You already have one internal machine, we can directly interact with the target enviroment using it as a brigde.
ipconfig
route
arp
netstat
for the pwned machine.arp_scanner -r [ip]/mask
.ping_sweep
set session. Useful for scanning hosts outside of the network.pivoting
- Pivoting - Client Side Exploitingcmd.exe ifconfig /all
cmd.exe ifconfig /displaydns
. show DNS cache.cmd.exe netstat -ano
.