labs第二题,虚拟机(Windows Privilege Escalation - Situational Awareness - VM #1 ):
Enumerate the installed applications on CLIENTWK220 (VM #1) and find the flag.
OS{540d2424db394b675b48cb0de78a4625}
PS C:\Users\dave> Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*"
SystemComponent : 1
PSPath : Microsoft.PowerShell.Core\Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Unin
stall\Connection Manager
PSParentPath : Microsoft.PowerShell.Core\Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Unin
stall
PSChildName : Connection Manager
PSDrive : HKLM
PSProvider : Microsoft.PowerShell.Core\Registry
(default) : OS{540d2424db394b675b48cb0de78a4625}
PSPath : Microsoft.PowerShell.Core\Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninsta
ll\flag
PSParentPath : Microsoft.PowerShell.Core\Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninsta
ll
PSChildName : flag
PSDrive : HKLM
PSProvider : Microsoft.PowerShell.Core\Registry
NoRemove : 1
PSPath : Microsoft.PowerShell.Core\Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninsta
ll\WIC
PSParentPath : Microsoft.PowerShell.Core\Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninsta
ll
PSChildName : WIC
PSDrive : HKLM
PSProvider : Microsoft.PowerShell.Core\Registry