NETSH
Windows Network Shell (netsh.exe). Configure network interfaces, firewall, routing, and more.
INTERFACE CONFIGURATION#
VIEW INTERFACES#
netsh interface show interface # List interfaces netsh interface ip show config # IP configuration netsh interface ip show addresses # IP addresses netsh interface ip show dnsservers # DNS servers netsh interface ip show wins # WINS servers
IP CONFIGURATION#
# Set static IP netsh interface ip set address "Ethernet" static 192.168.1.100 255.255.255.0 192.168.1.1 # Set DNS netsh interface ip set dns "Ethernet" static 8.8.8.8 netsh interface ip add dns "Ethernet" 8.8.4.4 index=2 # Enable DHCP netsh interface ip set address "Ethernet" dhcp netsh interface ip set dns "Ethernet" dhcp # Add secondary IP netsh interface ip add address "Ethernet" 192.168.1.101 255.255.255.0
ENABLE/DISABLE INTERFACE#
netsh interface set interface "Ethernet" disabled netsh interface set interface "Ethernet" enabled
WIRELESS (WLAN)#
netsh wlan show profiles # Saved networks netsh wlan show profile name="SSID" # Profile details netsh wlan show profile name="SSID" key=clear # Show password! netsh wlan show networks # Available networks netsh wlan show networks mode=bssid # Detailed scan netsh wlan show interfaces # Wireless interface info netsh wlan show drivers # Wireless driver info # Connect/disconnect netsh wlan connect name="SSID" # Connect to network netsh wlan disconnect # Disconnect # Delete profile netsh wlan delete profile name="SSID" netsh wlan delete profile name=* i=* # Delete all profiles # Export/import profile netsh wlan export profile name="SSID" folder=C:\ netsh wlan add profile filename="profile.xml"
FIREWALL#
STATUS#
netsh advfirewall show allprofiles # All firewall status netsh advfirewall show currentprofile netsh advfirewall show domainprofile netsh advfirewall show privateprofile netsh advfirewall show publicprofile
ENABLE/DISABLE#
netsh advfirewall set allprofiles state on netsh advfirewall set allprofiles state off netsh advfirewall set domainprofile state on netsh advfirewall set privateprofile state off
DEFAULT ACTIONS#
netsh advfirewall set allprofiles firewallpolicy blockinbound,allowoutbound netsh advfirewall set allprofiles firewallpolicy allowinbound,allowoutbound
FIREWALL RULES#
# List rules
netsh advfirewall firewall show rule name=all
netsh advfirewall firewall show rule name="Rule Name"
netsh advfirewall firewall show rule name=all dir=in
netsh advfirewall firewall show rule name=all dir=out
# Add rules
netsh advfirewall firewall add rule name="Allow Port 80" dir=in action=allow protocol=tcp localport=80
netsh advfirewall firewall add rule name="Block IP" dir=in action=block remoteip=192.168.1.100
netsh advfirewall firewall add rule name="Allow App" dir=in action=allow program="C:\app.exe"
netsh advfirewall firewall add rule name="Allow Ping" dir=in action=allow protocol=icmpv4
# Full rule syntax
netsh advfirewall firewall add rule ^
name="Rule Name" ^
dir=in ^
action=allow ^
protocol=tcp ^
localport=443 ^
remoteip=192.168.1.0/24 ^
profile=domain,private ^
enable=yes
# Delete rules
netsh advfirewall firewall delete rule name="Rule Name"
netsh advfirewall firewall delete rule name=all dir=in protocol=tcp localport=80
# Modify rules
netsh advfirewall firewall set rule name="Rule Name" new enable=no
netsh advfirewall firewall set rule name="Rule Name" new action=block
EXPORT/IMPORT FIREWALL#
netsh advfirewall export "C:\firewall.wfw" netsh advfirewall import "C:\firewall.wfw" netsh advfirewall reset # Reset to defaults
LOGGING#
netsh advfirewall set allprofiles logging filename="C:\fw.log" netsh advfirewall set allprofiles logging maxfilesize=4096 netsh advfirewall set allprofiles logging droppedconnections=enable netsh advfirewall set allprofiles logging allowedconnections=enable
ROUTING#
netsh interface ip show route # Show routing table netsh interface ip add route 10.0.0.0/8 "Ethernet" 192.168.1.1 netsh interface ip delete route 10.0.0.0/8 "Ethernet" # Persistent routes route add 10.0.0.0 mask 255.0.0.0 192.168.1.1 -p route delete 10.0.0.0
PORT PROXY#
