)
提示下面全部文本直接全选复制粘贴到 Microsoft Word 里即可自动生成文档可自行调整字体、标题、代码样式。⚠️ 重要声明仅限合法授权的内网运维或安全评估使用。部分命令需要管理员权限域相关命令需加 /domain 或提前安装 RSAT/AD 工具。示例中的 domain、host、user、IP 请替换为实际环境值。1. 系统与主机信息cmdwhoami /allhostnamesysteminfoverwmic os get Caption,Version,BuildNumber,OSArchitecturewmic computersystem get Name,Domain,Manufacturer,Model,TotalPhysicalMemorywmic qfe list brief /format:tabledriverquery /vwmic logicaldisk get Caption,Size,FreeSpace,FileSystem2. 网络与连通性cmdipconfig /allipconfig /displaydnsroute printarp -anetstat -anonetstat -ano | findstr LISTENINGnetstat -ano | findstr ESTABLISHEDping hosttracert hostpathping hostnslookup domainnslookup -typeSRV _ldap._tcp.dc._msdcs.domainnbtstat -A IPnetsh interface ip show confignetsh winhttp show proxy3. 用户、组、登录会话cmdnet usernet user user /domainnet localgroup administratorsnet group Domain Admins /domainnet group Domain Computers /domainnet accounts /domainnet config workstationnet time /domainquery userquserqwinstaklistcmdkey /listwhoami /groups4. 域与 AD 查询cmdnltest /dclist:domainnltest /dsgetdc:domainnltest /domain_trustsnetdom query dcnetdom query fsmodsquery user -limit 0dsquery computer -limit 0dsquery group -limit 0setspn -Q */*gpresult /rgpupdate /force5. 共享、会话、SMBcmdnet sharenet viewnet view /domainnet view \\hostnet usenet sessionnet statistics workstationwmic share get Name,Path,Status6. 进程、服务、启动项、计划任务cmdtasklist /svctasklist /vtasklist /msc query state allsc qc ServiceNamewmic service get Name,DisplayName,State,StartMode,PathNamewmic process get Name,ProcessId,ExecutablePath,CommandLinewmic startup get Caption,Command,Location,Userschtasks /query /fo LIST /vreg query HKLM\Software\Microsoft\Windows\CurrentVersion\Runreg query HKCU\Software\Microsoft\Windows\CurrentVersion\Run7. 防火墙、远程桌面、端口转发cmdnetsh advfirewall show allprofilesnetsh advfirewall firewall show rule nameallnetsh interface portproxy show allreg query HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server /v fDenyTSConnectionsmstsc /v:hostwinrs -r:host cmdpowershell -c Test-NetConnection host -Port 808. 日志、审计、时间cmdwevtutil qe Security /f:text /c:10wevtutil qe System /f:text /c:10auditpol /get /category:*w32tm /query /statusw32tm /monitor9. 文件与复制cmddir /a /stree /ftype filefindstr /s /i keyword *.*copy source destxcopy source dest /E /H /Krobocopy source dest /E /COPYALLcertutil -hashfile file SHA25610. CMD 中调用 PowerShell 辅助cmdpowershell -c Get-ADUser -Filter *powershell -c Get-ADComputer -Filter *powershell -c Get-ADGroupMember Domain Adminspowershell -c Get-ADDomainController -Filter *powershell -c Get-WmiObject Win32_Servicepowershell -c Get-NetTCPConnection常用组合速查cmdwhoami /all hostname systeminfoipconfig /all route print arp -a netstat -anonet user net localgroup administrators net share net viewtasklist /svc sc query state all schtasks /query /fo LIST /vwmic qfe list brief netsh advfirewall show allprofiles重要备注不要用于未授权环境凭据抓取、漏洞利用、未授权横向移动等不在本列表范围内。