daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit a66d99ebde37c48de68a58284fc18f74da282855
parent da4192ee6a431f30aedf931a43c31da65b88387d
Author: DAEMON <zer0sec.xp@icloud.com>
Date:   Sat, 19 Sep 2026 09:03:21 +0100

update

Diffstat:
Msrc/content/sheets/active-directory/powerview-powerup.md | 236++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++-
1 file changed, 235 insertions(+), 1 deletion(-)

diff --git a/src/content/sheets/active-directory/powerview-powerup.md b/src/content/sheets/active-directory/powerview-powerup.md @@ -6,7 +6,7 @@ subcategory: "Tooling & Recon" tags: [active-directory, powerview, powerup, powershell, enumeration, privilege-escalation] tools: [PowerView, PowerUp, PowerShell] difficulty: advanced -updated: "2026-08-29" +updated: "2026-09-19" source: "vault:ActiveDirectory/PowerView-PowerUp-Cheatsheet.md" --- # PowerView + PowerUp — Deep-Dive Cheat Sheet @@ -32,6 +32,8 @@ source: "vault:ActiveDirectory/PowerView-PowerUp-Cheatsheet.md" 4. [PowerView — Users, Computers, and Groups](#4-powerview--users-computers-and-groups) 5. [PowerView — Kerberos and Delegation](#5-powerview--kerberos-and-delegation) 6. [PowerView — ACL Analysis](#6-powerview--acl-analysis) + - [Fine-tune an ACL review](#66-fine-tune-an-acl-review) + - [Microsoft AD module: deleted objects and recovery](#67-microsoft-ad-module-deleted-objects-and-recovery) 7. [PowerView — GPOs, OUs, Sites, and Policy](#7-powerview--gpos-ous-sites-and-policy) 8. [PowerView — Sessions, Shares, Processes, and Local Admin](#8-powerview--sessions-shares-processes-and-local-admin) 9. [PowerView — Alternate Credentials and Impersonation](#9-powerview--alternate-credentials-and-impersonation) @@ -508,6 +510,238 @@ Find-DomainObjectPropertyOutlier -ClassName Group Find-DomainObjectPropertyOutlier -ClassName Computer ``` +### 6.6 Fine-tune an ACL review + +An ACL is a list of access-control entries (ACEs). Each ACE describes a permission rule for a principal, such as a user or group. `Get-DomainObjectAcl` normally reads the discretionary ACL (DACL), which contains allow and deny rules. Its output contains individual ACEs: several output rows can describe the permissions on one directory object. + +The examples below use synthetic ACL rows in memory. They explain scope and filtering without connecting to a domain or changing permissions. + +#### Read the pipeline in plain English + +A pipeline containing `Get-DomainObjectAcl ... | ? { $_.SecurityIdentifier -like '*-1111' }` has two separate jobs: the function retrieves ACL entries, then PowerShell keeps entries whose trustee SID ends in `-1111`. The filter after the pipe acts on returned rows; it does not narrow the directory query itself. [Source](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/where-object?view=powershell-7.6) + +- `|` passes output objects to the next command. +- `?` is shorthand for `Where-Object`. +- `$_` is the current row being tested. +- `SecurityIdentifier` is the trustee SID: the principal named in the permission rule. +- `ObjectDN` identifies the directory object whose permissions are being described. +- `ObjectSID`, when present, belongs to that directory object. It is a different field from the trustee SID; some directory objects have no SID. +- `-like '*-1111'` is a wildcard suffix comparison. `-eq` compares an exact value, while `-match` uses a regular expression. [Source](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_comparison_operators?view=powershell-7.6) + +The final component of a domain SID is its relative identifier (RID). A suffix such as `1111` does not uniquely identify a principal across domains. For a permission review, use the complete SID from the account record supplied for that review. Filtering only a user's SID also omits ACEs assigned to their groups. + +#### Choose the location and depth separately + +A distinguished name (DN) identifies a directory object. For example, `CN=Example User,OU=Training,DC=example,DC=test` places an object named `Example User` inside the `Training` organisational unit in `example.test`. `CN` means common name, `OU` means organisational unit, and `DC` means domain component. Each component needs its `=`; `DCtest` is not a correctly