daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

windows-enumeration.md (15891B)


      1 ---
      2 title: "Windows Enumeration"
      3 description: "Quick one-liners for post-exploitation enumeration on Windows systems."
      4 category: enumeration
      5 tags: ["enumeration", "privilege-escalation"]
      6 tools: ["PowerShell"]
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Enumeration/Windows Emumeration.md"
     10 ---
     11 # Windows Enumeration Cheat Sheet
     12 
     13 Quick one-liners for post-exploitation enumeration on Windows systems.
     14 
     15 ---
     16 
     17 ## System Information
     18 
     19 ```cmd
     20 :: Basic system info
     21 systeminfo
     22 hostname
     23 whoami /all
     24 
     25 :: OS version and architecture
     26 wmic os get caption,version,osarchitecture
     27 [Environment]::Is64BitOperatingSystem
     28 
     29 :: Installed patches/hotfixes
     30 wmic qfe list full
     31 wmic qfe get HotFixID,InstalledOn
     32 
     33 :: Environment variables
     34 set
     35 Get-ChildItem Env:
     36 
     37 :: Check if machine is domain-joined
     38 systeminfo | findstr /B "Domain"
     39 wmic computersystem get domain
     40 ```
     41 
     42 ---
     43 
     44 ## Current User Context
     45 
     46 ```cmd
     47 :: Who am I?
     48 whoami
     49 whoami /priv
     50 whoami /groups
     51 whoami /all
     52 
     53 :: Current user's home directory
     54 echo %USERPROFILE%
     55 $env:USERPROFILE
     56 
     57 :: Check for admin privileges
     58 net session 2>nul && echo Admin || echo Not Admin
     59 ```
     60 
     61 ---
     62 
     63 ## Users and Groups
     64 
     65 ```cmd
     66 :: List all local users
     67 net user
     68 Get-LocalUser
     69 
     70 :: Detailed user info
     71 net user <username>
     72 Get-LocalUser -Name <username> | Select-Object *
     73 
     74 :: List all local groups
     75 net localgroup
     76 Get-LocalGroup
     77 
     78 :: Members of specific groups
     79 net localgroup Administrators
     80 net localgroup "Remote Desktop Users"
     81 net localgroup "Backup Operators"
     82 Get-LocalGroupMember -Group "Administrators"
     83 
     84 :: Domain users (if domain-joined)
     85 net user /domain
     86 net group /domain
     87 net group "Domain Admins" /domain
     88 net group "Enterprise Admins" /domain
     89 ```
     90 
     91 ---
     92 
     93 ## Network Information
     94 
     95 ```cmd
     96 :: IP configuration
     97 ipconfig /all
     98 Get-NetIPConfiguration
     99 Get-NetIPAddress
    100 
    101 :: Routing table
    102 route print
    103 Get-NetRoute
    104 
    105 :: ARP cache
    106 arp -a
    107 Get-NetNeighbor
    108 
    109 :: Active connections
    110 netstat -ano
    111 netstat -anob
    112 Get-NetTCPConnection | Select-Object LocalAddress,LocalPort,RemoteAddress,RemotePort,State,OwningProcess
    113 
    114 :: Listening ports
    115 netstat -an | findstr LISTENING
    116 Get-NetTCPConnection -State Listen
    117 
    118 :: DNS cache
    119 ipconfig /displaydns
    120 
    121 :: Network shares
    122 net share
    123 Get-SmbShare
    124 
    125 :: Connected shares
    126 net use
    127 Get-SmbConnection
    128 
    129 :: Firewall status
    130 netsh advfirewall show allprofiles
    131 Get-NetFirewallProfile
    132 
    133 :: Firewall rules
    134 netsh advfirewall firewall show rule name=all
    135 Get-NetFirewallRule | Where-Object {$_.Enabled -eq 'True'}
    136 ```
    137 
    138 ---
    139 
    140 ## Password Hunting
    141 
    142 ### Common Credential Locations
    143 
    144 ```powershell
    145 # Search for files containing "password"
    146 findstr /si "password" *.txt *.ini *.config *.xml *.cfg
    147 findstr /spin "password" *.*
    148 
    149 # Search entire C: drive (slow but thorough)
    150 findstr /si /m "password" C:\*.txt C:\*.ini C:\*.config C:\*.xml
