| ** |
|
| Coerce a system to authenticate to a remote target |
CredCoerce |
| DCOM |
|
| Activate a COM object on a remote computer |
Dcom activate |
| Invoke a method on a COM object on a remote computer |
Dcom invoke |
| Directory Replication |
|
| Export Kerberos keys for domain accounts to a .keytab file |
Dsrep rep |
| Replicate secret attributes from a domain controller (DCSync) |
Dsrep rep |
| Enumeration |
|
| Check the encryption types supported for a user account |
Kerb getasinfo |
| Check the encryption types supported for a user account |
Kerb asreq |
| Check whether a user account requires pre-authentication |
Kerb getasinfo |
| Check whether a user account requires pre-authentication |
Kerb asreq |
| Check whether a user name is valid |
Kerb getasinfo |
| Check whether a user name is valid |
Kerb asreq |
| Enumerate accounts that are granted a privilege |
Lsa enumprivaccounts |
| Enumerate aliases in the Security Accounts Manager database |
Sam enumaliases |
| Enumerate dynamic RPC endpoints |
Epm lsep |
| Enumerate groups in the Security Accounts Manager database |
Sam enumgroups |
| Enumerate policy accounts |
Lsa enumaccounts |
| Enumerate the data streams of a file on an SMB server |
Smb2Client enumstreams |
| Enumerate the network interfaces and network addresses of an SMB server |
Smb2Client enumnics |
| Enumerate the open files on an SMB server |
Smb2Client enumopenfiles |
| Enumerate the privileges granted to an account |
Lsa getprivs |
| Enumerate the rights and privileges granted to an account |
Lsa getrights |
| Enumerate the sessions of users connected to an SMB server |
Smb2Client enumsessions |
| Enumerate the shares of an SMB server |
Smb2Client enumshares |
| Enumerate the system access rights granted to an account |
Lsa getsysaccess |
| Enumerate the volume snapshots on an SMB server |
Smb2Client enumsnapshots |
| Enumerate user accounts in the Security Accounts Manager database |
Sam enumusers |
| Executes a WMI query |
Wmi query |
| Export Kerberos keys for domain accounts to a .keytab file |
Dsrep rep |
| Get a list of registered DCOM applications |
Reg getdcomapp |
| Get a WMI object |
Wmi get |
| Get info on domain controllers |
Dsrep dcinfo |
| Get the members of an alias (group) |
Sam aliasmembers |
| Get the system key |
Reg syskey |
| Get user hashes from the SAM |
Reg dumpsam |
| Invoke a method on a WMI class or object |
Wmi invoke |
| List partitions (naming contexts) within an Active Directory forest |
Ldap lspart |
| List the classes within a WMI namespace |
Wmi lsclass |
| List the methods of a WMI class or object |
Wmi lsmethod |
| List the namespaces within a WMI namespace |
Wmi lsns |
| List the properties of a WMI class or object |
Wmi lsprop |
| Lists attributes defined within an Active Directory forest |
Ldap schema |
| Mount an LDAP directory as a file system |
Ldap mountfs |
| Query objects in Active Directory |
Ldap query |
| Query the status of a service |
Scm query |
| Query the triggers configured to start or stop a service |
Scm qtriggers |
| Replicate secret attributes from a domain controller (DCSync) |
Dsrep rep |
| Search for objects by name in Active Directory |
Ldap search |
| Translate an a SID to its account name and domain |
Lsa lookupsid |
| Translate an account name to its SID and domain name |
Lsa lookupname |
| Expanding Access |
|
| Add an object to Active Directory |
Ldap add |
| Change a password |
Kerb changepw |
| Create a computer account |
Ldap add |
| Create a computer account |
Ldap addcomputer |
| Create a user account |
Ldap add |
| Create a user account |
Ldap adduser |
| Create an LSA policy account |
Lsa createaccount |
| Get ticket hash for hash cracking |
Kerb tgsreq |
| Grant a privilege to an account |
Lsa addpriv |
| Modify a user account in Active Directory |
Ldap moduser |
| Modify an object in Active Directory |
Ldap mod |
| Request a ticket for a service |
Kerb tgsreq |
| Request a ticket-granting-ticket |
Kerb asreq |
| Set the password of another user account |
Kerb setpw |
| Set the security descriptor on a registry key |
Reg setsd |
| Set the system access rights for an account |
Lsa setsysaccess |
| Kerberos |
|
| Change a password |
Kerb changepw |
| Check the encryption types supported for a user account |
Kerb getasinfo |
| Check the encryption types supported for a user account |
Kerb asreq |
| Check whether a user account requires pre-authentication |
Kerb getasinfo |
| Check whether a user account requires pre-authentication |
Kerb asreq |
| Convert between a .ccache file and a .kirbi file (offline) |
Kerb select |
| Decrypt tickets (offline) |
Kerb select |
| Describe a Kerberos ticket (offline) |
Kerb select |
| Generate protocol key from password (offline) |
Kerb s2k |
| Get ticket hash for hash cracking |
Kerb tgsreq |
| List entries in a keytab file. |
Kerb keytab list |
| Print the contents of a .ccache file (offline) |
Kerb select |
| Print the contents of a .kirbi file (offline) |
Kerb select |
| Print ticket authorization data (offline) |
Kerb select |
| Query tickets within a .ccache file or .kirbi file (offline) |
Kerb select |
| Renew a ticket |
Kerb renew |
| Request a ticket for a service |
Kerb tgsreq |
| Request a ticket-granting-ticket |
Kerb asreq |
| Set the password of another user account |
Kerb setpw |
| Lateral Movement |
|
| Activate a COM object on a remote computer |
Dcom activate |
| Create a service |
Scm create |
