A multi-module collaborative domain penetration automatic vulnerability exploitation method and system

Through the multi-module collaborative domain penetration automatic vulnerability utilization method and system, the existing penetration testing methods are solved in the adaptability and execution efficiency limitations of the complex network environment, and efficient and automated penetration testing is achieved, improving the testing effect and efficiency.

CN120017415BActive Publication Date: 2025-06-13NANJING NANZI DIGITAL SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510465670.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-06-13
Estimated Expiration
2045-04-15

AI Technical Summary

Technical Problem

The adaptability and execution efficiency of existing penetration testing methods in complex network environments have great limitations and cannot meet the needs of modern network security protection systems for efficient and precise penetration testing.

Method used

Provide a multi-module collaborative domain penetration automatic vulnerability utilization method and system. Through multi-module collaborative utilization of vulnerabilities, and combined with the module dynamic orchestration mechanism, automated information collection and automated penetration testing are completed.

Benefits of technology

It realizes efficient and automated penetration testing in complex network environments, greatly saving manpower and time costs, able to fully cover all the processes of domain penetration, and improves the effectiveness and efficiency of testing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017415B_ABST
    Figure CN120017415B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for automatic vulnerability exploitation with multi-module collaboration. The system integrates a routing proxy module, an information collection module, a privilege escalation module, a lateral movement module, a cross-domain attack module, and a session management module, and introduces an intelligent orchestration engine to break through the problems of fixed process and single path in traditional penetration testing, realizing dynamic adjustment and optimization of the penetration process. Through multi-module collaboration and dynamic orchestration mechanism, it can perform automatic vulnerability exploitation according to the real-time changes of the target domain environment. The present invention can completely collect the network information of the domain environment, adapt to the complex environment of multiple domains, multiple services, multiple hosts, and multiple users in the domain forest to obtain high privileges of sub-domains or root domains, greatly saving manpower, material resources, and time costs. At the same time, it further reduces the usage threshold and learning cost of penetration personnel, providing a convenient, intelligent, and controllable security protection test solution for security protection tests of enterprises, schools, etc.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of cyberspace security technology, and in particular relates to a multi-module collaborative domain penetration automatic vulnerability exploitation method and system. Background Art

[0002] With the rapid development of information technology, the network has become an important part of social infrastructure and is widely used in various organizations such as enterprises, government agencies, scientific research institutions and universities. However, with the continuous expansion of network scale and the increasing complexity of information systems, network security issues have become more and more serious. Attackers often use system vulnerabilities and network configuration defects to carry out attacks. In order to improve network defense capabilities, various organizations generally use penetration testing as a key means to evaluate and strengthen their own security. Penetration testing simulates the behavior of real attackers and actively detects the security weaknesses of the target network so as to repair security risks before hackers exploit vulnerabilities and enhance overall defense capabilities. In the penetration test process, domain penetration is a key link. Its core goal is to further penetrate the internal network after breaking through the outer defense line, and use the controlled WEB server, database or other key nodes as a springboard to gradually expand the control scope of the entire intranet. In the end, the attacker may obtain sensitive database information, control a large number of high-value servers, and even capture the domain controller (DC) in the domain environment, thereby completely controlling the entire domain network. The complexity and concealment of domain penetration make it the focus and difficulty of network security protection. Traditional security reinforcement strategies often find it difficult to detect such potential threats in a timely and comprehensive manner.

[0003] The current penetration testing work still mainly relies on penetration testing experts for manual operations. Testers need to perform a series of operations on the target system, such as information collection, vulnerability analysis, exploitation attacks, privilege maintenance, and data acquisition, based on their own experience and skills. The entire process requires high professional capabilities and also places high demands on the tester's knowledge reserve, practical experience, and analysis and judgment abilities. In actual testing, penetration testers may need to face complex large enterprise intranets, involving dozens or even hundreds of hosts, and the differences in different systems, applications, and network architectures further increase the difficulty of penetration work. Due to the low efficiency of manual penetration testing, testers often have difficulty covering the entire target network in a timely and comprehensive manner, which may lead to some security vulnerabilities not being effectively discovered and exploited, reducing the effectiveness of penetration testing. In addition, multiple tools need to be used in coordination to complete tasks in different stages during the penetration testing process, such as information collection tools (e.g., Nmap, Masscan), vulnerability exploitation tools (e.g., Metasploit, Cobalt Strike), privilege maintenance tools (e.g., Empire, Mimikatz), etc. These tools often require testers to perform manual configuration and operations, which not only increases the time cost but also causes additional consumption of system resources, severely restricting the overall testing efficiency.