# Forward local port to remote netsh interface portproxy add v4tov4 listenport=80 listenaddress=0.0.0.0 connectport=8080 connectaddress=192.168.1.100 # List port proxies netsh interface portproxy show all netsh interface portproxy show v4tov4 # Delete port proxy netsh interface portproxy delete v4tov4 listenport=80 listenaddress=0.0.0.0 # Reset all port proxies netsh interface portproxy reset
IPSEC#
netsh ipsec static show all # Show IPsec policies netsh ipsec dynamic show all # Dynamic policies
WINHTTP PROXY#
netsh winhttp show proxy # Show proxy settings netsh winhttp set proxy proxy.example.com:8080 netsh winhttp set proxy proxy.example.com:8080 bypass-list="*.local;192.168.*" netsh winhttp reset proxy # Clear proxy netsh winhttp import proxy source=ie # Import from IE
DNS CLIENT#
netsh interface ip show dnsservers # Show DNS servers netsh interface ip set dnsservers "Ethernet" static 8.8.8.8 primary netsh interface ip add dnsservers "Ethernet" 8.8.4.4 index=2 # Flush DNS (alternative to ipconfig /flushdns) netsh interface ip delete dnscache
DHCP CLIENT#
netsh dhcp show server # Show DHCP servers netsh dhcp server show scope # Show scopes
HTTP#
# SSL certificate bindings
netsh http show sslcert # Show SSL bindings
netsh http show urlacl # Show URL reservations
netsh http add sslcert ipport=0.0.0.0:443 certhash=... appid={...}
netsh http delete sslcert ipport=0.0.0.0:443
WINSOCK#
netsh winsock show catalog # Show Winsock catalog netsh winsock reset # Reset Winsock (fixes network issues)
DIAGNOSTIC#
netsh interface ip show tcpstats # TCP statistics netsh interface ip show udpstats # UDP statistics netsh interface ip show icmpstats # ICMP statistics
TRACE#
# Network tracing netsh trace start capture=yes tracefile=C:\trace.etl netsh trace stop # With filters netsh trace start capture=yes IPv4.Address=192.168.1.100 netsh trace start capture=yes Protocol=TCP # Convert trace netsh trace convert input=trace.etl output=trace.txt
DUMP & EXEC#
netsh dump # Dump current config netsh dump > config.txt # Save config to file netsh exec config.txt # Execute config file
CONTEXT NAVIGATION#
netsh interface # Enter interface context netsh interface ip # Enter interface ip context netsh advfirewall # Enter firewall context netsh> # Interactive mode exit # Exit interactive mode ? # Help in current context
REMOTE EXECUTION#
netsh -r RemoteComputer command netsh -r RemoteComputer -u Domain\User -p Password command
USEFUL COMMANDS#
# Show all network config
netsh interface ip show config
# Reset TCP/IP stack
netsh int ip reset
# Reset firewall
netsh advfirewall reset
# Show WiFi password
netsh wlan show profile name="NetworkName" key=clear
# Enable all interfaces
for /f "tokens=*" %i in ('netsh interface show interface ^| findstr Disabled') do netsh interface set interface "%i" enabled
# Block all incoming except established
netsh advfirewall set allprofiles firewallpolicy blockinbound,allowoutbound
SECURITY USES#
# Create port forward for pivoting
netsh interface portproxy add v4tov4 listenport=4444 listenaddress=0.0.0.0 connectport=4444 connectaddress=10.10.10.100
# Open firewall for reverse shell
netsh advfirewall firewall add rule name="Allow" dir=in action=allow protocol=tcp localport=4444
# Disable firewall completely
netsh advfirewall set allprofiles state off
# Extract WiFi passwords
for /f "tokens=2 delims=:" %a in ('netsh wlan show profile ^| findstr Profile') do @netsh wlan show profile name=%a key=clear | findstr Key
QUICK REFERENCE#
# Interface netsh interface show interface netsh interface ip show config netsh interface ip set address "Ethernet" dhcp # Wireless netsh wlan show profiles netsh wlan show profile name="SSID" key=clear # Firewall netsh advfirewall show allprofiles netsh advfirewall set allprofiles state on/off netsh advfirewall firewall add rule name="Name" dir=in action=allow protocol=tcp localport=80 netsh advfirewall firewall delete rule name="Name" # Port proxy netsh interface portproxy add v4tov4 listenport=80 connectport=8080 connectaddress=IP netsh interface portproxy show all # Reset netsh winsock reset netsh int ip reset netsh advfirewall reset
NETSH CHEATSHEET
================
Source: https://cheatsheet.johlem.net
Windows Network Shell (netsh.exe).
Configure network interfaces, firewall, routing, and more.
