NTDS.dit
%SystemRoot%\NTDS
Windows Server
Tree
Domain Schema
Organizational Units
Security Groups
Domain Computers
Cert Publishers
Local Administrators
Allowed RODC Password Replication Group
Directional
Transitive
Kerberos
Certificate Services
Rest APIs
Tenants
Trusts
ssh Administrator:[email protected]
yes
password123@
cd Downloads
powershell -ep bypass
. .\PowerView.ps1
Get-NetComputer -fulldata | select operatingsystem🧰 https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993
Get-NetComputer -fulldata | select operatingsystemWindows 10 Enterprise Evaluation
Get-NetUser | select cnAdmin2
Get-NetGroup -GroupName *Hyper-V Administrators
Get-NetUser -SPN | ?{$_.memberof -match 'Domain Admins'}5/13/2020 8:26:58 PM