Windows services (detailed)

 

Windows services

 

Windows Post Exploitation Cmdlets Execution (PowerShell)

Presence

This section focuses on information gathering about the victim host and the network that it’s attached to.

System

shows-all-current-environmental-variables-macos

WMI

Networking

Users

Configs

Finding important files

Files to pull

Remote system access

Software

Auto­Start directories


Persistance

This section focuses on gaining a foothold to re­gain, or re­obtain access to a system through means of authentication, backdoors, etc..

Download

Compress or expand ZIP archive

Reg command exit

Deleting logs

Uninstalling software „Antivirus“

Invasive or altering commands

Convert text to Braille

Braille

Cmdlets for TCP/IP Model Layers

Cmdlets for TCP/IP Model Layers
The architecture of the TCP/IP protocol suite by Microsoft (https://technet.microsoft.com/en-us/library/bb726993.aspx)

 

Layer 1. Network Interface Layer

Hardware information of the network adapter


Returns all physical network adapters


Networking statistics from the network adapter. The statistics include broadcast, multicast, discards, and errors

 

Layer 2. Internet Layer

MAC (Media Access Control)

Get the current MAC


Neighbor cache entries (The neighbor cache maintains information for each on-link neighbor, including the IP address and the associated link-layer address. In IPv4, the neighbor cache is commonly known as the Address Resolution Protocol (ARP) cache)

 

IP (Internet Protocol)

Get the current IP address


IP version supported by the network adapter


Information about IP version


Assign a static IP address


IP route information from the IP routing table

 

NAT (Network Address Translation)

Information about NAT

 

Firewall

Information about firewall

 

ICMP (Internet Control Message Protocol)

Sends ICMP echo request packets („pings“) to one or more computers

 

Layer 3. Transport Layer

TCP (Transmission Control Protocol)

Settings


Gets information about current connection statistics


Ports

 

UDP (User Datagram Protocol)

Settings