WORKSPACE
2 COMMANDS Β· ASSESSMENT SETUP AND ORGANISATION
Create Assessment Workspace
π’ Beginner
πͺ Command Prompt (CMD)
mkdir ClientAssessment_2026
cd ClientAssessment_2026
mkdir Evidence Screenshots Network SystemInfo Passwords Reports
echo Assessment started: %date% %time% > _assessment_log.txt
π» PowerShell
New-Item -ItemType Directory -Path "ClientAssessment_2026"
Set-Location "ClientAssessment_2026"
"Evidence","Screenshots","Network","SystemInfo","Passwords","Reports" | ForEach-Object {New-Item -ItemType Directory -Name $_}
"Assessment started: $(Get-Date)" | Out-File "_assessment_log.txt"
Create Evidence Folder with Timestamp
π’ Beginner
πͺ Command Prompt (CMD)
mkdir Evidence_%date:~-4,4%%date:~-10,2%%date:~-7,2%_%time:~0,2%%time:~3,2%
π» PowerShell
New-Item -ItemType Directory -Name "Evidence_$(Get-Date -Format 'yyyyMMdd_HHmmss')"
USERS
9 COMMANDS Β· USER AND GROUP ENUMERATION
List All Local Users
π’ Beginner
πͺ Command Prompt (CMD)
net user
π» PowerShell
Get-LocalUser | Format-Table Name, Enabled, LastLogon, PasswordRequired, PasswordLastSet
Show User Details
π’ Beginner
πͺ Command Prompt (CMD)
net user Administrator
π» PowerShell
Get-LocalUser -Name Administrator | Format-List *
List Administrator Group Members
π’ Beginner
πͺ Command Prompt (CMD)
net localgroup administrators
π» PowerShell
Get-LocalGroupMember -Group "Administrators" | Format-Table Name, ObjectClass, PrincipalSource
Show Current User Info
π’ Beginner
πͺ Command Prompt (CMD)
whoami /all
π» PowerShell
whoami /all
List All Local Groups
π’ Beginner
πͺ Command Prompt (CMD)
net localgroup
π» PowerShell
Get-LocalGroup | Format-Table Name, Description, SID
Show Remote Desktop Users
π‘ Intermediate
πͺ Command Prompt (CMD)
net localgroup "Remote Desktop Users"
π» PowerShell
Get-LocalGroupMember -Group "Remote Desktop Users" | Format-Table
Show Currently Logged In Users
π’ Beginner
πͺ Command Prompt (CMD)
query user
π» PowerShell
quser
Show Active User Sessions
π’ Beginner
πͺ Command Prompt (CMD)
query session
π» PowerShell
query session
Show Password Policy
π‘ Intermediate
πͺ Command Prompt (CMD)
net accounts
π» PowerShell
Get-LocalUser | Select-Object Name, PasswordRequired, PasswordExpires, @{N='PasswordAge(Days)';E={(New-TimeSpan -Start $_.PasswordLastSet).Days}}
NETWORK
15 COMMANDS Β· NETWORK DISCOVERY AND ANALYSIS
Show IP Configuration
π’ Beginner
πͺ Command Prompt (CMD)
ipconfig /all
π» PowerShell
Get-NetIPConfiguration -Detailed
Show Network Interfaces
π’ Beginner
πͺ Command Prompt (CMD)
netsh interface show interface
π» PowerShell
Get-NetAdapter | Format-Table Name, InterfaceDescription, Status, LinkSpeed, MacAddress
Show ARP Cache
π’ Beginner
πͺ Command Prompt (CMD)
arp -a
π» PowerShell
Get-NetNeighbor | Format-Table IPAddress, LinkLayerAddress, State
Show Routing Table
π‘ Intermediate
πͺ Command Prompt (CMD)
route print
π» PowerShell
Get-NetRoute | Format-Table DestinationPrefix, NextHop, InterfaceAlias, RouteMetric
Show All Network Connections
π’ Beginner
πͺ Command Prompt (CMD)
