JF / 2026 Quick reference guides for the tools and techniques I use most — pentest commands, attack paths, and Windows internals.
Complete reference for NetExec: SMB, LDAP, WinRM, MSSQL, SSH, RDP and more. Enumeration, credential spraying, command execution with all four exec-methods, file transfer, BloodHound collection, NTDS dumping, and the modules that make nxc the standard tool for post-exploitation at scale.
The complete reference for bloodyAD: authentication methods, LAPS extraction (v1 and v2), gMSA password reading, RBCD, shadow credentials, DCSync, ADCS abuse, BadSuccessor (dMSA), object restoration, and every ACL abuse technique in between.
Request TGS tickets for accounts with SPNs and crack them offline. No elevated privileges required — just a valid domain user.