
ورقة غش تحتوي على طرق التعداد والهجوم الشائعة لـ Windows Active Directory.
تحتوي ورقة الغش هذه على طرق التعداد والهجوم الشائعة لنظام Windows Active Directory.
ℹ️ تم إنشاء هذا المستودع بواسطة Nikos Katsiopis و Nikos Vourdas.
هذه ورقة الغش مستوحاة من مستودع PayloadAllTheThings.

Powerview v.3.0
Powerview Wiki
الحصول على النطاق الحالي: Get-Domain
تعداد النطاقات الأخرى: Get-Domain -Domain <DomainName>
الحصول على SID النطاق: Get-DomainSID
الحصول على سياسة النطاق: ```powershell Get-DomainPolicy
#Will show us the policy configurations of the Domain about system access or kerberos Get-DomainPolicy | Select-Object -ExpandProperty SystemAccess Get-DomainPolicy | Select-Object -ExpandProperty KerberosPolicy
احصل على وحدات تحكم المجال: ```powershell Get-DomainController Get-DomainController -Domain
سرد مستخدمي المجال: ```powershell #Save all Domain Users to a file Get-DomainUser | Out-File -FilePath .\DomainUsers.txt
#Will return specific properties of a specific user Get-DomainUser -Identity [username] -Properties DisplayName, MemberOf | Format-List
#Enumerate user logged on a machine Get-NetLoggedon -ComputerName
#Enumerate Session Information for a machine Get-NetSession -ComputerName
#Enumerate domain machines of the current/specified domain where specific users are logged into Find-DomainUserLocation -Domain | Select-Object UserName, SessionFromName
تعداد أجهزة كمبيوتر المجال: ```powershell Get-DomainComputer -Properties OperatingSystem, Name, DnsHostName | Sort-Object -Property DnsHostName
#Enumerate Live machines Get-DomainComputer -Ping -Properties OperatingSystem, Name, DnsHostName | Sort-Object -Property DnsHostName
تعداد المجموعات وأعضاء المجموعات: ```powershell #Save all Domain Groups to a file: Get-DomainGroup | Out-File -FilePath .\DomainGroup.txt
#Return members of Specific Group (eg. Domain Admins & Enterprise Admins) Get-DomainGroup -Identity '' | Select-Object -ExpandProperty Member Get-DomainGroupMember -Identity '' | Select-Object MemberDistinguishedName
#Enumerate the local groups on the local (or remote) machine. Requires local admin rights on the remote machine Get-NetLocalGroup | Select-Object GroupName
#Enumerates members of a specific local group on the local (or remote) machine. Also requires local admin rights on the remote machine Get-NetLocalGroupMember -GroupName Administrators | Select-Object MemberName, IsGroup, IsDomain
#Return all GPOs in a domain that modify local group memberships through Restricted Groups or Group Policy Preferences Get-DomainGPOLocalGroup | Select-Object GPODisplayName, GroupName
تعداد المشاركات: ```powershell #Enumerate Domain Shares Find-DomainShare
#Enumerate Domain Shares the current user has access Find-DomainShare -CheckShareAccess
#Enumerate "Interesting" Files on accessible shares Find-InterestingDomainShareFile -Include passwords
تعداد سياسات المجموعة: ```powershell Get-DomainGPO -Properties DisplayName | Sort-Object -Property DisplayName
#Enumerate all GPOs to a specific computer Get-DomainGPO -ComputerIdentity -Properties DisplayName | Sort-Object -Property DisplayName
#Get users that are part of a Machine's local Admin group Get-DomainGPOComputerLocalGroupMapping -ComputerName
تعداد OUs: ```powershell Get-DomainOU -Properties Name | Sort-Object -Property Name
تعداد ACLs: ```powershell
Get-DomainObjectAcl -Identity -ResolveGUIDs