permalink: spells/useful-built-in-commands-for-windows-reconnaissance
tags:
- OS/Windows
- AttackCycle/Reconnaissance
- Application/arp
- Application/cmdkey
- Application/driverquery
- Application/hostname
- Application/net
- Application/query
- Application/reg
- OS/Windows/Services
- OS/Windows/Tasks
- Application/systeminfo
- Application/whoamiarp -a - display the ARP cache (find other machines on the network!)cmdkey /list - show saved credentialsdriverquery - list installed drivershostname - return system hostname$USERNAMEquery session - list other users who are currently logged in