logo

Windows Domain Privilege Escalation : Implementing PSLoggedOn in Metasploit (+ a bonus history module)

ID: 6111b266-612c-5b70-9291-941d3bbf7d75

STIX ID: report--6111b266-612c-5b70-9291-941d3bbf7d75

Feed Name: SensePost Blog

Date Published: 2013-04-22

Date Updated: 2026-04-29

...
...

This write-up introduces a Metasploit post-exploitation module that uses the Windows NetSessionEnum API to quickly identify systems where a specified domain user (e.g., a Domain Admin) has active sessions, offering a lighter-weight alternative to tools like nmap smb-enum-sessions or PsLoggedOn. It includes step-by-step usage in MSF/meterpreter, notes a current limitation with x64 meterpreter, and provides a simple msfconsole history plugin; both tools are available on GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.