PRIMARY CATEGORY → CHECKLISTS   •   WINDOWS PRIVESC

Mindmap

Windows Privesc Mindmap

Zoom in


Non-Privileged

e.g. Network Interfaces, ARP Table, Routing Table…

e.g. HTTP ↔ 8000 TCP Port ( 127.0.0.1:8080 )

See the point below

e.g. A Webapp with an Upload Feature → Uploaded files not accesible externally ( e.g. C:\Windows\Tasks\Uploads ) → Current user with WRITE Privileges over the Uploads directory → Junction ( Windows Symlink ) creation pointing to the webroot → Uploaded resources accesible externally

See Media from HTB

From LOCAL SERVICE or NETWORK SERVICE to LOCAL SYSTEM

   RoguePotatoRottenPotatoJuicyPotatoPrintSpoofer

e.g. seDebug, seBackup, seLoadDriver, seTcb and so on

e.g. A local user account named Alex which belongs to Backup Operators

e.g. MRemoteNG

   SherlockWindows Exploit Suggester

   NetexecImpacket’s REG.pyGet-GPPAutologon

e.g. Resources containing juicy strings such as “pass|password|passwd” and so on

See also Other Interesting Files and Unattended Installation Files

e.g. Cookies, Saved Logins…

See DPAPI Abuse

  • Look for system directories for which the current user has WRITE Permissions

Accesschk.exe


Pillaging

   Impacket’s Secretsdump.pyMimikatzNetexec

See DPAPI Abuse

e.g. Browser Credentials

   Impacket’s Secretsdump.py + ( Hashcat + John )

As we have access to the entire system ( Privileged Access )

e.g. Files with Sensitive Information, Unattended Installation Files, All PS History Files

Credentials for all system users