postzerologon

lsadump::postzerologon is a procedure to update AD domain password and its local stored password remotely mimic netdom resetpwd. Experimental and best situation after reboot (cf. ZeroLogonarrow-up-right). It has the following command line arguments:

  • /target: the target domain controller FQDN

  • /account: the target domain controller's sAMAccountName.

circle-exclamation
mimikatz # lsadump::postzerologon /target:192.168.0.10 /account:dc$

Last updated