netstat -ano
π» PowerShell
Get-NetTCPConnection | Format-Table LocalAddress, LocalPort, RemoteAddress, RemotePort, State, OwningProcess
Show Listening Ports
π’ Beginner
πͺ Command Prompt (CMD)
netstat -ano | findstr LISTENING
π» PowerShell
Get-NetTCPConnection | Where-Object {$_.State -eq "Listen"} | Format-Table LocalAddress, LocalPort, OwningProcess, @{N='Process';E={(Get-Process -Id $_.OwningProcess).ProcessName}}
Show Established Connections
π’ Beginner
πͺ Command Prompt (CMD)
netstat -ano | findstr ESTABLISHED
π» PowerShell
Get-NetTCPConnection | Where-Object {$_.State -eq "Established"} | Format-Table LocalAddress, LocalPort, RemoteAddress, RemotePort, @{N='Process';E={(Get-Process -Id $_.OwningProcess).ProcessName}}
Show DNS Cache
π’ Beginner
πͺ Command Prompt (CMD)
ipconfig /displaydns
π» PowerShell
Get-DnsClientCache | Format-Table Entry, Name, Type, TimeToLive
Clear DNS Cache
π’ Beginner
πͺ Command Prompt (CMD)
ipconfig /flushdns
π» PowerShell
Clear-DnsClientCache
Show Active SMB Sessions
π‘ Intermediate
πͺ Command Prompt (CMD)
net session
π» PowerShell
Get-SmbSession | Format-Table ClientComputerName, ClientUserName, NumOpens, SecondsIdle
Test Network Connectivity
π’ Beginner
πͺ Command Prompt (CMD)
ping google.com
π» PowerShell
Test-Connection google.com -Count 4
Trace Network Route
π’ Beginner
πͺ Command Prompt (CMD)
tracert google.com
π» PowerShell
Test-NetConnection google.com -TraceRoute
DNS Lookup
π’ Beginner
πͺ Command Prompt (CMD)
nslookup google.com
π» PowerShell
Resolve-DnsName google.com
Show Network Statistics
π‘ Intermediate
πͺ Command Prompt (CMD)
netstat -s
π» PowerShell
Get-NetTCPConnection | Group-Object State | Select-Object Count, Name
FIREWALL
5 COMMANDS Β· FIREWALL CONFIGURATION AND RULES
Show Firewall Status
π’ Beginner
πͺ Command Prompt (CMD)
netsh advfirewall show allprofiles
π» PowerShell
Get-NetFirewallProfile | Format-Table Name, Enabled, DefaultInboundAction, DefaultOutboundAction
Show All Firewall Rules
π‘ Intermediate
πͺ Command Prompt (CMD)
netsh advfirewall firewall show rule name=all
π» PowerShell
Get-NetFirewallRule | Format-Table DisplayName, Direction, Action, Enabled
Show Enabled Firewall Rules
π‘ Intermediate
πͺ Command Prompt (CMD)
netsh advfirewall firewall show rule name=all | findstr "Rule Name"
π» PowerShell
Get-NetFirewallRule | Where-Object {$_.Enabled -eq "True"} | Format-Table DisplayName, Direction, Action
Show Inbound Firewall Rules
π‘ Intermediate
πͺ Command Prompt (CMD)
netsh advfirewall firewall show rule name=all dir=in
π» PowerShell
Get-NetFirewallRule | Where-Object {$_.Direction -eq "Inbound" -and $_.Enabled -eq "True"} | Format-Table DisplayName, Action
Show Outbound Firewall Rules
π‘ Intermediate
πͺ Command Prompt (CMD)
netsh advfirewall firewall show rule name=all dir=out
π» PowerShell
Get-NetFirewallRule | Where-Object {$_.Direction -eq "Outbound" -and $_.Enabled -eq "True"} | Format-Table DisplayName, Action
PROCESSES
9 COMMANDS Β· PROCESS INSPECTION AND MANAGEMENT
List All Running Processes
