You already have one internal machine, we can directly interact with the target enviroment using it as a brigde.

ipconfig route arp netstat for the pwned machine.arp_scanner -r [ip]/mask .ping_sweep set session. Useful for scanning hosts outside of the network.pivoting - Pivoting - Client Side Exploitingcmd.exe ifconfig /allcmd.exe ifconfig /displaydns. show DNS cache.cmd.exe netstat -ano.