Enumerate with GPOs
# import PowerView
Import-Module ..\PowerView.ps1
# domain Kerberos settings
$Settings = Get-DomainPolicyData -Policy 'Domain'
$Settings.KerberosPolicy
# who has SeEnableDelegationPrivilege over the DC
$Settings = Get-DomainPolicyData -Policy 'DomainController'
$Settings.PrivilegeRights
# what GPOs are applied to the domain controller
$DomainController = (Get-DomainController).Name
Get-DomainGPO -ComputerIdentity $DomainController
# enumerate all GptTmpl.inf settings for GPOs in the domain
Get-DomainGPO | Get-DomainPolicyData
# find any GPOs that modify local group memberships through GPOs
Get-DomainGPOLocalGroup
# to find what machines an "interesting" GPO applies to
Get-DomainGPO WorkstationGPO | %{Get-DomainOU -GPLink $_.Name} | % {Get-DomainComputer -SearchBase $_.distinguishedname -Properties dnshostname}
Get-DomainGPO ServerGPO | %{Get-DomainOU -GPLink $_.Name} | % {Get-DomainComputer -SearchBase $_.distinguishedname -Properties dnshostname}Last updated