Penelope is presented as a full post-exploitation framework that managed a complete Windows and Linux engagement, from initial reverse shell access on a Windows Server 2019 Domain Controller to credential dumping, Active Directory abuse, Kerberoasting, and cleanup. The walkthrough also showed pivoting with Ligolo-ng into a hidden subnet, compromising a Linux host, and using Penelope’s built-in listeners, port forwarding, file transfer, and HTTP serving features to control the operation end to end. #Penelope #Ligolo-ng #Meterpreter #Mimikatz #Rubeus #LinPEAS #LSE #LinuxExploitSuggester #winPEAS #GodPotato #PrintSpoofer
Keypoints
- Penelope handled reverse shells, session management, and shell upgrades across Windows and Linux.
- The framework staged tools for privilege escalation, credential dumping, and Active Directory reconnaissance.
- GodPotato was used to elevate to SYSTEM and change the administrator password.
- Rubeus Kerberoasted the service account raj and saved the crackable ticket hash.
- Ligolo-ng enabled pivoting into a hidden subnet, leading to compromise of an Ubuntu host.
Read More: https://www.hackingarticles.in/penelope-a-modern-alternative-to-netcat-for-red-teamers/