Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion src/Producers/BaseProducer.cs
Original file line number Diff line number Diff line change
Expand Up @@ -24,12 +24,14 @@ public abstract class BaseProducer
protected readonly Channel<IDirectoryObject> Channel;
protected readonly Channel<OutputBase> OutputChannel;
protected readonly IContext Context;
protected readonly Channel<CSVComputerStatus> CompStatusChannel;

protected BaseProducer(IContext context, Channel<IDirectoryObject> channel, Channel<OutputBase> outputChannel)
protected BaseProducer(IContext context, Channel<IDirectoryObject> channel, Channel<OutputBase> outputChannel, Channel<CSVComputerStatus> compStatusChannel)
{
Context = context;
Channel = channel;
OutputChannel = outputChannel;
CompStatusChannel = compStatusChannel;
}

public abstract Task Produce();
Expand Down
14 changes: 12 additions & 2 deletions src/Producers/ComputerFileProducer.cs
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,10 @@ namespace Sharphound.Producers
/// </summary>
internal class ComputerFileProducer : BaseProducer
{
public ComputerFileProducer(IContext context, Channel<IDirectoryObject> channel, Channel<OutputBase> outputChannel) : base(context, channel, outputChannel)
public ComputerFileProducer(IContext context,
Channel<IDirectoryObject> channel,
Channel<OutputBase> outputChannel,
Channel<CSVComputerStatus> compStatusChannel) : base(context, channel, outputChannel, compStatusChannel)
{
}

Expand Down Expand Up @@ -65,7 +68,14 @@ public override async Task Produce()
string sid;
if (!computer.StartsWith("S-1-5-21")) {
//The computer isn't a SID so try to convert it to one
if (await Context.LDAPUtils.ResolveHostToSid(computer, domainName) is (true, var tempSid)) {
if (await Context.LDAPUtils.ResolveHostToSid(computer, domainName) is (true, var tempSid))
{
await CompStatusChannel.Writer.WriteAsync(new CSVComputerStatus
{
Status = ComputerStatus.Success,
ComputerName = computer,
Task = "ComputerFileProducer - Produce"
}, cancellationToken);
sid = tempSid;
} else {
Context.Logger.LogError("Failed to resolve host {Computer} to SID", computer);
Expand Down
5 changes: 4 additions & 1 deletion src/Producers/LdapProducer.cs
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,10 @@ namespace Sharphound.Producers
{
public class LdapProducer : BaseProducer
{
public LdapProducer(IContext context, Channel<IDirectoryObject> channel, Channel<OutputBase> outputChannel) : base(context, channel, outputChannel)
public LdapProducer(IContext context,
Channel<IDirectoryObject> channel,
Channel<OutputBase> outputChannel,
Channel<CSVComputerStatus> compStatusChannel) : base(context, channel, outputChannel, compStatusChannel)
{
}

Expand Down
11 changes: 10 additions & 1 deletion src/Producers/StealthProducer.cs
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,10 @@ internal class StealthProducer : BaseProducer
private readonly LdapFilter _query;
private readonly LdapFilter _queryConfigNC;

public StealthProducer(IContext context, Channel<IDirectoryObject> channel, Channel<OutputBase> outputChannel) : base(context, channel, outputChannel)
public StealthProducer(IContext context,
Channel<IDirectoryObject> channel,
Channel<OutputBase> outputChannel,
Channel<CSVComputerStatus> compStatusChannel) : base(context, channel, outputChannel, compStatusChannel)
{
var ldapData = CreateDefaultNCData();
_query = ldapData.Filter;
Expand Down Expand Up @@ -161,6 +164,12 @@ private async Task<Dictionary<string, IDirectoryObject>> FindPathTargetSids()
foreach (var path in paths.Keys)
{
if (await Context.LDAPUtils.ResolveHostToSid(path, Context.DomainName) is (true, var sid)) {
await CompStatusChannel.Writer.WriteAsync(new CSVComputerStatus
{
Status = ComputerStatus.Success,
ComputerName = path,
Task = "StealthProducer - FindPathTargetSids"
});
if (sid != null && sid.StartsWith("S-1-5")) {
var searchResult = await Context.LDAPUtils.Query(new LdapQueryParameters() {
LDAPFilter = CommonFilters.SpecificSID(sid),
Expand Down
6 changes: 3 additions & 3 deletions src/Runtime/CollectionTask.cs
Original file line number Diff line number Diff line change
Expand Up @@ -54,11 +54,11 @@ public CollectionTask(IContext context)
_outputWriter = new OutputWriter(context, _outputChannel);