formed `DC=test` component. + +`-SearchBase` specifies where a query starts. `-SearchScope` specifies how much of that location it includes. [Source](https://learn.microsoft.com/en-us/windows/win32/ad/search-scope) + +| Scope | Includes the starting object | Includes immediate children | Includes deeper descendants | +|---|---|---|---| +| `Base` | Yes | No | No | +| `OneLevel` | No | Yes | No | +| `Subtree` | Yes | Yes | Yes | + +These scopes count directory objects, not ACE rows. A `Base` search can still yield many ACL entries for its one object. [Source](https://learn.microsoft.com/en-us/windows/win32/ad/search-scope) + +For this fictional directory layout, a search base of `OU=Training,DC=example,DC=test` has the following reach: + +```text +OU=Training Base and Subtree + CN=Example User OneLevel and Subtree + OU=Archive OneLevel and Subtree + CN=Archived User Subtree only +``` + +The Configuration naming context holds forest configuration rather than the ordinary domain user and computer inventory. Choose the naming context that contains the objects being reviewed; the default domain search is not a substitute for selecting Configuration explicitly. Do not assume a child domain's DN is the forest Configuration DN. + +#### Use full parameter names and inspect the loaded version + +In the bundled `Get-DomainObjectAcl`, both `-SearchBase` and `-SearchScope` exist, so `-Search` is ambiguous. Use the complete parameter names in notes. The following commands inspect local function metadata and help; they do not execute an LDAP query: + +```powershell +Get-Command Get-DomainObjectAcl -Syntax +(Get-Command Get-DomainObjectAcl).Parameters.Keys | Sort-Object +Get-Help Get-DomainObjectAcl -Full +``` + +The bundled source defines these controls: + +| Control | What it selects or changes | +|---|---| +| `-Identity` | Which directory object's ACL to read; it does not select the trustee inside an ACE | +| `-SearchBase` | Starting directory location | +| `-SearchScope` | Depth below that location; the bundled default is `Subtree` | +| `-LDAPFilter` | Directory objects matching LDAP attributes before their ACLs are processed | +| `-Server` | Domain controller used for the query | +| `-ResolveGUIDs` | Names for recognised schema/right GUIDs; it does not resolve trustee SIDs to account names | +| `-ResultPageSize` | Objects requested per LDAP page; it is not a total-result limit | +| `Where-Object` | Returned ACE rows that satisfy a local condition | +| `Select-Object` | Output fields to retain, or rows to display with `-First` | + +`-LDAPFilter` takes LDAP expressions such as `(name=Example User)`. A PowerShell condition such as `{ $_.SecurityIdentifier -eq $PrincipalSid }` belongs in `Where-Object`. `SecurityIdentifier` is a field produced when PowerView parses an ACE, not a normal directory attribute that this LDAP filter can use to select trustees. [Source](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-powershell-1.0/ff730967(v=technet.10)) [Source](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/where-object?view=powershell-7.6) + +The bundled ACL reader has no `-Properties` parameter. Select its output columns with `Select-Object`. Its `-RightsFilter` accepts only `All`, `ResetPassword`, and `WriteMembers`; these are implementation-specific GUID filters, not arbitrary permission names. Leave that option unset when reviewing the complete DACL. Check the loaded function before borrowing flags from another fork. + +#### Practise filtering without a domain connection + +This dataset is invented. The repeated `1200` suffix in two different domain SIDs demonstrates why an exact SID comparison matters. The allow and deny rows are separate rules, not a computed effective-access result. + +```powershell +$PrincipalSid = 'S-1-5-21-100-200-300-1200' + +$SampleAces = @( + [pscustomobject]@{ + ObjectDN = 'CN=Example Group,OU=Training,DC=example,DC=test' + SecurityIdentifier = $PrincipalSid + ActiveDirectoryRights = 'ReadProperty' + AceType = 'AccessAllowed' + IsInherited = $false + } + [pscustomobject]@{ + ObjectDN = 'CN=Example User,OU=Training,DC=example,DC=test' + SecurityIdentifier = $PrincipalSid + ActiveDirectoryRights = 'ReadProperty' + AceType = 