| Execute a command line on a remote system |
Wmi exec |
| Invoke a method on a COM object on a remote computer |
Dcom invoke |
| Invoke a method on a WMI class or object |
Wmi invoke |
| Start a service |
Scm start |
| LDAP |
|
| Add an object to Active Directory |
Ldap add |
| Convert between date/times and LDAP timestamps |
Ldap timestamp |
| Create a computer account |
Ldap add |
| Create a computer account |
Ldap addcomputer |
| Create a user account |
Ldap add |
| Create a user account |
Ldap adduser |
| Create an organizational unit (OU) |
Ldap addou |
| Delete a computer account |
Ldap rm |
| Delete a user account |
Ldap rm |
| Delete an object from Active Directory |
Ldap rm |
| Get your current user name |
Ldap whoami |
| List named bit flags used by LDAP attributes (offline) |
Ldap namedbits |
| List partitions (naming contexts) within an Active Directory forest |
Ldap lspart |
| List syntaxes used by LDAP (offline) |
Ldap listsyntax |
| Lists attributes defined within an Active Directory forest |
Ldap schema |
| Modify a user account in Active Directory |
Ldap moduser |
| Modify an object in Active Directory |
Ldap mod |
| Mount an LDAP directory as a file system |
Ldap mountfs |
| Query objects in Active Directory |
Ldap query |
| Search for objects by name in Active Directory |
Ldap search |
| Watch for changes to Active Directory |
Ldap watch |
| LSA |
|
| Create an LSA policy account |
Lsa createaccount |
| Enumerate accounts that are granted a privilege |
Lsa enumprivaccounts |
| Enumerate policy accounts |
Lsa enumaccounts |
| Enumerate the privileges granted to an account |
Lsa getprivs |
| Enumerate the rights and privileges granted to an account |
Lsa getrights |
| Enumerate the system access rights granted to an account |
Lsa getsysaccess |
| Get the name of the current user account |
Lsa whoami |
| Grant a privilege to an account |
Lsa addpriv |
| Revoke a privilege from an account |
Lsa rmpriv |
| Set the system access rights for an account |
Lsa setsysaccess |
| Translate an a SID to its account name and domain |
Lsa lookupsid |
| Translate an account name to its SID and domain name |
Lsa lookupname |
| Registry |
|
| Create a registry key |
Reg set |
| Get a list of registered DCOM applications |
Reg getdcomapp |
| Get a security descriptor of a registry key |
Reg getsd |
| Get information on a registry key |
Reg keyinfo |
| Get the system key |
Reg syskey |
| Get user hashes from the SAM |
Reg dumpsam |
| List the contents of a registry key |
Reg list |
| Saves a registry key to a file on the remote host |
Reg save |
| Set a value in a registry key |
Reg set |
| Set the security descriptor on a registry key |
Reg setsd |
| RPC |
|
| Enumerate dynamic RPC endpoints |
Epm lsep |
| Get info on domain controllers |
Dsrep dcinfo |
| SAM |
|
| Enumerate aliases in the Security Accounts Manager database |
Sam enumaliases |
| Enumerate groups in the Security Accounts Manager database |
Sam enumgroups |
| Enumerate user accounts in the Security Accounts Manager database |
Sam enumusers |
| Get the members of an alias (group) |
Sam aliasmembers |
| SCM |
|
| Create a service |
Scm create |
| Delete a service |
Scm delete |
| Query the status of a service |
Scm query |
| Query the triggers configured to start or stop a service |
Scm qtriggers |
| Start a service |
Scm start |
| Stop a service |
Scm stop |
| SDDL |
|
| Describe a security descriptor (SDDL or hex) (offline) |
Sddl describe |
| Look up a property by GUID (offline) |
Sddl lookupguid |
| Look up a property set by GUID (offline) |
Sddl lookupguid |
| Look up a well-known SID (offline) |
Sddl lookupwks |
| Look up an extended right by GUID (offline) |
Sddl lookupguid |
| Security |
|
| Describe a security descriptor (SDDL or hex) (offline) |
Sddl describe |
| Look up a property by GUID (offline) |
Sddl lookupguid |
| Look up a property set by GUID (offline) |
Sddl lookupguid |
| Look up a well-known SID (offline) |
Sddl lookupwks |
| Look up an extended right by GUID (offline) |
Sddl lookupguid |
| SMB |
|
| Create a directory junction or mount point on an SMB share |
Smb2Client mount |
| Create a directory on an SMB share |
Smb2Client mkdir |
| Create a file on an SMB share |
Smb2Client touch |
| Create a filesystem link on an SMB share |
Smb2Client mklink |
| Delete a directory on an SMB share |
Smb2Client rmdir |
| Delete a file in SMB share |
Smb2Client rm |
| Get a file from an SMB server |
Smb2Client get |
| List the contents of directory on an SMB share |
Smb2Client ls |
| Remove a directory junction or mount point within an SMB share |
Smb2Client umount |
| Timestomp a file on an SMB share |
Smb2Client touch |
| Update directory entry attributes and timestamps for a new or existing file on an SMB share |
Smb2Client touch |
| Upload a file to an SMB share |
Smb2Client put |
| Watch a file or directory on an SMB server for changes |
Smb2Client watch |
| WMI |
|
| Back up the WMI MOF repository |
Wmi backup |
| Delete a WMI object |
Wmi delete |
| Execute a command line on a remote system |
Wmi exec |
| Executes a WMI query |
Wmi query |
| Get a WMI object |
Wmi get |
| Invoke a method on a WMI class or object |
Wmi invoke |
| List the classes within a WMI namespace |
Wmi lsclass |
| List the methods of a WMI class or object |
Wmi lsmethod |
| List the namespaces within a WMI namespace |
Wmi lsns |
| List the properties of a WMI class or object |
Wmi lsprop |
| Restore the WMI MOF repository |
Wmi restore |