Skip to content

Foothold

username + password (or hash)

  • SMB / Admin Sharespsexec.py, smbexec.py, wmiexec.py, PsExec.exe PowerShell Invoke-WmiMethod
  • WinRM (PS Remoting)evil-winrm, Enter-PSSession, Invoke-Command
  • SSH -> ssh
  • DCOMInvoke-DCOM.ps1, MMC20.Application, ShellWindows, dcomexec.py
  • Scheduled Tasksschtasks.exe, at.exe
  • SCM (Services)sc.exe, PsExec technique
  • MSSQLmssqlclient.py, xp_cmdshell
  • LDAP / Kerberos (Domain)ldapsearch, Impacket Kerberos tools
  • VPN / Web Portals (OWA, etc.) → reuse creds for remote access
  • RDPxfreerdp, rdesktop, mstsc