Extra
PowerView
*local admin required
this goes through RPC and SMB ports:
Find-LocalAdminAccess -Verbose [-Thread <int>]
Invoke-CheckLocalAdminAccess
Invoke-EnumerateLocalAdmin -Verbose
Get-NetLocalGroupusing WMI is more stealthy:
Find-WMILocalAdminAccess.ps1find where the domain admin has an open session:
Invoke-UserHunter [-GroupName <name> -Domain <domain> -CheckAccess -Stealth]
Get-NetSession
Get-NetLoggedOnLast updated