    151 
    152 # PowerShell recursive search
    153 Get-ChildItem -Path C:\ -Include *.txt,*.ini,*.config,*.xml,*.cfg -Recurse -ErrorAction SilentlyContinue | Select-String -Pattern "password" -ErrorAction SilentlyContinue
    154 
    155 # Search for common credential patterns
    156 findstr /si "pwd= pass= passwd= credentials" *.* 2>nul
    157 findstr /si "connectionstring" *.config *.xml 2>nul
    158 ```
    159 
    160 ### Unattended Installation Files
    161 
    162 ```cmd
    163 :: Classic unattend files (often contain plaintext/base64 passwords)
    164 type C:\unattend.xml
    165 type C:\Windows\Panther\unattend.xml
    166 type C:\Windows\Panther\Unattend\unattend.xml
    167 type C:\Windows\system32\sysprep.inf
    168 type C:\Windows\system32\sysprep\sysprep.xml
    169 
    170 :: Check all possible locations
    171 dir /s /b C:\*unattend*.xml 2>nul
    172 dir /s /b C:\*sysprep*.xml 2>nul
    173 dir /s /b C:\*sysprep*.inf 2>nul
    174 ```
    175 
    176 ### Web Config Files
    177 
    178 ```cmd
    179 :: IIS web.config files
    180 type C:\inetpub\wwwroot\web.config
    181 type C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\web.config
    182 
    183 :: Find all web.config files
    184 dir /s /b C:\web.config 2>nul
    185 dir /s /b C:\inetpub\*.config 2>nul
    186 
    187 :: Search for connection strings
    188 findstr /si "connectionString" C:\inetpub\*.config 2>nul
    189 ```
    190 
    191 ### Registry Stored Credentials
    192 
    193 ```cmd
    194 :: Autologon credentials
    195 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v DefaultUserName
    196 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v DefaultPassword
    197 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v AutoAdminLogon
    198 
    199 :: VNC passwords
    200 reg query "HKCU\Software\ORL\WinVNC3\Password" 2>nul
    201 reg query "HKLM\SOFTWARE\RealVNC\WinVNC4" /v Password 2>nul
    202 reg query "HKLM\SOFTWARE\RealVNC\vncserver" /v Password 2>nul
    203 
    204 :: Putty stored sessions
    205 reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" /s
    206 
    207 :: SNMP community strings
    208 reg query "HKLM\SYSTEM\CurrentControlSet\Services\SNMP\Parameters\ValidCommunities" 2>nul
    209 
    210 :: Search registry for password strings
    211 reg query HKLM /f password /t REG_SZ /s 2>nul
    212 reg query HKCU /f password /t REG_SZ /s 2>nul
    213 ```
    214 
    215 ### SAM and SYSTEM Files (requires SYSTEM privileges)
    216 
    217 ```cmd
    218 :: Check for backup SAM files
    219 dir /s /b C:\Windows\repair\SAM 2>nul
    220 dir /s /b C:\Windows\System32\config\RegBack\SAM 2>nul
    221 
    222 :: Shadow copy SAM extraction
    223 vssadmin list shadows
    224 copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SAM C:\temp\SAM
    225 copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SYSTEM C:\temp\SYSTEM
    226 ```
    227 
    228 ### Credential Manager
    229 
    230 ```cmd
    231 :: List saved credentials
    232 cmdkey /list
    233 vaultcmd /listcreds:"Windows Credentials" /all
    234 
    235 :: PowerShell credential manager enum
    236 Get-ChildItem -Path C:\Users\*\AppData\Local\Microsoft\Credentials -Recurse -Force -ErrorAction SilentlyContinue
    237 Get-ChildItem -Path C:\Users\*\AppData\Roaming\Microsoft\Credentials -Recurse -Force -ErrorAction SilentlyContinue
    238 ```
    239 
    240 ### DPAPI Master Keys
    241 
    242 ```powershell
    243 # DPAPI master key locations
    244 Get-ChildItem -Path C:\Users\*\AppData\Roaming\Microsoft\Protect -Recurse -Force -ErrorAction SilentlyContinue
    245 Get-ChildItem -Path C:\Users\*\AppData\Local\Microsoft\Protect -Recurse -Force -ErrorAction SilentlyContinue
    246 ```
    247 
    248 ### WiFi Passwords
    249 
    250 ```cmd
    251 :: List saved WiFi profiles
    252 netsh wlan show profiles
    253 
    254 :: Extract WiFi password (run for each profile)
