pub mod adcs;
pub mod gpo;
pub mod resolver;
pub mod sessions;
use std::error::Error;
use futures::future;
use crate::api::ADResults;
use crate::args::{CollectionMethod, Options};
use crate::modules::adcs::probe_enterpriseca_esc8;
use crate::modules::gpo::sysvol::collect_sysvol_targets;
pub async fn run_modules(
common_args: &Options,
ad: &mut ADResults
) -> Result<(), Box<dyn Error>> {
let cert_auth = common_args.uses_cert();
if cert_auth {
log::warn!("Certificate authentication in use: skipping SMB-based modules \
(sessions and GPO/SYSVOL) no SMB credentials available.");
}
if common_args.fqdn_resolver {
resolver::resolv::resolving_all_fqdn(
common_args.dns_tcp,
&common_args.name_server,
&mut ad.mappings.fqdn_ip,
&ad.computers,
)
.await;
}
if common_args.collection_method.does_sessions() && !cert_auth {
sessions::run(common_args, &ad.users, &mut ad.computers).await?;
}
if !matches!(common_args.collection_method, CollectionMethod::DCOnly)
&& !matches!(common_args.collection_method, CollectionMethod::LdapOnly)
&& !ad.enterprisecas.is_empty()
{
log::info!(
"Starting ESC8 web enrollment probe on {} CA(s)...",
ad.enterprisecas.len()
);
let hosts: Vec<String> = ad
.enterprisecas
.iter()
.map(|ca| ca.dns_host().to_string())
.collect();
let probes = future::join_all(hosts.into_iter().map(|host| {
tokio::task::spawn_blocking(move || probe_enterpriseca_esc8(&host))
}))
.await;
for (ca, probe) in ad.enterprisecas.iter_mut().zip(probes) {
match probe {
Ok(esc8) => ca.apply_esc8(esc8.http_enrollment_endpoints),
Err(join_err) => log::warn!(
"[adcs] ESC8 probe task for {} did not complete ({}), skipping",
ca.dns_host(),
join_err
),
}
}
}
if common_args.collection_method.does_gpo() && !cert_auth {
let computer_scope = gpo::sysvol::ComputerGpoScope::from_gpos(&ad.gpos);
let sysvol = match collect_sysvol_targets(common_args, &computer_scope).await {
Ok(v) => v,
Err(e) => {
log::warn!("[gpo] SYSVOL collection failed: {e}");
Vec::new()
}
};
if !sysvol.is_empty() {
log::info!(
"[gpo] mapping {} GPO(s) to GPOChanges / UserRights",
sysvol.len()
);
gpo::apply_gpo(
&mut ad.ous,
&mut ad.domains,
&ad.users,
&ad.groups,
&mut ad.computers,
&sysvol,
&ad.mappings.dn_sid,
);
}
}
Ok(())
}