diff --git a/Scripts/Analyze-HuntSMBShares.ps1 b/Scripts/Analyze-HuntSMBShares.ps1 index 712b8ea..a5433e1 100644 --- a/Scripts/Analyze-HuntSMBShares.ps1 +++ b/Scripts/Analyze-HuntSMBShares.ps1 @@ -5,7 +5,7 @@ #-------------------------------------- # Author: Scott Sutherland, 2024 NetSPI # License: 3-clause BSD -# Version: v1.73 +# Version: v1.74 # References: This script includes custom code and code taken and modified from the open source projects PowerView, Invoke-Ping, and Invoke-Parrell. function Analyze-HuntSMBShares { @@ -4704,11 +4704,11 @@ input[type="checkbox"]:checked::before {
-
+

Affected Assets

-
+
Below is a summary of the computers, shares, and ACEs (Access Control Entries) associated with shares configured with excessive privileges. - $ExcessiveSharePrivsCount ACL entries, on $ExcessiveSharesCount shares, hosted by $ComputerWithExcessive computers were found configured with excessive privileges on the $TargetDomain domain. Click the "Exposure Summary" or the titles on the cards below to explore the details.

+ $ExcessiveSharePrivsCount ACL entries, on $ExcessiveSharesCount shares, hosted by $ComputerWithExcessive computers were found configured with excessive privileges on the $TargetDomain domain. Overall, $IdentityReferenceListCount identities were assigned excessive privileges. Click the "Exposure Summary" or the titles on the cards below to explore the details.

@@ -4719,7 +4719,7 @@ input[type="checkbox"]:checked::before { -
+
@@ -4778,7 +4778,7 @@ input[type="checkbox"]:checked::before { |||||||||| CARD: SHARE SUMMARY --> -
+
@@ -4837,7 +4837,7 @@ input[type="checkbox"]:checked::before { |||||||||| CARD: ACL SUMMARY --> -
+
@@ -4892,6 +4892,30 @@ input[type="checkbox"]:checked::before {
+ + +
+ +
+ + $IdentityReferenceListCount + +
+ +
+
+
+ Coming soon. +
+
+
+
+
+
@@ -4904,11 +4928,11 @@ input[type="checkbox"]:checked::before { -
+

Exposure Summary

In total, $RiskLevelCountCritical critical, $RiskLevelCountHigh high, $RiskLevelCountMedium medium, and $RiskLevelCountLow low risk ACE configurations were discovered across shares in the $TargetDomain Active Directory domain. The affected shares were found hosting $InterestingFilesAllObjectsSecretCount files that may contain passwords and $InterestingFilesAllObjectsSensitiveCount files that may contain sensitive data. Overall, $InterestingFilesAllFilesCount interesting files were found that could potentially lead to unauthorized data access or remote code execution. Click the chart titles below to explore the details.

-