• To request a ticket from windows

  • Convert Password to NTLM

  • capture NTLM hash after RCE

  • To connect to a SQL server use

  • Establishing of WinRM Session from Windows

  • using Kerberos from Linux

  • Downloading application

  • Enable RDP on a machine

  • Port Forwarding

  • ligolo-ng

  • chisel

  • Copy tool from one machine to another

  • Download file direct

  • Bypass execution policy for a specific script

  • query deleted items if you have access to the Recycle bin group

  • Mount a share locally Linux

  • Time calibration between host and the machine, sometimes things not gonna work

  • enable disabled account

  • Add SPN to account

  • Extract data using jq from bloodhound extracted data