OP 15 April, 2020 - 04:31 PM
Open powershell and paste the below cmd
LIKE THE POST
- Edit Local Host For SMB Relay (Redirect share to attacker IP)
- Probe For SMB Shares
- RedRabbit now checks for admin session and tries to query AD to check if Domain Admin.
- Password extraction (SAM/SYSTEM File, Credential Manager and Wireless Profiles)
- Encode Commands
- Run Encoded Commands
- Azure Feature has now been added!
LIKE THE POST