π’ Beginner
πͺ Command Prompt (CMD)
tasklist
π» PowerShell
Get-Process | Format-Table ProcessName, Id, CPU, @{N='Memory(MB)';E={[math]::Round($_.WS/1MB,2)}}
Show Process Tree
π‘ Intermediate
πͺ Command Prompt (CMD)
wmic process get name,processid,parentprocessid
π» PowerShell
Get-CimInstance Win32_Process | Select-Object ProcessName, ProcessId, ParentProcessId | Format-Table
Show Processes with Full Path
π’ Beginner
πͺ Command Prompt (CMD)
wmic process get name,processid,executablepath
π» PowerShell
Get-Process | Select-Object ProcessName, Id, Path | Format-Table
Show Processes with Command Line
π‘ Intermediate
πͺ Command Prompt (CMD)
wmic process get name,processid,commandline
π» PowerShell
Get-CimInstance Win32_Process | Select-Object Name, ProcessId, CommandLine | Format-Table -Wrap
Show Top CPU Processes
π’ Beginner
πͺ Command Prompt (CMD)
wmic process get name,processid,workingsetsize /format:list | sort
π» PowerShell
Get-Process | Sort-Object CPU -Descending | Select-Object -First 10 | Format-Table ProcessName, Id, CPU, @{N='Memory(MB)';E={[math]::Round($_.WS/1MB,2)}}
Show Top Memory Processes
π’ Beginner
πͺ Command Prompt (CMD)
tasklist /fi "memusage gt 100000"
π» PowerShell
Get-Process | Sort-Object WS -Descending | Select-Object -First 10 | Format-Table ProcessName, Id, @{N='Memory(MB)';E={[math]::Round($_.WS/1MB,2)}}
Show Process Services
π‘ Intermediate
πͺ Command Prompt (CMD)
tasklist /svc
π» PowerShell
Get-Process | Where-Object {$_.Name -match 'svchost'} | Format-Table ProcessName, Id
Kill Process by Name
β ADMIN
π’ Beginner
β οΈ Forces termination - unsaved data will be lost
πͺ Command Prompt (CMD)
taskkill /F /IM notepad.exe
π» PowerShell
Stop-Process -Name notepad -Force
Kill Process by PID
β ADMIN
π’ Beginner
β οΈ Forces termination - unsaved data will be lost
πͺ Command Prompt (CMD)
taskkill /F /PID 1234
π» PowerShell
Stop-Process -Id 1234 -Force
SERVICES
5 COMMANDS Β· WINDOWS SERVICE ENUMERATION
List All Services
π’ Beginner
πͺ Command Prompt (CMD)
sc query type= service state= all
π» PowerShell
Get-Service | Format-Table Name, DisplayName, Status, StartType
Show Running Services
π’ Beginner
πͺ Command Prompt (CMD)
sc query type= service state= running
π» PowerShell
Get-Service | Where-Object {$_.Status -eq "Running"} | Format-Table Name, DisplayName
Show Stopped Services
π’ Beginner
πͺ Command Prompt (CMD)
sc query type= service state= inactive
π» PowerShell
Get-Service | Where-Object {$_.Status -eq "Stopped"} | Format-Table Name, DisplayName
Show Service Details
π‘ Intermediate
πͺ Command Prompt (CMD)
sc qc Spooler
π» PowerShell
Get-Service Spooler | Format-List *
Show Automatic Services
π‘ Intermediate
πͺ Command Prompt (CMD)
wmic service where StartMode="Auto" get Name,State
π» PowerShell
Get-Service | Where-Object {$_.StartType -eq "Automatic"} | Format-Table Name, Status
SECURITY
8 COMMANDS Β· SECURITY CONFIGURATION ASSESSMENT
Extract WiFi Passwords
β ADMIN
π΄ Advanced
β οΈ Requires Administrator privileges. For authorized assessments only.
