← Back to catalog
Security

CATACOMB

File share and NTFS permissions review.

Answers "who has access to this share?" for every non-administrative SMB share — share permissions, NTFS permissions at the root, and a walk down each tree (-Depth, default 2) recording folders with explicit permissions or broken inheritance. Flags broad write (Everyone, Authenticated Users, Users or Domain Users allowed through both share and NTFS), direct user grants, orphaned SIDs, Deny entries, and unreadable folders. -Path reviews a single folder tree. Produces an HTML report plus a CSV of every access-control entry, ready for a customer access review. Read-only.

Quick Launch

Run CATACOMB

Run in an elevated PowerShell window. Downloads catacomb.ps1 from CursedTechnocrat/TechnicianToolkit and executes it.

Set-ExecutionPolicy Bypass -Scope Process -Force; $f="$(Get-Location)\catacomb.ps1"; irm https://raw.githubusercontent.com/CursedTechnocrat/TechnicianToolkit/main/catacomb.ps1 -OutFile $f; [IO.File]::WriteAllText($f,[IO.File]::ReadAllText($f,[Text.Encoding]::UTF8),[Text.UTF8Encoding]::new($true)); & $f
Category
Security
Identifier
CATACOMB
Tags
file-shares, ntfs, permissions, access-review