PrivExchange
Exchange your privileges for Domain Admin privs by abusing Exchange
Install / Use
/learn @dirkjanm/PrivExchangeREADME
PrivExchange
POC tools accompanying the blog Abusing Exchange: One API call away from Domain Admin.
Requirements
These tools require impacket. You can install it from pip with pip install impacket, but it is recommended to use the latest version from GitHub.
privexchange.py
This tool simply logs in on Exchange Web Services to subscribe to push notifications. This will make Exchange connect back to you and authenticate as system.
httpattack.py
Attack module that can be used with ntlmrelayx.py to perform the attack without credentials. To get it working:
- Modify the attacker URL in
httpattack.pyto point to the attacker's server where ntlmrelayx will run - Clone impacket from GitHub
git clone https://github.com/SecureAuthCorp/impacket - Copy this file into the
/impacket/impacket/examples/ntlmrelayx/attacks/directory. cd impacket- Install the modified version of impacket with
pip install . --upgradeorpip install -e .
Related Skills
node-connect
349.0kDiagnose OpenClaw node connection and pairing failures for Android, iOS, and macOS companion apps
frontend-design
109.4kCreate distinctive, production-grade frontend interfaces with high design quality. Use this skill when the user asks to build web components, pages, or applications. Generates creative, polished code that avoids generic AI aesthetics.
openai-whisper-api
349.0kTranscribe audio via OpenAI Audio Transcriptions API (Whisper).
qqbot-media
349.0kQQBot 富媒体收发能力。使用 <qqmedia> 标签,系统根据文件扩展名自动识别类型(图片/语音/视频/文件)。
