Description
SOAPy is a Proof of Concept (PoC) utility for conducting offensive interaction with Active Directory Web Services (ADWS) through a SOCKS5 proxy.
SOAPy includes previously undeveloped custom python implementations of a collection of Microsoft protocols required for interaction with the ADWS service. This includes but is not limited to: NNS (.NET NegotiateStream Protocol), NMF (.NET Message Framing Protocol), and NBFSE (.NET Binary Format: SOAP Extension).
SOAPy started as a research project at IBM X-Force Red with Jackson Leverett to rewrite the proprietary Microsoft .NET mechanisms/library that FalconForce’s SOAPHound uses to interact with ADWS, so recon and post-exploitation operations would be possible through a SOCKS5 proxy from Linux on Red Team assessments. After joining SpecterOps, I decided to continue development on the project to bring it up to operational speed.
SOAPy is used for interacting with ADWS over a proxy for stealthy recon into an internal Active Directory environment. SOAPy can also perform targeted post-exploitation operations on LDAP, useful in many assessments when evasive LDAP write operations are required.
This includes the following tradecraft:
- servicePrincipalName writing for targeted kerberoasting
- userAccountControl writing for targeted AS-REProasting
- msDs-AllowedToActOnBehalfOfOtherIdentity writing for Resource-Based Constrained Delegation (RBCD) attacks
- msDs-KeyCredentialLink writing for Shadow Credentials attacks
- DNS record additions for authentication coercion primitives
The protocol structure for interacting with ADWS is shown below:
The blog detailing the original research largely from an engineering perspective can be found here:
SOAPy: Stealthy enumeration of Active Directory environments through ADWS - IBM X-Force Red
A SpecterOps blog detailing new and modern operational guidance for ADWS tradecraft with SOAPy can be found here:
Make Sure to Use SOAP(y) – An Operators Guide to Stealthy AD Collection Using ADWS - SpecterOps