Windows Domain Privilege Escalation : Implementing PSLoggedOn in Metasploit (+ a bonus history module)
ID: 6111b266-612c-5b70-9291-941d3bbf7d75
STIX ID: report--6111b266-612c-5b70-9291-941d3bbf7d75
Feed Name: SensePost Blog
This write-up introduces a Metasploit post-exploitation module that uses the Windows NetSessionEnum API to quickly identify systems where a specified domain user (e.g., a Domain Admin) has active sessions, offering a lighter-weight alternative to tools like nmap smb-enum-sessions or PsLoggedOn. It includes step-by-step usage in MSF/meterpreter, notes a current limitation with x64 meterpreter, and provides a simple msfconsole history plugin; both tools are available on GitHub.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
