跳转至

SPN发现

cmd

>setspn -T 域名 -Q */*

image

Powershell

https://github.com/PyroTek3/PowerShell-AD-Recon

image

Powerview
>Get-NetComputer -SPN termsrv*
>Get-NetUser -SPN

image

>import module GetUserSPNs.ps1

Empire

>usemodule situational_awareness/network/get_spn