{"id":26219493,"url":"https://github.com/byt3n33dl3/sharkmapexec","last_synced_at":"2025-04-16T01:57:46.796Z","repository":{"id":261905440,"uuid":"836188950","full_name":"byt3n33dl3/SharkMapExec","owner":"byt3n33dl3","description":"Active Directory Full House Enumeration, the Operator of toxic Pacific Ocean. Miscellaneous tools for BlackMarlinExec.","archived":false,"fork":false,"pushed_at":"2024-11-11T09:12:06.000Z","size":1493,"stargazers_count":10,"open_issues_count":0,"forks_count":2,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-04-16T01:57:33.759Z","etag":null,"topics":["active-directory","architecture","blackmarlinexec","enumeration","kerberos-attack","linux-shell","pathfinder","windows"],"latest_commit_sha":null,"homepage":"https://learn.microsoft.com","language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"bsd-3-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/byt3n33dl3.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":".github/funding.yml","license":"LICENSE.md","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null},"funding":{"custom":"be.net/BloodHoundAD","patreon":"byt3n33dl3","ko_fi":"byt3n33dl3"}},"created_at":"2024-07-31T10:31:21.000Z","updated_at":"2025-02-05T16:19:40.000Z","dependencies_parsed_at":"2024-11-09T06:31:20.270Z","dependency_job_id":"28c87b0f-ded5-4c55-a27e-9ffdf066d345","html_url":"https://github.com/byt3n33dl3/SharkMapExec","commit_stats":null,"previous_names":["byt3n33dl3/sharkmapexec"],"tags_count":4,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/byt3n33dl3%2FSharkMapExec","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/byt3n33dl3%2FSharkMapExec/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/byt3n33dl3%2FSharkMapExec/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/byt3n33dl3%2FSharkMapExec/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/byt3n33dl3","download_url":"https://codeload.github.com/byt3n33dl3/SharkMapExec/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":249183107,"owners_count":21226141,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["active-directory","architecture","blackmarlinexec","enumeration","kerberos-attack","linux-shell","pathfinder","windows"],"created_at":"2025-03-12T14:18:20.566Z","updated_at":"2025-04-16T01:57:46.777Z","avatar_url":"https://github.com/byt3n33dl3.png","language":"C","funding_links":["be.net/BloodHoundAD","https://patreon.com/byt3n33dl3","https://ko-fi.com/byt3n33dl3"],"categories":[],"sub_categories":[],"readme":"# SharkMapExec / `Master` : `v1.3`\n\n\u003ca href=\"https://github.com/byt3n33dl3/SharkMapExec/\"\u003e\u003cp align=\"center\"\u003e\n\u003cimg width=\"300\" height=\"300\" src=\"/inc/sahrk.png\"\u003e\n\u003c/p\u003e\u003c/a\u003e\n\n\u003cdiv align=\"center\"\u003e\n\u003ch2\u003eBlackMarlinExec Attack Research Kit\u003c/h2\u003e\n\u003cp\u003e\u003c/div\u003e\n\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://github.com/byt3n33dl3/CrackMapExec/blob/master/LICENSE.txt\"\u003e\n      \u003cimg src=\"https://img.shields.io/badge/license-BSD3-green.svg?style=flat-square\" alt=\"License\"\u003e\n  \u003c/a\u003e\n  \u003ca href=\"https://github.com/byt3n33dl3/CrackMapExec/blob/master/LICENSE.txt\"\u003e\n      \u003cimg src=\"https://img.shields.io/badge/Offensive-red.svg?style=flat-square\" alt=\"LPT-Master\"\u003e\n  \u003c/a\u003e\n  \u003ca href=\"https://github.com/byt3n33dl3/CrackMapExec/blob/master/LICENSE.txt\"\u003e\n      \u003cimg src=\"https://img.shields.io/badge/Powershell-blue.svg?style=flat-square\" alt=\"Python\"\u003e\n  \u003c/a\u003e\n  \u003ca href=\"https://github.com/byt3n33dl3/CrackMapExec/issues\"\u003e\n    \u003cimg src=\"https://img.shields.io/github/issues/byt3n33dl3/CrackMapExec.svg?style=flat-square\" alt=\"Issues\"\u003e\n  \u003c/a\u003e\n  \u003ca href=\"https://github.com/byt3n33dl3/CrackMapExec/blob/master/CONTRIBUTING.md\"\u003e\n      \u003cimg src=\"https://img.shields.io/badge/contributions-welcome-brightgreen.svg?style=flat-square\" alt=\"Contributing\"\u003e\n  \u003c/a\u003e\n\u003c/p\u003e\n\nThis is a **BlackMarlinExec** Attack Research Kit.