πͺ Command Prompt (CMD)
for /f "skip=9 tokens=1,2 delims=:" %i in ('netsh wlan show profiles') do @echo %j | findstr -i -v echo | netsh wlan show profiles %j key=clear | findstr "Key Content"
π» PowerShell
(netsh wlan show profiles) | Select-String "\:(.+)$" | ForEach-Object {
$name=$_.Matches.Groups[1].Value.Trim()
$wifi = (netsh wlan show profile name=$name key=clear)
$pass = $wifi | Select-String "Key Content\W+\:(.+)$"
if($pass){
[PSCustomObject]@{
SSID=$name
Password=$pass.Matches.Groups[1].Value.Trim()
}
}
} | Format-Table -AutoSize
Show Windows Defender Status
π’ Beginner
πͺ Command Prompt (CMD)
powershell Get-MpComputerStatus | Select-Object AntivirusEnabled, RealTimeProtectionEnabled
π» PowerShell
Get-MpComputerStatus | Select-Object AntivirusEnabled, RealTimeProtectionEnabled, IoavProtectionEnabled, BehaviorMonitorEnabled, AntivirusSignatureLastUpdated
Show Defender Exclusions
π‘ Intermediate
πͺ Command Prompt (CMD)
powershell Get-MpPreference | Select-Object ExclusionPath, ExclusionProcess
π» PowerShell
Get-MpPreference | Select-Object ExclusionPath, ExclusionProcess, ExclusionExtension
Show Security Event Log
π‘ Intermediate
πͺ Command Prompt (CMD)
wevtutil qe Security /c:20 /f:text /rd:true
π» PowerShell
Get-EventLog -LogName Security -Newest 20 | Format-Table TimeGenerated, EventID, Message -Wrap
Show Failed Login Attempts
π΄ Advanced
πͺ Command Prompt (CMD)
wevtutil qe Security "/q:*[System[(EventID=4625)]]" /c:20 /f:text /rd:true
π» PowerShell
Get-EventLog -LogName Security | Where-Object {$_.EventID -eq 4625} | Select-Object -First 20 | Format-Table TimeGenerated, Message -Wrap
Show Successful Logins
π΄ Advanced
πͺ Command Prompt (CMD)
wevtutil qe Security "/q:*[System[(EventID=4624)]]" /c:20 /f:text /rd:true
π» PowerShell
Get-EventLog -LogName Security | Where-Object {$_.EventID -eq 4624} | Select-Object -First 20 | Format-Table TimeGenerated, Message -Wrap
Show UAC Settings
π‘ Intermediate
πͺ Command Prompt (CMD)
reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA
π» PowerShell
Get-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" | Select-Object EnableLUA, ConsentPromptBehaviorAdmin
Check if Admin
π’ Beginner
πͺ Command Prompt (CMD)
net session >nul 2>&1 && echo Administrator || echo Not Administrator
π» PowerShell
([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).IsInRole([Security.Principal.WindowsBuiltInRole]"Administrator")
FILES
7 COMMANDS Β· FILE SYSTEM SEARCH AND INSPECTION
Search for Files by Name
π’ Beginner
πͺ Command Prompt (CMD)
dir /s /b C:\*.txt
π» PowerShell
Get-ChildItem -Path C:\ -Recurse -Filter *.txt -ErrorAction SilentlyContinue | Select-Object FullName
Find Large Files
π‘ Intermediate
πͺ Command Prompt (CMD)
forfiles /S /M * /C "cmd /c if @fsize GTR 104857600 echo @path @fsize"
π» PowerShell
Get-ChildItem -Path C:\ -Recurse -File -ErrorAction SilentlyContinue | Where-Object {$_.Length -gt 100MB} | Select-Object FullName, @{N='Size(MB)';E={[math]::Round($_.Length/1MB,2)}} | Sort-Object 'Size(MB)' -Descending
Find Recent Files
π’ Beginner
πͺ Command Prompt (CMD)
forfiles /P C:\ /S /D -7 /C "cmd /c echo @path @fdate"
π» PowerShell
Get-ChildItem -Path C:\ -Recurse -File -ErrorAction SilentlyContinue | Where-Object {$_.LastWriteTime -gt (Get-Date).AddDays(-7)} | Select-Object FullName, LastWriteTime