'AccessAllowed' + IsInherited = $true + } + [pscustomobject]@{ + ObjectDN = 'CN=Example User,OU=Training,DC=example,DC=test' + SecurityIdentifier = $PrincipalSid + ActiveDirectoryRights = 'ReadProperty' + AceType = 'AccessDenied' + IsInherited = $false + } + [pscustomobject]@{ + ObjectDN = 'CN=Example Group,OU=Training,DC=example,DC=test' + SecurityIdentifier = 'S-1-5-21-400-500-600-1200' + ActiveDirectoryRights = 'ListChildren' + AceType = 'AccessAllowed' + IsInherited = $false + } +) + +# A suffix comparison includes both fictional domains: four rows. +$SampleAces | + Where-Object { $_.SecurityIdentifier -like '*-1200' } + +# An exact comparison keeps one principal: three rows. +$PrincipalAces = @( + $SampleAces | + Where-Object { [string]$_.SecurityIdentifier -eq $PrincipalSid } +) +$PrincipalAces.Count + +# Combine conditions to review that principal on one known object. +$ReviewedObjectDN = 'CN=Example User,OU=Training,DC=example,DC=test' +$PrincipalAces | + Where-Object { $_.ObjectDN -eq $ReviewedObjectDN } | + Format-List ObjectDN,SecurityIdentifier,ActiveDirectoryRights,AceType,IsInherited + +# Separate explicit entries for comparison; inherited entries still matter. +$PrincipalAces | + Where-Object { $_.IsInherited -eq $false } | + Format-Table ObjectDN,AceType,IsInherited -Wrap +``` + +Keep `$PrincipalAces` as structured objects so you can inspect the same dataset repeatedly. Put `Format-Table` or `Format-List` at the end of a display pipeline; assigning formatted output back to the variable loses the original row structure. `Format-List` is useful when a long DN is cut off in a narrow terminal. + +#### Interpret empty results and permission rows carefully + +An empty filtered result means no returned row matched that condition. It does not prove the principal has no access. Review the unfiltered data already collected, the chosen naming context, the full trustee SID, and any collection errors. Missing permission data and an empty DACL are different findings. + +- `IsInherited = False` identifies an explicit ACE. It does not mean the entry is suspicious; inherited ACEs can also grant or deny access. +- Inspect allow and deny entries together. Removing deny rows for display does not remove their effect. +- Effective access depends on group memberships, ACE scope, inheritance, object-specific restrictions, and the access check. A matching user SID alone is incomplete. +- In this bundled implementation, object-specific GUID fields come from raw ACEs and can appear as `ObjectAceType` and `InheritedObjectAceType`. Other wrappers can expose different names. Inspect an existing row with `Get-Member` and `Format-List *` before selecting fields. +- CSV imports contain text values. For a CSV export of these Boolean fields, compare `IsInherited` with `'False'` or `'True'`; `[bool]'False'` is true because it is a non-empty string. The synthetic dataset above uses actual Boolean values. [Source](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/import-csv?view=powershell-7.6) + +### 6.7 Microsoft AD module: deleted objects and recovery + +`Get-ADObject`, `Restore-ADObject`, and `Get-ADUser` belong to Microsoft's `ActiveDirectory` PowerShell module. They are separate from PowerView's `Get-DomainObject` and `Get-DomainUser`. Loading `PowerView.ps1` does not install these Microsoft cmdlets. This section explains the supplied transcript and administrative recovery checks; it does not execute a restore. [Source](https://learn.microsoft.com/en-us/powershell/module/activedirectory/?view=windowsserver2025-ps) + +#### Check which commands are available + +Inspect the current PowerShell session's command metadata and help before borrowing parameters from a different module. These commands do not query or modify directory objects: + +```powershell +Get-Command Get-ADObject,Restore-ADObject,Get-ADUser -ErrorAction SilentlyContinue | + Select-Object Name,Source,CommandType + +Get-Help Get-ADObject -Full +Get-Help Restore-ADObject -Full +Get-Help Get-ADUser -Full +``` + +The expected module source for these cmdlets is `ActiveDirectory`. If the commands are unavailable, use a management host where that module is installed; an Evil-WinRM prompt alone does not establish that