PowerView

Domain enum

circle-info

You can enumerate other domains in the Forest as well

Get-Domain
Get-Domain -Domain moneycorp.local
Get-DomainSID
circle-exclamation
Get-DomainPolicyData
Get-DomainController
Get-DomainController -Domain moneycorp.local

Users enum

Get-DomainUser | select samaccountname
Get-DomainUser -Identity student1
circle-exclamation
Get-DomainUser -Identity student1 -Properties *
Get-DomainUser -Properties samaccountname,logonCount,Description

Grep out a specific string

Computer enum

circle-info

Computer objects and Computers are different things

Check the logon count to find out

Group enum

circle-info

Need to specify the domain for Enterprise Admins and others to show

Domain Group Membership

circle-info

Helpful to rename the local machine Administrators for post enumeration

SID will be the same for domain Admin

ALSO having a target user in multiple groups helps with privileges to other objects down the road

Local Group Membership

circle-info

You can view local groups on Domain Controllers but need local Admin on other remote computers to list them

Shares, Sensitive files and FileServers

Last updated