Privileged Access
Privileged Access
1. Enumerate Remote Desktop Users Group
Command:
Get-NetLocalGroupMember -ComputerName ACADEMY-EA-MS01 -GroupName "Remote Desktop Users"2. Enumerate Remote Management Users Group
Command:
Get-NetLocalGroupMember -ComputerName ACADEMY-EA-MS01 -GroupName "Remote Management Users"3. Create a Secure Password Variable
Command:
$password = ConvertTo-SecureString "Klmcargo2" -AsPlainText -Force4. Create a Credential Object
Command:
5. Establish a PowerShell Session
Command:
6. Establish a PowerShell Session Using Evil-WinRM
Command:
7. Import PowerUpSQL
Command:
8. Enumerate SQL Server Instances
Command:
9. Query SQL Server Version
Command:
10. Display mssqlclient.py Options
Command:
11. Connect to MSSQL Server
Command:
12. Display SQL Client Options
Command:
13. Enable xp_cmdshell
Command:
14. Enumerate System Rights
Last updated