    255 netsh wlan show profile name="<SSID>" key=clear
    256 
    257 :: One-liner to dump all WiFi passwords
    258 for /f "tokens=2 delims=:" %a in ('netsh wlan show profiles ^| findstr "Profile"') do @netsh wlan show profile name=%a key=clear | findstr "Key Content"
    259 ```
    260 
    261 ### Browser Credentials
    262 
    263 ```cmd
    264 :: Chrome saved passwords location
    265 dir "C:\Users\*\AppData\Local\Google\Chrome\User Data\Default\Login Data" 2>nul
    266 
    267 :: Firefox profiles
    268 dir "C:\Users\*\AppData\Roaming\Mozilla\Firefox\Profiles\*" 2>nul
    269 
    270 :: Edge passwords
    271 dir "C:\Users\*\AppData\Local\Microsoft\Edge\User Data\Default\Login Data" 2>nul
    272 ```
    273 
    274 ### Common Application Credentials
    275 
    276 ```cmd
    277 :: FileZilla
    278 type "C:\Users\*\AppData\Roaming\FileZilla\recentservers.xml" 2>nul
    279 type "C:\Users\*\AppData\Roaming\FileZilla\sitemanager.xml" 2>nul
    280 
    281 :: WinSCP
    282 reg query "HKCU\Software\Martin Prikryl\WinSCP 2\Sessions" /s 2>nul
    283 
    284 :: mRemoteNG (encrypted but crackable)
    285 type "C:\Users\*\AppData\Roaming\mRemoteNG\confCons.xml" 2>nul
    286 
    287 :: RDP connection history
    288 reg query "HKCU\Software\Microsoft\Terminal Server Client\Servers" /s
    289 
    290 :: AWS credentials
    291 type C:\Users\*\.aws\credentials 2>nul
    292 
    293 :: Azure CLI
    294 type C:\Users\*\.azure\accessTokens.json 2>nul
    295 ```
    296 
    297 ---
    298 
    299 ## PowerShell History
    300 
    301 ```powershell
    302 # Current user's PSReadLine history (most common)
    303 type $env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt
    304 Get-Content (Get-PSReadLineOption).HistorySavePath
    305 
    306 # All users' PowerShell history
    307 Get-ChildItem -Path C:\Users\*\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt -ErrorAction SilentlyContinue | ForEach-Object { Write-Host "`n=== $($_.FullName) ===" -ForegroundColor Yellow; Get-Content $_ }
    308 
    309 # Search history for interesting strings
    310 Select-String -Path C:\Users\*\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt -Pattern "password","credential","secret","key","token" -ErrorAction SilentlyContinue
    311 
    312 # Transcript logs (if enabled)
    313 Get-ChildItem -Path C:\Users\*\Documents\PowerShell_transcript* -ErrorAction SilentlyContinue
    314 dir /s /b C:\*transcript*.txt 2>nul
    315 ```
    316 
    317 ---
    318 
    319 ## Scheduled Tasks
    320 
    321 ```cmd
    322 :: List all scheduled tasks
    323 schtasks /query /fo LIST /v
    324 Get-ScheduledTask | Where-Object {$_.State -ne "Disabled"}
    325 
    326 :: Detailed task info
    327 schtasks /query /tn "<taskname>" /fo LIST /v
    328 Get-ScheduledTask -TaskName "<taskname>" | Get-ScheduledTaskInfo
    329 
    330 :: Find tasks running as SYSTEM or high-priv users
    331 schtasks /query /fo LIST /v | findstr /i "Task To Run: Run As User:"
    332 
    333 # PowerShell - tasks with actions
    334 Get-ScheduledTask | ForEach-Object { $task = $_; $_.Actions | ForEach-Object { [PSCustomObject]@{TaskName=$task.TaskName; Execute=$_.Execute; Arguments=$_.Arguments; RunAs=$task.Principal.UserId} }}
    335 ```
    336 
    337 ---
    338 
    339 ## Services
    340 
    341 ```cmd
    342 :: List all services
    343 sc query state= all
    344 Get-Service
    345 wmic service list brief
    346 
    347 :: Find services running as SYSTEM
    348 wmic service get name,startname | findstr /i "LocalSystem"
    349 
    350 :: Detailed service info
    351 sc qc <servicename>
    352 Get-Service -Name <servicename> | Select-Object *
    353 Get-WmiObject win32_service | Where-Object {$_.Name -eq "<servicename>"} | Select-Object *
    354 
    355 :: Find unquoted service paths
    356 wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "C:\Windows\\" | findstr /i /v """
