Windows
Service
Service Information
Start / stop windows service
List all services
List all services with binpath (powershell)
Where State -eq "Running"
File
Display ACL of a file
Unquoted Service Path
C:\Program Files\A Subfolder\B Subfolder\C Subfolder\SomeExecutable.exe
In order to run SomeExecutable.exe, the system will interpret this path in the following order from 1 to 5.
C:\Program.exe
C:\Program Files\A.exe
C:\Program Files\A Subfolder\B.exe
C:\Program Files\A Subfolder\B Subfolder\C.exe
C:\Program Files\A Subfolder\B Subfolder\C Subfolder\SomeExecutable.exe
source: below (sehr empfehlenswert zu lesen)
Check Unquoted Service Path
Welche Gruppe befindet sich der user
Privilegien auflisten vom Benutzer
Nishang
Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security, penetration testing and red teaming.
Use the in-memory dowload and execute:
Powershell
From the Target, download a Script provided by the attacker and execute it
Start files from CMD
Last updated