Fuzzing Windows RPC with RpcView

RpcView

From RPC to RCE - Workstation Takeover via RBCD and MS-RPChoose-Your-Own-Adventure

In the default configuration of Active Directory, it is possible to remotely take over Workstations (Windows 7/10/11) and possibly servers (if Desktop Experience is installed) when their WebClient service is running.

https://www.youtube.com/watch?v=BNzfmYwkioY

https://github.com/trailofbits/RpcInvestigator

RPC Investigator (RPCI) is a .NET/C# Windows Forms UI application that provides an advanced discovery and analysis interface to Windows RPC endpoints. The tool provides a visual interface around the existing core RPC capabilities of the NtApiDotNet platform, including:

Beyond these core features, RPCI provides additional capabilities: