> For the complete documentation index, see [llms.txt](https://baric6.gitbook.io/barics-knowledge-base/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://baric6.gitbook.io/barics-knowledge-base/it-help/windows/sysadmin/windows-common-commands-enum.md).

# Windows common commands enum

When attackers initially gain access to a machine, they are known to run the following commands in a short period of time :

* ```
  tasklist
  ```
* ```
  ver
  ```
* ```
  ipconfig
  ```
* ```
  systeminfo
  ```
* ```
  net time
  ```
* ```
  netstat
  ```
* ```
  whoami
  ```
* ```
  net start
  ```
* ```
  qprocess
  ```
* ```
  query
  ```

After doing this, attackers then perform Recon on the wider environment using these commands :

* ```
  dir
  ```
* ```
  net view
  ```
* ```
  ping
  ```
* ```
  net use
  ```
* ```
  type
  ```
* ```
  net user
  ```
* ```
  net localgroup
  ```
* ```
  net group
  ```
* ```
  net config
  ```
* ```
  net share
  ```

After they have gained a foothold in a network and want to spread, they commonly use these commands :

* ```
  at
  ```
* ```
  reg
  ```
* ```
  wmic
  ```
* ```
  wusa
  ```
* ```
  netsh advfirewall
  ```
* ```
  sc
  ```
* ```
  rundll32
  ```
