3.3.1.1 - Domain Enumeration (Video Lab)
C:\AD\Tools\InviShell\RunWithRegistryNonAdmin.bat. C:\AD\Tools\Powerview.ps1Get-NetDomain
Get-DomainSID















Last updated
C:\AD\Tools\InviShell\RunWithRegistryNonAdmin.bat. C:\AD\Tools\Powerview.ps1Get-NetDomain
Get-DomainSID















Last updated
Get-Domain -Domain moneycorp.localGet-DomainPolicyData
Get-DomainPolicyData (Get-DomainPolicyData).systemaccess
(Get-DomainPolicyData -domain moneycorp.local).systemaccessGet-DomainControllerGet-DomainUser
Get-DomainUser -Identity student867Get-DomainUser | select samaccountname
Get-DomainUser -Properties samaccountname,logonCountGet-DomainUser -LDAPFilter "Description=*built*" | Select name,DescriptionGet-DomainGroup | select Name
Get-DomainGroup -Domain moneycorp.localGet-DomainComputer | select dnshostname,logonCountGet-DomainGroup | select Name
Get-DomainGroup -Domain AdministratorsGet-DomainGroup *admin* | select nameGet-DomainGroupMember -Identity "Domain Admins" -Recurse
Get-DomainGroup -UserName student867Get-NetLocalGroup -ComputerName dcorp-dcGet-NetLocalGroupMember -ComputerName dcorp-dc -GroupName AdministratorsGet-NetLoggedon -ComputerName dcorp-adminsrvInvoke-ShareFinder -Verbose