Situational Awareness
In this section we will show basic commands to gather enough information about our current situation and how we can use it to escalate privilege.
Current User
Privileges
whoami /privGroups Member
whoami /groupsCommand History
Get-History(Get-PSReadlineOption).HistorySavePathSaved Credentials
cmdkey /listreg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"Users
cmd.exe
net userpowershell.exe
Groups
cmd.exe
powershell.exe
System Information
Network Information
Processes
cmd.exe
powershell.exe
Installed Programs
32-bit
64-bit
Files
Winpeas.exe
Last updated