logo

Account Hunting for Invoke-TokenManipulation

ID: f9c0f0da-80db-576e-b276-52c30361ea5c

STIX ID: report--f9c0f0da-80db-576e-b276-52c30361ea5c

Feed Name: TrustedSec blog

Threat Score
75/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

**Executive summary:** This article demonstrates a scalable offensive technique for harvesting domain admin Kerberos tokens and credentials by delivering in-memory PowerSploit/Mimikatz payloads via encoded PowerShell, executing them remotely with Metasploit psexec_command, and exfiltrating results to an SMB share; example commands, outputs, and helper scripts are provided to automate collection across many hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.