PowerView
Intro
Domain Enumeration
Import PowerView
Get current domain
Get object of another domain
Get domain SID for the current domain
Get the domain password policy
Users Groups and Computers Enumeration
Get Information of domain controller
Get information of users in the domain
Get list of all users
Get list of usernames, last logon and password last set
Get list of usernames and their groups
Get list of all properties for users in the current domain
Get descripton field from the user
Get computer information
Get computers with operating system "Server 2016"
Get list of all computer names and operating systems
List all groups of the domain
Get all the members of the group
Get the group membership of a user
List all the local groups on a machine (needs admin privs on non dc machines)
Get Member of all the local groups on a machine (needs admin privs on non dc machines)
Get actively logged users on a computer (needs local admin privs)
Get locally logged users on a computer (needs remote registry rights on the target)
Get the last logged users on a computer (needs admin rights and remote registary on the target)
Shares Enumeration
Find shared on hosts in the current domain
Find sensitive files on computers in the domain
Get all fileservers of the domain
GPO Enumeration
Get list of GPO's in the current domain
Get GPO's which uses restricteds groups or groups.xml for interesting users
Get users which are in a local group of a machine using GPO
Get machines where the given user is member of a specific group
Get OU's in a domain
Get machines that are part of an OU
Get GPO applied on an OU
ACL Enumeration
Get the ACL's associated with the specified object
Get the ACL's associated with the specified prefix to be used for search
Get the ACL's associated with the specified path
Search for interesting ACL's
Search of interesting ACL's for the current user
Domain Trust Enumeration
Get a list of all the domain trusts for the current domain
Get details about the forest
Get all domains in the forest
Get global catalogs for the current forest
Map trusts of a forest
User Hunting
Find all machines on the current domain where the current user has local admin access
Find local admins on all machines of the domain (needs administrator privs on non-dc machines)
Find Computers where a domain admin (or specified user/group) has session
Find computers where a domain admin is logged-in
Defense
Last updated