\n\n`SME` requires no third party dependencies. `SME`'s functions are designed to be as simple and maintainable as possible. Most functions are very simple wrappers for making requests to various REST API endpoints. `SME`'s basic functions do not even require each other, you can pull almost any `SME` function out of `SME` and it will work perfectly as a standalone function in your own scripts.\n\nYou are on the last **Up to Date** repository of the project SharkMapExec\n\n- If you want to report a problem, open un [Issue](https://github.com/byt3n33dl3/SharkMapExec/issues) \n- If you want to contribute, open a [Pull Request](https://github.com/byt3n33dl3/SharkMapExec/pulls)\n- If you want to discuss, open a [Discussion](https://github.com/byt3n33dl3/SharkMapExec/discussions)\n\nToken Management\n-------------------------------------------\n* ``SharkMapExec-AzureKeyVaultTokenWithClientCredentials`` requests a token from STS with Azure Vault specified as the resource/intended audience using a client ID and secret.\n* ``SharkMapExec-AzureKeyVaultTokenWithUsernamePassword`` requests a token from STS with Azure Vault specified as the resource/intended audience using a user-supplied username and password.\n* ``SharkMapExec-AzurePortalTokenWithRefreshToken`` requests an Azure Portal Auth Refresh token with a user-supplied refresh token.\n* ``SharkMapExec-AzureRMTokenWithClientCredentials`` requests an AzureRM-scoped JWT with a client ID and secret. Useful for authenticating as an Entra service principal.\n* ``SharkMapExec-AzureRMTokenWithPortalAuthRefreshToken`` requests an AzureRM-scoped JWT with a user-supplied Azure Portal Auth Refresh token.\n* ``SharkMapExec-AzureRMTokenWithRefreshToken`` requests an AzureRM-scoped JWT with a user-supplied refresh token.\n* ``SharkMapExec-AzureRMTokenWithUsernamePassword`` requests an AzureRM-scoped JWT with a user-supplied username and password.\n* ``SharkMapExec-EntraRefreshTokenWithUsernamePassword`` requests a collection of tokens, including a refresh token, from login.microsoftonline.com with a user-supplied username and password. This will fail if the user has Multi-Factor Authentication requirements or is affected by a Conditional Access Policy.\n* ``SharkMapExec-MSGraphTokenWithClientCredentials`` requests an MS Graph-scoped JWT with a client ID and secret. Useful for authenticating as an Entra service principal.\n* ``SharkMapExec-MSGraphTokenWithPortalAuthRefreshToken`` requests an MS Graph-scoped JWT with a user-supplied Azure Portal Auth Refresh token.\n* ``SharkMapExec-MSGraphTokenWithRefreshToken`` requests an MS Graph-scoped JWT with a user-supplied refresh token.\n* ``SharkMapExec-MSGraphTokenWithUsernamePassword`` requests an MS Graph-scoped JWT with a user-supplied username and password.\n* ``SharkMapExec-JWTToken`` will take a Base64 encoded JWT as input and parse it for you. Useful for verifying correct token audience and claims.\n\nThe refresh token-based functions in SharkMapExec are based on functions in [TokenTactics](https://github.com/rvrsh3ll/TokenTactics) by Steve [Borosh](https://twitter.com/424f424f).\n\nEntra Enumeration\n---------------------------\n* ``SharkMapExec-AllEntraApps`` collects all Entra application registration objects.\n* ``SharkMapExec-AllEntraGroups`` collects all Entra groups.\n* ``SharkMapExec-AllEntraRoles`` collects all Entra admin roles.\n* ``SharkMapExec-AllEntraServicePrincipals`` collects all Entra service principal objects.\n* ``SharkMapExec-AllEntraUsers`` collects all Entra users.\n* ``SharkMapExec-EntraAppOwner`` collects owners of an Entra app registration.\n* ``SharkMapExec-EntraDeviceRegisteredUsers`` collects users of an Entra device.