[0004] In recent years, with the development of automation technology, some penetration testing tools have begun to attempt to automate some processes to reduce the dependence on manual decision-making. However, these tools can often only provide semi-automated assistance in specific links and are difficult to cover the entire penetration testing process. For example, some vulnerability scanning tools can automatically detect known vulnerabilities, but still require penetration testers to manually analyze and exploit them; some attack frameworks can automatically execute part of the attack chain, but lack the ability of intelligent decision-making and cannot dynamically adjust the attack strategy according to the test environment. Therefore, the existing penetration testing methods still have great limitations in adaptability and execution efficiency in complex network environments and cannot meet the requirements of modern network security protection systems for efficient and accurate penetration testing. Summary of the Invention

[0005] To solve the above technical problems, the present invention provides a multi-module collaborative domain penetration automatic vulnerability exploitation method and system, aiming to complete automated information collection and automated penetration testing by collaborating to exploit vulnerabilities through multiple modules and combining a module dynamic orchestration mechanism.

[0006] The technical solution provided by the present invention is as follows:

[0007] A multi-module collaborative domain penetration automatic vulnerability exploitation method includes the steps of:

[0008] S1. Establish an initial session from the border host of the target network, perform cross-segment detection, and set up a routing proxy;

[0009] S2. Identify the live hosts and open ports in the target network, and collect host information and domain information;

[0010] S3. Elevate the privilege level of the current session through operating system vulnerabilities or configuration defects;

[0011] S4. Use the obtained privileges to move laterally and expand the scope of the penetration attack;

[0012] S5. Conduct cross-domain penetration attacks after successful lateral movement.

[0013] Furthermore, step S1 includes:

[0014] Obtain and analyze network card information on the initial session, and determine whether there are multiple network segments on the host; if there are multiple network segments, route establishment and internal network proxy settings are required; monitor the proxy stability in real time, and if the proxy is interrupted, automatically rebuild or switch the route: assign a dynamic route weight score to each network segment. If the proxy is interrupted, first try to restart the proxy service on the original path. If the reconstruction fails, enter the standby path switching process and use the standby path with the highest dynamic route weight score.

[0015] Furthermore, the dynamic route weight score is expressed as:

[0016] ,

[0017] where represents the comprehensive route weight score of the i th network segment, represents the proportion of available bandwidth of the i th network segment, and , is the current network load of the i th network segment, is the maximum bandwidth of the network card; represents the bandwidth utilization rate of the i th network segment, and ; represents the stability coefficient of the i th network segment, that is, the proxy success rate within a set time; is the average response delay ratio of the i th network segment, w 1 ~ w 4 are the coefficients of each factor.

[0018] Furthermore, step S2 includes:

[0019] Deploy a host information collection script on the host where the current session is located to collect host information, including the host name, the domain name where the host is located, the system architecture, the operating system version, and the currently logged-in user;

[0020] Deploy a domain information collection script on the host where the current session is located to collect basic domain information and other information within the domain. The basic domain information includes the forest root domain name, the names of all domain controllers, the names of all subdomains, the parent domain name, the current domain name, and the name of the primary domain controller. The other information within the domain includes services within the domain, logged-in domain users, members of high-privilege groups within the domain, and delegation information within the domain.

[0021] Furthermore, after collecting the host information, dynamically adjust the parameters of the information collection script and real-time filter key data:

[0022] First, classify and judge the host based on the collected information to form policy tags: If the host runs a server version of the operating system, mark it as a "critical node"; if it is a client operating system, mark it as an "ordinary domain member"; if the system role includes "domain controller", "DNS server", "file sharing", mark it as a "high-value target"; if it is not joined to the domain or has no domain information, mark it as a "non-domain member" or a "peripheral host";

[0023] Then, dynamically adjust the parameters of the information collection script according to the classification results: For "ordinary domain member" hosts, perform basic user information enumeration to obtain logged-in users, members of domain user groups, service information, scan the open ports on the local machine, and simple LDAP information; for "high-value target" hosts, increase LDAP deep query to obtain all domain users, domain controller lists, domain trust relationships, try to read the permissions of critical accounts, enable ACL enumeration and SID history field identification, and check whether DCSync attacks or forged ticket forgery are allowed; for "critical node" hosts, strengthen the behavior of extracting credentials, tokens, and keys.

