CrackMapExec
CrackMapExec
CrackMapExec (a.k.a CME) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks. Built with stealth in mind, CME follows the concept of "Living off the Land": abusing built-in Active Directory features/protocols to achieve it's functionality and allowing it to evade most endpoint protection/IDS/IPS solutions.
As CME is already pretty well documented and explained by byt3bl33d3r himself, this article will serve the purpose of command reference.
> crackmapexec smb 10.10.10.52 -u demonas -p 'M374L_P@ssW0rd!'
SMB 10.10.10.52 445 EMPEROR [*] Windows Server 2008 R2 Standard 7601 Service Pack 1 x64 (name:EMPEROR) (domain:KVLT) (signing:True) (SMBv1:True)
SMB 10.10.10.52 445 EMPEROR [+] KVLT\demonas:M374L_P@ssW0rd!> crackmapexec smb 10.10.10.1/24 -u demonas -p 'M374L_P@ssW0rd!' --pass-pol
SMB 10.10.10.52 445 EMPEROR [*] Windows Server 2008 R2 Standard 7601 Service Pack 1 x64 (name:EMPEROR) (domain:KVLT) (signing:True) (SMBv1:True)
SMB 10.10.10.40 445 FREEZING-MOON [*] Windows 7 Professional 7601 Service Pack 1 x64 (name:FREEZING-MOON) (domain:FREEZING-MOON) (signing:False) (SMBv1:True)
SMB 10.10.10.59 445 MAYHEM [*] Windows Server 2016 Standard 14393 x64 (name:MAYHEM) (domain:MAYHEM) (signing:False) (SMBv1:True)
SMB 10.10.10.52 445 EMPEROR [+] KVLT\demonas:M374L_P@ssW0rd!
SMB 10.10.10.40 445 FREEZING-MOON [+] FREEZING-MOON\demonas:M374L_P@ssW0rd!
SMB 10.10.10.59 445 MAYHEM [-] MAYHEM\demonas:M374L_P@ssW0rd! STATUS_LOGON_FAILURE
SMB 10.10.10.52 445 EMPEROR [+] Dumping password info for domain: KVLT
SMB 10.10.10.52 445 EMPEROR Minimum password length: 7
SMB 10.10.10.52 445 EMPEROR Password history length: 24
SMB 10.10.10.52 445 EMPEROR Maximum password age:
SMB 10.10.10.52 445 EMPEROR
SMB 10.10.10.52 445 EMPEROR Password Complexity Flags: 000001
SMB 10.10.10.52 445 EMPEROR Domain Refuse Password Change: 0
SMB 10.10.10.52 445 EMPEROR Domain Password Store Cleartext: 0
SMB 10.10.10.52 445 EMPEROR Domain Password Lockout Admins: 0
SMB 10.10.10.52 445 EMPEROR Domain Password No Clear Change: 0
SMB 10.10.10.52 445 EMPEROR Domain Password No Anon Change: 0
SMB 10.10.10.52 445 EMPEROR Domain Password Complex: 1
SMB 10.10.10.52 445 EMPEROR
SMB 10.10.10.52 445 EMPEROR Minimum password age:
SMB 10.10.10.52 445 EMPEROR Reset Account Lockout Counter: 30 minutes
SMB 10.10.10.52 445 EMPEROR Locked Account Duration: 30 minutes
SMB 10.10.10.52 445 EMPEROR Account Lockout Threshold: None
SMB 10.10.10.52 445 EMPEROR Forced Log off Time: Not Set
SMB 10.10.10.3 445 FUNERAL-FOG [*] Unix (name:FUNERAL-FOG) (domain:FUNERAL-FOG) (signing:False) (SMBv1:True)
SMB 10.10.10.3 445 FUNERAL-FOG [-] FUNERAL-FOG\demonas:M374L_P@ssW0rd! STATUS_LOGON_FAILUREPass the Hash
CME with user hash against our subnet:
Shares Recon
Mimikatz
Executing commands as Domain Admin to DC (creating a new user and adding him to Domain Admins group):
Last updated