INTERFACE CONFIGURATION
=======================
VIEW INTERFACES
---------------
netsh interface show interface # List interfaces
netsh interface ip show config # IP configuration
netsh interface ip show addresses # IP addresses
netsh interface ip show dnsservers # DNS servers
netsh interface ip show wins # WINS servers
IP CONFIGURATION
----------------
# Set static IP
netsh interface ip set address "Ethernet" static 192.168.1.100 255.255.255.0 192.168.1.1
# Set DNS
netsh interface ip set dns "Ethernet" static 8.8.8.8
netsh interface ip add dns "Ethernet" 8.8.4.4 index=2
# Enable DHCP
netsh interface ip set address "Ethernet" dhcp
netsh interface ip set dns "Ethernet" dhcp
# Add secondary IP
netsh interface ip add address "Ethernet" 192.168.1.101 255.255.255.0
ENABLE/DISABLE INTERFACE
------------------------
netsh interface set interface "Ethernet" disabled
netsh interface set interface "Ethernet" enabled
WIRELESS (WLAN)
===============
netsh wlan show profiles # Saved networks
netsh wlan show profile name="SSID" # Profile details
netsh wlan show profile name="SSID" key=clear # Show password!
netsh wlan show networks # Available networks
netsh wlan show networks mode=bssid # Detailed scan
netsh wlan show interfaces # Wireless interface info
netsh wlan show drivers # Wireless driver info
# Connect/disconnect
netsh wlan connect name="SSID" # Connect to network
netsh wlan disconnect # Disconnect
# Delete profile
netsh wlan delete profile name="SSID"
netsh wlan delete profile name=* i=* # Delete all profiles
# Export/import profile
netsh wlan export profile name="SSID" folder=C:\
netsh wlan add profile filename="profile.xml"
FIREWALL
========
STATUS
------
netsh advfirewall show allprofiles # All firewall status
netsh advfirewall show currentprofile
netsh advfirewall show domainprofile
netsh advfirewall show privateprofile
netsh advfirewall show publicprofile
ENABLE/DISABLE
--------------
netsh advfirewall set allprofiles state on
netsh advfirewall set allprofiles state off
netsh advfirewall set domainprofile state on
netsh advfirewall set privateprofile state off
DEFAULT ACTIONS
---------------
netsh advfirewall set allprofiles firewallpolicy blockinbound,allowoutbound
netsh advfirewall set allprofiles firewallpolicy allowinbound,allowoutbound
FIREWALL RULES
--------------
# List rules
netsh advfirewall firewall show rule name=all
netsh advfirewall firewall show rule name="Rule Name"
netsh advfirewall firewall show rule name=all dir=in
netsh advfirewall firewall show rule name=all dir=out
# Add rules
netsh advfirewall firewall add rule name="Allow Port 80" dir=in action=allow protocol=tcp localport=80
netsh advfirewall firewall add rule name="Block IP" dir=in action=block remoteip=192.168.1.100
netsh advfirewall firewall add rule name="Allow App" dir=in action=allow program="C:\app.exe"
netsh advfirewall firewall add rule name="Allow Ping" dir=in action=allow protocol=icmpv4
# Full rule syntax
netsh advfirewall firewall add rule ^
name="Rule Name" ^
dir=in ^
action=allow ^
protocol=tcp ^
localport=443 ^
remoteip=192.168.1.0/24 ^
profile=domain,private ^
enable=yes
# Delete rules
netsh advfirewall firewall delete rule name="Rule Name"
netsh advfirewall firewall delete rule name=all dir=in protocol=tcp localport=80
# Modify rules
netsh advfirewall firewall set rule name="Rule Name" new enable=no
netsh advfirewall firewall set rule name="Rule Name" new action=block
EXPORT/IMPORT FIREWALL
----------------------
netsh advfirewall export "C:\firewall.wfw"
netsh advfirewall import "C:\firewall.wfw"
netsh advfirewall reset # Reset to defaults
LOGGING
-------
netsh advfirewall set allprofiles logging filename="C:\fw.log"
netsh advfirewall set allprofiles logging maxfilesize=4096
netsh advfirewall set allprofiles logging droppedconnections=enable
netsh advfirewall set allprofiles logging allowedconnections=enable
ROUTING
=======
netsh interface ip show route # Show routing table
netsh interface ip add route 10.0.0.0/8 "Ethernet" 192.168.1.1
netsh interface ip delete route 10.0.0.0/8 "Ethernet"
# Persistent routes
route add 10.0.0.0 mask 255.0.0.0 192.168.1.1 -p
route delete 10.0.0.0
PORT PROXY
==========
# Forward local port to remote
netsh interface portproxy add v4tov4 listenport=80 listenaddress=0.0.0.0 connectport=8080 connectaddress=192.168.1.100
