Rough Draft
UNSORTED: Draft 1
PowerShell Execution Policy Bypass
powershell.exe -nop -exec bypass
powershell.exe -nop -ep bypass
powershell -ep bypassEnable Alternate Methods for Lateral-Movement
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /fEnable-PSRemoting -Force# New User
net localgroup [username] [password] /add
# Macine user to Administrators group
net localgroup administrators [username] /addEnumeration
getting rev-shell
AD recycle bin enumeration
Generic All on user / Force-Change-Password
Generic Write on user
Generic All on DC
Server Operator group
UNSORTED : Draft 2
Generic All
Generic Write on user
Generic All on Computer / DC-computer
RBCD
DC-Sync
GPO abuse
Server Operator group
GMSAPasswordReader
Last updated