Built-in Windows commands for post-exploitation situational awareness. These require no external tools — they work on any Windows system, are less likely to trigger application whitelisting, and map directly to MITRE ATT&CK Discovery techniques.
Network and system identity
Command
Purpose
MITRE ATT&CK
arp -a
Display the ARP cache — reveals other machines on the local network segment
sc conflicts with the PowerShell Set-Content alias. Use sc.exe in PowerShell, or run from cmd.exe.
Commands prefixed with /domain require the machine to be domain-joined and the current user to have domain read access (any authenticated user by default).
These are the minimum viable recon — supplement with PowerShell equivalents (Get-LocalUser, Get-LocalGroup, Get-Service, etc.) and dedicated tools like PowerView for deeper AD enumeration.
Defense perspective
These commands are ubiquitous and low-noise, making detection difficult. However:
Sysmon event 1 (process creation) logs command lines — forward to SIEM and alert on recon patterns (whoami /priv, net group "Domain Admins")
Baseline normal admin activity; alert on recon commands from unexpected accounts or machines