impacket-tstool uses MSRPC to remotely enumerate, control, disconnect, log off, reboot, and even hijack Windows Terminal Services sessions without dropping a binary or opening an RDP client. It also supports passwordless authentication methods like Pass-the-Hash, Pass-the-Key, and Pass-the-Ticket, making it a stealthy post-exploitation tool against systems such as the DC1 domain controller in ignite.local. #impacket-tstool #TerminalServices #DC1 #ignite.local #tscon #qwinsta
Keypoints
- impacket-tstool remotely ΡΠΏΡΠ°Π²Π»ΡΠ΅Ρ Windows Terminal Services through MSRPC.
- qwinsta and tasklist reveal active sessions and running processes on the target.
- taskkill, tsdiscon, logoff, and shutdown provide remote session and host control.
- tscon can hijack an active RDP session when the operator has sufficient privileges.
- Pass-the-Hash, Pass-the-Key, and Pass-the-Ticket enable passwordless access to the domain controller.
Read More: https://www.hackingarticles.in/impacket-for-pentester-tstool/