[0024] Furthermore, step S4 includes:

[0025] S401. Check whether there are high-privilege credentials or processes within the domain on the local machine. If so, directly perform token stealing;

[0026] S402. Traverse the un-attacked hosts, obtain the information of the host, and call the corresponding common vulnerabilities to attack;

[0027] S403. Traverse the un-attacked services within the domain, obtain the information of the service, and call the corresponding service vulnerabilities to attack;

[0028] S404. Use domain-related vulnerabilities to attack the domain environment itself to obtain the credentials of the krbtgt user of the domain controller;

[0029] If the token stealing is successful in S401, the vulnerability attack process is immediately paused, and lateral movement is preferentially carried out using credentials; if the vulnerability attacks in S402 - 404 fail continuously, it will automatically switch to the password brute - force or phishing module.

[0030] Further, step S5 includes: traversing all the obtained sessions and credentials, selecting high - privilege sessions and credentials, using the obtained high - privilege credentials to directly attack the root domain through SID - History, and obtaining high - privilege credentials for the root domain; if the SID - History attack fails, Golden Ticket forgery or DNS hijacking is carried out.

[0031] Further, the security protection level of the root domain is evaluated to obtain the defense intensity level, and corresponding cross - domain penetration attack strategies are adopted according to the defense intensity level of the root domain: for low defense intensity, the attack is immediately executed without hiding, and SID - History is directly used; for medium defense intensity, the attack strategies include adding attack delays, simulating normal traffic camouflage before execution, and delaying the delivery of attack payloads; for high defense intensity, the attack strategies include reducing the attack frequency, disguising user behavior, Golden Ticket forgery, and DNS hijacking.

[0032] A domain penetration automatic vulnerability exploitation system based on the above - mentioned method, including a routing proxy module, an information collection module, a privilege escalation module, a lateral movement module, a cross - domain attack module, and an intelligent orchestration engine;

[0033] The routing proxy module is used to set up routes for cross - segment attack sessions and add internal network proxies. During the session communication process, the intelligent orchestration engine dynamically assigns route weights according to the multi - network - card information of the border host and monitors the proxy stability in real - time. If the proxy is interrupted, it will automatically rebuild or switch to a standby route;

[0034] The information collection module is used to collect information about the host where the session is located and obtain relevant information about the target domain. The privilege escalation module is used to elevate the privilege level of the session through operating system vulnerabilities or configuration defects. If the privilege escalation fails, the intelligent orchestration engine records the reason for the privilege escalation failure, dynamically shields high - risk operations, and marks the current host as a "low - privilege temporary target";

[0035] The lateral movement module is used to carry out lateral movement in the target network using known vulnerabilities or credentials to obtain high - privilege user credentials within the domain to expand the scope of the penetration attack;

[0036] The cross - domain attack module is used to initiate a cross - domain penetration attack. During the cross - domain penetration process, the intelligent orchestration engine adjusts the attack rhythm according to the defense strategy of the cross - domain attack. If the target root domain has strong defense, the orchestration engine will automatically delay the attack or switch to other attack methods to avoid triggering alarms and being detected by the defense system.

[0037] Furthermore, it also includes a session management module for tracking and managing all penetration testing sessions, recording the session information and credentials obtained after successful cross-domain attacks, continuously monitoring the status of the controlled hosts, and timely updating the session management policy after cross-domain attacks to ensure the effectiveness of high-privilege sessions and credentials throughout the penetration process.

[0038] Compared with the prior art, the present invention has at least the following beneficial effects:

[0039] By synergistically utilizing vulnerabilities through multiple modules and combining with the module dynamic orchestration mechanism, the present invention can flexibly adjust the execution order and strategy of each module according to the real-time situation during the penetration process, complete the work of automated information collection and automated penetration testing, greatly saving manpower and time costs. For automated penetration testing in the intra-domain environment, the present invention uses dynamic orchestration to achieve adaptation and optimization of complex environments, completely covering all processes of domain penetration, with a much higher completeness than the current semi-automated penetration scripts, filling the gap in the lack of automated penetration tools for domain penetration.

