RT @filip_dragovic
One of paths to DA in current engagement.
Run gowitneess and take screenshot of servers in scope.
Identified Cisco Unified Call Manager on one of the servers. Used SeeYouCM Thief to enumerate AD users.
Used kerbute to spray password and get one hit. 1/n