#1
Open powershell and paste the below cmd


 
  • Edit Local Host For SMB Relay (Redirect share to attacker IP)
  • Probe For SMB Shares
  • RedRabbit now checks for admin session and tries to query AD to check if Domain Admin.
  • Password extraction (SAM/SYSTEM File, Credential Manager and Wireless Profiles)
  • Encode Commands
  • Run Encoded Commands
  • Azure Feature has now been added!



 


Hidden Content
You must register or login to view this content.




                                                                                                          LIKE THE POST
                                                                                           [Image: 68747470733a2f2f692e696d6775722e636f6d2f...512e676966]