[0040] The present invention is easy to deploy and operate. The module dynamic orchestration mechanism enables the system to adapt to various network structures and defense strategies without manual intervention, only requiring one online session and one attacking host, greatly reducing the usage threshold and learning cost for penetration testers. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] The drawings are used to provide further understanding of the present invention and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention and do not constitute a limitation to the present invention.

[0042] Figure 1 It is a schematic flow chart of information collection provided by an embodiment of the present invention;

[0043] Figure 2 It is a schematic flow chart of lateral movement provided by an embodiment of the present invention;

[0044] Figure 3 It is a schematic framework diagram of a domain penetration automatic vulnerability exploitation system provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0045] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0046] Example 1

[0047] This embodiment provides a multi-module collaborative domain penetration automatic vulnerability exploitation method, which penetrates the internal network domain environment from the perspective of penetration testers. The method mainly includes the following steps:

[0048] Step 1: Establish an initial session and set up a routing proxy

[0049] When conducting a penetration test, it is first necessary to establish an initial session from the boundary host of the target network. At this time, it is necessary to detect the network environment and topology structure of the target host, perform cross-segment detection, and set appropriate routes as needed to ensure the smooth progress of subsequent penetration operations.

[0050] Specifically, it can include the following steps:

[0051] S101. Collect network card information on the initial session of the boundary host, including IP address, subnet mask, network segment, etc., and obtain and analyze whether there are multiple network segments on this host.

[0052] S102. If the network where the host is located involves multiple subnets, for example, the IP of the target host is 192.168.1.100, the subnet mask is 255.255.255.0, and the host is also connected to another network segment 192.168.2.0 / 24, then routing settings and proxy establishment are required to ensure communication with the target system across different network areas.

[0053] S103. Set up a proxy server (such as a Socket5 proxy) so that penetration traffic can communicate between the external network and the internal network through this proxy, ensuring seamless connection of penetration operations between different network segments.

[0054] During the penetration process, the network usually consists of multiple subnets, VLANs or physically isolated segments. Penetration testers often need to cross these different network segments to complete the penetration control of deep internal network resources. At this time, the ability to automatically adjust routing policies is of great significance to the efficiency, concealment and stability of penetration testing.

[0055] In this embodiment, the routing weights are dynamically allocated according to the multi-network card information of the boundary host (such as preferentially proxying the network segment with less traffic), and the proxy stability is monitored in real time. If the proxy is interrupted, the standby route is automatically rebuilt or switched.

[0056] Specifically, considering factors such as network load, bandwidth utilization, topological structure distance, path historical stability, etc., a dynamic routing priority weight value is assigned to each network interface. Let the i comprehensive routing weight score of the W i, then

[0057] ,

[0058] Among them, represents the available bandwidth ratio of the i th network segment, and , is the current network load, is the maximum bandwidth of the network card; represents the bandwidth utilization rate of the i th network segment, and , is logically complementary to, the lower the better, indicating that the current network segment is idle; is the average response delay ratio (current path RTT / maximum tolerable RTT), represents the path stability coefficient (proxy success rate in the past period of time), w 1 ~ w 4 are the coefficients of each factor, with the default value of 0.25 for all, and can be specifically set according to the task scenario. The higher the comprehensive routing weight score, the better the path, and it is preferentially selected as the main route.

[0059] If the proxy is interrupted, first try to restart the proxy service on the original path. If the reconstruction fails, enter the standby path switching process, and use the standby path with the highest comprehensive routing weight score as above. If the scores are close, preferentially select the one with a higher stability coefficient.

[0060] Step 2: Network Scanning and Information Collection

[0061] After successfully establishing a session and configuring the route, the next step of the penetration test is to collect information. The goal of this stage is to obtain as much information about the target network and hosts as possible to provide data support for subsequent vulnerability exploitation, privilege escalation, and attack path planning.

[0062] As Figure 1 shown, this stage can specifically include the following steps:

[0063] S201, Network Scanning: Use tools such as Nmap and Masscan to perform port scanning to identify the live hosts and open ports in the target network. Usually start scanning from the boundary hosts and gradually expand to the internal network.

[0064] S202, Host Information Collection: Deploy a host information collection script on the host where the current session is located, such as using a PowerShell script (PowerView) to collect host information, including: host name, domain name where the host is located, system architecture, operating system version, and currently logged-in user.

