Skip to content

Features Request: Stealthiness, usage flexibility #1

@mgeeky

Description

@mgeeky

Hi!

Thanks for a great tool, I'm really fond of it :-)

The tool is blazingly fast and stable, but that can trigger lots of events that would correlate into alerts and offenses.
To combat that and make it more usable for Red Teams that require running their ops low and slow, I could suggest a few features that would be really helpful:

  1. Throttle time between subsequent connections: Just a delay before connecting to the next server.
  2. Jitter that would be introducing variance in specified throttle time
  3. List of servers to evaluate fed from parameter and from input file. There are use cases when we have for instance hundred of servers and would like to check only them for any exposed SMB shares. Can we have that implemented in SharpShares?
  4. The option /filter is great as it acts as a blacklist. What about introducing whitelist-alike option as well? Something like /pattern. Also, both options - filter and new proposed pattern could accept regular expressions (or create dedicated switches for regular expression to avoid loosing performance while evaluating simple literal /filter and /pattern ones)
  5. Accept username and password credentials to make authenticated shares scan on behalf of other user identity.
  6. LDAP Filter: let me specify my custom LDAP Filter that would be use to pull list of computers to check their SMB shares from AD, based on OU or my custom LDAP filter.

Cheers!
Mariusz.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions