• Lateral movement

    Logon on another system with a NTLM hash Sce­nario: Then, use mimikatz to inject anoth­er user’s NTLM hash into the secret storage: Steal another user’s session Sce­nario: Then, with the use of mimikatz: privilege::debugsekurlsa::tickets /export This exports avail­able tick­ets into the work­ing direc­to­ry (suf­fix .kirbi). Then, choose one file/ticket from the cor­rect user and ser­vice. For…