Password hash dump and reuse
Local logon password dump
mimikatz.exe (need high integrity)
CME dump hashes remotely (with local admin creds/hash)
Impacket dump all user password from SAM
Domain password dump
Check where the credentials can be used
CME PtH for rev
NTLM PtH with local Administrator / AD user (not applicable to kerberos)
NTLM -> TGT Overpass the hash - gain tickets as specific users (other logoned local admin)
No SMB Winrm
Last updated
