🔎Windows Post Enumeration

If SYSTEM or SAM found in winPEAS use one of this:

windows/system32/config/SAM(or SYSTEM) is where password hashes are located

If AD ntds.dit will have the database

To get the hash:

If starts with 3186 it is an empty string

Automatic

Wesng:

Manual:

Get stored passwords:

System info (cmd):

Check files with pass in name or .config in current directory recursively:

List all scheduled tasks:

To check all processes running:

Check password in registry:

Get patches:

To get disks:

To check privileges:

To check groups involved in:

To check users:

Can also check specific user with:

We can check group details from above command with:

To look at arp table:

Print route:

For active connections:

Search password (In the directory)

Check Firewall and AV

To check windows defender

Check all processes

Check firewall :

Last updated

Was this helpful?