\n* ``SharkMapExec-EntraGroupMembers`` collects members of an Entra group.\n* ``SharkMapExec-EntraGroupOwner`` collects owners of an Entra group.\n* ``SharkMapExec-EntraRoleTemplates`` collects Entra admin role templates.\n* ``SharkMapExec-EntraServicePrincipal`` collects an Entra service principal.\n* ``SharkMapExec-EntraServicePrincipalOwner`` collects owners of an Entra service principal.\n* ``SharkMapExec-EntraTierZeroServicePrincipals`` collects Entra service principals that have a Tier Zero Entra Admin Role or Tier Zero MS Graph App Role assignment.\n* ``SharkMapExec-MGAppRoles`` collects the app roles made available by the MS Graph service principal.\n\nAzure Enumeration\n--------------------------------------------\n* ``SharkMapExec-AllAzureManagedIdentityAssignments`` collects all managed identity assignments. \n* ``SharkMapExec-AllAzureRMAKSClusters`` collects all kubernetes service clusters under a subscription.\n* ``SharkMapExec-AllAzureRMAutomationAccounts`` collects all automation accounts under a subscription.\n* ``SharkMapExec-AllAzureRMAzureContainerRegistries`` collects all container registies under a subscription.\n* ``SharkMapExec-AllAzureRMFunctionApps`` collects all function apps under a subscription.\n* ``SharkMapExec-AllAzureRMKeyVaults`` collects all key vaults under a subscription.\n* ``SharkMapExec-AllAzureRMLogicApps`` collects all logic apps under a subscription.\n* ``SharkMapExec-AllAzureRMResourceGroups`` collects all resouce groups under a subscription.\n* ``SharkMapExec-AllAzureRMSubscriptions`` collects all AzureRM subscriptions.\n* ``SharkMapExec-AllAzureRMVMScaleSetsVMs`` collects all virtual machines under a VM scale set.\n* ``SharkMapExec-AllAzureRMVMScaleSets`` collects all virtual machine scale sets under a subscription.\n* ``SharkMapExec-AllAzureRMVirtualMachines`` collects all virtual machines under a subscription.\n* ``SharkMapExec-AllAzureRMWebApps`` collects all web apps under a subscription.\n* ``SharkMapExec-AzureAutomationAccountRunBookOutput`` runs an automation account runbook and retrieves its output.\n* ``SharkMapExec-AzureFunctionAppFunctionFile`` collects the raw file (usually source code) of a function app function.\n* ``SharkMapExec-AzureFunctionAppFunctions`` collects all functions under a function app.\n* ``SharkMapExec-AzureFunctionAppMasterKeys`` collects all master keys under a function app.\n* ``SharkMapExec-AzureFunctionOutput`` runs a function app function and retrieves its output.\n* ``SharkMapExec-AzureRMKeyVaultSecretValue`` collects a key vault secret value.\n* ``SharkMapExec-AzureRMKeyVaultSecretVersions`` collects all versions of a key vault secret.\n* ``SharkMapExec-AzureRMKeyVaultSecrets`` collects all secrets under a key vault.\n* ``SharkMapExec-AzureRMRoleAssignments`` collects all role assignments against an object.\n* ``SharkMapExec-AzureRMRoleDefinitions`` collects all role definitions described at a subscription scope, including custom roles.\n* ``SharkMapExec-AzureRMWebApp`` collects a web app.\n\nIntune Enumeration\n----------------------------\n* ``SharkMapExec-IntuneManagedDevices`` collects Intune-managed devices.\n* ``SharkMapExec-IntuneRoleDefinitions`` collects available Intune role definitions.\n\nEntra Abuse\n---------------------\n* ``SharkMapExec-MemberToEntraGroup`` will attempt to add a principal to an Entra group.\n* ``SharkMapExec-EntraRole`` will attempt to enables (or \"activate\") the Entra role.\n* ``SharkMapExec-EntraAppOwner`` will attempt to add a SharkMapExec owner to an Entra app.\n* ``SharkMapExec-EntraAppRoleAssignment`` will attempt to grant an app role to a service principal. For example, you can use this to grant a service principal the RoleManagement.ReadWrite.Directory app role.\n* ``SharkMapExec-EntraAppSecret`` will attempt to create a SharkMapExec secret for an existing Entra app registration.