[0065] S203. Domain Information Collection: Deploy a domain information collection script on the host where the current session is located. Use the LDAP protocol to query the AD (Active Directory) directory and collect basic domain information, including: forest root domain name, all domain controller names, all subdomain names, parent domain name, current domain name, and primary domain controller name, as well as other domain information such as in-domain services, logged-in domain users, members of high-privilege groups in the domain, and delegation information within the domain.

[0066] After initially collecting host information, the parameters of the information collection script can be dynamically adjusted (for example, increasing the domain controller scan depth for Windows Server hosts), and key data (such as domain trust relationships) can be screened in real time to prepare for cross-domain attacks or preload corresponding modules.

[0067] Specifically, first, the host can be classified and judged based on the collected information to form policy tags: If the host runs a server version of the operating system, it is marked as a "critical node", and further identify whether it is a domain controller; if it is a client operating system, such as Windows 10, it is marked as an "ordinary domain member"; if the system role contains features such as "domain controller", "DNS server", "file sharing", etc., it is marked as a "high-value target"; if it is not joined to the domain or has no domain information, it is marked as a "non-domain member" or "peripheral host". Then, according to the host classification results, the parameters of information collection are dynamically adjusted. For example, for ordinary domain member hosts: perform basic user information enumeration, obtain logged-in users, domain user group members, service information, scan the open ports on the local machine and simple LDAP information; for domain controller hosts: increase LDAP deep query, obtain all domain users, domain controller list, domain trust relationships, try to read the permissions of key accounts (such as krbtgt), enable ACL enumeration and SID history field identification, and check whether DCSync attacks or ticket forgery are allowed; for hosts with active high-privilege users: strengthen the extraction of information such as credentials, tokens, and keys, and activate the ticket extraction and session listening policies in memory.

[0068] Through these dynamic parameter adjustments, the characteristics of the target host can be accurately matched, redundant scans can be reduced, and the efficiency of information acquisition and security concealment can be improved. After receiving the scan results, perform real-time structured parsing and pay attention to the following key data items: domain controller name and IP address, trust relationships between the current domain and other domains (such as parent-child domains, forest trusts, external trusts), key domain users (such as Enterprise Admins, Domain Admins), in-domain permission delegation information, service delegation accounts, implicit permission chains, suspicious cross-domain login traces or account usage records, etc. Once these key fields are identified, immediately evaluate the potential subsequent attack value they may bring.

[0069] Step 3: Privilege Escalation

[0070] After the information collection is completed, the next step is to escalate privileges. If the privileges of the current penetration session are not sufficient for further penetration, privilege escalation operations need to be carried out to raise the privilege level of the current session. Through privilege escalation, the attacker can obtain higher system access privileges and thus be able to perform more attack operations.

[0071] The specific operations for privilege escalation include the steps:

[0072] S301, Privilege detection: Detect the privileges of the current session and determine whether it is an administrator or system privilege (System privilege). If the current session has low privileges (such as ordinary user privileges), privilege escalation is required. For example, by executing the whoami command to view the current user identity. If the result is DOMAIN\user, it indicates that the current privileges are low; if it is SYSTEM or Administrator, it means that the current already has high privileges.

[0073] S302, Use known vulnerabilities for privilege escalation: Use operating system vulnerabilities or configuration defects to escalate the privileges of the current session. For example, use the getsystem command in the MSF (Metasploit) framework or Windows privilege escalation vulnerabilities (such as MS14-058) for privilege elevation.

[0074] S303, If the privilege escalation fails, record the reason for the failure (such as being blocked by anti-virus software), dynamically block high-risk operations (such as disabling the exploitation of the MS14-058 vulnerability), and mark the current host as a "low-privilege staging target" to be rescanned for privilege escalation after other modules succeed.

[0075] Step 4: Lateral movement

[0076] Lateral movement is an important step in penetration testing. Its purpose is to expand the attack scope within the target network and obtain more resources or credentials. Through lateral movement, the obtained privileges can be used to gradually penetrate more systems and ultimately control high-privilege users in the domain environment.

[0077] As Figure 2 shown, the specific steps for lateral movement include:

[0078] S401, Check whether there are high-privilege credentials or processes within the domain on the local machine. If so, directly perform token stealing;

[0079] S402, Traverse un-attacked hosts, obtain information about the host (such as system version and open ports), and call corresponding common vulnerabilities to attack;

[0080] S403. Traverse the services within the domain that have not been attacked, obtain the service information, and call the corresponding service vulnerabilities to conduct attacks.