the module is available. [Source](https://learn.microsoft.com/en-us/powershell/module/activedirectory/?view=windowsserver2025-ps) + +#### Understand the deleted-object query + +The supplied command is a read-only directory query: + +```powershell +Get-ADObject -ldapfilter "(&(isDeleted=TRUE))" -IncludeDeletedObjects +``` + +`Get-ADObject` retrieves directory objects of different classes, including users, groups, and organisational units. `-LDAPFilter` specifies which objects match. Here, `isDeleted=TRUE` asks for objects marked as deleted. `-IncludeDeletedObjects` allows deleted objects to be returned, which an ordinary query excludes. That switch alone does not mean “only deleted objects”; the filter supplies that restriction. [Source](https://learn.microsoft.com/en-us/powershell/module/activedirectory/get-adobject?view=windowsserver2025-ps) + +The filter has one condition inside an AND group: `(&(isDeleted=TRUE))`. With only one condition, the outer AND is redundant; `(isDeleted=TRUE)` expresses the same test. An AND group becomes useful when combining conditions. LDAP filter text is different from a PowerShell `Where-Object` script block. [Source](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-powershell-1.0/ff730967(v=technet.10)) + +A match is a directory record, not a file recovered from a user's desktop. Deleted records can retain identifiers and recovery metadata. A visible deleted record is not proof that a complete recovery remains possible: the deletion lifecycle and Recycle Bin configuration matter. [Source](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/adac/active-directory-recycle-bin) [Source](https://learn.microsoft.com/en-us/training/modules/troubleshoot-active-directory/2-recover-objects-from-active-directory-recycle-bin) + +#### Understand the recovery metadata + +`Get-ADObject` returns a default property set. Additional attributes must be requested with `-Properties`; selecting a field for display does not fetch it from the server. For an administrative recovery review, distinguish the record's identity from its previous location. [Source](https://learn.microsoft.com/en-us/powershell/module/activedirectory/get-adobject?view=windowsserver2025-ps) + +| Field | Meaning | +|---|---| +| `ObjectGUID` | Unique object identifier; the GUID form of `-Identity` refers to this value | +| `DistinguishedName` | Current directory location, which changes when an object is deleted or restored | +| `isDeleted` | Whether the record is marked as deleted | +| `isRecycled` | Whether it has entered the recycled state; this is different from an intact recoverable deleted object | +| `lastKnownParent` | DN of the object's previous parent container or OU | +| `msDS-LastKnownRDN` | Original relative distinguished name, the object's name within its parent | + +`lastKnownParent` and `msDS-LastKnownRDN` are the default destination and name inputs used by the restore cmdlet when no replacement is specified. Recycled objects have already lost many attributes, so the presence of a GUID alone does not establish full recoverability. [Source](https://learn.microsoft.com/en-us/powershell/module/activedirectory/restore-adobject?view=windowsserver2025-ps) [Source](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adls/22c77623-1d54-459a-b283-0c0587d651c9) [Source](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adls/6c02256f-ae04-4104-9296-6f48d9aeb692) [Source](https://learn.microsoft.com/en-us/training/modules/troubleshoot-active-directory/2-recover-objects-from-active-directory-recycle-bin) + +#### Interpret the supplied restore command + +The transcript contains `Restore-ADObject -Identity "c1f1f0fe-df9c-494c-bf05-0679e181b358"`. This requests restoration of the deleted directory object with that `ObjectGUID`. The GUID is an identifier, not a password, SID, or value generated for each attempt. `Restore-ADObject` changes directory state; it is not another search command. [Source](https://learn.microsoft.com/en-us/powershell/module/activedirectory/restore-adobject?view=windowsserver2025-ps) + +The command does not name `cert_admin`. The link between that account and the restore request comes from the matching `ObjectGUID` in the later user output. The