Practical Windows Commands
Basic Recon: System & Patch Info
systeminfo
systeminfo | findstr /B /C:"OS Name" /C:"OS Version" #Get only that information
wmic os get osarchitecture || echo %PROCESSOR_ARCHITECTURE% #Get architecture
wmic computersystem LIST full #Get PC info
wmic qfe list brief #Updates
wmic qfe get Caption,Description,HotFixID,InstalledOn #Patches
hostname
DRIVERQUERY #3rd party driver vulnerable?π Environment Variables Worth Checking
Drives and Disk Info
Windows Defender & Recycle Bin
Processes, Services & Installed Software
Active Directory Enumeration
Basic Domain Info
Enumerate Users
Enumerate Groups
List Domain Computers
Logs & Sessions
Password Policy
Credentials
Persistence with users
Local & Domain Users / Groups
Network Enumeration
Windows Firewall Control
Persistence & RDP Access
Shares, SNMP, and Wi-Fi Access
Wifi
SNMP
File Downloading Tricks
Certutil:
Bitsadmin:
Extra Tricks
Alternate Data Streams (ADS)
π€― CMD Obfuscation & DNS Exfiltration
Run CMD from C (Persistence Example)
Misc.
Bypass Char Blacklisting
DOSfuscation
Listen address ACLs
Manual DNS shell
Victim
Last updated