Tags access mask3 acl3 autorun2 BloodHound2 channel binding token CBT1 cim2 coercion1 com hijack2 CreateService2 cve1 CVE-2025-330731 CVE-2025-549181 CVE-2025-587261 dcom2 DCSync1 DRSUAPI1 enumeration3 EPA1 esc81 Find-DCOMLocalAdminAccess.ps12 ghost task2 GhostSPN1 Impacket1 invoke-movementhound3 lateral movement4 ldap1 local ntlm authentication1 mhound3 MIC1 microsoft policy2 minimal rights3 movement hound3 network provider2 NTLM MIC bypass1 ntlm reflection1 ntlm relay1 ntlmrelayx1 NTLMSSP1 OpenService2 penetration testing1 privilege escalation1 quser2 qwinsta2 RACE3 rce4 rdp2 rdp shadow2 red team1 Remote Credential Guard (RCG)2 remote registry3 restricted admin mode2 rpc3 sc.exe2 scm2 scmanager2 scshell2 SDDL3 service creation2 service reconfiguration2 services2 signing1 smb1 ssh2 task scheduling3 uac2 UBR1 User Right Assignment (URA)2 winrm3 wmi2 wmiman2