User Hunting

Find local admin access on machines for current user

Find-LocalAdminAccess -Verbose

We can also use the scripts Find-PSRemotingLocalAdminAccess.ps1 and Find-WMILocalAdminAccess.ps1

. .\Find-PSRemotingLocalAdminAccess.ps1
Find-PSRemotingLocalAdminAccess.ps1

Find domain admin sessions (SessionHunter)

We can dump their creds if we have local admin

Invoke-SessionHunter -FailSafe

OPSEC OPTION

Invoke-SessionHunter -NoPortScan -Targets C:\AD\Tools\servers.txt

PowerView option

Find-DomainUserLocation -Verbose
Find-DomainUserLocation -CheckAccess
Find-DomainUserLocation -UserGroupIdentity "RDPUsers"

Server 2019 and onwards, local administrator privileges are required to list sessions

Last updated