UNSORTED/MICROSOFT/unsort
UNSORTED/MICROSOFT/PowerShell
PowerShell
Get the list of the services
get-service
change the type of startup of a specific service (here lanmanserver)
get-service lanmanserver|set-service -startuptype disable
Change the previous information from the AD controller (ex. on my <VM_HOSTNAME>)
set-service -Name lanmanserver -Computer <VM_HOSTNAME>.Name -startup automatic
Looks for informations about a computer
Get-ADComputer -Filter 'name -like "<VM_HOSTNAME>"'
Get-Service -Name bits -ComputerName <VM_HOSTNAME> | Set-Service -Status Running
Start-Process powershell -Verb runAs
Invoke-Command -credential (get-credential) dc-g1 -scriptblock {$script}
netdom RENAMECOMPUTER <SOURCE_HOSTNAME> /newname:<TARGET_HOSTNAME> /userd:administrateur /passwordd:* /FORCE
Enable psremoting
Enable-PSRemoting -force
Enable c$
REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\system /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f
netsh advfirewall firewall add rule name="ICMP Allow incoming V4 echo request" protocol=icmpv4:8,any dir=in action=allow
dism /online /get-packages | clip
or
wmic qfe list full /format:table
or (html export)
wmic qfe list full /format:htable >D:\hotfixes.htm
or specific kb
wmic qfe list full /format:table | findstr /i "50000802"
wmic qfe list full /format:table | findstr /i "50000808"
wmic qfe list full /format:table | findstr /i "50000809"
wmic qfe list full /format:table | findstr /i "50000822"
Get-Aduser -Filter * -Properties *|select name,SamAccountName,PasswordExpired,PasswordLastSet,LastLogonDate,Enabled,DistinguishedName,DisplayName,GivenName,SurName|export-csv C:\output.csv
Get-Content -Path <file>
REG add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\system /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /fle
forfiles /S /M * /C "cmd /c if @fsize GEQ 104857600 echo @path"