logo

Check-LocalAdminHash & Exfiltrating All PowerShell History

ID: 992c9fb3-a9bc-5eaf-8e4a-3b09c57c44f6

STIX ID: report--992c9fb3-a9bc-5eaf-8e4a-3b09c57c44f6

Feed Name: Black Hills Infosec Blog

Date Published: 2019-06-05

Date Updated: 2026-04-27

Author: BHIS

...
...

The report introduces Check-LocalAdminHash, a PowerShell-based tool that uses pass-the-hash over WMI/SMB to identify systems where a local admin hash grants access and can optionally exfiltrate PSReadline console history files to a controlled web server. It details how the tool enumerates domain hosts (via PowerView), executes remote commands (via Invoke-TheHash’s WMI/SMB exec), and outlines web server setup considerations for secure file upload handling, emphasizing operational caution and potential extensibility.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.