[0081] S404. Use domain-related vulnerabilities to attack the domain environment itself and obtain the credentials of the krbtgt user of the domain controller.

[0082] If the token stealing (S401) is successful, immediately pause the vulnerability attack process and preferentially use the credentials for lateral movement. If the vulnerability attacks (S402 - 404) fail continuously, automatically switch to password brute force (by trying a large number of possible password combinations to guess the login credentials of the target system to obtain unauthorized access rights) or the phishing module (by forging trusted communications or interfaces to deceive users into providing sensitive information such as usernames and passwords).

[0083] Step 5: Cross-domain penetration attack

[0084] Once sufficient permissions are successfully obtained within the target network, especially the credentials of the domain controller or high-privilege users, the penetration tester can start cross-domain penetration. After successful lateral movement, traverse all the obtained sessions and credentials, and select the high-privilege sessions and credentials. Use the obtained high-privilege credentials to directly attack the root domain through SID-History to obtain the high-privilege credentials of the root domain. If the SID-History attack fails, then conduct Golden Ticket forgery or DNS hijacking.

[0085] During the cross-domain penetration process, it may be blocked by defense mechanisms. At this time, the attack strategy can be adjusted (such as delaying the attack) to avoid triggering alarms or being recognized by the security defense system. Specifically, the security protection level of the root domain can be evaluated based on the following metrics to generate a defense score or intensity level:

[0086]

[0087] According to different defense intensity levels, different attack control strategies are adopted. For example: for low defense intensity, immediately execute the attack without hiding, and directly use SID-History; for medium defense intensity, add an attack delay, simulate normal traffic camouflage before execution, and delay the delivery of the attack payload (such as trigger after 5 - 10 minutes); for high defense intensity, reduce the attack frequency, stagger the time (such as at the low peak time in the early morning), disguise user behavior (simulate normal login), and select a more concealed alternative (such as forging a Golden Ticket or conducting DNS hijacking).

[0088] Embodiment 2

[0089] Based on the above method, this embodiment provides a multi-module collaborative domain penetration automatic vulnerability exploitation system, as Figure 3As shown in the figure, the system mainly includes routing proxy module, information collection module, privilege escalation module, lateral movement module, cross-domain attack module and session management module, and introduces an intelligent orchestration engine to break through the problems of fixed process and single path of traditional penetration testing, and realize dynamic adjustment and optimization of the penetration process.

[0090] in:

[0091] The routing proxy module is responsible for setting routes for cross-segment attack sessions and adding intranet proxies. Through this module, attackers can establish a reliable communication channel between the border host and the intranet. During the session communication process, the intelligent orchestration engine dynamically allocates routing weights based on the multi-NIC information of the border host (such as giving priority to the network segment with less proxy traffic), and monitors the proxy stability in real time. If the proxy is interrupted, it will automatically rebuild or switch to an alternate route.

[0092] The information collection module is responsible for collecting information about the host where the session is located and obtaining relevant information about the target domain. It collects the operating system information, open ports, domain services and user information of the target host by running specific scripts and scanning tools (such as Nmap and PowerView) to prepare for subsequent penetration behavior. During the information scanning and collection process, the intelligent orchestration engine automatically adjusts the scanning strategy based on the collected information (such as operating system type, open ports, and domain controller information). For example, for Windows domain controllers, the intelligent orchestration engine automatically adjusts script parameters, increases scanning depth and priority, and ensures that the most relevant data is collected.

[0093] The privilege escalation module is responsible for elevating newly launched sessions to high privileges. This module escalates privileges on the target host through automated privilege escalation vulnerability exploits (such as MS14-058, UAC bypass, etc.). If privilege escalation fails, the intelligent orchestration engine will record the reasons for the privilege escalation failure (such as antivirus software interception), dynamically block high-risk operations (such as disabling MS14-058 vulnerability exploits), and mark the current host as a "low-privilege temporary target" and scan back for privilege escalation after other modules succeed.

[0094] The lateral movement module is used to exploit known vulnerabilities or credentials to move laterally in the target network to attack more hosts, especially to obtain high-privileged user credentials in the domain. The focus of the lateral movement module is to obtain new sessions through vulnerability exploitation or credential theft.

