You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解决PowerShell双跳问题并远程执行Get-DomainSID?

问题概述

从Kali通过PowerShell远程会话(PSSession)连接到目标系统attacker-win10(server A),该服务器已安装PowerSploit模块。需要运行Get-DomainSID命令(该命令通过LDAP与域控制器**hacklab-dc(server B)**通信获取域SID,在server A本地执行正常),但遇到双跳认证问题,测试两种方案均失败:

Case #1:嵌套Invoke-Command

$cred = Get-Credential hacklab.local\administrator
[192.168.0.102]: PS C:\Users\administrator\Documents> Invoke-Command -ComputerName attacker-win10 -Credential $cred -ScriptBlock { Invoke-Command -ComputerName hacklab-dc -Credential $Using:cred -ScriptBlock {hostname}}
# 返回结果:HACKLAB-DC

[192.168.0.102]: PS C:\Users\administrator\Documents> Invoke-Command -ComputerName attacker-win10 -Credential $cred -ScriptBlock { Invoke-Command -ComputerName hacklab-dc -Credential $Using:cred -ScriptBlock {Get-DomainSID}}

执行hostname成功返回域控制器名称,但Get-DomainSID提示未识别:

The term 'Get-DomainSID' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try again.
    + CategoryInfo          : ObjectNotFound: (Get-DomainSID:String) [], CommandNotFoundException
    + FullyQualifiedErrorId : CommandNotFoundException
    + PSComputerName        : attacker-win10

Case #2:注册PSSession配置

[192.168.0.102]: PS C:\Users\administrator\Documents> Invoke-Command -ComputerName hacklab-dc -ScriptBlock { Register-PSSessionConfiguration -Name Demo -RunAsCredential 'hacklab.local\administrator' -Force }

输入凭据后报错:

[hacklab-dc] Connecting to remote server hacklab-dc failed with the following error message : A specified logon session does not exist. It may already have been terminated. For more information, see the about_Remote_Troubleshooting 
Help topic.
    + CategoryInfo          : OpenError: (hacklab-dc:String) [], PSRemotingTransportException
    + FullyQualifiedErrorId : 1312,PSSessionStateBroken

更新:后台作业尝试

按建议修改命令后创建了后台作业,但无法获取输出:

┌──(asad㉿Yah-Aleemo)-[/home/asad]
└─PS> Invoke-Command -Session $offsecsession -ScriptBlock &{Invoke-Command -ComputerName hacklab-dc -Credential hacklab.local\administrator -ScriptBlock &{Get-DomainSID} }

返回作业信息:

Id     Name            PSJobTypeName   State         HasMoreData     Location             Command
--     ----            -------------   -----         -----------     --------             -------
14     Job14           BackgroundJob   Running       True            localhost            Microsoft.PowerShell.Man…
Invoke-Command -ComputerName hacklab-dc -Credential hacklab.local\administrator -ScriptBlock &{Get-DomainSID} 

尝试获取输出失败:

└─PS> Invoke-Command -Session $offsecsession -ScriptBlock {Receive-job 14}

报错:

Receive-Job: The command cannot find a job with the job ID 14. Verify the value of the Id parameter and then try the command again.

解决方案

1. 修复Case#1的核心问题

Get-DomainSID是PowerSploit模块专属命令,仅在server A(attacker-win10)上存在。Case#1中内层Invoke-Command是在server B(hacklab-dc)上执行命令,自然找不到该命令。正确逻辑是在server A上运行Get-DomainSID,让它直接与域控制器建立LDAP连接,同时解决双跳认证问题:

# 从Kali执行,先获取域凭据
$cred = Get-Credential hacklab.local\administrator

# 连接到server A,在会话中执行操作
Invoke-Command -Session $offsecsession -Credential $cred -ScriptBlock {
    # 手动导入PowerSploit的Recon模块(若未自动加载)
    Import-Module .\PowerSploit\Recon\Recon.psm1
    # 将凭据传递给Get-DomainSID,让server A用该凭据访问域控制器LDAP
    Get-DomainSID -Credential $Using:cred
}

2. 解决后台作业输出问题

后台作业是在server A的会话中创建的,单独调用Receive-Job无法跨会话识别作业ID,需在同一个脚本块内完成作业创建与结果接收:

# 从Kali执行,在同一脚本块中处理作业
Invoke-Command -Session $offsecsession -Credential $cred -ScriptBlock {
    # 若需远程到server B执行命令,在同一脚本块内接收结果
    $job = Invoke-Command -ComputerName hacklab-dc -Credential $Using:cred -ScriptBlock {hostname} -AsJob
    Receive-Job $job -Wait -AutoRemoveJob
}

注意:若目标是获取域SID,仍推荐直接在server A上运行Get-DomainSID并传入凭据,无需远程到server B。

3. 长期双跳解决方案:Kerberos约束委派

若需长期解决双跳认证问题,可在AD中配置server A的约束委派,允许它代表用户访问域控制器的LDAP服务。此操作需要域管理员权限,适合持久化场景。


内容的提问来源于stack exchange,提问作者catchabyte

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 03:17:05