1 - Situational Awarness

Get an idea of the environment before starting deeper enumeration.

Network Information

Interfaces

ipconfig /all

ARP Table

arp -a

Routing Table

route print

Protections

Windows Defender Status

Get-MpComputerStatus

List AppLocker Rules

Get-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections

Test AppLocker Policy

Initial Enumeration

Environment Variables

System Informations (OS, Version, Hot Fixes...)

Hot Fixes (Patches)

Installed Programs

Sockets (TCP/UPD)

Get Process Name Associated to PID

User & Group Information

Logged-In Users

Current User

Current User Privileges

Current User Group Information

Get all Users

Get all Groups

Get Group Details

Get Password Policy & Other Account Information

Named Pipes

Listing Named Pipes

Retrieve Pipe DACL

Find all writtable Named Pipes

Privesc Cheatsheets

Last updated