{"id":7276,"date":"2023-09-01T03:25:02","date_gmt":"2023-09-01T03:25:02","guid":{"rendered":"https:\/\/pariswells.com\/blog\/?p=7276"},"modified":"2024-01-24T23:12:43","modified_gmt":"2024-01-24T23:12:43","slug":"powershell-script-to-get-all-active-local-administrators-on-the-pc","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc","title":{"rendered":"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Get Local Admins<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code lang=\"powershell\" class=\"language-powershell\">\n#Check is Machine in Azure AD as LAPs Azure AD only works in Domain Joined Mchines\n\n$subKey = Get-Item \"HKLM:\/SYSTEM\/CurrentControlSet\/Control\/CloudDomainJoin\/JoinInfo\"\n\n$guids = $subKey.GetSubKeyNames()\nforeach($guid in $guids) {\n$guidSubKey = $subKey.OpenSubKey($guid);\n$tenantId = $guidSubKey.GetValue(\"TenantId\");\n}\n\nif ($tenantId -ne $null) {\n\n\t# get the list of user names that are member of the Administrators group\n\t# we can't use Get-LocalGroupMember due to bug https:\/\/github.com\/PowerShell\/PowerShell\/issues\/2996\n\t# remove empty and non usable lines of the output\n\n\n\n\t$adminlist = (net localgroup Administrators) | Where-Object { $_ -match '\\S' } | Select-Object -Skip 4 | Select-Object -SkipLast 1\n\n\t# now filter away the domain members you do not want to be listed  by finding items without \\\n\n\t$Regexes = '^[^\\\\]+$'\n\t$localAdmins = ($adminlist | Select-String -Pattern $Regexes).Line\n\n\t# now filter away the allow local admins \n\n\t$localadminallow = \"palocaladmin\" \n\t$localAdmins = $localAdmins | Where-Object { $localadminallow -ne $_ }\n\n\n\t#Get just the Active local Admins \n\t$ActiveLocalAdmins = foreach ($admin in $localAdmins)\n\t{\n\t (Get-LocalUser -Name $admin | ? {$_.enabled -eq 'True'}).name\n\t}\n\n\n\n\tif ($ActiveLocalAdmins) {\n\tWrite-host $ActiveLocalAdmins\n\tExit 1\n\t}\n\n}\n\nelse {\n\t\n\tExit 0\n\tWrite-host \"Not In Azure AD\"\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Get Local and Domains Users in Admins<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code lang=\"powershell\" class=\"language-powershell\">\n#Check is Machine in Azure AD as LAPs Azure AD only works in Domain Joined Mchines\n\n$subKey = Get-Item \"HKLM:\/SYSTEM\/CurrentControlSet\/Control\/CloudDomainJoin\/JoinInfo\"\n\n$guids = $subKey.GetSubKeyNames()\nforeach($guid in $guids) {\n$guidSubKey = $subKey.OpenSubKey($guid);\n$tenantId = $guidSubKey.GetValue(\"TenantId\");\n}\n\nif ($tenantId -ne $null) {\n\n\t# get the list of user names that are member of the Administrators group\n\t# we can't use Get-LocalGroupMember due to bug https:\/\/github.com\/PowerShell\/PowerShell\/issues\/2996\n\t# remove empty and non usable lines of the output\n\n\t$adminlist = (net localgroup Administrators) | Where-Object { $_ -match '\\S' } | Select-Object -Skip 4 | Select-Object -SkipLast 1\n\t\n\t# now filter away accounts that have \\ for anything on the domain \n\n\t$Regexes = '^.*(\\\\).*$'\n\t$LocalDomainlAdmins = ($adminlist | Select-String -Pattern $Regexes).Line\n\t\n\t# now filter away Domain Admins \n\t$Regexes = '^((?!Domain Admins).)*$'\n\t$LocalDomainlAdmins = ($LocalDomainlAdmins | Select-String -Pattern $Regexes).Line\n\n\t# now filter away allowed Admins from list \n\t$Regexes = '(?i)^((?!mpandey|jcooper|chorton).)*$'\n\t$LocalDomainlAdmins = ($LocalDomainlAdmins | Select-String -Pattern $Regexes).Line\n\n\n\t# now filter only members without \\ for local admins\n\n\t$Regexes = '^[^\\\\]+$'\n\t$localAdmins = ($adminlist | Select-String -Pattern $Regexes).Line\n\n\t# now filter away the allowed local admins \n\n\t$Regexes = '(?i)^((?!property).)*$'\n\t$localAdmins = ($localAdmins | Select-String -Pattern $Regexes).Line\n\n\t#Get just the Active local Admins \n\t$ActiveLocalAdmins = foreach ($admin in $localAdmins)\n\t{\n\t (Get-LocalUser -Name $admin | ? {$_.enabled -eq 'True'}).name\n\t}\n\n\tif ($ActiveLocalAdmins -or $LocalDomainlAdmins ){\n\tWrite-host \"Local $ActiveLocalAdmins\" \"Domain $LocalDomainlAdmins\"\n\tExit 1\n\t}\n\n\n\n}\n\nelse {\n\t\n\tExit 0\n\tWrite-host \"Not In Azure AD\"\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Find Local Admin Logins with Defender Advanced Hunting<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code class=\"\">DeviceLogonEvents\r\n| where