Windows Post-Exploitation Discovery¶
Enumerating a compromised Windows host with built-in commands: system, network, domain, and user information.
Why It Matters¶
Built-in commands draw little attention and are available on every Windows host, so they are the safest first pass on a foothold. They reveal the host's patch level, its place in the network and domain, and the current user's privileges, which together set up escalation and lateral movement.
wmic is deprecated
wmic is deprecated and removed from current Windows 11 and Server builds. Where it is gone, use the PowerShell Get-CimInstance equivalents.
Reference¶
What to Enumerate¶
- Current user ID and privileges
- Network connections (for lateral movement)
- Running processes and scheduled tasks
- Whether the host is domain-joined, and if so its users, groups, and computers
- Installed applications, firewall, and AV
System Info (CMD)¶
| Description | Command |
|---|---|
| System information | systeminfo |
| Logical drives | wmic logicaldisk get name,freespace,filesystem,size |
| Environment variables | set |
| Running processes (verbose) | tasklist /v |
| Services per process | tasklist /svc |
| Full process attributes | wmic process list full |
| Started services | net start |
| Scheduled tasks | schtasks /query /fo LIST /v |
| Installed patches | wmic qfe get Caption,HotFixID,InstalledOn |
| Installed applications | wmic product get name |
Network and Domain Info (CMD)¶
| Description | Command |
|---|---|
| IP and interfaces | ipconfig /all |
| Routing table | route print |
| ARP table | arp -a |
| Active TCP connections | netstat -an |
| Current domain | echo %USERDOMAIN% |
| Logon server | echo %LOGONSERVER% |
| Domain password policy | net accounts /domain |
| Network shares | net share |
| Hosts in the domain | net view |
| Domain trusts | nltest /trusted_domains |
User Info (CMD)¶
| Description | Command |
|---|---|
| Current user | whoami |
| Full token and privileges | whoami /all |
| Local users | net users |
| Detailed user info | net user <username> |
| RDP-capable sessions | qwinsta |
| Local groups | net localgroup |
| Local administrators | net localgroup administrators |
Piped variants (for example systeminfo | findstr /B /C:"OS Name") work the same from the command line.
How I Use It¶
I start with whoami /all and systeminfo to establish who I am and how far behind the host is on patches, then enumerate the network and domain to understand where it sits. On a domain-joined host this hands off to Active Directory Enumeration and PowerView; the privilege findings feed Local Windows Privilege Escalation.