Skip to content

Windows Post-Exploitation Discovery

Enumerating a compromised Windows host with built-in commands: system, network, domain, and user information.

Why It Matters

Built-in commands draw little attention and are available on every Windows host, so they are the safest first pass on a foothold. They reveal the host's patch level, its place in the network and domain, and the current user's privileges, which together set up escalation and lateral movement.

wmic is deprecated

wmic is deprecated and removed from current Windows 11 and Server builds. Where it is gone, use the PowerShell Get-CimInstance equivalents.

Reference

What to Enumerate

  • Current user ID and privileges
  • Network connections (for lateral movement)
  • Running processes and scheduled tasks
  • Whether the host is domain-joined, and if so its users, groups, and computers
  • Installed applications, firewall, and AV

System Info (CMD)

Description Command
System information systeminfo
Logical drives wmic logicaldisk get name,freespace,filesystem,size
Environment variables set
Running processes (verbose) tasklist /v
Services per process tasklist /svc
Full process attributes wmic process list full
Started services net start
Scheduled tasks schtasks /query /fo LIST /v
Installed patches wmic qfe get Caption,HotFixID,InstalledOn
Installed applications wmic product get name

Network and Domain Info (CMD)

Description Command
IP and interfaces ipconfig /all
Routing table route print
ARP table arp -a
Active TCP connections netstat -an
Current domain echo %USERDOMAIN%
Logon server echo %LOGONSERVER%
Domain password policy net accounts /domain
Network shares net share
Hosts in the domain net view
Domain trusts nltest /trusted_domains

User Info (CMD)

Description Command
Current user whoami
Full token and privileges whoami /all
Local users net users
Detailed user info net user <username>
RDP-capable sessions qwinsta
Local groups net localgroup
Local administrators net localgroup administrators

Piped variants (for example systeminfo | findstr /B /C:"OS Name") work the same from the command line.

How I Use It

I start with whoami /all and systeminfo to establish who I am and how far behind the host is on patches, then enumerate the network and domain to understand where it sits. On a domain-joined host this hands off to Active Directory Enumeration and PowerView; the privilege findings feed Local Windows Privilege Escalation.

Resources