Search File Contents
π‘ Intermediate
πͺ Command Prompt (CMD)
findstr /S /I /M "password" C:\*.txt
π» PowerShell
Get-ChildItem -Path C:\ -Recurse -Include *.txt -ErrorAction SilentlyContinue | Select-String -Pattern "password" | Select-Object Path, LineNumber, Line
List Files in Directory
π’ Beginner
πͺ Command Prompt (CMD)
dir
π» PowerShell
Get-ChildItem | Format-Table Name, Length, LastWriteTime
Show File Permissions
π‘ Intermediate
πͺ Command Prompt (CMD)
icacls C:\
π» PowerShell
Get-Acl C:\ | Format-List
SYSTEM
13 COMMANDS Β· SYSTEM INFORMATION AND CONFIGURATION
Show Full System Information
π’ Beginner
πͺ Command Prompt (CMD)
systeminfo
π» PowerShell
Get-ComputerInfo | Format-List
Show Computer Name and Domain
π’ Beginner
πͺ Command Prompt (CMD)
systeminfo | findstr /C:"Host Name" /C:"Domain"
π» PowerShell
Get-ComputerInfo | Select-Object CsName, CsDomain, CsWorkgroup
Show OS Version
π’ Beginner
πͺ Command Prompt (CMD)
ver
π» PowerShell
Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsHardwareAbstractionLayer
Show Installed Updates
π’ Beginner
πͺ Command Prompt (CMD)
wmic qfe list
π» PowerShell
Get-HotFix | Format-Table Description, HotFixID, InstalledOn
Show CPU Information
π’ Beginner
πͺ Command Prompt (CMD)
wmic cpu get name,numberofcores,maxclockspeed
π» PowerShell
Get-CimInstance Win32_Processor | Select-Object Name, NumberOfCores, NumberOfLogicalProcessors, MaxClockSpeed
Show Memory Information
π’ Beginner
πͺ Command Prompt (CMD)
wmic memorychip get capacity,speed
π» PowerShell
Get-CimInstance Win32_PhysicalMemory | Select-Object @{N='Capacity(GB)';E={[math]::Round($_.Capacity/1GB,2)}}, Speed, Manufacturer
Show Disk Information
π’ Beginner
πͺ Command Prompt (CMD)
wmic diskdrive get model,size,interfacetype
π» PowerShell
Get-CimInstance Win32_DiskDrive | Select-Object Model, @{N='Size(GB)';E={[math]::Round($_.Size/1GB,2)}}, InterfaceType
Show Drive Space
π’ Beginner
πͺ Command Prompt (CMD)
wmic logicaldisk get caption,size,freespace
π» PowerShell
Get-PSDrive -PSProvider FileSystem | Select-Object Name, @{N='Used(GB)';E={[math]::Round($_.Used/1GB,2)}}, @{N='Free(GB)';E={[math]::Round($_.Free/1GB,2)}}
Show BIOS Information
π’ Beginner
πͺ Command Prompt (CMD)
wmic bios get serialnumber,version
π» PowerShell
Get-CimInstance Win32_BIOS | Select-Object SerialNumber, Version, Manufacturer
Show Motherboard Information
π’ Beginner
πͺ Command Prompt (CMD)
wmic baseboard get product,manufacturer,version,serialnumber
π» PowerShell
Get-CimInstance Win32_BaseBoard | Select-Object Manufacturer, Product, Version, SerialNumber
Show Uptime
π’ Beginner
πͺ Command Prompt (CMD)
systeminfo | findstr /C:"System Boot Time"
π» PowerShell
Get-CimInstance Win32_OperatingSystem | Select-Object @{N='Uptime';E={(Get-Date) - $_.LastBootUpTime}}, LastBootUpTime
Show Environment Variables
π’ Beginner
πͺ Command Prompt (CMD)
set
π» PowerShell
Get-ChildItem Env: | Format-Table Name, Value
Show Timezone
π’ Beginner
πͺ Command Prompt (CMD)
tzutil /g
π» PowerShell
Get-TimeZone
SOFTWARE
4 COMMANDS Β· INSTALLED APPLICATIONS AND STARTUPS
List Installed Programs
π’ Beginner
πͺ Command Prompt (CMD)
wmic product get name,version
π» PowerShell
Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Select-Object DisplayName, DisplayVersion, Publisher | Format-Table