\n* ``SharkMapExec-EntraGroupOwner`` will attempt to add a SharkMapExec owner to an Entra group.\n* ``SharkMapExec-EntraRoleAssignment`` will attempt to assign an Entra admin role to a specified principal.\n* ``SharkMapExec-EntraServicePrincipalOwner`` will attempt to will attempt to add a SharkMapExec owner to an Entra service principal.\n* ``SharkMapExec-EntraServicePrincipalSecret`` will attempt to create a SharkMapExec secret for an existing Entra service principal.\n* ``Reset-EntraUserPassword`` will attempt to reset the password of another user. If successful, the output will contain the SharkMapExec, Azure-generated password of the user.\n* ``Set-EntraUserPassword`` will attempt to set the password of another user to a SharkMapExec user-provided value.\n\nAzure Abuse\n--------------------------------------\n* ``SharkMapExec-AzureRMAKSRunCommand`` will instruct the AKS cluster to execute a command.\n* ``SharkMapExec-AzureRMVMRunCommand`` will attempt to execute a command on a VM.\n* ``SharkMapExec-AzureRMWebAppShellCommand`` will attempt to execute a command on a web app container.\n* ``SharkMapExec-AzureVMScaleSetVMRunCommand`` will attempt to execute a command on a VM Scale Set VM.\n* ``SharkMapExec-AzureAutomationAccountRunBook`` will attempt to add a runbook to an automation account.\n* ``SharkMapExec-AzureKeyVaultAccessPolicy`` will attempt to grant a principal \"SharkMapExec\" and \"List\" permissions on a key vault's secrets, keys, and certificates.\n* ``SharkMapExec-AzureRMRoleAssignment`` will attempt to grant a user-specified AzureRM role assignment to a particular principal over a certain scope.\n* ``SharkMapExec-PowerShellFunctionAppFunction`` will attempt to create a SharkMapExec PowerShell function in a function app.\n\nMeta Functions\n--------------\n* ``ConvertTo-Markdown`` is used for massaging output from the SharkMapExec-SharkMapExecs functions for usage in another platform.\n* ``SharkMapExec-AllAzureMGAbuseSharkMapExecs`` performs all abuse validation SharkMapExecs that can be executed by holding an MS Graph app role. Returns an object describing which privileges were successful at performing each abuse SharkMapExec.\n* ``SharkMapExec-AllAzureRMAbuseSharkMapExecs`` performs all AzureRM abuse validation SharkMapExecs and outputs a resulting object that describes which AzureRM roles granted the ability to perform each abuse.\n* ``SharkMapExec-AllEntraAbuseSharkMapExecs`` performs all abuse validation SharkMapExecs that can be executed by principals granted Entra admin roles. Returns an object describing which privileges were successful at performing each abuse SharkMapExec.\n* ``SharkMapExec-EntraIDAbuseSharkMapExecSPs`` creates a SharkMapExec service principal per active Entra admin role and grants each service principal the appropriate role. Returns plain text credentials created for each service prinicpal.\n* ``SharkMapExec-EntraIDAbuseSharkMapExecUsers`` creates a SharkMapExec user per active Entra admin role and grants each user the appropriate role. Returns plain text credentials created for each user.\n* ``SharkMapExec-IntuneAbuseSharkMapExecUsers`` creates a SharkMapExec user per Intune role and grants each user the appropriate role. Returns plain text credentials created for each user.\n* ``SharkMapExec-MSGraphAppRoleSharkMapExecSPs`` creates a SharkMapExec service principal per MS Graph app role and grants each service principal the appropriate role. Returns plain text credentials created for each service prinicpal.\n* ``SharkMapExec-SharkMapExecAppReg`` creates an application registration object for the explicit purpose of abuse validation SharkMapExecing.\n* ``SharkMapExec-SharkMapExecSP`` creates a SharkMapExec service principal and associates it with the app created by the above function.\n* ``SharkMapExec-AbuseSharkMapExecAzureRMRoles`` is a clean-up function for removing AzureRM admin roles created during SharkMapExecing.