Expand description
WebClient / WebDAV service probe for RustHound-CE (issue #72 - IsWebClientRunning) https://github.com/g0h4n/IsWebClientRunning-rs
Runs AFTER the LDAP phase, from modules::run_modules, and only when the
collection method contacts machines (NOT DCOnly / LdapOnly).
SMB / CREATE \PIPE\DAV RPC SERVICE on IPC$ -> Computer.IsWebClientRunning
A host with the WebClient (WebDAV) service running can be coerced to authenticate over HTTP and relayed to AD CS web enrollment: it is an ESC8 relay candidate. Combined with the HttpEnrollmentEndpoints probe, this closes the two preconditions BloodHound needs to light up the coercion/ESC8 path.
Same SharpHound-style behaviour as the sessions and local-group modules:
445 pre-check (transport::smb::is_reachable), active-computer filter
(Computer::is_active), bounded concurrency, no machine contact under
DCOnly. Authentication reuses the SMB transport (password, pass the hash,
pass the ticket), so nothing new is needed there. The detection stops one
step earlier than LocalGroups: no DCE/RPC bind, no opnum, just the CREATE.
Modules§
- scanner
- The WebDAV detection itself: on an already-authenticated IPC$ session, CREATE
the WebClient named pipe and read the NTSTATUS. The pipe’s presence is the
whole signal; no DCE/RPC bind, no opnum, read-only (the CREATE only opens the
pipe). The connection + SESSION_SETUP live in
mod.rs(shared SMB transport, all three auth paths), exactly likesamr.rsoperates on a connected client for the LocalGroups module. - types
- What the WebClient scanner collects: the WebDAV pipe name, the NTSTATUS
values we branch on, the per-host
Outcome, and theclassifythat maps one onto the other. Kept free of any SMB types so it unit-tests with no Domain Controller (like LocalGroups-rs tests its NDR decoders).
Functions§
- run
- Entry point called by run_modules.