List Installed Programs (32-bit)
π‘ Intermediate
πͺ Command Prompt (CMD)
reg query HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall /s /v DisplayName
π» PowerShell
Get-ItemProperty HKLM:\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* | Select-Object DisplayName, DisplayVersion, Publisher | Format-Table
Show Startup Programs
π‘ Intermediate
πͺ Command Prompt (CMD)
wmic startup list full
π» PowerShell
Get-CimInstance Win32_StartupCommand | Select-Object Name, Command, Location, User | Format-Table
Show Scheduled Tasks
π‘ Intermediate
πͺ Command Prompt (CMD)
schtasks /query /fo LIST
π» PowerShell
Get-ScheduledTask | Where-Object {$_.State -ne "Disabled"} | Select-Object TaskName, State, TaskPath | Format-Table
EVENT LOGS
4 COMMANDS Β· WINDOWS EVENT LOG ANALYSIS
Show System Event Log
π’ Beginner
πͺ Command Prompt (CMD)
wevtutil qe System /c:20 /f:text /rd:true
π» PowerShell
Get-EventLog -LogName System -Newest 20 | Format-Table TimeGenerated, EntryType, Source, Message -Wrap
Show Application Event Log
π’ Beginner
πͺ Command Prompt (CMD)
wevtutil qe Application /c:20 /f:text /rd:true
π» PowerShell
Get-EventLog -LogName Application -Newest 20 | Format-Table TimeGenerated, EntryType, Source, Message -Wrap
Show Error Events Only
π‘ Intermediate
πͺ Command Prompt (CMD)
wevtutil qe System "/q:*[System[(Level=2)]]" /c:20 /f:text /rd:true
π» PowerShell
Get-EventLog -LogName System -EntryType Error -Newest 20 | Format-Table TimeGenerated, Source, Message -Wrap
Show Warning Events Only
π‘ Intermediate
πͺ Command Prompt (CMD)
wevtutil qe System "/q:*[System[(Level=3)]]" /c:20 /f:text /rd:true
π» PowerShell
Get-EventLog -LogName System -EntryType Warning -Newest 20 | Format-Table TimeGenerated, Source, Message -Wrap
EVIDENCE
4 COMMANDS Β· EVIDENCE COLLECTION AND HASHING
Take Screenshot
π’ Beginner
πͺ Command Prompt (CMD)
powershell Add-Type -AssemblyName System.Windows.Forms; $screen = [System.Windows.Forms.Screen]::PrimaryScreen.Bounds; $bitmap = New-Object System.Drawing.Bitmap($screen.Width, $screen.Height); $graphics = [System.Drawing.Graphics]::FromImage($bitmap); $graphics.CopyFromScreen($screen.Location, [System.Drawing.Point]::Empty, $screen.Size); $bitmap.Save('screenshot.png'); $graphics.Dispose(); $bitmap.Dispose()
π» PowerShell
Add-Type -AssemblyName System.Windows.Forms
$screen = [System.Windows.Forms.Screen]::PrimaryScreen.Bounds
$bitmap = New-Object System.Drawing.Bitmap($screen.Width, $screen.Height)
$graphics = [System.Drawing.Graphics]::FromImage($bitmap)
$graphics.CopyFromScreen($screen.Location, [System.Drawing.Point]::Empty, $screen.Size)
$bitmap.Save("screenshot_$(Get-Date -Format 'yyyyMMdd_HHmmss').png")
$graphics.Dispose()
$bitmap.Dispose()
Create Evidence Archive
π’ Beginner
πͺ Command Prompt (CMD)
powershell Compress-Archive -Path "Evidence" -DestinationPath "Evidence_Archive_%date:~-4,4%%date:~-10,2%%date:~-7,2%.zip"
π» PowerShell
Compress-Archive -Path "Evidence" -DestinationPath "Evidence_Archive_$(Get-Date -Format 'yyyyMMdd_HHmmss').zip"
Calculate File Hash (MD5)
π‘ Intermediate
πͺ Command Prompt (CMD)
certutil -hashfile filename.txt MD5
π» PowerShell
Get-FileHash -Path filename.txt -Algorithm MD5
Calculate File Hash (SHA256)
π‘ Intermediate
πͺ Command Prompt (CMD)
certutil -hashfile filename.txt SHA256
π» PowerShell
