Skip to content

Windows Enumeration

After getting execution on a Windows host (shell, user session), the first job isn’t to escalate: it’s to understand where you are. Who you are, what privileges you hold, what runs on the machine, what network you reach, and whether the host is domain-joined. Orderly enumeration avoids blind shots and usually reveals the escalation path before you touch any exploit.

The attacker starts from low-privilege access and wants to turn it into local SYSTEM or a pivot into the domain. Almost all the info they need is available without privileges: Windows itself is talkative. The defender sees this phase as recon-command noise (whoami, net, systeminfo) that, correlated, exposes an intruder in the post-exploitation stage.

The goal is to answer, in order: who am I and what can I do? → what’s locally exploitable? → am I in a domain and what do I reach?

whoami /all # user, groups, and PRIVILEGES (key for privesc)
whoami /priv # SeImpersonate, SeBackup, SeDebug... = direct paths
echo %USERNAME% & echo %USERDOMAIN%
net user %USERNAME% # user's local groups
net localgroup administrators

whoami /priv is the first stop: SeImpersonatePrivilege → Potato; SeBackupPrivilege → read SAM/NTDS; SeDebugPrivilege → dump LSASS.

systeminfo # version, build, hotfixes (for kernel exploits)
wmic qfe get HotFixID # installed patches
[System.Environment]::OSVersion.Version # PowerShell

Cross build + hotfixes with Watson/wesng for known kernel exploits (PrintNightmare, etc.).

wmic product get name,version # installed software (slow)
tasklist /v # processes and the user running them
sc query # services
wmic service get name,pathname,startmode,startname # paths and service account
netstat -ano # ports and PIDs (internal services)

Look for services running as SYSTEM with weak binaries/paths (see Windows Privilege Escalation: unquoted paths, permissions).

ipconfig /all
route print
arp -a # hosts seen on the LAN
netstat -ano -p tcp
nslookup -type=srv _ldap._tcp.dc._msdcs.<domain> # locate DCs
systeminfo | findstr /i domain
net config workstation
nltest /dsgetdc:<domain>
echo %LOGONSERVER% # DC that authenticated

If there’s a domain, enumeration jumps to AD (see Active Directory Enumeration).

# deployment files and configs with secrets
findstr /si password *.xml *.ini *.txt *.config
dir /s /b *unattend* *sysprep* web.config
# stored credentials
cmdkey /list
reg query HKLM /f password /t REG_SZ /s
# autologon, VNC, PuTTY in the registry
reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"
  • winPEAS — the reference all-in-one enumerator (privesc + credentials + configs).
  • Seatbelt — thorough host-focused collection (C#).
  • PowerUp (Invoke-AllChecks) — PowerShell privesc vectors.
  • JAWS, Watson/wesng — basic enum and kernel-exploit mapping.
  • Snaffler — sweep shares for secrets.

Enumeration doesn’t exploit, but it selects the exploit: the local privesc vector and the decision to pivot to the domain come from here. Skipping it burns noisy exploits needlessly.

  • Bursts of whoami /all, net user/group, systeminfo, wmic, nltest from a normal user account → post-exploitation recon pattern.
  • Execution of winPEAS/Seatbelt (known hashes and behavior; spikes of registry/FS reads).
  • Mass registry reads searching for “password”.
  • Sysmon (event 1 process create, 10 process access, 11 file create) + command line.
  • PowerShell auditing: Script Block Logging (4104), Module Logging (4103), transcription.
  • Process 4688 logs with command line enabled.
  • Reduce talkativeness: remove unnecessary tools, restrict wmic/cscript, apply AppLocker/WDAC.
  • Remove cleartext credentials from configs, GPP, deployment scripts; use gMSA/LAPS.
  • Least privilege: a normal user’s whoami /priv should have nothing juicy.
  • EDR that alerts on recon chains and known-enumerator execution.

Isolate the host, identify the compromised account, rotate its credentials, and review what was enumerated (shares, DCs, secrets found) to anticipate the attacker’s next step.

  • Enumeration itself isn’t a CVE, but it enables picking kernel exploits like PrintNightmare (CVE-2021-34527), CVE-2021-1675, HiveNightmare/SeriousSAM (CVE-2021-36934).
  • winPEAS/Seatbelt/PowerUp are standard in pentest reports and real actors’ TTPs (MITRE ATT&CK T1082, T1087, T1057).
  • Countless breaches began with cleartext credentials in unattend.xml/GPP (cpassword, MS14-025).
  • whoami /all and whoami /priv — dangerous privileges (SeImpersonate/Backup/Debug)?
  • systeminfo + hotfixes — unpatched build mappable to a kernel exploit?
  • Services/processes as SYSTEM with weak paths or permissions
  • Credentials in configs, registry, cmdkey, autologon?
  • Host domain-joined? DCs located?
  • Internal ports and non-exposed services (netstat -ano)
  • Reachable shares with secrets (Snaffler)
  • Does winPEAS flag any obvious vector?