- BloodHound
- Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
- snmpwalk
- hydra - bruteforce logins
- slow to avoid timeouts, so you want a smaller password lists
- enum4linux - Null session enumeration
- CrackMapExec - grab plaintext passwords out of memory
- Responder - DNS spoofing tool
- Bettercap - ARP spoofing
- SMB (server message block) for inter-node communication
- 139, 445 ports
- domain controllers 53 (DNS), 88 (kerberos), 389 (ldap), RDP (3389)
- Kerberoasting
- Null Session - Anonymous
- connect with empty username and password
- NTLM
- checks password hash
- https://en.wikipedia.org/wiki/NT_LAN_Manager
- Getting System is higher than admin
- psexec - https://ss64.com/nt/psexec.html