supplied excerpt does not show the deleted-object query's results, so it does not show how that GUID was originally selected. [Source](https://learn.microsoft.com/en-us/powershell/module/activedirectory/restore-adobject?view=windowsserver2025-ps) [Source](https://learn.microsoft.com/en-us/powershell/module/activedirectory/get-aduser?view=windowsserver2025-ps) + +No object output after `Restore-ADObject` is normal: the cmdlet returns no object by default. Its documented `-PassThru` option returns the restored object. Silence alone is not a substitute for checking errors and verifying the resulting record. [Source](https://learn.microsoft.com/en-us/powershell/module/activedirectory/restore-adobject?view=windowsserver2025-ps) + +For an administrative recovery, establish the intended identity, recoverability, and destination before making a change. Restoring an account can restore security-relevant state and access. The Recycle Bin preserves attributes for objects deleted after it was enabled; enabling it later does not recover attributes from earlier deletions. Recovery windows depend on the directory configuration, so do not assume every deleted record can be restored indefinitely. [Source](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/adac/active-directory-recycle-bin) [Source](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/adac/advanced-ad-ds-management-using-active-directory-administrative-center--level-200-) + +#### Read the user verification output + +The final supplied command reads the current user record: + +```powershell +Get-ADUser -Identity cert_admin +``` + +Here, `cert_admin` is a `sAMAccountName` accepted by `-Identity`. This cmdlet also accepts a user object's distinguished name, GUID, or SID. It retrieves information; it does not enable the account, reset its password, authenticate as it, or grant permissions. [Source](https://learn.microsoft.com/en-us/powershell/module/activedirectory/get-aduser?view=windowsserver2025-ps) + +| Supplied field | Interpretation | +|---|---| +| `DistinguishedName : CN=cert_admin,OU=ADCS,DC=tombwatcher,DC=htb` | The returned user is currently under the `ADCS` OU in `tombwatcher.htb` | +| `ObjectGUID : c1f1f0fe-df9c-494c-bf05-0679e181b358` | Matches the identifier in the supplied restore request | +| `SamAccountName : cert_admin` | The account name used by the lookup | +| `ObjectClass : user` | This record is a user object | +| `Enabled : True` | The returned account state is enabled; this is not a successful sign-in test | +| `SID : S-1-5-21-1392491010-1358638721-2126982587-1110` | The user's security identifier, distinct from its GUID | +| Blank `UserPrincipalName` | No UPN value is displayed; the `sAMAccountName` lookup still returned the user | + +The matching GUID is the useful identity check in this transcript. The account name `cert_admin` and OU name `ADCS` alone do not establish certificate authority privileges or any other effective access. The default `Get-ADUser` output is a limited property set, not a permissions report. [Source](https://learn.microsoft.com/en-us/powershell/module/activedirectory/get-aduser?view=windowsserver2025-ps) + +#### Avoid misleading conclusions + +An empty deleted-object search means the query returned no visible matches in its scope. Check collection errors and the chosen server and search base before treating that as proof that nothing was deleted. `-IncludeDeletedObjects` neither expands the search to every domain nor bypasses directory access controls. [Source](https://learn.microsoft.com/en-us/powershell/module/activedirectory/get-adobject?view=windowsserver2025-ps) + +A restore and a later lookup are separate operations. A lookup by account name can identify a different object if that name was reused; compare the object GUID with the reviewed record. Review account state and intended access after recovery rather than assuming the original access is still appropriate. [Source](https://learn.microsoft.com/en-us/powershell/module/activedirectory/restore-adobject?view=windowsserver2025-ps) [Source](https://learn.microsoft.com/en-us/powershell/module/activedirectory/get-aduser?view=windowsserver2025-ps) + --- ## 7. PowerView — GPOs, OUs, Sites, and Policy