[0095] The cross-domain attack module is responsible for launching cross-domain penetration attacks, especially when obtaining high-privilege credentials, breaking through the security lines between domains and entering the root domain controller by using these credentials. During the cross-domain penetration process, the intelligent orchestration engine adjusts the attack rhythm according to the cross-domain attack defense strategy. If the target root domain has strong defense, the orchestration engine will automatically delay the attack or switch to other attack methods to avoid triggering alarms and being detected by the defense system.

[0096] The session management module is responsible for tracking and managing all penetration testing sessions, and recording the session information and credentials obtained after successful cross-domain attacks. It continuously monitors the status of the compromised hosts and updates the session management policy in a timely manner after cross-domain attacks to ensure the validity of high-privilege sessions and credentials throughout the penetration process.

[0097] Through the collaborative work of the above functional modules, penetration testing can break through from the network boundary to control the entire domain network, and the process is more efficient and automated. Each module is responsible for a specific function, but in the actual penetration testing process, their collaborative work is crucial. For example, the routing proxy module provides support for cross-segment attacks, the information collection module collects all target data, the privilege escalation module escalates privileges, the lateral movement module expands the attack scope, the cross-domain attack module breaks through the domain defense line, and the session management module ensures data tracking and control throughout the attack process. Finally, the intelligent orchestration engine optimizes the penetration path to improve the testing efficiency and success rate.

[0098] The above system can execute the multi-module collaborative domain penetration automatic vulnerability exploitation method described in Embodiment 1, and has the corresponding functional modules and beneficial effects of the method. For the technical details not described in detail in this embodiment, reference can be made to the multi-module collaborative domain penetration automatic vulnerability exploitation method provided in Embodiment 1 of the present invention.

[0099] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solutions, or the part that contributes to the related technologies, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0100] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; under the idea of the present invention, the technical features in the above embodiments or different embodiments can also be combined, and the steps can be implemented in any order, and there are many other changes in different aspects of the present invention as described above. For the sake of brevity, they are not provided in detail; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A multi-module collaborative domain penetration automatic vulnerability exploitation method, characterized in that: Includes steps: S1. Establish an initial session from the boundary host of the target network, perform cross-segment detection and set up a routing proxy; S2, identify live hosts and open ports in the target network, and collect host information and domain information; S3, elevating the privilege level of the current session through operating system vulnerabilities or configuration flaws; S4. Use the obtained permissions to move laterally and expand the scope of penetration attacks; S5: Carry out cross-domain penetration attacks after successful lateral movement; Wherein, step S1 comprises: Obtain and analyze network card information in the initial session to determine whether the host has multiple network segments; if there are multiple network segments, it is necessary to establish routes and set up intranet proxies; monitor proxy stability in real time, and automatically rebuild or switch routes if the proxy is interrupted: assign a dynamic routing weight score to each network segment. If the proxy is interrupted, first try to restart the proxy service on the original path. If the reconstruction fails, enter the backup path switching process and use the backup path with the highest dynamic routing weight score.

2. The domain penetration automatic vulnerability exploitation method according to claim 1, characterized in that: The dynamic routing weight score is expressed as: , in, Indicates i The comprehensive routing weight score of each network segment, Indicates i The available bandwidth ratio of each network segment, and , For the i The current network load of each network segment, The maximum bandwidth of the network card; Indicates i The bandwidth utilization of each network segment, and ; Indicates i The stability coefficient of each network segment, that is, the proxy success rate within the set time; For the i The average response delay ratio of the network segments, w 1~ w 4 is the coefficient of each factor.

3. The domain penetration automatic vulnerability exploitation method according to claim 1, characterized in that: Step S2 includes: Deploy a host information collection script on the host where the current session is located to collect host information, including the host name, domain name where the host is located, system architecture, operating system version, and current logged-in user; Deploy a domain information collection script on the host where the current session is located to collect basic domain information and other domain information. The basic domain information includes the forest root domain name, all domain controller names, all child domain names, the parent domain name, the current domain name and the primary domain controller name. The other domain information includes domain services, logged-in domain users, domain high-authority group members, and domain delegation information.

