Methodology¶
Poison & Relay¶
- Run Responder
- Run ntlmrelayx
- Check for ARP Poisoning
- Check for RPC Coercion
Discovery and Audit¶
- Network Credential Capture (PCredz)
- AS-REP Roast
- SMB/RPC Enumeration
- Printer Enumeration & Credential Exposure
- PXE / SCCM Credential Exposure
- User Enumeration
- Password Spraying
- Bloodhound
- LDAP Checks
- SMB Data Hunting