Windows Privilege Escalation
Useful Tools
Tool
Description
Run PowerUp
. .\PowerUp.ps1
Invoke-AllChecksInitial Enumeration
System Information
Windows Kernel Versions
Running Processes & Services
User & Group Info
Network Info
Environment Variables
Enumerating Protections
Installed Programs
Named Pipes
Important Files
PowerShell Setup
Token Privileges (Low Hanging Fruit)
SeBackupPrivilege
Weak Permissions
Permissive File System ACLs
XAMPP Control Panel Editor Hijack
Weak Service Permissions
Service Escalation via binpath Change
Unquoted Service Path
Permissive Registry ACLs
Modifiable Registry Autorun Binary
AlwaysInstallElevated
Startup Applications
DLL Hijacking
Kernel Exploits
Enumerating Missing Patches
Notable Vulnerabilities
HiveNightmare (CVE-2021-36934)
PrintNightmare Local Priv Esc
Vulnerable Services
User Account Control (UAC) Bypass
Check UAC Status
UAC Bypass via DLL Hijacking (SystemPropertiesAdvanced.exe)
UACME
Credential Hunting
Search for Files with Passwords
Unattended Setup Files
Search Registry for Passwords
PowerShell History
Credentials in Process Command Lines
LSASS Credential Dumping
LaZagne
Additional Credential Locations
Credential Search Terms
Interacting with Users
SCF File Attack (Steal NTLMv2 Hashes)
Force SMB Authentication From a Shell
Process Command Line Monitoring
Traffic Capture
Post-Exploitation Quickwins
Add Admin & Enable RDP
Disable/Enable Group Policy
Run Executable in Background
SMB File Transfer
xfreerdp
Scheduled Tasks
Enumerate Scheduled Tasks
Exploit Writable Task Scripts
Exploit Writable Scheduled Binaries
User/Computer Description Field
LOLBAS (Living Off The Land Binaries and Scripts)
certutil - File Transfer / Encode
rundll32 - Execute DLL
CVE-2019-1388 - Windows Certificate Dialog LPE
Legacy Operating Systems
Windows Server 2008 / Windows 7
Notable Legacy Exploits
Windows Hardening Checklist
Resources
Last updated