4. The domain penetration automatic vulnerability exploitation method according to claim 3, characterized in that: After collecting host information, dynamically adjust the parameters of the information collection script and filter key data in real time: First, the host is classified and judged based on the collected information to form a policy label: if the host runs a server version operating system, it is marked as a "key node"; if it is a client operating system, it is marked as a "normal domain member"; if the system role includes "domain controller", "DNS server" and "file sharing", it is marked as a "high-value target"; if it is not joined to the domain or has no domain information, it is marked as a "non-domain member" or "peripheral host"; Then, according to the classification results, the parameters of the information collection script are dynamically adjusted: for "ordinary domain member" hosts, basic user information enumeration is performed to obtain logged-in users, domain user group members, service information, and scan local open ports and simple LDAP information; for "high-value target" hosts, LDAP deep query is added to obtain all domain users, domain control lists, domain trust relationships, try to read key account permissions, enable ACL enumeration and SID history field recognition, and check whether DCSync attacks or forged tickets are allowed; for "key node" hosts, credential, token, and key extraction behaviors are strengthened.

5. The domain penetration automatic vulnerability exploitation method according to claim 1, characterized in that: Step S4 includes: S401, check whether there are high-authority credentials or processes in the domain on the local machine, and if so, directly steal the token; S402, traverse the host that has not been attacked, obtain the host information and call the corresponding common vulnerability to attack; S403, traverse the unattacked domain services, obtain the service information and call the corresponding service vulnerability to attack; S404, using domain-related vulnerabilities to attack the domain environment itself and obtain the credentials of the domain controller's krbtgt user; If the token theft in S401 is successful, the vulnerability attack process will be immediately suspended, and lateral movement using credentials will be prioritized; if the vulnerability attacks in S402~404 fail continuously, it will automatically switch to the password blasting or phishing module.

6. The domain penetration automatic vulnerability exploitation method according to claim 1, characterized in that: Step S5 includes: traversing all acquired sessions and credentials, selecting high-authority sessions and credentials, using the acquired high-authority credentials to directly attack the root domain through SID-History to obtain the root domain high-authority credentials; if the SID-History attack fails, Golden Ticket forgery or DNS hijacking is performed.

7. The domain penetration automatic vulnerability exploitation method according to claim 6, characterized in that: Evaluate the security protection level of the root domain to obtain the defense strength level, and adopt corresponding cross-domain penetration attack strategies according to the defense strength level of the root domain: for low defense strength, execute the attack immediately without hiding, and directly use SID-History; For medium defense intensity, attack strategies include adding attack delays, simulating normal traffic disguise before execution, and delaying the delivery of attack payloads; for high defense intensity, attack strategies include reducing attack frequency, disguising user behavior, GoldenTicket forgery, and DNS hijacking.

8. A domain penetration automatic vulnerability exploitation system based on the method according to any one of claims 1 to 7, characterized in that: It includes routing proxy module, information collection module, privilege escalation module, lateral movement module, cross-domain attack module and intelligent orchestration engine; The routing proxy module is used to set routes for cross-segment attack sessions and add intranet proxies. During session communication, the intelligent orchestration engine dynamically allocates routing weights based on the multi-NIC information of the border host and monitors the proxy stability in real time. If the proxy is interrupted, it automatically rebuilds or switches to an alternate route. The information collection module is used to collect information about the host where the session is located and obtain relevant information about the target domain. The privilege escalation module is used to elevate the privilege level of the session through operating system vulnerabilities or configuration defects. If the privilege escalation fails, the intelligent orchestration engine records the reason for the privilege escalation failure, dynamically blocks high-risk operations, and marks the current host as a "low-privilege temporary storage target"; The lateral movement module is used to utilize known vulnerabilities or credentials to move laterally in the target network and obtain high-privilege user credentials in the domain to expand the scope of penetration attack; The cross-domain attack module is used to launch a cross-domain penetration attack. During the cross-domain penetration process, the intelligent orchestration engine adjusts the attack rhythm according to the cross-domain attack defense strategy. If the target root domain defense is strong, the orchestration engine will automatically delay the attack or switch to other attack methods to avoid triggering an alarm and being detected by the defense system.

9. The domain penetration automatic vulnerability exploitation system according to claim 8, characterized in that: It also includes a session management module, which is responsible for tracking and managing all penetration test sessions, recording session information and credentials obtained after a successful cross-domain attack, continuously monitoring the status of the controlled host, and promptly updating the session management policy after the cross-domain attack to ensure the validity of high-privilege sessions and credentials throughout the entire penetration process.