Shell Acess
Gaining Shell Access Overview
If we're able to dump the SAM in the SMB Relay attack then we can use those hashes to pop a shell on a machine.
We can use the actual password of the user if we cracked it or we can pass the hash instead.
Impacket-psexec
Impacket-wmiexec and Impacket-smbexec are also options that work the same way.
Impacket-smbexec gets picked up much less than the others
Last updated
Was this helpful?