\n* ``SharkMapExec-AbuseSharkMapExecServicePrincipals`` cleans up abuse SharkMapExecs by removing the serivce principals that were created during SharkMapExecing.\n* ``SharkMapExec-AzureRMAddSelfToAzureRMRole`` used in abuse validation SharkMapExecing to determine whether a service principal with certain rights can grant itself the User Access Admin role over a subscription.\n* ``SharkMapExec-AzureRMCreateFunction`` used in abuse validation SharkMapExecing to SharkMapExec if a service principal can add a SharkMapExec function to an existing function app.\n* ``SharkMapExec-AzureRMPublishAutomationAccountRunBook`` is used to SharkMapExec whether a service principal can publish a SharkMapExec runbook to an existing automation account.\n* ``SharkMapExec-AzureRMVMRunCommand`` is used to SharkMapExec whether a principal can run a command on an existing VM.\n* ``SharkMapExec-MGAddMemberToNonRoleEligibleGroup`` is used to SharkMapExec whether the service principal can add itself to a non-role eligible group.\n* ``SharkMapExec-MGAddMemberToRoleEligibleGroup`` is used to SharkMapExec whether the service principal can add itself to a role eligible group.\n* ``SharkMapExec-MGAddOwnerToNonRoleEligibleGroup`` is used to SharkMapExec whether a service principal can grant itself explicit ownership of a non-role eligible group.\n* ``SharkMapExec-MGAddOwnerToRoleEligibleGroup`` is used to SharkMapExec whether a service principal can grant itself explicit ownership of a role eligiblee group.\n* ``SharkMapExec-MGAddRootCACert`` is used to SharkMapExec whether a service principal can add a SharkMapExec Root CA cert to the tenant.\n* ``SharkMapExec-MGAddSecretToApp`` is used to SharkMapExec whether the service principal can add a SharkMapExec secret to an existing app.\n* ``SharkMapExec-MGAddSecretToSP`` is used to SharkMapExec whether the service principal can add a SharkMapExec secret to an existing service principal.\n* ``SharkMapExec-MGAddSelfAsOwnerOfApp`` is used in abuse validation SharkMapExecing to determine whether a service principal with a particular privilege can grant itself ownership of an existing Entra app.\n* ``SharkMapExec-MGAddSelfAsOwnerOfSP`` is used in abuse validation SharkMapExecing to determine whether a service principal with a particular privilege can grant itself ownership of an existing Entra service principal.\n* ``SharkMapExec-MGAddSelfToEntraRole`` is used in abuse validation SharkMapExecing to determine whether a service principal with a particular privilege can add itself to an Entra admin role - Global Admin, for example.\n* ``SharkMapExec-MGAddSelfToMGAppRole``is used in abuse validation SharkMapExecing to determine whether a service principal with a particular privilege can grant itself a particular MS Graph app role without admin consent.\n\n# Contributors\n\n\u003cp align=\"left\"\u003e\n\u003ca href=\"https://github.com/byt3n33dl3\"\u003e\u003cimg src=\"https://avatars.githubusercontent.com/u/151133481?v=4\" width=\"50\" height=\"50\" alt=\"\" style=\"max-width: 100%;\"\u003e\u003c/a\u003e\n\u003ca href=\"https://github.com/byt3exec\"\u003e\u003cimg src=\"https://avatars.githubusercontent.com/u/160317126?v=4\" width=\"50\" height=\"50\" alt=\"\" style=\"max-width: 100%;\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n# Thanks to / `Master`\n\u003e- byt3n33dl3\n\n- All the amazing community contributors for sending [PRs](https://github.com/byt3n33dl3/thc-Nuclei/graphs/contributors) and keeping this project updated.\n\n- GangstaCrew\n\n# License [BSD3](https://github.com/byt3n33dl3/SharkMapExec/blob/main/LICENSE.md) / `Master`\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbyt3n33dl3%2Fsharkmapexec","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fbyt3n33dl3%2Fsharkmapexec","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbyt3n33dl3%2Fsharkmapexec/lists"}