Skip to content

PowerView

PowerShell tool (part of PowerSploit) for enumerating users, groups, computers, shares, ACLs, and trust relationships in Active Directory.

When I Use It

  • Enumerating a domain from a compromised host without dropping obvious tooling
  • Finding attack paths: where users are logged in, who has local admin, and which ACLs are abusable
  • Quick domain reconnaissance when a full BloodHound collection is not warranted

Detection and policy

PowerView is widely flagged by AV and EDR, and setting an unrestricted execution policy is itself noisy. Expect detection on a monitored network and prefer it where that is acceptable in scope.

Setup

  • Obtain the Recon module from PowerSploit
  • Import it: Import-Module .\PowerView.ps1 (or Import-Module Recon)

Common Tasks

Domain Info

Task Cmdlet
Current domain Get-NetDomain
Domain SID Get-DomainSID
Domain controllers Get-NetDomainController
Domain shares Find-DomainShare
GPOs / OUs Get-NetGPO / Get-NetOU
Forest domains Get-NetForestDomain

Users, Groups, Computers

Task Cmdlet
Domain users Get-NetUser
Domain groups Get-NetGroup
Members of a group Get-DomainGroup -Identity <group> \| Select -Expand Member
Domain computers Get-NetComputer

ACLs and Trusts

Task Cmdlet
ACLs for an object Get-ObjectAcl -SamAccountName <acct> -ResolveGUIDs
Interesting ACEs Invoke-ACLScanner -ResolveGUIDs
ACL of a share path Get-PathAcl -Path "\host\share"

User Hunting

Task Cmdlet
Machines where you are local admin Find-LocalAdminAccess
Local admins on machines Invoke-EnumerateLocalAdmin
Where a target user has a session Invoke-UserHunter

Reading the Output

  • Find-LocalAdminAccess and Invoke-UserHunter are the fastest way to find a path to privileged access
  • ACL results from Invoke-ACLScanner reveal delegation and abusable rights that are not obvious from group membership
  • For large domains, BloodHound visualizes these same relationships more clearly

Resources