Windows Enumeration
After getting execution on a Windows host (shell, user session), the first job isn’t to escalate: it’s to understand where you are. Who you are, what privileges you hold, what runs on the machine, what network you reach, and whether the host is domain-joined. Orderly enumeration avoids blind shots and usually reveals the escalation path before you touch any exploit.
Threat model
Section titled “Threat model”The attacker starts from low-privilege access and wants to turn it into local SYSTEM or a pivot into the domain. Almost all the info they need is available without privileges: Windows itself is talkative. The defender sees this phase as recon-command noise (whoami, net, systeminfo) that, correlated, exposes an intruder in the post-exploitation stage.
What to enumerate and why
Section titled “What to enumerate and why”The goal is to answer, in order: who am I and what can I do? → what’s locally exploitable? → am I in a domain and what do I reach?
Red Team
Section titled “Red Team”User context and privileges
Section titled “User context and privileges”whoami /all # user, groups, and PRIVILEGES (key for privesc)whoami /priv # SeImpersonate, SeBackup, SeDebug... = direct pathsecho %USERNAME% & echo %USERDOMAIN%net user %USERNAME% # user's local groupsnet localgroup administratorswhoami /priv is the first stop: SeImpersonatePrivilege → Potato; SeBackupPrivilege → read SAM/NTDS; SeDebugPrivilege → dump LSASS.
System and patches
Section titled “System and patches”systeminfo # version, build, hotfixes (for kernel exploits)wmic qfe get HotFixID # installed patches[System.Environment]::OSVersion.Version # PowerShellCross build + hotfixes with Watson/wesng for known kernel exploits (PrintNightmare, etc.).
Software, services, and processes
Section titled “Software, services, and processes”wmic product get name,version # installed software (slow)tasklist /v # processes and the user running themsc query # serviceswmic service get name,pathname,startmode,startname # paths and service accountnetstat -ano # ports and PIDs (internal services)Look for services running as SYSTEM with weak binaries/paths (see Windows Privilege Escalation: unquoted paths, permissions).
Network and connectivity
Section titled “Network and connectivity”ipconfig /allroute printarp -a # hosts seen on the LANnetstat -ano -p tcpnslookup -type=srv _ldap._tcp.dc._msdcs.<domain> # locate DCsDomain-joined?
Section titled “Domain-joined?”systeminfo | findstr /i domainnet config workstationnltest /dsgetdc:<domain>echo %LOGONSERVER% # DC that authenticatedIf there’s a domain, enumeration jumps to AD (see Active Directory Enumeration).
Credentials on the host (quick wins)
Section titled “Credentials on the host (quick wins)”# deployment files and configs with secretsfindstr /si password *.xml *.ini *.txt *.configdir /s /b *unattend* *sysprep* web.config# stored credentialscmdkey /listreg query HKLM /f password /t REG_SZ /s# autologon, VNC, PuTTY in the registryreg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"- winPEAS — the reference all-in-one enumerator (privesc + credentials + configs).
- Seatbelt — thorough host-focused collection (C#).
- PowerUp (
Invoke-AllChecks) — PowerShell privesc vectors. - JAWS, Watson/wesng — basic enum and kernel-exploit mapping.
- Snaffler — sweep shares for secrets.
Impact
Section titled “Impact”Enumeration doesn’t exploit, but it selects the exploit: the local privesc vector and the decision to pivot to the domain come from here. Skipping it burns noisy exploits needlessly.
Blue Team
Section titled “Blue Team”Detection
Section titled “Detection”- Bursts of
whoami /all,net user/group,systeminfo,wmic,nltestfrom a normal user account → post-exploitation recon pattern. - Execution of winPEAS/Seatbelt (known hashes and behavior; spikes of registry/FS reads).
- Mass registry reads searching for “password”.
Telemetry
Section titled “Telemetry”- Sysmon (event 1 process create, 10 process access, 11 file create) + command line.
- PowerShell auditing: Script Block Logging (4104), Module Logging (4103), transcription.
- Process 4688 logs with command line enabled.
Hardening
Section titled “Hardening”- Reduce talkativeness: remove unnecessary tools, restrict
wmic/cscript, apply AppLocker/WDAC. - Remove cleartext credentials from configs, GPP, deployment scripts; use gMSA/LAPS.
- Least privilege: a normal user’s
whoami /privshould have nothing juicy. - EDR that alerts on recon chains and known-enumerator execution.
Response
Section titled “Response”Isolate the host, identify the compromised account, rotate its credentials, and review what was enumerated (shares, DCs, secrets found) to anticipate the attacker’s next step.
CVEs and real-world cases
Section titled “CVEs and real-world cases”- Enumeration itself isn’t a CVE, but it enables picking kernel exploits like PrintNightmare (CVE-2021-34527), CVE-2021-1675, HiveNightmare/SeriousSAM (CVE-2021-36934).
- winPEAS/Seatbelt/PowerUp are standard in pentest reports and real actors’ TTPs (MITRE ATT&CK T1082, T1087, T1057).
- Countless breaches began with cleartext credentials in
unattend.xml/GPP (cpassword, MS14-025).
Testing checklist
Section titled “Testing checklist”-
whoami /allandwhoami /priv— dangerous privileges (SeImpersonate/Backup/Debug)? -
systeminfo+ hotfixes — unpatched build mappable to a kernel exploit? - Services/processes as SYSTEM with weak paths or permissions
- Credentials in configs, registry,
cmdkey, autologon? - Host domain-joined? DCs located?
- Internal ports and non-exposed services (
netstat -ano) - Reachable shares with secrets (Snaffler)
- Does winPEAS flag any obvious vector?