Modifying Remote Protocol Security Descriptors
Modifying the Descriptors Manually From the DC - Giving a User Full Control Over the WMI Namespace
Step 1 - In Component Services, Change the DCOM Permissions of the Computer


Step 2 - Modify the WMI Namespace Settings in Computer Management


Step 3 - Check the Access of the Non-Admin User to the DC
Giving a User Access to WMI From Powershell
With Set-RemoteWMI.ps1 (from Nishang)
To Remove the Modified Descriptor
Change the Powershell Remoting Descriptors
With Set-RemotePSRemoting.ps1 (from Nishang)
Then Execute Commands Remotely on the DC
Changing the Remote Registry to Add a Backdoor and Retrieve Hashes
Step 1 - With Add-RemoteRegBackdoor.ps1
Step 2 - In a New Window as the User, Use RemoteHashRetrieval.ps1
Step 3 - Exploit
Last updated