# List port proxies
netsh interface portproxy show all
netsh interface portproxy show v4tov4
# Delete port proxy
netsh interface portproxy delete v4tov4 listenport=80 listenaddress=0.0.0.0
# Reset all port proxies
netsh interface portproxy reset
IPSEC
=====
netsh ipsec static show all # Show IPsec policies
netsh ipsec dynamic show all # Dynamic policies
WINHTTP PROXY
=============
netsh winhttp show proxy # Show proxy settings
netsh winhttp set proxy proxy.example.com:8080
netsh winhttp set proxy proxy.example.com:8080 bypass-list="*.local;192.168.*"
netsh winhttp reset proxy # Clear proxy
netsh winhttp import proxy source=ie # Import from IE
DNS CLIENT
==========
netsh interface ip show dnsservers # Show DNS servers
netsh interface ip set dnsservers "Ethernet" static 8.8.8.8 primary
netsh interface ip add dnsservers "Ethernet" 8.8.4.4 index=2
# Flush DNS (alternative to ipconfig /flushdns)
netsh interface ip delete dnscache
DHCP CLIENT
===========
netsh dhcp show server # Show DHCP servers
netsh dhcp server show scope # Show scopes
HTTP
====
# SSL certificate bindings
netsh http show sslcert # Show SSL bindings
netsh http show urlacl # Show URL reservations
netsh http add sslcert ipport=0.0.0.0:443 certhash=... appid={...}
netsh http delete sslcert ipport=0.0.0.0:443
WINSOCK
=======
netsh winsock show catalog # Show Winsock catalog
netsh winsock reset # Reset Winsock (fixes network issues)
DIAGNOSTIC
==========
netsh interface ip show tcpstats # TCP statistics
netsh interface ip show udpstats # UDP statistics
netsh interface ip show icmpstats # ICMP statistics
TRACE
=====
# Network tracing
netsh trace start capture=yes tracefile=C:\trace.etl
netsh trace stop
# With filters
netsh trace start capture=yes IPv4.Address=192.168.1.100
netsh trace start capture=yes Protocol=TCP
# Convert trace
netsh trace convert input=trace.etl output=trace.txt
DUMP & EXEC
===========
netsh dump # Dump current config
netsh dump > config.txt # Save config to file
netsh exec config.txt # Execute config file
CONTEXT NAVIGATION
==================
netsh interface # Enter interface context
netsh interface ip # Enter interface ip context
netsh advfirewall # Enter firewall context
netsh> # Interactive mode
exit # Exit interactive mode
? # Help in current context
REMOTE EXECUTION
================
netsh -r RemoteComputer command
netsh -r RemoteComputer -u Domain\User -p Password command
USEFUL COMMANDS
===============
# Show all network config
netsh interface ip show config
# Reset TCP/IP stack
netsh int ip reset
# Reset firewall
netsh advfirewall reset
# Show WiFi password
netsh wlan show profile name="NetworkName" key=clear
# Enable all interfaces
for /f "tokens=*" %i in ('netsh interface show interface ^| findstr Disabled') do netsh interface set interface "%i" enabled
# Block all incoming except established
netsh advfirewall set allprofiles firewallpolicy blockinbound,allowoutbound
SECURITY USES
=============
# Create port forward for pivoting
netsh interface portproxy add v4tov4 listenport=4444 listenaddress=0.0.0.0 connectport=4444 connectaddress=10.10.10.100
# Open firewall for reverse shell
netsh advfirewall firewall add rule name="Allow" dir=in action=allow protocol=tcp localport=4444
# Disable firewall completely
netsh advfirewall set allprofiles state off
# Extract WiFi passwords
for /f "tokens=2 delims=:" %a in ('netsh wlan show profile ^| findstr Profile') do @netsh wlan show profile name=%a key=clear | findstr Key
QUICK REFERENCE
---------------
# Interface
netsh interface show interface
netsh interface ip show config
netsh interface ip set address "Ethernet" dhcp
# Wireless
netsh wlan show profiles
netsh wlan show profile name="SSID" key=clear
# Firewall
netsh advfirewall show allprofiles
netsh advfirewall set allprofiles state on/off
netsh advfirewall firewall add rule name="Name" dir=in action=allow protocol=tcp localport=80
netsh advfirewall firewall delete rule name="Name"
# Port proxy
netsh interface portproxy add v4tov4 listenport=80 connectport=8080 connectaddress=IP
netsh interface portproxy show all
# Reset
netsh winsock reset
netsh int ip reset
netsh advfirewall reset
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.