Powerview
Last updated
Last updated
You need first to download PowerView to the host you compromised (up to you how you want to do it)
Now we need to launch powershell and bypass the execution policy by doing :
next we need to load PowerView :
Now obviously this script can retrieve a lot of information, you can for example get information about the domain by :
or DC :
If for example you want to check a particular attribute (say, system access) of the Domain policy you can :
Look for shares :
GPO:
a cheat sheet is available here :