This talk takes a closer look at open source offensive tooling used to perform lateral movement and post exploitation on Windows. We look under the hood how these tools work and shows how their behavior can be abused by an attacker in the environment.