Skip to content

Latest commit

 

History

History
140 lines (99 loc) · 10.1 KB

checklist-windows-privilege-escalation.md

File metadata and controls

140 lines (99 loc) · 10.1 KB

Checklist - Local Windows Privilege Escalation

Support HackTricks and get benefits!

Do you work in a cybersecurity company? Do you want to see your company advertised in HackTricks? or do you want to have access the latest version of the PEASS or download HackTricks in PDF? Check the SUBSCRIPTION PLANS!

Discover The PEASS Family, our collection of exclusive NFTs

Get the official PEASS & HackTricks swag

Join the 💬 Discord group or the telegram group or follow me on Twitter 🐦@carlospolopm.

Share your hacking tricks submitting PRs to the hacktricks github repo.

Best tool to look for Windows local privilege escalation vectors: WinPEAS

  • Can you write in any folder inside PATH?
  • Is there any known service binary that tries to load any non-existant DLL?
  • Can you write in any binaries folder?
  • Enumerate the network(shares, interfaces, routes, neighbours...)
  • Take a special look to network services listing on local (127.0.0.1)
  • Have you access to any handler of a process run by administrator?
  • Check if you can abuse it
Support HackTricks and get benefits!

Do you work in a cybersecurity company? Do you want to see your company advertised in HackTricks? or do you want to have access the latest version of the PEASS or download HackTricks in PDF? Check the SUBSCRIPTION PLANS!

Discover The PEASS Family, our collection of exclusive NFTs

Get the official PEASS & HackTricks swag

Join the 💬 Discord group or the telegram group or follow me on Twitter 🐦@carlospolopm.

Share your hacking tricks submitting PRs to the hacktricks github repo.