Metasploit and owning Windows: LANMan Rainbow cracking

Previously I have gone through using metasploit to own your windows targets. In that article we looked at the password hashes stored locally on the target and using a rainbow cracking mechanism on those hashes. Great. But that does not help you if you are targeting domain credentials. Those hashes are not stored locally on workstations. But all is not lost. We can still try something, lets start by assuming you already have exploited your target..
