Post Exploitation
Stabilization and Persistence
evil-winrm -u adot8 -p password1 -i 10.200.101.150
OR RDP
/drive creates a shared drive between you and the machine. Access in file explorer with \\tsclient
Mimikatz
Run Mimikatz as Administrator
Use crackstation to crack Thomas's and Arheo5's NTLM hashes
Pass Administrators hash in evil-winrm
Last updated
Was this helpful?