Check-LocalAdminHash & Exfiltrating All PowerShell History
ID: 992c9fb3-a9bc-5eaf-8e4a-3b09c57c44f6
STIX ID: report--992c9fb3-a9bc-5eaf-8e4a-3b09c57c44f6
Feed Name: Black Hills Infosec Blog
The report introduces Check-LocalAdminHash, a PowerShell-based tool that uses pass-the-hash over WMI/SMB to identify systems where a local admin hash grants access and can optionally exfiltrate PSReadline console history files to a controlled web server. It details how the tool enumerates domain hosts (via PowerView), executes remote commands (via Invoke-TheHash’s WMI/SMB exec), and outlines web server setup considerations for secure file upload handling, emphasizing operational caution and potential extensibility.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
