Enumeration
- 기본정보 탐색
systeminfo
// os name, os version, bit
systeminfo | findstr /B /C:"OS Name" /C:"OS Version" /C:"System Type"
whoami /priv
whoami /groups
netstat -ano
Procdump
https://docs.microsoft.com/en-us/sysinternals/downloads/procdump
get-process
./procdump64.exe -ma 1528 firefox.dmp // 1528 = Process ID, -ma = Full dump