Get-FileHash -Path filename.txt -Algorithm SHA256
REPORTING
2 COMMANDS Β· ASSESSMENT REPORT GENERATION
Generate Quick Report
π’ Beginner
πͺ Command Prompt (CMD)
echo ===== QUICK ASSESSMENT REPORT ===== > quick_report.txt
echo Date: %date% >> quick_report.txt
echo Time: %time% >> quick_report.txt
echo. >> quick_report.txt
systeminfo | findstr /C:"Host Name" /C:"OS Name" /C:"OS Version" >> quick_report.txt
ipconfig | findstr /C:"IPv4" >> quick_report.txt
net user >> quick_report.txt
π» PowerShell
@"
===== QUICK ASSESSMENT REPORT =====
Date: $(Get-Date)
Assessor: [Your Name]
$((Get-ComputerInfo | Select-Object CsName, WindowsVersion | Format-List | Out-String))
$((Get-NetIPConfiguration | Select-Object IPv4Address | Format-List | Out-String))
$((Get-LocalUser | Format-Table | Out-String))
"@ | Out-File "quick_report_$(Get-Date -Format 'yyyyMMdd').txt"
Generate Full Assessment Report
π’ Beginner
πͺ Command Prompt (CMD)
echo ===== FULL SECURITY ASSESSMENT REPORT ===== > full_report.txt
echo Generated: %date% %time% >> full_report.txt
echo. >> full_report.txt
echo [SYSTEM INFORMATION] >> full_report.txt
systeminfo >> full_report.txt
echo. >> full_report.txt
echo [NETWORK CONFIGURATION] >> full_report.txt
ipconfig /all >> full_report.txt
echo. >> full_report.txt
echo [USER ACCOUNTS] >> full_report.txt
net user >> full_report.txt
echo. >> full_report.txt
echo [RUNNING PROCESSES] >> full_report.txt
tasklist >> full_report.txt
π» PowerShell
$report = @"
===== FULL SECURITY ASSESSMENT REPORT =====
Generated: $(Get-Date -Format 'yyyy-MM-dd HH:mm:ss')
Assessor: [Your Name]
[SYSTEM INFORMATION]
$((Get-ComputerInfo | Format-List | Out-String))
[NETWORK CONFIGURATION]
$((Get-NetIPConfiguration -Detailed | Format-List | Out-String))
[USER ACCOUNTS]
$((Get-LocalUser | Format-Table | Out-String))
[LOCAL GROUPS]
$((Get-LocalGroup | Format-Table | Out-String))
[RUNNING PROCESSES]
$((Get-Process | Format-Table | Out-String))
[SERVICES]
$((Get-Service | Format-Table | Out-String))
[NETWORK CONNECTIONS]
$((Get-NetTCPConnection | Format-Table | Out-String))
"@
$report | Out-File "full_report_$(Get-Date -Format 'yyyyMMdd').txt"
ADVANCED
5 COMMANDS Β· ADVANCED TECHNIQUES β AUTHORISED USE ONLY
Dump Cached Credentials
β ADMIN
π΄ Advanced
β οΈ Requires Administrator privileges
πͺ Command Prompt (CMD)
reg query "HKLM\SECURITY\Cache"
π» PowerShell
reg query "HKLM\SECURITY\Cache"
Show PowerShell History
π‘ Intermediate
πͺ Command Prompt (CMD)
type %APPDATA%\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt
π» PowerShell
Get-Content (Get-PSReadLineOption).HistorySavePath
Show Browser History (Chrome)
π΄ Advanced
πͺ Command Prompt (CMD)
type "%LOCALAPPDATA%\Google\Chrome\User Data\Default\History"
π» PowerShell
# Chrome stores history in SQLite - use external tool to read
Write-Host "Chrome history located at: $env:LOCALAPPDATA\Google\Chrome\User Data\Default\History"
Export Registry Key
π΄ Advanced
πͺ Command Prompt (CMD)
reg export HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion backup.reg
π» PowerShell
reg export HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion backup.reg
Show Shadow Copies
π΄ Advanced
πͺ Command Prompt (CMD)
vssadmin list shadows
π» PowerShell
Get-CimInstance Win32_ShadowCopy | Select-Object InstallDate, VolumeName, DeviceObject