IsLocalAdmin == 1\r\n| project DeviceName, AccountDomain, AccountName, LogonType, ActionType\r\n| summarize count() by DeviceName, AccountName<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Get Local Admins Get Local and Domains Users in Admins Find Local Admin Logins with Defender Advanced Hunting<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-7276","post","type-post","status-publish","format-standard","hentry","category-research"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"Get Local Admins #Check is Machine in Azure AD as LAPs Azure AD only works in Domain Joined Mchines $subKey = Get-Item &quot;HKLM:\/SYSTEM\/CurrentControlSet\/Control\/CloudDomainJoin\/JoinInfo&quot; $guids = $subKey.GetSubKeyNames() foreach($guid in $guids) { $guidSubKey = $subKey.OpenSubKey($guid); $tenantId = $guidSubKey.GetValue(&quot;TenantId&quot;); } if ($tenantId -ne $null) { # get the list of user names that are member of the Administrators\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"paris\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Welcome to Pariswells.com |\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC | Welcome to Pariswells.com\" \/>\n\t\t<meta property=\"og:description\" content=\"Get Local Admins #Check is Machine in Azure AD as LAPs Azure AD only works in Domain Joined Mchines $subKey = Get-Item &quot;HKLM:\/SYSTEM\/CurrentControlSet\/Control\/CloudDomainJoin\/JoinInfo&quot; $guids = $subKey.GetSubKeyNames() foreach($guid in $guids) { $guidSubKey = $subKey.OpenSubKey($guid); $tenantId = $guidSubKey.GetValue(&quot;TenantId&quot;); } if ($tenantId -ne $null) { # get the list of user names that are member of the Administrators\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-09-01T03:25:02+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-01-24T23:12:43+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC | Welcome to Pariswells.com\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Get Local Admins #Check is Machine in Azure AD as LAPs Azure AD only works in Domain Joined Mchines $subKey = Get-Item &quot;HKLM:\/SYSTEM\/CurrentControlSet\/Control\/CloudDomainJoin\/JoinInfo&quot; $guids = $subKey.GetSubKeyNames() foreach($guid in $guids) { $guidSubKey = $subKey.OpenSubKey($guid); $tenantId = $guidSubKey.GetValue(&quot;TenantId&quot;); } if ($tenantId -ne $null) { # get the list of user names that are member of the Administrators\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/powershell-script-to-get-all-active-local-administrators-on-the-pc#article\",\"name\":\"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC | Welcome to Pariswells.com\",\"headline\":\"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC\",\"author\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/author\\\/paris#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/#organization\"},\"datePublished\":\"2023-09-01T03:25:02+00:00\",\"dateModified\":\"2024-01-24T23:12:43+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/powershell-script-to-get-all-active-local-administrators-on-the-pc#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/powershell-script-to-get-all-active-local-administrators-on-the-pc#webpage\"},\"articleSection\":\"Research\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/powershell-script-to-get-all-active-local-administrators-on-the-pc#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/pariswells.com\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/category\\\/research#listItem\",\"name\":\"Research\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/category\\\/research#listItem\",\"position\":2,\"name\":\"Research\",\"item\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/category\\\/research\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/powershell-script-to-get-all-active-local-administrators-on-the-pc#listItem\",\"name\":\"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/powershell-script-to-get-all-active-local-administrators-on-the-pc#listItem\",\"position\":3,\"name\":\"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/category\\\/research#listItem\",\"name\":\"Research\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/#organization\",\"name\":\"Welcome to Pariswells.com\",\"url\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/author\\\/paris#author\",\"url\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/author\\\/paris\",\"name\":\"paris\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/powershell-script-to-get-all-active-local-administrators-on-the-pc#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/93b8ee3f592ac401167f870452bd82d43de80152cd3524e2853403658ada9984?