if (context.Flags.Stealth)
_producer = new StealthProducer(context, _ldapChannel, _outputChannel);
_producer = new StealthProducer(context, _ldapChannel, _outputChannel, _compStatusChannel);
else if (context.ComputerFile != null)
_producer = new ComputerFileProducer(context, _ldapChannel, _outputChannel);
_producer = new ComputerFileProducer(context, _ldapChannel, _outputChannel, _compStatusChannel);
else
_producer = new LdapProducer(context, _ldapChannel, _outputChannel);
_producer = new LdapProducer(context, _ldapChannel, _outputChannel, _compStatusChannel);
}

internal async Task<string> StartCollection()
Expand Down
19 changes: 17 additions & 2 deletions src/Runtime/ObjectProcessors.cs
Original file line number Diff line number Diff line change
Expand Up @@ -88,7 +88,7 @@ internal async Task<OutputBase> ProcessObject(IDirectoryObject entry,
case Label.AIACA:
return await ProcessAIACA(entry, resolvedSearchResult);
case Label.EnterpriseCA:
return await ProcessEnterpriseCA(entry, resolvedSearchResult);
return await ProcessEnterpriseCA(entry, resolvedSearchResult, compStatusChannel);
case Label.NTAuthStore:
return await ProcessNTAuthStore(entry, resolvedSearchResult);
case Label.CertTemplate:
Expand Down Expand Up @@ -654,7 +654,8 @@ private async Task<AIACA> ProcessAIACA(IDirectoryObject entry, ResolvedSearchRes
}

private async Task<EnterpriseCA> ProcessEnterpriseCA(IDirectoryObject entry,
ResolvedSearchResult resolvedSearchResult) {
ResolvedSearchResult resolvedSearchResult,
Channel<CSVComputerStatus> compStatusChannel) {
var ret = new EnterpriseCA {
ObjectIdentifier = resolvedSearchResult.ObjectId,
Properties = new Dictionary<string, object>(GetCommonProperties(entry, resolvedSearchResult))
Expand Down Expand Up @@ -697,6 +698,13 @@ private async Task<EnterpriseCA> ProcessEnterpriseCA(IDirectoryObject entry,
if (await _context.LDAPUtils.ResolveHostToSid(dnsHostName, resolvedSearchResult.DomainSid) is
(true, var sid) && sid.StartsWith("S-1-")) {
ret.HostingComputer = sid;
await compStatusChannel.Writer.WriteAsync(new CSVComputerStatus
{
Status = ComputerStatus.Success,
ComputerName = resolvedSearchResult.DisplayName,
Task = nameof(ProcessEnterpriseCA)
},
_cancellationToken);
} else {
_log.LogWarning("CA {Name} host ({Dns}) could not be resolved to a SID.", caName, dnsHostName);
}
Expand All @@ -719,6 +727,13 @@ private async Task<EnterpriseCA> ProcessEnterpriseCA(IDirectoryObject entry,
if (caName != null && dnsHostName != null) {
if (await _context.LDAPUtils.ResolveHostToSid(dnsHostName, resolvedSearchResult.DomainSid) is
(true, var sid) && sid.StartsWith("S-1-")) {
await compStatusChannel.Writer.WriteAsync(new CSVComputerStatus
{
Status = ComputerStatus.Success,
ComputerName = resolvedSearchResult.DisplayName,
Task = nameof(ProcessEnterpriseCA)
},
_cancellationToken);
ret.HostingComputer = sid;
} else {
_log.LogWarning("CA {Name} host ({Dns}) could not be resolved to a SID.", caName, dnsHostName);
Expand Down