Windows Privilege Escalation
Automation
LOLBAS (Living Off the Land Binaries, Scripts and Libraries)
OS Information
hostname
systeminfo
systeminfo | findstr "OS"
ver
[System.Environment]::OSVersion.Version
# Datetime
Get-DateFind OS Vulnerabilities
Interesting Information
Find Vulnerable Privileges
Recent Files
Running Services
Override Service Executable
Running Processes
Histories
Command History in PowerShell Console
Web Browser Hidsotries
VSS (Volume Shadow Copy Service)
Registry Keys
Sensitive Information
Find Interesting Files
Find Interesting Information in Files
Collect Emails
Open Ports
Getting All Local Users/Groups
Enumerate Users
Enumerate Groups
Set New Password for Existing User
Change Another User Password
Change File Permission
From Command-Line
From GUI
Take Ownership of a File (Administrators Group Required)
All Privs for Local Service, Network Service Account
PowerView
Sysinternals
Dump Sensitive Data from Recall
References
Last updated