    357 Get-WmiObject win32_service | Where-Object {$_.PathName -notlike "*`"*" -and $_.PathName -like "* *"} | Select-Object Name,PathName,StartMode
    358 
    359 :: Service binary permissions (check with icacls)
    360 for /f "tokens=2 delims='='" %a in ('wmic service list full ^| findstr /i "pathname" ^| findstr /i /v "system32"') do @echo %a >> c:\temp\services.txt
    361 ```
    362 
    363 ---
    364 
    365 ## Installed Software
    366 
    367 ```cmd
    368 :: Installed programs (32-bit and 64-bit)
    369 wmic product get name,version
    370 Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Select-Object DisplayName, DisplayVersion
    371 Get-ItemProperty HKLM:\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* | Select-Object DisplayName, DisplayVersion
    372 
    373 :: Programs in Program Files
    374 dir "C:\Program Files" /b
    375 dir "C:\Program Files (x86)" /b
    376 
    377 :: Recently installed programs
    378 Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Sort-Object InstallDate -Descending | Select-Object -First 20 DisplayName,InstallDate
    379 ```
    380 
    381 ---
    382 
    383 ## Processes
    384 
    385 ```cmd
    386 :: List all processes
    387 tasklist /v
    388 Get-Process | Select-Object ProcessName,Id,Path
    389 
    390 :: Processes with owners
    391 Get-WmiObject Win32_Process | Select-Object ProcessId,Name,@{N='Owner';E={$_.GetOwner().User}}
    392 
    393 :: Find processes running as SYSTEM
    394 tasklist /v | findstr /i "SYSTEM"
    395 
    396 :: Process command lines
    397 wmic process get processid,commandline
    398 Get-WmiObject Win32_Process | Select-Object ProcessId,CommandLine
    399 ```
    400 
    401 ---
    402 
    403 ## Privilege Escalation Vectors
    404 
    405 ### AlwaysInstallElevated
    406 
    407 ```cmd
    408 :: Check if AlwaysInstallElevated is set (both must be 1)
    409 reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated 2>nul
    410 reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated 2>nul
    411 ```
    412 
    413 ### Token Privileges
    414 
    415 ```powershell
    416 # Check for dangerous privileges
    417 whoami /priv | findstr /i "SeImpersonate SeAssignPrimaryToken SeBackup SeRestore SeDebug SeTakeOwnership SeLoadDriver"
    418 
    419 # Commonly exploitable privileges:
    420 # - SeImpersonatePrivilege -> Potato attacks
    421 # - SeAssignPrimaryTokenPrivilege -> Token manipulation
    422 # - SeBackupPrivilege -> Read any file
    423 # - SeRestorePrivilege -> Write any file
    424 # - SeDebugPrivilege -> Debug any process
    425 # - SeTakeOwnershipPrivilege -> Take ownership of objects
    426 # - SeLoadDriverPrivilege -> Load kernel drivers
    427 ```
    428 
    429 ### Modifiable Services
    430 
    431 ```powershell
    432 # Find services with weak permissions (requires accesschk from Sysinternals)
    433 accesschk.exe /accepteula -uwcqv "Authenticated Users" * 2>nul
    434 accesschk.exe /accepteula -uwcqv "Everyone" * 2>nul
    435 accesschk.exe /accepteula -uwcqv "Users" * 2>nul
    436 
    437 # Check specific service
    438 accesschk.exe /accepteula -ucqv <servicename>
    439 ```
    440 
    441 ### PATH Hijacking
    442 
    443 ```cmd
    444 :: Check PATH for writable directories
    445 echo %PATH%
    446 $env:PATH -split ';' | ForEach-Object { if (Test-Path $_) { Get-Acl $_ | Select-Object Path,AccessToString } }
    447 ```
    448 
    449 ### Startup Programs
    450 
    451 ```cmd
    452 :: Current user startup
    453 dir "C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup"
    454 reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Run"
    455 reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce"
    456 
    457 :: All users startup
    458 dir "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup"
    459 reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\Run"
    460 reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce"
    461 ```
    462 