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"paris\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/powershell-script-to-get-all-active-local-administrators-on-the-pc#webpage\",\"url\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/powershell-script-to-get-all-active-local-administrators-on-the-pc\",\"name\":\"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC | Welcome to Pariswells.com\",\"description\":\"Get Local Admins #Check is Machine in Azure AD as LAPs Azure AD only works in Domain Joined Mchines $subKey = Get-Item \\\"HKLM:\\\/SYSTEM\\\/CurrentControlSet\\\/Control\\\/CloudDomainJoin\\\/JoinInfo\\\" $guids = $subKey.GetSubKeyNames() foreach($guid in $guids) { $guidSubKey = $subKey.OpenSubKey($guid); $tenantId = $guidSubKey.GetValue(\\\"TenantId\\\"); } if ($tenantId -ne $null) { # get the list of user names that are member of the Administrators\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/powershell-script-to-get-all-active-local-administrators-on-the-pc#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/author\\\/paris#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/author\\\/paris#author\"},\"datePublished\":\"2023-09-01T03:25:02+00:00\",\"dateModified\":\"2024-01-24T23:12:43+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/\",\"name\":\"Welcome to Pariswells.com\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC | Welcome to Pariswells.com","description":"Get Local Admins #Check is Machine in Azure AD as LAPs Azure AD only works in Domain Joined Mchines $subKey = Get-Item \"HKLM:\/SYSTEM\/CurrentControlSet\/Control\/CloudDomainJoin\/JoinInfo\" $guids = $subKey.GetSubKeyNames() foreach($guid in $guids) { $guidSubKey = $subKey.OpenSubKey($guid); $tenantId = $guidSubKey.GetValue(\"TenantId\"); } if ($tenantId -ne $null) { # get the list of user names that are member of the Administrators","canonical_url":"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc#article","name":"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC | Welcome to Pariswells.com","headline":"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC","author":{"@id":"https:\/\/pariswells.com\/blog\/author\/paris#author"},"publisher":{"@id":"https:\/\/pariswells.com\/blog\/#organization"},"datePublished":"2023-09-01T03:25:02+00:00","dateModified":"2024-01-24T23:12:43+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc#webpage"},"isPartOf":{"@id":"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc#webpage"},"articleSection":"Research"},{"@type":"BreadcrumbList","@id":"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/pariswells.com\/blog#listItem","position":1,"name":"Home","item":"https:\/\/pariswells.com\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/pariswells.com\/blog\/category\/research#listItem","name":"Research"}},{"@type":"ListItem","@id":"https:\/\/pariswells.com\/blog\/category\/research#listItem","position":2,"name":"Research","item":"https:\/\/pariswells.com\/blog\/category\/research","nextItem":{"@type":"ListItem","@id":"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc#listItem","name":"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC"},"previousItem":{"@type":"ListItem","@id":"https:\/\/pariswells.com\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc#listItem","position":3,"name":"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC","previousItem":{"@type":"ListItem","@id":"https:\/\/pariswells.com\/blog\/category\/research#listItem","name":"Research"}}]},{"@type":"Organization","@id":"https:\/\/pariswells.com\/blog\/#organization","name":"Welcome to Pariswells.com","url":"https:\/\/pariswells.com\/blog\/"},{"@type":"Person","@id":"https:\/\/pariswells.com\/blog\/author\/paris#author","url":"https:\/\/pariswells.com\/blog\/author\/paris","name":"paris","image":{"@type":"ImageObject","@id":"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/93b8ee3f592ac401167f870452bd82d43de80152cd3524e2853403658ada9984?s=96&d=mm&r=g","width":96,"height":96,"caption":"paris"}},{"@type":"WebPage","@id":"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc#webpage","url":"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc","name":"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC | Welcome to Pariswells.com","description":"Get Local Admins #Check is Machine in Azure AD as LAPs Azure AD only works in Domain Joined Mchines $subKey = Get-Item \"HKLM:\/SYSTEM\/CurrentControlSet\/Control\/CloudDomainJoin\/JoinInfo\" $guids = $subKey.GetSubKeyNames() foreach($guid in $guids) { $guidSubKey = $subKey.OpenSubKey($guid); $tenantId = $guidSubKey.GetValue(\"TenantId\"); } if ($tenantId -ne $null) { # get the list of user names that are member of the Administrators","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/pariswells.com\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc#breadcrumblist"},"author":{"@id":"https:\/\/pariswells.com\/blog\/author\/paris#author"},"creator":{"@id":"https:\/\/pariswells.com\/blog\/author\/paris#author"},"datePublished":"2023-09-01T03:25:02+00:00","dateModified":"2024-01-24T23:12:43+00:00"},{"@type":"WebSite","@id":"https:\/\/pariswells.com\/blog\/#website","url":"https:\/\/pariswells.com\/blog\/","name":"Welcome to Pariswells.com","inLanguage":"en-US","publisher":{"@id":"https:\/\/pariswells.com\/blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"Welcome to Pariswells.com |","og:type":"article","og:title":"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC | Welcome to Pariswells.com","og:description":"Get Local Admins #Check is Machine in Azure AD as LAPs Azure AD only works in Domain Joined Mchines $subKey = Get-Item &quot;HKLM:\/SYSTEM\/CurrentControlSet\/Control\/CloudDomainJoin\/JoinInfo&quot; $guids = $subKey.GetSubKeyNames() foreach($guid in $guids) { $guidSubKey = $subKey.OpenSubKey($guid); $tenantId = $guidSubKey.GetValue(&quot;TenantId&quot;); } if ($tenantId -ne $null) { # get the list of user names that are member of the Administrators","og:url":"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc","article:published_time":"2023-09-01T03:25:02+00:00","article:modified_time":"2024-01-24T23:12:43+00:00","twitter:card":"summary","twitter:title":"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC | Welcome to Pariswells.com","twitter:description":"Get Local Admins #Check is Machine in Azure AD as LAPs Azure AD only works in Domain Joined Mchines $subKey = Get-Item &quot;HKLM:\/SYSTEM\/CurrentControlSet\/Control\/CloudDomainJoin\/JoinInfo&quot; $guids = $subKey.GetSubKeyNames() foreach($guid in $guids) { $guidSubKey = $subKey.OpenSubKey($guid); $tenantId = $guidSubKey.GetValue(&quot;TenantId&quot;); } if ($tenantId -ne $null) { # get the list of user names that are member of the Administrators"},"aioseo_meta_data":{"post_id":"7276","title":null,"description":null,"keywords":[],"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":[],"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","location":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2023-09-01 03:22:27","updated":"2024-01-24 23:13:28","primary_term":null,"seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/pariswells.com\/blog\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/pariswells.com\/blog\/category\/research\" title=\"Research\">Research<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tPowershell Script or Advanced Hunting to Get All Active Local Administrators on the PC\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/pariswells.com\/blog"},{"label":"Research","link":"https:\/\/pariswells.com\/blog\/category\/research"},{"label":"Powershell Script or Advanced Hunting to Get All Active Local Administrators on the PC","link":"https:\/\/pariswells.com\/blog\/research\/powershell-script-to-get-all-active-local-administrators-on-the-pc"}],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/7276","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=7276"}],"version-history":[{"count":8,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/7276\/revisions"}],"predecessor-version":[{"id":7610,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/7276\/revisions\/7610"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=7276"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=7276"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=7276"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}