Post-Exploitation Commands
26 commands across 4 subcategories. Every entry lists the authentication material it needs, the protocols it speaks and links to upstream tool documentation.
AD Object Manipulation 17
- bloodyAD add dnsRecord Create a new AD-integrated DNS record. Authenticated users can create records by default — chains nicely…
- bloodyAD Add GenericAll Grant attacker GenericAll over a target object via LDAP. Requires WriteDacl or Owner on the target. Pair…
- bloodyAD Add Group Member Add a user/computer to a group via LDAP. Common abuse path when GenericAll/WriteProperty over a privileged…
- bloodyAD Create User Create a new domain user object. Requires Create Child rights on a Users container (which OU operators /…
- bloodyAD remove object Delete an arbitrary AD object you have rights on. Cleanup step for accounts/computers you created…
- bloodyAD set restore Restore a tombstoned object from the AD recycle bin. Useful for resurrecting accounts you accidentally…
- Impacket addcomputer.py Add a machine account to the domain using the default MachineAccountQuota (10). Foundation step for RBCD,…
- Impacket Net Enumerate AD users, groups, and shares via Net commands over SMB
- Impacket Remote Registry Query, add, or save remote registry hives over SMB without dropping a binary on the host. Commonly used to…
- Impacket Remote Services Enumerate, create, start, stop, and delete Windows services on a remote host through MS-SCMR. Useful for…
- Impacket WMI Query Execute WMI queries on a remote host to enumerate processes, services, and system info
- LDAP Deleted Objects Query Query for deleted objects
- NetExec Add Machine Account Create a new machine account using a low-privileged user (default ms-DS-MachineAccountQuota is 10). Required…
- PowerShell Enable AD Account Enable disabled Active Directory account
- PowerShell Get Deleted AD Objects Get deleted Active Directory objects
- PowerShell Restore AD Object Restore deleted Active Directory object
- PowerShell Restore Deleted User Restore Deleted User Object
File Search 1
- PowerShell File Search Search for files matching pattern in PowerShell
Data Collection 5
- Impacket NTFS-Read (Offline NTDS Browse) Browse a raw NTFS image (e.g. a VSS shadow copy of C:\Windows\NTDS) offline as if it were a filesystem. Use…
- NetExec RDP Screenshot Capture a screenshot of the current RDP login screen / desktop without authenticating into a session. Useful…
- NetExec SMB BitLocker Recovery Keys Retrieve BitLocker recovery keys stored in Active Directory
- NetExec WMI bitlocker Module Pull BitLocker recovery keys from a host over WMI. Faster than the SMB equivalent in environments where…
- SMBClient Recursive Download Download folder recursively from SMB share
Persistence 3
- Impacket Scheduled Tasks Create, delete, or run scheduled tasks on a remote host via ATSVC
- Impacket WMI Persist Install or remove WMI event subscriptions for remote persistence
- Rubeus ptt (Pass-the-Ticket) Inject a Kerberos ticket into the current logon session. Accepts base64 from asktgt/s4u output or a .kirbi…