    463 ---
    464 
    465 ## Antivirus and Security
    466 
    467 ```cmd
    468 :: Windows Defender status
    469 sc query WinDefend
    470 Get-MpComputerStatus
    471 
    472 :: Check for running AV processes
    473 tasklist | findstr /i "avast avg avira bitdefender eset kaspersky malware mcafee norton sophos symantec trend"
    474 
    475 :: AMSI bypass check
    476 [Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiInitFailed','NonPublic,Static').GetValue($null)
    477 
    478 :: AppLocker policy
    479 Get-AppLockerPolicy -Effective | Select-Object -ExpandProperty RuleCollections
    480 
    481 :: Check for Constrained Language Mode
    482 $ExecutionContext.SessionState.LanguageMode
    483 ```
    484 
    485 ---
    486 
    487 ## Files and Directories of Interest
    488 
    489 ```cmd
    490 :: User directories
    491 dir C:\Users /b
    492 Get-ChildItem C:\Users -Directory
    493 
    494 :: Desktop files (all users)
    495 dir C:\Users\*\Desktop\*.* /s 2>nul
    496 
    497 :: Documents (all users)  
    498 dir C:\Users\*\Documents\*.* /s 2>nul
    499 
    500 :: Downloads (all users)
    501 dir C:\Users\*\Downloads\*.* /s 2>nul
    502 
    503 :: Recently accessed files
    504 dir C:\Users\*\AppData\Roaming\Microsoft\Windows\Recent\*.lnk 2>nul
    505 
    506 :: Find interesting file extensions
    507 dir /s /b C:\*.kdbx 2>nul
    508 dir /s /b C:\*.pfx 2>nul
    509 dir /s /b C:\*.ppk 2>nul
    510 dir /s /b C:\*.pem 2>nul
    511 dir /s /b C:\*.key 2>nul
    512 dir /s /b C:\*password*.txt 2>nul
    513 dir /s /b C:\*cred*.txt 2>nul
    514 
    515 # PowerShell find interesting files
    516 Get-ChildItem -Path C:\ -Include *.kdbx,*.pfx,*.ppk,*.pem,*.key -Recurse -ErrorAction SilentlyContinue
    517 ```
    518 
    519 ---
    520 
    521 ## Quick Wins - Combined Commands
    522 
    523 ```powershell
    524 # Dump everything to a file
    525 systeminfo > enum.txt & whoami /all >> enum.txt & ipconfig /all >> enum.txt & netstat -ano >> enum.txt & net user >> enum.txt & net localgroup Administrators >> enum.txt
    526 
    527 # Quick credential hunt
    528 findstr /si "password=" *.xml *.ini *.txt *.config 2>nul
    529 
    530 # Check for low-hanging fruit
    531 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" 2>nul | findstr /i "DefaultUserName DefaultPassword"
    532 type C:\Users\*\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt 2>nul
    533 cmdkey /list
    534 ```
    535 
    536 ---
    537 
    538 ## Useful One-Liner Collection
    539 
    540 ```powershell
    541 # Find all writable directories in PATH
    542 $env:PATH -split ';' | Where-Object { $_ } | ForEach-Object { try { if ((Get-Acl $_).Access | Where-Object { $_.FileSystemRights -match 'Write|FullControl' -and $_.IdentityReference -match 'Users|Everyone|Authenticated' }) { $_ } } catch {} }
    543 
    544 # Find all files modified in last 7 days
    545 Get-ChildItem -Path C:\ -Recurse -ErrorAction SilentlyContinue | Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-7) -and !$_.PSIsContainer } | Select-Object FullName,LastWriteTime
    546 
    547 # Extract all IPs from files
    548 Select-String -Path C:\*.txt,C:\*.log -Pattern '\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b' -ErrorAction SilentlyContinue | Select-Object -Unique Matches
    549 
    550 # Find files containing specific strings
    551 Get-ChildItem -Path C:\Users -Recurse -Include *.txt,*.config,*.xml,*.ini -ErrorAction SilentlyContinue | Select-String -Pattern "password|credential|secret" -ErrorAction SilentlyContinue | Select-Object Path,LineNumber,Line
    552 
    553 # Enum all services with binary paths outside System32
    554 Get-WmiObject win32_service | Where-Object {$_.PathName -notmatch 'system32'} | Select-Object Name,PathName,State,StartMode
    555 ```
    556 
    557 ---
    558 
    559 _For automated enumeration, consider using tools like WinPEAS, PowerUp, Seatbelt, or SharpUp._