)
def get_computer_rids(domain, k, username, password, dc):
output = run_rpcclient(domain, k, username, password, dc, "querygroupmem 0x203")
return re.findall(r"rid:\[0x([0-9a-fA-F]+)\]", output)
def resolve_computer_names(domain_sid, rids, domain, k, username, password, dc, verbose):
full_sids = [f"{domain_sid}-{int(rid,16)}" for rid in rids]
sids_str = ' '.join(full_sids)
output = run_rpcclient(domain, k, username, password, dc, f"lookupsids {sids_str}")
for line in output.splitlines():
match = re.match(r"(S-[^\s]+)\s+([^\s]+) \((\d+)\)", line.strip())
if match and '$' in match.group(2):
sid, account, sidtype = match.groups()
if verbose:
print(f"{sid} {account} ({sidtype})")
else:
print(account.split("\\",1)[-1]) # print just the computer name
def main():
parser = argparse.ArgumentParser(description="Enumerate computer accounts dynamically with rpcclient.")
parser.add_argument("--domain", required=True, help="Target domain name (e.g., rustykey.htb)")
parser.add_argument("-k", action="store_true", help="Use Kerberos authentication")
parser.add_argument("-u", help="Username")
parser.add_argument("-p", help="Password")
parser.add_argument("--dc-ip", required=True, help="Domain controller IP or hostname")
parser.add_argument("--verbose", action="store_true", help="Show full SID, domain name, and SID type")
args = parser.parse_args()
domain_sid = get_domain_sid(args.domain, args.k, args.u, args.p, args.dc_ip)
rids = get_computer_rids(args.domain, args.k, args.u, args.p, args.dc_ip)
if not rids:
print("[!] No computer RIDs found.")
return
resolve_computer_names(domain_sid, rids, args.domain, args.k, args.u, args.p, args.dc_ip, args.verbose)
if __name__ == "__main__":
main()