TL;DR
We start off with finding guest user SQL credentials from a PDF document and right off the bat we could able to perform SMB Relay attack and capture Service Account hash. Upon cracking the hash we could able to login into the system via WinRM p...