Note:
- ACL-Pwn relies on Sharphound's binary
- Netview has Share finders
- Password sprayin -> Attempt only 1 password! (CrackMapExec)
- If possible do Nessus scan
Missing:
- Nmap -> MS17-010
- MS17-010 exploit needs to be changed with proper exploitation e.g. run powershell netcat reverse shell
- Impacket for SMB Relaying
- Search shares for embedded passwords in scripts
- Responder
TODO:
- Ensure that the Pentesting host has CrackMapExec https://github.com/byt3bl33d3r/CrackMapExec