Whenever a user runs a command using Powershell, it gets stored into a file that keeps a memory of past commands. This is useful for repeating commands you have used before quickly. If a user runs a command that includes a password directly as part of the Powershell command line, it can later be retrieved by using the following command from a cmd.exe Promp
type %userprofile%\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txt
The command above will only work from cmd.exe, as Powershell won't recognize %userprofile%
as an environment variable. To read the file from Powershell, you'd have to replace %userprofile%
with $Env:userprofile
.