Skip to main content
00:00/00:00
Lecture 15 of 100

crackmapexec - Command execution + Using Local Auth

Download Course (Free)

Course Content

0 / 100 completed
Section 1: Introduction1 videos

Introduction

5m
Section 2: Network Enumeration - Kali3 videos

More NMAP Enumeration

53m

NMAP SMB

1h 24m

NMAP

1h 4m
Section 3: Domain Enumeration - Kali5 videos

winapsearch

1h 17m

NMAP - Users

22m

LdapDomainDump

1h 1m

GetADUsers.py

33m

Enumerating With Enum4Linux

49m
Section 4: SwisArmy - CrackMapExec - Kali14 videos

CrackMapExec Intro

36m

CrackMapExec - Password Spraying

40m

CrackMapExec - ENUM 1.1

43m

CrackMapExec - ENUM 1.2

40m

CrackMapExec - Command Execution

45m

crackmapexec - Command execution + Using Local Auth

40mNow Playing

Dumping SAM

11m

Get PowerShell Reverse Shell

32m

pth-winexe and xfreerdp

31m

CrackMapExec CMEDB

25m

CrackMapExec Modules

1h 15m

Dumping LSA + PTH with CME

1h 15m

BADDD No AUDIO Getting Shells with CrackMapExec

26m

BloodHound Installation

1h 4m
Section 5: EvilWinRM + Local Privilege Escalation - Kali11 videos

Upload and Download

14m

Basic commands

23m

User, Group, and Network

3m

PowerView.ps1

24m

OS, AV, and Configuration

5m

Build SharpSploit - Enumeration

25m

Tools - Local Priv Esc

5m

Sherlock and Watson

17m

CVE-2019-1388

26m

SEImpersonate

20m

Unquoted Service Path

54m
Section 6: PowerShell Empire - The Ultimate Tool - Kali12 videos

Getting a Shell + CME + Powershell

38m

Basics and Installing

50m

Getting a shell + Evil-WinRM + Bat File

46m

Privilege Escalation 2 - Stager with NTSYSTEM

23m

Privilege Escalation 3

35m

Elevated with Empire - Mimikatz and pth

38m

Failed to get + dcsync + dcshadow - 3

17m

Pth + dcsync + dcshadow -1

1h 1m

Privilege Escalation 1 - ReverShell With Unquoted Path

1h 30m

Getting Shell with JenkinsAdmin

25m

Troubleshooting Empire Pth + dcsync + dcshadow - 2

1h 8m

Finally Getting Dcsync + Persistent

29m
Section 7: Metasploit - Kali16 videos

Intro

49m

Exploiting Ethernal Blue Metasploit

45m

Enumeration 2 - Arp, Tokens, Patches

52m

Enumeration 1 - User, Groups, Computers

53m

Exploit Suggestor

34m

Enumeration 3 - Shares, SMB, and More

48m

Back door add user

28m

Exploit Suggestor 2

44m

HashDump With Metasploit

26m

Lateral Movement - PTH With metasploit

1h 8m

DcSync With Metasploit

18m

Steal Token and Dumping All Hashes - Metasploit

27m

Lateral Movement To DC - Metasploit

49m

BACKDOOR METERPRETER SERVICE 2

8m

Golden Ticket With Metasploit

35m

BACKDOOR METERPRETER SERVICE 1

21m
Section 8: Domain Enumeration - RDP10 videos

Intro Domain Enumeration

3m

Domain Group Enumeration

32m

Domain ComputerServers Enumeration

25m

Domain User Enumeration

33m

PowerView - GPO and OU

38m

Active Directory Recon

23m

Domain Shares Enumeration

38m

BloodHound Installation

39m

PowerView - ACL

57m

BloodHound Basics

59m
Section 9: Lateral Movement - RDP8 videos

Intro to Lateral Movement - RDP

5m

SAM & LSA with MimiKatz

20m

Dumping SAM and SYSTEM For Offline Cracking

32m

PassTheHash with MimiKatz

54m

Session Hijack

8m

Pass the ticket with Rubeus

32m

Passing the ticket

47m

SMB Relay Attack

23m
Section 10: Domain Privilege Escalation - RDP10 videos

Intro - Domain Privilege Escalation

4m

ACL - GenericAll on Group

26m

Unconstrained delegation - Computer

39m

Priv Esc – DNSAdmins

57m

dcsync

44m

constrained Delegation - Computer

31m

ACL - GenericWrite on User

36m

Targeted Kerberoasting - AS-REPs - FINDING

29m

SET-SPN - Kerberoast

43m

Targeted Kerberoasting - AS-REPs - SET

32m
Section 11: Domain Persistence and Dominance - RDP10 videos

Intro Domain Persistence and Dominance - RDP

5m

DCShadow - Change Attribute

15m

DSRM

28m

DCShadow - SIDHistory

17m

Golden Ticket

31m

Silver Ticket

29m

DCShadow - hash

53m

AdminSDHolder - Adding Permission

30m

ZeroLogon -- Do This Last

18m

AdminSDHolder - Abusing Permission

24m